FIG. 05 Pricing

Premium. Honest. Price-locked for 24 months.

Three tiers — Watchtower, Keep, and Citadel — sized for SMBs that take security seriously. No per-event surcharges, no log-volume gotchas, no professional services line items. We charge what a real SOC + a real AI defender costs to run, and we don't pretend otherwise.

TIER 01 · WATCHTOWER

Watchtower

The outer wall. Passive AI monitoring with weekly digests and the 30-minute analyst response that opens every door.

$40/ device / month
$480 / device / year · min 10 devices
Book a walkthrough →
  • Coverage
  • Endpoint & identity monitoring (incl. M365 / Google Workspace)
  • Cloud & SaaS connectors
  • Cloud telemetry — 1 cloud account
  • 30-day hot retention
  • AI & SOC
  • AI Guardian — autonomous incident triage
  • 24×7 monitoring
  • 30-min response SLA (business hours)
  • Sparring (adversary simulation)
  • Edge Triage (on-device AI)
  • Auto-cascade response
  • Owner experience
  • Weekly digest · monthly async review
  • Email + in-portal contact
  • SOC 2 evidence pack (read-only)
TIER 02 · KEEP

Keep

The inner stronghold. Everything in the AI-defender stack — Sparring, Edge Triage, auto-cascade, a named analyst, and the GCC compliance overlay.

$90/ device / month
$1,080 / device / year · min 25 devices
Book a walkthrough →
  • Everything in Watchtower, plus
  • Coverage
  • Network & email security telemetry
  • Cloud & SaaS connectors + priority requests
  • Cloud telemetry — up to 5 accounts
  • Behavioural baselines — per-user & per-host
  • 90-day hot retention
  • AI & SOC
  • Sparring — weekly adversary simulation against your fleet
  • Edge Triage — on-device AI first-pass filter (data-residency + offline)
  • Auto-cascade — kill, quarantine, blocklist, isolate
  • 24×7 monitoring & response
  • 15-min response SLA
  • Named analyst + direct phone line
  • Compliance
  • GCC overlay — NESA · ITDA · NCA mappings
  • SOC 2 + ISO 27001 evidence packs
  • 5 custom Sigma detections
  • Quarterly tabletop exercises
  • Cyber-insurance attestation letters
TIER 03 · CITADEL

Citadel

The summit. A dedicated analyst pod, custom Sparring scenarios, AI-vs-AI campaigns, quarterly internal pen-test reports, and a 5-minute SLA.

$200/ device / month
$2,400 / device / year · 100+ devices
Talk to sales →
  • Everything in Keep, plus
  • Coverage
  • Unlimited cloud accounts & SaaS
  • Unlimited custom Sigma detections
  • Air-gapped / on-prem collector option
  • 90 days hot · 365 days cold retention
  • AI & SOC
  • AI-vs-AI Sparring — AI-generated novel attacks tailored to your stack
  • Custom Sparring scenarios authored by our red team
  • Dedicated analyst pod — 3 named analysts on your tenant
  • 5-min response SLA · 24×7
  • Shared Slack / Teams channel
  • Apple Endpoint Security custom rules
  • Compliance & programs
  • HIPAA · ADGM · PCI · custom frameworks
  • Quarterly internal pen-test report
  • Annual external red-team engagement
  • Forensic retainer + DFIR-ready
  • Executive briefing — monthly call with founder + CSO
  • Annual on-site visit
  • White-label partner portal access (MSSPs)
§ 02Side-by-side

Every capability, every tier.

A complete reference. If you're comparing us to an incumbent MSSP, this is the page to send to procurement.

Watchtower$40 / device / mo Keep$90 / device / mo Citadel$200 / device / mo
Coverage
Endpoints monitoredPer device, includedUp to 5051–250Unlimited
Cloud accountsAWS · GCP · Azure15Unlimited
SaaS connectorsOAuth-based1040+All + custom
Network & emailFirewalls, gateways, M365/Workspace email security
Behavioural baselinesPer-user / per-host fingerprintsUniversal onlyPer-user & per-host+ per-tenant
Custom Sigma detectionsAuthored for your environment5 includedUnlimited
Log retention30 days hot90 days hot90 hot · 365 cold
AI defender stack
AI GuardianAutonomous incident triage (latest frontier models)
Edge TriageOn-device AI filter — data-residency + offline
SparringWeekly adversary simulation against your fleet
AI-vs-AI SparringAI-generated attacks tailored to your stack
Custom Sparring scenariosAuthored by our red team
Security operations
24×7 monitoring
24×7 responseBusiness hours
Response SLA30 min15 min5 min
Auto-cascadeKill · quarantine · blocklist · isolate
Direct phone lineManned by SOC, not call centreEmail + portal
Named analystPooled
Dedicated analyst pod3 named analysts on your tenant
Executive briefingMonthly call with founder + CSO
Compliance & reporting
Owner's weekly digest
Monthly posture reviewAsync report30-min call+ on-site annually
SOC 2 evidence packRead-onlyFullFull + auditor liaison
ISO 27001 evidence
GCC overlayNESA · ITDA · NCA mappings
HIPAA · ADGM · PCI
Cyber-insurance attestationAnnualQuarterly
Exercises & testing
Onboarding tabletop
Quarterly tabletop
Quarterly internal pen-testAuthored by our red team
Annual external red-teamAdd-on
Phishing simulationAdd-onAdd-on
Commercial
Minimum term12 months12 months24 months
Price-lock24 months24 months36 months
Implementation fee$0$0Quoted
Out-clause30 days30 days60 days
§ 03Estimate

A rough idea of your monthly bill.

Plug in your seat count and tier. Real quotes are tighter than this — there are usually multi-year and bundle discounts available — but this is the right rough number to take to your CFO.

Your shape

Adjust to match your business.

ESTIMATED MONTHLY
$9,720
120 devices × $90 · Keep
3 cloud accounts included
− 10% annual prepay
Get a real quote →
§ 04Add-ons

Optional extras, all à la carte.

No bundling, no upsell traps. Add what you need; drop what you don't.

ADD-ON · DFIR

Forensic retainer

From $1,200 / month · 20 hours pooled

When something serious happens, you don't want to be sourcing a DFIR firm at 2am. We pre-stage hours so we move from response to investigation without procurement friction.

ADD-ON · OFFENSIVE

Annual red-team

From $18,000 / engagement · 2 weeks

A real adversary simulation against your environment, delivered by our specialist channel partner's OSCP, CEH and CISSP-certified operators, working to OWASP, PTES and MITRE ATT&CK. Findings fed back into your detection stack. Optional purple-team replay with your IT team.

ADD-ON · AWARENESS

Phishing simulation

$3 / seat / month

Twelve campaigns a year, calibrated to your industry. Click rates trended in the owner portal. Just-in-time micro-training for users who fall for it — no shaming, no enterprise-LMS slog.

ADD-ON · COMPLIANCE

Audit liaison

From $4,500 / audit cycle

A named IronCastle GRC engineer joins your auditor calls. They speak SOC 2 / ISO 27001 / HIPAA / IRAP fluently. We've shortened a lot of audits this way.

ADD-ON · COVERAGE

Custom detections

$1,800 / detection · or unlimited on Citadel

Have a workflow that's specific to your business — finance approval flows, R&D source-code egress, vendor portal abuse? We engineer detections for it.

ADD-ON · HARDWARE

IronCastle Probe

$349 USD one-time — Coming Q3 2026

A purpose-built network sensor that passively fingerprints every device on your LAN, feeds telemetry directly into the SOC, and works without an agent. No drivers, no SPAN port required.

ADD-ON · STORAGE

Extended retention

$0.04 / event-day · or 365d on Citadel

Beyond the included 30 / 90 days. Cold storage, retrieved into hot when an investigation needs it. Useful for IRAP / regulated tenants.

§ 05Pricing FAQ

The questions finance teams ask.

A short list — the rest live on the FAQ page.

Are there per-event or log-volume surcharges?

No. Per-seat pricing covers the telemetry your business generates. We've never billed a customer a "log overage" and we don't intend to.

What happens if our seat count grows mid-term?

You're billed in 25-seat increments quarterly in arrears. No mid-term renegotiation. Your locked rate applies to all new seats.

Is there a non-profit / education discount?

Yes — 25% off list for registered non-profits and accredited educational institutions, no minimum term.

Can we pay in AED, AUD, or GBP?

Yes — and we lock the FX at signing. We invoice in your local currency from the relevant Permus entity (Dubai, Sydney, or London).

What does "no implementation fee" actually mean?

Onboarding is included on Watchtower and Keep. For Citadel we quote implementation only when there's genuine custom work (air-gapped collector, custom detections, IRAP scoping, etc.) — never as a way to backfill a discount.

Can we leave?

Yes. 30-day out-clause on Watchtower & Keep (60 days on Citadel). We'll export your telemetry to S3-compatible storage on the way out — no retention as a hostage.