Pricing that does not punish you for collecting good telemetry
One price per protected node. Every OCSF class, every rule pack, and the full retention window on your plan. The sensor and core are Apache-2.0, so the exit door is always open.
Community
self-hosted, unlimited nodes
The sensor and core, Apache-2.0. Everything you need to run Falak Neo yourself, including the full detection content pack.
- eBPF sensor and Go core, Apache-2.0
- All 11 OCSF classes plus the container extension
- Community detection content, ATT&CK mapped
- Single tenant, self-managed ClickHouse and Postgres
- Community support via GitHub
Team
per protected node / month
Managed core, managed storage, and the analyst console. For teams that would rather operate their product than their security pipeline.
- Everything in Community, hosted
- 30-day hot retention, 1 year cold archive
- Analyst console with alert triage and hunting
- Slack, PagerDuty, Jira and webhook integrations
- Email support, next business day
- Up to 250 nodes
Business
per protected node / month
For security teams with an on-call rotation, a compliance obligation, and more than one cluster to worry about.
- Everything in Team
- 90-day hot retention, 3 year cold archive
- Attack graph, case management and coverage matrix
- Signed response actions with RBAC
- SSO (SAML / OIDC) and SCIM provisioning
- Cloud control-plane ingestion (CloudTrail, GCP, Azure)
- AI analyst assistance
- 8×5 support with a 4-hour response target
Enterprise
volume and residency dependent
Regulated environments, air-gapped deployments, and estates where the node count stopped being the interesting number a while ago.
- Everything in Business
- Custom retention and data residency
- Air-gapped and BYO-cloud deployment
- Custom detection content engineering
- Dedicated ClickHouse and Postgres clusters
- 24×7 support with a 1-hour P1 target
- Named security engineer and quarterly reviews
All plans include unlimited users, unlimited API keys and the OCSF NDJSON export. Prices exclude VAT.
Compare
What is in each plan
| Capability | Community | Team | Business | Enterprise |
|---|---|---|---|---|
| Collection | ||||
| eBPF sensor (all probes) | ||||
| OCSF v1.3 event classes | 11 + ext | 11 + ext | 11 + ext | 11 + ext |
| Cloud control-plane ingestion | ||||
| Per-policy sampling and filters | ||||
| Detection | ||||
| Community rule packs | ||||
| Behavioural and statistical analytics | ||||
| Sensor fast-path (local) rules | ||||
| Custom detection engineering | ||||
| Investigation | ||||
| Alert feed and incident timeline | ||||
| Process tree and OCSF document viewer | ||||
| Attack graph | ||||
| Case management | ||||
| ATT&CK coverage matrix | ||||
| AI analyst assistance | ||||
| Response | ||||
| Signed response actions | ||||
| Role-based approval | ||||
| SOAR / webhook dispatch | ||||
| Operations | ||||
| Hot retention | your call | 30 days | 90 days | custom |
| Cold archive | your call | 1 year | 3 years | custom |
| SSO and SCIM | ||||
| Audit log | ||||
| Data residency choice | self-hosted | EU or US | EU or US | custom |
Questions
Pricing FAQ
What is a protected node?
One machine running one sensor — a Kubernetes node, a VM, or a bare-metal host. Containers and pods are not counted; a node running 300 pods is one node. We do not charge per container, per event or per gigabyte, because those numbers punish you for having good telemetry.
Why not charge per event or per gigabyte?
Because volume-based pricing makes every filter decision a budget decision, and teams end up sampling away the events they most need six months later. Node pricing is predictable and it does not create an incentive to see less.
Is the sensor really Apache-2.0?
Yes, along with core. You can run the whole platform yourself, read every line that runs in your kernel, and fork it if we ever disappoint you. The commercial product is the managed service, the console, and the support.
What happens when the trial ends?
Ingestion stops and the console becomes read-only for 30 days so you can export. Nothing is deleted during that window, and the OCSF NDJSON export is available on every plan including the trial.
Do you offer a discount for annual billing?
Two months free on annual, on Team and Business. Enterprise agreements are negotiated per contract.
Can we start self-hosted and move to managed later?
Yes, and the migration is mostly a config change: sensors re-enroll against a new core endpoint, and historical events can be replayed from your ClickHouse into the managed store as OCSF NDJSON.
Still not sure which plan fits? Tell us about your estate and we will tell you honestly.
Book a demo