$10–$25 per endpoint, per month. Three tiers, the same audited core.
Pick the tier that matches the depth of coverage, patch authority, and reporting your team and your underwriters need. Every tier ships with the same Merkle-anchored audit log and the same triage agent — the difference is what the agent has authority to do on its own.
Autonomous triage and patching for teams that want the L1 queue off their hands.
$10per endpoint, per month
Triage depth
EDR and identity signals fan into the triage agent. Confidence-based closure for noise; the rest files for review.
Patch windows
Routine OS and third-party patches apply inside a single nightly window you configure at enrolment.
Incident reporting
Every triage decision appended to the audit log with agent ID, evidence, and outcome — readable end-to-end.
The most common fleet shape. Continuous triage, broader patch authority, and SLA-bound escalations.
$17per endpoint, per month
Triage depth
EDR + identity + SaaS signals correlated together. Low-confidence alerts auto-quarantine and revoke tokens before paging.
Patch windows
Two maintenance windows — nightly and weekend — so mission-critical changes get a deliberate hold-and-review path.
Incident reporting
Reports group by containment lineage and export as CSV for the underwriter on demand. SLA: 15 minutes to acknowledge.
For teams underwriter scrutiny or running regulated workloads. Named escalation and deeper reporting.
$25per endpoint, per month
Triage depth
Adds deep SaaS + cloud-control-plane signal. Identity-graph correlation reaches into Okta / Entra ID for token-graph review.
Patch windows
Three configurable windows with staged rollout. Risk-tiered patches can be optional-held until a named operator signs off.
Incident reporting
Merkle-anchored audit rows, weekly attestation pack for underwriters, named technician on call during declared windows.
Three lenses: triage depth, patch windows, incident reporting.
The three lenses match the three things a CISO or underwriter asks about first — “how deep does the agent see”, “how much can it change unattended”, and “what does the auditor read.”
The ones we get most.
If yours isn’t on the list, write to us — a real person reads it.
Can we change tier mid-contract?
Yes. Tier changes take effect at the start of the next monthly billing window. The agent config diff is logged alongside the audit log and rerun against your fleet.
Are there per-user fees?
No. The flat subscription is per endpoint, not per seat. Onboarding the wider org does not re-license.
Does an incident raise the bill?
No. There is no surge pricing. An incident does not change your invoice — that is by design.
What does the underwriter read?
The same audit log you read. On Standard and Complete the export is grouped by containment lineage and available as CSV; Complete also ships a weekly attestation pack.
Pick a tier, enrol the fleet. We’ll confirm scope on the discovery call.
curtainwall@polsia.app