Pricing

One platform, one licence, no per-module surprises

Guardian Sentinel is priced per protected asset and billed annually. Detection, response, threat intelligence and the full API are included at every tier — what changes is retention, automation depth and how much of the work Guardian does for you.

All prices in USD · billed annually · 30-day proof of value available on every tier

Choose a plan

Four ways to run Guardian Sentinel

Every plan includes the same sensor, the same detection engine and the same Guardian Labs intelligence. Minimum commitment is 50 protected assets on Essentials and 500 on Professional and above.

Essentials

Prevention, detection and response for a lean team that needs one agent and one console, not a research project.

$6.50 per endpoint
per month
Start a 30-day evaluation
  • Next-generation antivirus, EDR and device control in a single sensor
  • Behavioural ransomware prevention with one-click rollback
  • Guardian Labs intelligence feed and weekly detection content
  • 30 days of searchable telemetry retention
  • Standard support, 8×5 local business hours
  • Up to 10 automated response playbooks

Minimum 50 endpoints. Cloud, identity and network modules available as add-ons.

Enterprise

Multi-tenant governance, sovereign data residency and the controls global regulators expect to see.

$19.50 per endpoint
per month
Contact sales
  • Everything in Professional, plus data protection and OT/ICS monitoring
  • Multi-tenant hierarchy with delegated administration and per-tenant policy
  • Regional data residency, customer-managed encryption keys, FedRAMP High region
  • 36 months of searchable retention, unlimited cold archive
  • Signature support: named technical account manager, 15-minute Severity 1
  • Quarterly threat briefing from Guardian Labs and an annual value review

Minimum 500 protected assets. Custom terms available above 25,000 assets.

Sentinel Complete

Enterprise plus a Guardian SOC that watches, triages and responds on your behalf, around the clock.

$27.80 per endpoint
per month
Explore managed detection
  • Everything in Enterprise, delivered as a managed service
  • 24/7/365 Guardian SOC with a three-minute triage service level
  • Analyst-led containment on your behalf, under a written authority matrix
  • Proactive threat hunting, delivered as a monthly written report
  • 40 hours of pre-paid incident response retained annually
  • $3M ransomware warranty, subject to deployment standards

Minimum 1,000 protected assets. Onboarding includes a joint runbook workshop.

No charge for data ingest from Guardian sensors Public sector and education discounts available Multi-year terms lock the per-asset rate MSSP and partner pricing via Guardian Partners

Never an upsell

Included at every tier, from 50 endpoints to 500,000

Security vendors have trained buyers to expect a matrix of hidden modules. These capabilities are not modules. They ship with the platform, and they are covered by the same service levels regardless of what you pay.

Capabilities included on every Guardian Sentinel plan

Unlimited users

Analyst, administrator and read-only seats are never metered. Invite your auditors.

Guardian Labs intelligence

Adversary tracking, IOC feeds and detection content, refreshed continuously.

Sensor data ingest

Telemetry from Guardian sensors is never billed by volume. No ingest tax, no sampling.

SSO and SCIM

SAML 2.0, OIDC and directory provisioning at no extra cost, on every tier.

400+ integrations

SIEM, SOAR, ITSM, identity and cloud connectors, plus a documented open API.

Executive reporting

Board-ready posture and risk reporting generated continuously, exportable on demand.

Compliance evidence

Control mappings for SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, DORA and NIS2.

Community and docs

Guardian Connect, full product documentation and the detection content library.

Plan comparison

Every capability, plan by plan

If a capability is not listed here, it is because it is included everywhere. Anything marked as an add-on is priced in the module table below.

Guardian Sentinel plan comparison. Prices are per protected asset, per month, billed annually.
Capability Essentials
$6.50
Professional
$12.90
Enterprise
$19.50
Complete
$27.80
Detection & response
Behavioural threat detection engine IncludedIncludedIncludedIncluded
Sentinel AI Analyst incident triage —IncludedIncludedIncluded
Automated response playbooks Up to 10UnlimitedUnlimitedUnlimited, Guardian-operated
Guided threat hunting workspace —IncludedIncludedIncluded
Proactive hunting by Guardian analysts ——QuarterlyContinuous
Attack path and blast-radius mapping —IncludedIncludedIncluded
Protected surfaces
Endpoint: prevention, EDR, rollback IncludedIncludedIncludedIncluded
Cloud workload and container runtime Add-onIncludedIncludedIncluded
Cloud posture management and IaC scanning —IncludedIncludedIncluded
Identity threat detection and response Add-onIncludedIncludedIncluded
Network detection with inline blocking —IncludedIncludedIncluded
Data classification and loss prevention —Add-onIncludedIncluded
OT and ICS passive monitoring ——IncludedIncluded
Mobile (iOS, Android) threat defence —Add-onIncludedIncluded
Data, scale & residency
Searchable telemetry retention 30 days12 months36 months36 months
Cold archive retention —12 monthsUnlimitedUnlimited
Third-party log ingest —Metered1 TB/day included1 TB/day included
Regional data residency US or EU9 regions19 regions19 regions
Customer-managed encryption keys ——IncludedIncluded
FedRAMP High and IL5 environments ——IncludedIncluded
Administration & integration
SSO (SAML 2.0, OIDC) and SCIM provisioning IncludedIncludedIncludedIncluded
Role-based access control 6 built-in rolesCustom rolesCustom roles, per-tenantCustom roles, per-tenant
Multi-tenant hierarchy and delegated admin —2 levelsUnlimitedUnlimited
REST and GraphQL API Read-onlyRead/writeRead/write, 10× rate limitRead/write, 10× rate limit
Prebuilt integrations 60+400+400+400+
Audit log export and SIEM streaming —IncludedIncludedIncluded
Support & services
Support plan StandardPremiumSignatureSignature + SOC
Severity 1 response target 4 hours, 8×51 hour, 24×715 minutes, 24×73 minutes, 24×7
Named technical account manager ——IncludedIncluded
Managed detection and response (Guardian SOC) —Add-onAdd-onIncluded
Pre-paid incident response hours —Add-onAdd-on40 hours / year
Certification seats included annually —266
Ransomware warranty ——$1M$3M
Contractual uptime SLA 99.9%99.95%99.99%99.99%

Scroll the table sideways to compare all four plans.

Add-on availability and pricing is listed below. Service levels are defined in full on the Support page, and the uptime SLA is part of the Terms of Service.

How a licence is counted

You pay for what is protected, not for what is logged

A protected asset is anything Guardian actively defends. Telemetry volume, console users, API calls and detection content are not licensable units — a design decision we made because volume-based pricing quietly punishes visibility.

What counts as one protected asset

  • One physical or virtual endpoint, server or workstation
  • One cloud instance, or every 8 vCPU of container capacity
  • One human identity monitored for credential abuse
  • One OT asset discovered by a passive network sensor
Ephemeral workloads are averaged, not peaked Containers and autoscaled instances are billed on a monthly average of concurrent protected capacity. A traffic spike does not generate a true-up invoice.
Service accounts are free Non-human identities are monitored at no charge. We would rather see all of them than bill you into a blind spot.
licence model / protected asset units
BILLABLE Endpoints Cloud workloads Human identities OT assets 1 device = 1 unit 8 vCPU = 1 unit 1 person = 1 unit 1 discovered asset Protected asset count × plan rate NEVER BILLED Sensor telemetry volume Console and analyst seats API calls and webhooks Detection content updates Service accounts unlimited unlimited fair-use rate limits only continuous, included

Size the estate

Run the Guardian discovery collector for 48 hours, or export from your existing asset inventory. It counts what is actually alive, not what the CMDB believes.

Choose a plan and term

One, three or five years. Multi-year terms fix the per-asset rate for the whole period, including any assets you add mid-term.

Grow without repapering

Add assets at any point at your contracted rate, invoiced pro rata from the month they are protected. No renegotiation, no penalty tier.

True down at renewal

If your estate shrank — a divestment, a data-centre exit — the renewal is based on the new count. Committed spend does not ratchet.

Add-on modules

Extend a plan without changing it

Add-ons attach to any base plan and are co-terminus with your subscription. Each one is a genuine capability with its own runbook — not a feature flag we removed from the base product in order to sell it back.

Managed service from $8.40

Guardian MDR

Our SOC operates your tenant 24/7/365: triage within three minutes, containment under a written authority matrix, and a named shift lead you can call. Available on Professional and Enterprise.

per endpoint / month

Data from $0.09

Extended retention

Push searchable retention beyond your plan default to 24, 36 or 84 months, with the same query latency. Frequently required for DORA, PCI DSS 4.0 and litigation-hold obligations.

per GB / month, compressed

Identity $4.10

Identity Protection Advanced

Adds privileged-session recording, Kerberoasting and AS-REP roasting detection, on-premises Active Directory attack-path analysis and just-in-time privilege elevation with approval workflow.

per human identity / month

Cloud $9.80

Cloud Security Advanced

Agentless snapshot scanning, Kubernetes admission control, CI/CD pipeline gating, IaC policy-as-code and multi-cloud entitlement analysis across AWS, Azure, Google Cloud and Oracle Cloud.

per protected workload / month

Intelligence from $4,200

Threat Intelligence Premium

Finished intelligence written for your sector, adversary dossiers, dark-web and credential-leak monitoring for your domains, plus scheduled time with a named Guardian Labs analyst.

per month, per organisation

Response from $38,000

Incident response retainer

Forty pre-paid hours with a one-hour engagement SLA and a named lead responder who already knows your architecture. Unused hours convert to consulting or training credit at renewal.

per year

Assurance from $24,000

Adversary simulation programme

Quarterly red-team and purple-team exercises mapped to MITRE ATT&CK, run against your live Sentinel deployment, with detection gaps converted into shipped content.

per engagement

Deception $2.90

Deception grid

Honeytokens, decoy credentials, fake file shares and phantom cloud keys distributed across the estate. Any interaction is a high-confidence signal with effectively zero false-positive rate.

per endpoint / month

Sovereignty Custom

Dedicated and sovereign tenancy

A physically isolated Sentinel instance in a jurisdiction you nominate, operated under local personnel and clearance requirements. Used by defence, central banking and national infrastructure customers.

quoted per deployment

The real comparison

Compare against your stack, not against a line item

Sentinel is rarely the cheapest single line on a security budget. It is almost always the cheapest total, because it replaces a column of renewals, a column of integration work and a measurable share of analyst time.

Annual cost per 1,000 protected endpoints — representative mid-market estate
$400k $300k $200k $100k $0 $318k Seven-product stack EPP + EDR + NDR + CSPM + ITDR + DLP + SIEM overage $155k Guardian Sentinel Professional, 1,000 assets, Premium support included −51% annual

Modelled on published list pricing for the seven most common incumbent products in that category, plus 0.6 FTE of integration and maintenance effort at a fully loaded $148,000. Your figures will differ; we will build the model with your actual renewal dates.

19 → 6 Median number of security products in production, before and after consolidation Across 412 enterprise deployments
61% Median reduction in total cost of security operations per endpoint Guardian subscription fees are included in the “after” figure
7.4 mo Median payback period on the Guardian subscription Measured from first production wave
Bring your renewal calendar Most customers sequence the Guardian rollout against incumbent contract end dates so overlap never exceeds one quarter. Our commercial team will build that plan with you before you sign anything.

Pricing questions

The things buyers actually ask us

More answers on licensing, deployment and data handling are on the full FAQ.

Is there a free tier or a trial?

There is no perpetual free tier. There is a 30-day proof of value on every plan, run against your own environment with your own data and a Guardian solutions architect assigned to it. It is a full-function deployment, not a sandbox, and the telemetry you generate during the trial is retained if you convert.

Trials typically cover between 500 and 5,000 assets. If your evaluation needs to run longer than 30 days — a common request during a competitive bake-off — we extend it rather than expire you mid-test.

What exactly counts as a protected asset?

One endpoint, server or workstation counts as one asset. Cloud capacity is counted at 8 vCPU of concurrent protected container capacity per asset unit, averaged monthly. One monitored human identity counts as one asset. One OT device discovered by a passive sensor counts as one asset.

Service accounts, machine identities, console users, API clients and ingested telemetry are never counted. A single laptop that is also a monitored identity is billed once, as an endpoint.

Do you charge for data ingest like a SIEM does?

No. Telemetry produced by Guardian sensors is unlimited and unmetered at every tier. We consider volume-based pricing actively harmful in security: it makes teams turn off logging precisely where visibility matters.

Third-party log ingest — firewall, proxy, SaaS audit logs you want correlated inside Sentinel — is metered on Professional and includes 1 TB per day on Enterprise and Complete. Beyond that, additional ingest is $0.14 per GB.

Can we mix plans across the organisation?

Yes. A common pattern is Enterprise for the regulated core — payment systems, clinical networks, trading infrastructure — and Professional for general corporate IT, all under one contract and one console with a multi-tenant hierarchy.

Blended contracts are billed per business unit and roll up to a single invoice. Volume tiers are calculated on the combined asset count, so mixing plans does not cost you discount.

What happens when we grow mid-term?

New assets are protected the moment the sensor checks in — there is no licence gate that leaves a machine undefended while procurement catches up. They are invoiced pro rata from the following month at your contracted rate.

If growth pushes you past a volume threshold, the better rate applies to the whole estate at the next invoice, not just to the incremental assets.

Is there a discount for multi-year commitments?

Three-year terms are typically 12 percent below the annual rate and five-year terms around 18 percent, with the per-asset rate fixed for the whole period including assets added later. That price protection is usually worth more than the headline discount over a five-year horizon.

We do not offer a discount in exchange for a public logo, a case study or a reference commitment. Those are separate conversations and always voluntary.

Do you offer public sector, non-profit or education pricing?

Yes. Accredited educational institutions receive 40 percent off list, registered non-profits 30 percent, and public-sector buyers can transact through existing framework agreements including GSA, G-Cloud and equivalent regional vehicles.

Healthcare providers operating under public funding are assessed case by case. Talk to our public sector team or read the government and defence and education pages.

What is included in the ransomware warranty?

Enterprise includes a $1M warranty and Sentinel Complete a $3M warranty, covering incident response costs, forensic investigation and business interruption arising from a successful ransomware encryption event on a protected asset.

It is conditional on the deployment standard published in your contract: prevention in blocking mode, current sensor version, and containment playbooks enabled for ransomware precursors. It is a warranty on our engineering, not a substitute for cyber insurance.

How do you handle contract overlap with an incumbent vendor?

We sequence the rollout against your existing renewal dates so overlap is minimised, and where the incumbent contract has more than six months to run we will discuss a deferred start or a ramped commitment rather than asking you to pay twice.

Migration tooling for policy, exclusions and detection logic is included at no cost for the major EDR and SIEM platforms. See the integrations page for the current list.

How is the subscription invoiced?

Annually in advance by default, in USD, EUR, GBP, AUD, SGD, JPY or CAD. Quarterly and monthly billing are available on Enterprise and Complete, and payment terms of net 30, 45 or 60 are standard depending on region.

Purchases through a Guardian partner or a cloud marketplace are invoiced by that party and can usually be drawn down against committed cloud spend.

Talk to sales

A quote in five business days, and an honest answer sooner than that

Give us your asset counts, your compliance obligations and your incumbent renewal dates. You will get a written proposal with the assumptions visible, a deployment plan sized to your team, and a named architect for the evaluation.

  • No mandatory professional-services attach on any plan
  • Security questionnaire, SOC 2 report and DPA available before first call
  • We will tell you if a smaller plan fits — churn costs us more than upsell earns

Prefer to self-serve first?

Everything you need for an internal business case, without talking to anyone.

Run Sentinel against your own environment for 30 days

Full platform, your data, your detections, a named architect. At the end you get a written findings report whether or not you buy — including anything we found that your current tooling missed.