SOC + AlertMonitor.
Complete visibility, bundled in.
Every plan — every size — gets the complete AlertMonitor platform, the same analyst team, and the same level of protection. The only thing that changes is how many endpoints you have.
All prices are starting points. Complex environments may require a custom quote — contact us for a scoping call.
One platform. Every capability. Every tier.
We don’t waterfall features down to higher tiers. A 5-endpoint Starter client and a 250-endpoint Business client run the exact same AlertMonitor platform, the same AI engines, the same analyst team. Scale = endpoints, not security.
AutoPT (automated penetration testing) is available as a paid per-engagement add-on inside AlertMonitor — from $35 per test. View AutoPT pricing →
Choose your scale
Every plan below includes every feature listed above. Pick the tier that matches your endpoint count.
Optional Add-On Services
These services are billed on top of your base SOC tier and managed through the AlertMonitor platform.
Endpoint Backup
Long-term cloud backup with retention for workstations and servers. Deployed and monitored directly through the AlertMonitor platform.
Billed per protected endpoint. Minimum 1 endpoint.
AutoPT — Automated Penetration Testing
On-demand automated pen tests. AutoPT builds an isolated sandbox network per engagement, deploys jump host agents for internal access, and routes through AlertMonitor Sensors when deployed. Findings surface in AlertMonitor, invoices generate automatically.
Per engagement, per target. Full pipelines from $300. Volume packages available.
Full pricing & detailsProject-Based Services
Scoped engagements with fixed deliverables. No subscription required — though many clients combine a pen test with ongoing SOC coverage.
Penetration Testing
Learn moreSecurity Awareness Training
Learn moreIncident Response Retainer
Learn morePricing FAQs
Why does every plan include every feature?
Because security doesn't scale by feature — it scales by exposure. A 5-endpoint dental office faces the same phishing, the same ransomware, the same insider threats as a 250-seat enterprise. The only thing that changes is how many endpoints you have and how much data we're processing. Withholding features from small plans would mean giving small businesses fake security, and we refuse to do that.
Why is AlertMonitor required with every SOC engagement?
Without AlertMonitor we don't have the network mapping, AI incident enrichment, or endpoint-to-network dependency context that makes our SOC response faster and more accurate than a standard MSSP. We can't give you the level of visibility and protection we promise without it — so the AlertMonitor license is included in your SOC tier price. One invoice, one number.
What does "up to X endpoints" and network device cap mean?
Endpoints are laptops, desktops, servers, and VMs under active monitoring. Network devices (Cisco switches, firewalls, APs, routers) are managed separately through the AlertMonitor Cisco Management module with daily config backups. Each tier has a network device cap because large environments generate significant monitoring data and traffic. Enterprise plans allow custom scoping for very large or multi-site deployments.
What is the AlertMonitor Sensor and why is it needed?
The AlertMonitor Sensor is a lightweight appliance or VM we deploy inside your network. Internal vulnerability scans, lateral movement detection, and traffic analysis run from this sensor — they cannot run reliably from outside your network. It is included and deployed as part of every onboarding.
Are the SOC prices monthly with no annual commitment?
We offer both month-to-month and annual agreements. Annual commitments come with a reduced rate. Month-to-month pricing as listed is available with 30-day notice to cancel.
How is your SOC different from a budget MSSP at $500–$1,200/mo?
Budget providers typically give you a dashboard and alert notifications — you still do the work. Our SOC includes AlertMonitor's AI Incident Engine, human analyst triage, active threat hunting, network mapping with blast radius, self-healing automation, and Phishing? analysis. When an alert fires, we investigate and act — not forward it to you.
Do you really offer enterprise security for businesses with just 5 or 10 endpoints?
Yes — this is the entire point. Our platform was built to serve everyone equally, not to sell watered-down security to small businesses. A SOC Starter client at $150/mo gets the full AI Incident Engine, continuous recon, vulnerability scanning, HoneyBadger tripwires, Phishing? analysis, Cisco management, a dedicated analyst, and every other capability in the platform. The only difference from an Enterprise client is the endpoint count.
Is the penetration test price all-in?
Yes. The project price includes scoping, execution, the full report (executive summary + technical findings + remediation guidance with CVSS scores), and one free retest of critical and high findings within 60 days.
Can we start with a pen test and move to Managed SOC?
Absolutely — and that's a common path. The pen test gives you a clear picture of your actual exposure. We scope the SOC coverage based on what we find, so you're not paying to monitor the wrong things.
What add-on services are available beyond the base SOC price?
AlertMonitor supports optional paid add-ons billed on top of your base SOC tier. Currently available: endpoint backup at $10/endpoint/month with long-term cloud storage, and AutoPT — automated penetration testing starting from $35 per test with full pipelines from $300. Invoices are generated automatically. Visit the AutoPT product page for the full pricing table.
Do you serve organizations outside Dallas?
Yes. Our SOC operations are fully remote — we monitor and respond nationwide. AlertMonitor deploys via managed agents that work anywhere. Physical security and on-site pen tests can be scoped for any location.
Not sure which tier fits?
A 20-minute scoping call is usually all it takes — we confirm your endpoint count, environment complexity, and SLA requirements before sending a final number.