Transparent Pricing

SOC + AlertMonitor.
Complete visibility, bundled in.

Every plan — every size — gets the complete AlertMonitor platform, the same analyst team, and the same level of protection. The only thing that changes is how many endpoints you have.

All prices are starting points. Complex environments may require a custom quote — contact us for a scoping call.

Every size. Every feature. No compromises. A 5-endpoint small business gets the exact same AI, the same analyst, the same Recon engine, the same HoneyBadger tripwires, the same built-in vulnerability scanner as a 250-endpoint enterprise. We built it this way on purpose.
Every plan includes all of this

One platform. Every capability. Every tier.

We don’t waterfall features down to higher tiers. A 5-endpoint Starter client and a 250-endpoint Business client run the exact same AlertMonitor platform, the same AI engines, the same analyst team. Scale = endpoints, not security.

AI Incident Engine
Enriches, correlates, and re-assesses every alert — quick-fix vs correct-fix guidance built in
Continuous Recon & Risk Scoring
Passive + active recon runs continuously against your attack surface and updates your risk score in real time
Built-in Vulnerability Scanner
Scans endpoints and network devices for CVEs, misconfigurations, and common exposures — no separate tool needed
AlertMonitor Sensor
Internal sensor deployed to your network — internal scanning, lateral movement detection, and traffic analysis run from inside your environment
Network Mapping & Blast Radius
Real-time switchport topology, wireless RF health, VPN/firewall presence — instant dependency context when an alert fires
Self-Healing Software Monitoring
Scheduled verification, automatic repair, re-test confirmation — reduces repeat incidents without manual intervention
Phishing? Outlook Add-in
SOC-grade analysis in ~8 seconds: header enrichment, domain history, attachment detonation, 0–100 risk score
HoneyBadger — Digital Tripwires
Deploy weaponized decoy files across your environment. Catch lateral movement, insider threats, and active breaches the instant they happen
Identity & Cloud Monitoring
Active Directory, Azure AD, AWS — identity anomalies, privilege escalation, and cloud misconfigs all monitored continuously
Active Threat Hunting
Human analysts proactively hunt for IOCs and attacker TTPs across your environment — not waiting for alerts to fire
Website Workflow Monitoring
Click-through workflow validation with step timing and screenshots at the exact failure point
Cisco Device Management
Cisco switches, firewalls, routers, and APs managed and backed up daily. Config restore ready at any time
One Time Share
Encrypted credential delivery with expiry and self-destruction — credentials never travel over email
Global Smart Search
Live results across every device, alert, ticket, and contact — instant access, no page navigation
Patch Management & Inventory
Full endpoint and server inventory with automated patch orchestration — no separate asset management tool
Help Desk with Device Linking
Integrated ticketing — tickets auto-link to the monitored device and identity for instant analyst context
Incident Response Coordination
When an incident fires, your dedicated analyst coordinates containment, forensics, and remediation
Compliance-Ready Reporting
HIPAA, PCI-DSS, NIST-mapped reports — ready for auditors and leadership without extra work
Weekly & Executive Reporting
Weekly threat summary plus monthly executive report — always know your security posture
Dedicated Analyst
One point of contact who knows your environment — not a rotating helpdesk queue

AutoPT (automated penetration testing) is available as a paid per-engagement add-on inside AlertMonitor — from $35 per test. View AutoPT pricing →

Managed SOC + AlertMonitor

Choose your scale

Every plan below includes every feature listed above. Pick the tier that matches your endpoint count.

Note on network devices: Cisco switches, firewalls, routers, and wireless APs are managed through the AlertMonitor Cisco Management module with daily config backups. Each tier includes a cap on monitored network devices. Large environments (250+ nodes) generate significant data volume — Enterprise plans allow for custom scoping.
SOC Starter
Solo operators & micro-businesses
$150/month
Up to 5 endpoints
Up to 3 managed network devices
AlertMonitor Sensor included
All 20 platform features included
Join the Family
Best for small business
SOC Growth
Small teams ready for full coverage
$300/month
Up to 10 endpoints
Up to 5 managed network devices
AlertMonitor Sensor included
All 20 platform features included
Join the Family
SOC Essential
Growing businesses & medical practices
$1,500/month
Up to 50 endpoints
Up to 15 managed network devices
AlertMonitor Sensor included
All 20 platform features included
Get Started
SOC Mid-Market
Growing mid-size organizations
$3,506.25/month
Up to 125 endpoints
Up to 25 managed network devices
Multiple AlertMonitor Sensors supported
All 20 platform features included
Start a Conversation
Most Popular
SOC Business
Mid-market & multi-site operations
$7,012.50/month
Up to 250 endpoints
Up to 50 managed network devices
Multiple AlertMonitor Sensors supported
All 20 platform features included
Start a Conversation
SOC Enterprise
Multi-site, co-managed & compliance-driven
Custom
250+ endpoints
Custom network device scope
Custom Sensor deployment plan
All 20 platform features included
Request a Quote
AlertMonitor Add-Ons

Optional Add-On Services

These services are billed on top of your base SOC tier and managed through the AlertMonitor platform.

Endpoint Backup

Long-term cloud backup with retention for workstations and servers. Deployed and monitored directly through the AlertMonitor platform.

$10/ endpoint / month

Billed per protected endpoint. Minimum 1 endpoint.

AutoPT — Automated Penetration Testing

On-demand automated pen tests. AutoPT builds an isolated sandbox network per engagement, deploys jump host agents for internal access, and routes through AlertMonitor Sensors when deployed. Findings surface in AlertMonitor, invoices generate automatically.

From $35/ test

Per engagement, per target. Full pipelines from $300. Volume packages available.

Full pricing & details

Project-Based Services

Scoped engagements with fixed deliverables. No subscription required — though many clients combine a pen test with ongoing SOC coverage.

Penetration Testing

Learn more
Web Application
From $3,500
OWASP Top 10 + business logic, retest included
External Network
From $5,500
External perimeter + exposed services, retest included
Full Scope (Web + Network + Cloud)
From $9,500
Comprehensive engagement across all attack surfaces, retest included

Security Awareness Training

Learn more
Group Training Session
$695 / session
Live instructor-led, up to 30 employees
Annual Training Program
From $2,500 / year
Ongoing curriculum, phishing simulation, and reporting

Incident Response Retainer

Learn more
IR Retainer
From $7,500 / year
Guaranteed rapid response for ransomware, BEC, and active breaches

Pricing FAQs

Why does every plan include every feature?

Because security doesn't scale by feature — it scales by exposure. A 5-endpoint dental office faces the same phishing, the same ransomware, the same insider threats as a 250-seat enterprise. The only thing that changes is how many endpoints you have and how much data we're processing. Withholding features from small plans would mean giving small businesses fake security, and we refuse to do that.

Why is AlertMonitor required with every SOC engagement?

Without AlertMonitor we don't have the network mapping, AI incident enrichment, or endpoint-to-network dependency context that makes our SOC response faster and more accurate than a standard MSSP. We can't give you the level of visibility and protection we promise without it — so the AlertMonitor license is included in your SOC tier price. One invoice, one number.

What does "up to X endpoints" and network device cap mean?

Endpoints are laptops, desktops, servers, and VMs under active monitoring. Network devices (Cisco switches, firewalls, APs, routers) are managed separately through the AlertMonitor Cisco Management module with daily config backups. Each tier has a network device cap because large environments generate significant monitoring data and traffic. Enterprise plans allow custom scoping for very large or multi-site deployments.

What is the AlertMonitor Sensor and why is it needed?

The AlertMonitor Sensor is a lightweight appliance or VM we deploy inside your network. Internal vulnerability scans, lateral movement detection, and traffic analysis run from this sensor — they cannot run reliably from outside your network. It is included and deployed as part of every onboarding.

Are the SOC prices monthly with no annual commitment?

We offer both month-to-month and annual agreements. Annual commitments come with a reduced rate. Month-to-month pricing as listed is available with 30-day notice to cancel.

How is your SOC different from a budget MSSP at $500–$1,200/mo?

Budget providers typically give you a dashboard and alert notifications — you still do the work. Our SOC includes AlertMonitor's AI Incident Engine, human analyst triage, active threat hunting, network mapping with blast radius, self-healing automation, and Phishing? analysis. When an alert fires, we investigate and act — not forward it to you.

Do you really offer enterprise security for businesses with just 5 or 10 endpoints?

Yes — this is the entire point. Our platform was built to serve everyone equally, not to sell watered-down security to small businesses. A SOC Starter client at $150/mo gets the full AI Incident Engine, continuous recon, vulnerability scanning, HoneyBadger tripwires, Phishing? analysis, Cisco management, a dedicated analyst, and every other capability in the platform. The only difference from an Enterprise client is the endpoint count.

Is the penetration test price all-in?

Yes. The project price includes scoping, execution, the full report (executive summary + technical findings + remediation guidance with CVSS scores), and one free retest of critical and high findings within 60 days.

Can we start with a pen test and move to Managed SOC?

Absolutely — and that's a common path. The pen test gives you a clear picture of your actual exposure. We scope the SOC coverage based on what we find, so you're not paying to monitor the wrong things.

What add-on services are available beyond the base SOC price?

AlertMonitor supports optional paid add-ons billed on top of your base SOC tier. Currently available: endpoint backup at $10/endpoint/month with long-term cloud storage, and AutoPT — automated penetration testing starting from $35 per test with full pipelines from $300. Invoices are generated automatically. Visit the AutoPT product page for the full pricing table.

Do you serve organizations outside Dallas?

Yes. Our SOC operations are fully remote — we monitor and respond nationwide. AlertMonitor deploys via managed agents that work anywhere. Physical security and on-site pen tests can be scoped for any location.

Not sure which tier fits?

A 20-minute scoping call is usually all it takes — we confirm your endpoint count, environment complexity, and SLA requirements before sending a final number.