Pricing

$10–$25 per endpoint, per month. Three tiers, the same audited core.

Pick the tier that matches the depth of coverage, patch authority, and reporting your team and your underwriters need. Every tier ships with the same Merkle-anchored audit log and the same triage agent — the difference is what the agent has authority to do on its own.

Starter
Starter

Autonomous triage and patching for teams that want the L1 queue off their hands.

$10per endpoint, per month

Triage depth

EDR and identity signals fan into the triage agent. Confidence-based closure for noise; the rest files for review.

Patch windows

Routine OS and third-party patches apply inside a single nightly window you configure at enrolment.

Incident reporting

Every triage decision appended to the audit log with agent ID, evidence, and outcome — readable end-to-end.

Standard
Most popular
Standard

The most common fleet shape. Continuous triage, broader patch authority, and SLA-bound escalations.

$17per endpoint, per month

Triage depth

EDR + identity + SaaS signals correlated together. Low-confidence alerts auto-quarantine and revoke tokens before paging.

Patch windows

Two maintenance windows — nightly and weekend — so mission-critical changes get a deliberate hold-and-review path.

Incident reporting

Reports group by containment lineage and export as CSV for the underwriter on demand. SLA: 15 minutes to acknowledge.

Complete
Complete

For teams underwriter scrutiny or running regulated workloads. Named escalation and deeper reporting.

$25per endpoint, per month

Triage depth

Adds deep SaaS + cloud-control-plane signal. Identity-graph correlation reaches into Okta / Entra ID for token-graph review.

Patch windows

Three configurable windows with staged rollout. Risk-tiered patches can be optional-held until a named operator signs off.

Incident reporting

Merkle-anchored audit rows, weekly attestation pack for underwriters, named technician on call during declared windows.

What changes between tiers

Three lenses: triage depth, patch windows, incident reporting.

The three lenses match the three things a CISO or underwriter asks about first — “how deep does the agent see”, “how much can it change unattended”, and “what does the auditor read.”

Triage depth
How broad the signal graph is, and how much authority the agent has to act on a low-confidence alert.
Patch windows
How many maintenance windows, how patches are staged, and where human sign-off is required before applying.
Incident reporting
What the audit log captures, what the customer + underwriter read, and the SLA on the handoff to a human.
Questions

The ones we get most.

If yours isn’t on the list, write to us — a real person reads it.

curtainwall@polsia.app
  • Can we change tier mid-contract?

    Yes. Tier changes take effect at the start of the next monthly billing window. The agent config diff is logged alongside the audit log and rerun against your fleet.

  • Are there per-user fees?

    No. The flat subscription is per endpoint, not per seat. Onboarding the wider org does not re-license.

  • Does an incident raise the bill?

    No. There is no surge pricing. An incident does not change your invoice — that is by design.

  • What does the underwriter read?

    The same audit log you read. On Standard and Complete the export is grouped by containment lineage and available as CSV; Complete also ships a weekly attestation pack.

Ready when you are

Pick a tier, enrol the fleet. We’ll confirm scope on the discovery call.

curtainwall@polsia.app