Guardian MDR
Our SOC operates your tenant 24/7/365: triage within three minutes, containment under a written authority matrix, and a named shift lead you can call. Available on Professional and Enterprise.
per endpoint / month
Pricing
Guardian Sentinel is priced per protected asset and billed annually. Detection, response, threat intelligence and the full API are included at every tier — what changes is retention, automation depth and how much of the work Guardian does for you.
All prices in USD · billed annually · 30-day proof of value available on every tier
Choose a plan
Every plan includes the same sensor, the same detection engine and the same Guardian Labs intelligence. Minimum commitment is 50 protected assets on Essentials and 500 on Professional and above.
Prevention, detection and response for a lean team that needs one agent and one console, not a research project.
Minimum 50 endpoints. Cloud, identity and network modules available as add-ons.
The full Sentinel platform across endpoint, cloud, identity and network, with automation your team controls.
Minimum 500 protected assets. Volume tiers begin at 5,000 assets.
Multi-tenant governance, sovereign data residency and the controls global regulators expect to see.
Minimum 500 protected assets. Custom terms available above 25,000 assets.
Enterprise plus a Guardian SOC that watches, triages and responds on your behalf, around the clock.
Minimum 1,000 protected assets. Onboarding includes a joint runbook workshop.
Never an upsell
Security vendors have trained buyers to expect a matrix of hidden modules. These capabilities are not modules. They ship with the platform, and they are covered by the same service levels regardless of what you pay.
Analyst, administrator and read-only seats are never metered. Invite your auditors.
Adversary tracking, IOC feeds and detection content, refreshed continuously.
Telemetry from Guardian sensors is never billed by volume. No ingest tax, no sampling.
SAML 2.0, OIDC and directory provisioning at no extra cost, on every tier.
SIEM, SOAR, ITSM, identity and cloud connectors, plus a documented open API.
Board-ready posture and risk reporting generated continuously, exportable on demand.
Control mappings for SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, DORA and NIS2.
Guardian Connect, full product documentation and the detection content library.
Plan comparison
If a capability is not listed here, it is because it is included everywhere. Anything marked as an add-on is priced in the module table below.
| Capability | Essentials $6.50 |
Professional $12.90 |
Enterprise $19.50 |
Complete $27.80 |
|---|---|---|---|---|
| Detection & response | ||||
| Behavioural threat detection engine | Included | Included | Included | Included |
| Sentinel AI Analyst incident triage | — | Included | Included | Included |
| Automated response playbooks | Up to 10 | Unlimited | Unlimited | Unlimited, Guardian-operated |
| Guided threat hunting workspace | — | Included | Included | Included |
| Proactive hunting by Guardian analysts | — | — | Quarterly | Continuous |
| Attack path and blast-radius mapping | — | Included | Included | Included |
| Protected surfaces | ||||
| Endpoint: prevention, EDR, rollback | Included | Included | Included | Included |
| Cloud workload and container runtime | Add-on | Included | Included | Included |
| Cloud posture management and IaC scanning | — | Included | Included | Included |
| Identity threat detection and response | Add-on | Included | Included | Included |
| Network detection with inline blocking | — | Included | Included | Included |
| Data classification and loss prevention | — | Add-on | Included | Included |
| OT and ICS passive monitoring | — | — | Included | Included |
| Mobile (iOS, Android) threat defence | — | Add-on | Included | Included |
| Data, scale & residency | ||||
| Searchable telemetry retention | 30 days | 12 months | 36 months | 36 months |
| Cold archive retention | — | 12 months | Unlimited | Unlimited |
| Third-party log ingest | — | Metered | 1 TB/day included | 1 TB/day included |
| Regional data residency | US or EU | 9 regions | 19 regions | 19 regions |
| Customer-managed encryption keys | — | — | Included | Included |
| FedRAMP High and IL5 environments | — | — | Included | Included |
| Administration & integration | ||||
| SSO (SAML 2.0, OIDC) and SCIM provisioning | Included | Included | Included | Included |
| Role-based access control | 6 built-in roles | Custom roles | Custom roles, per-tenant | Custom roles, per-tenant |
| Multi-tenant hierarchy and delegated admin | — | 2 levels | Unlimited | Unlimited |
| REST and GraphQL API | Read-only | Read/write | Read/write, 10× rate limit | Read/write, 10× rate limit |
| Prebuilt integrations | 60+ | 400+ | 400+ | 400+ |
| Audit log export and SIEM streaming | — | Included | Included | Included |
| Support & services | ||||
| Support plan | Standard | Premium | Signature | Signature + SOC |
| Severity 1 response target | 4 hours, 8×5 | 1 hour, 24×7 | 15 minutes, 24×7 | 3 minutes, 24×7 |
| Named technical account manager | — | — | Included | Included |
| Managed detection and response (Guardian SOC) | — | Add-on | Add-on | Included |
| Pre-paid incident response hours | — | Add-on | Add-on | 40 hours / year |
| Certification seats included annually | — | 2 | 6 | 6 |
| Ransomware warranty | — | — | $1M | $3M |
| Contractual uptime SLA | 99.9% | 99.95% | 99.99% | 99.99% |
Scroll the table sideways to compare all four plans.
Add-on availability and pricing is listed below. Service levels are defined in full on the Support page, and the uptime SLA is part of the Terms of Service.
How a licence is counted
A protected asset is anything Guardian actively defends. Telemetry volume, console users, API calls and detection content are not licensable units — a design decision we made because volume-based pricing quietly punishes visibility.
Run the Guardian discovery collector for 48 hours, or export from your existing asset inventory. It counts what is actually alive, not what the CMDB believes.
One, three or five years. Multi-year terms fix the per-asset rate for the whole period, including any assets you add mid-term.
Add assets at any point at your contracted rate, invoiced pro rata from the month they are protected. No renegotiation, no penalty tier.
If your estate shrank — a divestment, a data-centre exit — the renewal is based on the new count. Committed spend does not ratchet.
Add-on modules
Add-ons attach to any base plan and are co-terminus with your subscription. Each one is a genuine capability with its own runbook — not a feature flag we removed from the base product in order to sell it back.
Our SOC operates your tenant 24/7/365: triage within three minutes, containment under a written authority matrix, and a named shift lead you can call. Available on Professional and Enterprise.
per endpoint / month
Push searchable retention beyond your plan default to 24, 36 or 84 months, with the same query latency. Frequently required for DORA, PCI DSS 4.0 and litigation-hold obligations.
per GB / month, compressed
Adds privileged-session recording, Kerberoasting and AS-REP roasting detection, on-premises Active Directory attack-path analysis and just-in-time privilege elevation with approval workflow.
per human identity / month
Agentless snapshot scanning, Kubernetes admission control, CI/CD pipeline gating, IaC policy-as-code and multi-cloud entitlement analysis across AWS, Azure, Google Cloud and Oracle Cloud.
per protected workload / month
Finished intelligence written for your sector, adversary dossiers, dark-web and credential-leak monitoring for your domains, plus scheduled time with a named Guardian Labs analyst.
per month, per organisation
Forty pre-paid hours with a one-hour engagement SLA and a named lead responder who already knows your architecture. Unused hours convert to consulting or training credit at renewal.
per year
Quarterly red-team and purple-team exercises mapped to MITRE ATT&CK, run against your live Sentinel deployment, with detection gaps converted into shipped content.
per engagement
Honeytokens, decoy credentials, fake file shares and phantom cloud keys distributed across the estate. Any interaction is a high-confidence signal with effectively zero false-positive rate.
per endpoint / month
A physically isolated Sentinel instance in a jurisdiction you nominate, operated under local personnel and clearance requirements. Used by defence, central banking and national infrastructure customers.
quoted per deployment
The real comparison
Sentinel is rarely the cheapest single line on a security budget. It is almost always the cheapest total, because it replaces a column of renewals, a column of integration work and a measurable share of analyst time.
Modelled on published list pricing for the seven most common incumbent products in that category, plus 0.6 FTE of integration and maintenance effort at a fully loaded $148,000. Your figures will differ; we will build the model with your actual renewal dates.
Pricing questions
More answers on licensing, deployment and data handling are on the full FAQ.
There is no perpetual free tier. There is a 30-day proof of value on every plan, run against your own environment with your own data and a Guardian solutions architect assigned to it. It is a full-function deployment, not a sandbox, and the telemetry you generate during the trial is retained if you convert.
Trials typically cover between 500 and 5,000 assets. If your evaluation needs to run longer than 30 days — a common request during a competitive bake-off — we extend it rather than expire you mid-test.
One endpoint, server or workstation counts as one asset. Cloud capacity is counted at 8 vCPU of concurrent protected container capacity per asset unit, averaged monthly. One monitored human identity counts as one asset. One OT device discovered by a passive sensor counts as one asset.
Service accounts, machine identities, console users, API clients and ingested telemetry are never counted. A single laptop that is also a monitored identity is billed once, as an endpoint.
No. Telemetry produced by Guardian sensors is unlimited and unmetered at every tier. We consider volume-based pricing actively harmful in security: it makes teams turn off logging precisely where visibility matters.
Third-party log ingest — firewall, proxy, SaaS audit logs you want correlated inside Sentinel — is metered on Professional and includes 1 TB per day on Enterprise and Complete. Beyond that, additional ingest is $0.14 per GB.
Yes. A common pattern is Enterprise for the regulated core — payment systems, clinical networks, trading infrastructure — and Professional for general corporate IT, all under one contract and one console with a multi-tenant hierarchy.
Blended contracts are billed per business unit and roll up to a single invoice. Volume tiers are calculated on the combined asset count, so mixing plans does not cost you discount.
New assets are protected the moment the sensor checks in — there is no licence gate that leaves a machine undefended while procurement catches up. They are invoiced pro rata from the following month at your contracted rate.
If growth pushes you past a volume threshold, the better rate applies to the whole estate at the next invoice, not just to the incremental assets.
Three-year terms are typically 12 percent below the annual rate and five-year terms around 18 percent, with the per-asset rate fixed for the whole period including assets added later. That price protection is usually worth more than the headline discount over a five-year horizon.
We do not offer a discount in exchange for a public logo, a case study or a reference commitment. Those are separate conversations and always voluntary.
Yes. Accredited educational institutions receive 40 percent off list, registered non-profits 30 percent, and public-sector buyers can transact through existing framework agreements including GSA, G-Cloud and equivalent regional vehicles.
Healthcare providers operating under public funding are assessed case by case. Talk to our public sector team or read the government and defence and education pages.
Enterprise includes a $1M warranty and Sentinel Complete a $3M warranty, covering incident response costs, forensic investigation and business interruption arising from a successful ransomware encryption event on a protected asset.
It is conditional on the deployment standard published in your contract: prevention in blocking mode, current sensor version, and containment playbooks enabled for ransomware precursors. It is a warranty on our engineering, not a substitute for cyber insurance.
We sequence the rollout against your existing renewal dates so overlap is minimised, and where the incumbent contract has more than six months to run we will discuss a deferred start or a ramped commitment rather than asking you to pay twice.
Migration tooling for policy, exclusions and detection logic is included at no cost for the major EDR and SIEM platforms. See the integrations page for the current list.
Annually in advance by default, in USD, EUR, GBP, AUD, SGD, JPY or CAD. Quarterly and monthly billing are available on Enterprise and Complete, and payment terms of net 30, 45 or 60 are standard depending on region.
Purchases through a Guardian partner or a cloud marketplace are invoiced by that party and can usually be drawn down against committed cloud spend.
Talk to sales
Give us your asset counts, your compliance obligations and your incumbent renewal dates. You will get a written proposal with the assumptions visible, a deployment plan sized to your team, and a named architect for the evaluation.
Everything you need for an internal business case, without talking to anyone.
Full platform, your data, your detections, a named architect. At the end you get a written findings report whether or not you buy — including anything we found that your current tooling missed.