Never per scan
Scan hourly or nightly; it costs the same. Per-scan pricing would make you widen your schedule to save money, which defeats the entire point of continuous assurance.
ShareCare is listed in full. Everything else is quoted, and this page says which is which — plus every factor that moves the number, so you can size it before you ask.
Every product is priced on the thing that actually drives its cost and its value to you. Those are not the same unit, and forcing them into one would misprice most of the portfolio.
Four of these are available today — ShareCare, SecurityPortal, WebScan and MailTrust. ConditionalAccessPortal and CompliancePortal are built and close but not released; their prices are published so the number is settled before they ship rather than negotiated after. Dredd and PosturePortal are further out, and neither carries a list price.
| Product | Priced on |
|---|---|
| ShareCare | Microsoft 365 users |
| SecurityPortal | Users, at a lower rate with any ShareCare tier · $50 monthly tenant minimum |
| ConditionalAccessPortal | Users, on the same terms as SecurityPortal |
| WebScan | Monitored sites · free on every tenant |
| MailTrust | Sending domains; parked domains at a lower rate, five included with each |
| CompliancePortal | Per tenant, banded by how many frameworks are in scope |
| Dredd | Monitored configuration scope — quoted, not listed |
| PosturePortal | Not yet priced — still in development |
Each tier contains the one below. Moving up is an entitlement change, not a migration or a reinstall — the capability is already in the product, waiting to be switched on.
Tiers 1 and 2 read and record. Tier 3 changes your production tenant. That is a difference in kind, not degree, so it is a distinct purchase and a distinct consent — and it stays revocable without losing the visibility and evidence you already paid for.
The tiers set how often a scan runs on a schedule — daily, every six hours, hourly. They never limit how often you may look: an on-demand scan is available on every tier, at any time, as many times as you need. Nothing about an incident should require a purchase order.
The distinction matters and it is deliberate. Continuous scanning is the cost we carry on your behalf, and tighter cadence genuinely costs more to run — so a tighter loop between a change and its finding is something you buy. But charging per scan would teach you to look less often, which is the one behaviour this product exists to prevent. A floor on automatic frequency does the opposite: every tier still sees everything, and the higher tiers see it sooner.
Pick the one you are buying. Everything that applies to the whole account — the floor, the volume bands, and what does and does not move your number — is below, outside the tabs, because it applies whichever you pick.
Per user, per month
$1.50 per user with any ShareCare tier, which is the usual case, or $3.50 standalone. Same denominator as ShareCare, so it adds to an existing line rather than starting a new negotiation.
Charged greater-of, and it exists because roughly half of what this product checks does not shrink with headcount. A 20-seat tenant has about as many Conditional Access policies, app registrations and configuration settings as a 2,000-seat one, and every one of them is evaluated either way. Per-user alone would price a full posture scan of a small tenant at thirty dollars. The floor bites below 34 users; above that the per-user arithmetic is the whole bill.
What you get — read-only Microsoft 365 and Entra posture scans, on demand or daily, with findings history across managed tenants..
| Capability | Includedone tier |
|---|---|
| Price | |
| Per user, per month — with any ShareCare tier | $1.50 |
| Per user, per month — standalone | $3.50 |
| Monthly minimum per tenant, greater-of | $50 |
| Capability | |
| On-demand scan, whenever you want one | Included |
| Scheduled scan cadence — daily | Included |
| Microsoft 365 and Entra posture — Conditional Access, MFA, app permissions | Included |
| Log-analytics checks, where activity logs are exported | Included |
| Posture ladder, advanced only by scan evidence | Included |
| Control-reference tags on every finding | Included |
| Findings history and reports | Included |
| Fleet-wide across managed tenants | Included |
| Write access to your tenant | Not included |
Why a per-tenant minimum on a per-user product. Roughly half of what this checks does not shrink with headcount — a 20-seat tenant has about as many Conditional Access policies, app registrations and configuration settings as a 2,000-seat one, and every one is evaluated either way. Per-user alone would price a full posture scan of a small tenant at thirty dollars. The floor bites below 34 users and does nothing above it.
One tier, not a ladder: SecurityPortal is scan-only, so there is no write access to sell on a higher tier. Remediation lives in the products built to write safely. The log-analytics checks need the tenant to export activity logs; without that export they report “not assessed” rather than a pass. The public web and domain surface is WebScan, licensed separately and free to run.
Per user, per month · not released yet
On the same denominator and the same $50 monthly tenant minimum as SecurityPortal, because it answers the same question about the same estate.
| Visibilitysee it | Governancegovern it | Automationact on it | |
|---|---|---|---|
| Per user, per month | $0.60 | $1.00 | $1.50 |
| Monthly minimum per tenant, greater-of | $50 | $50 | $50 |
| Capability | Visibilitysee it | Governancegovern it | Automationact on it |
|---|---|---|---|
| Price | |||
| Per user, per month | $0.60 | $1.00 | $1.50 |
| Monthly minimum per tenant, greater-of | $50 | $50 | $50 |
| Capability | |||
| Conditional Access policy inventory | Included | Included | Included |
| Access map — endpoints, policies, resources, allowed and blocked paths | Included | Included | Included |
| On-demand scan, fleet-wide across managed tenants | Included | Included | Included |
| Baseline coverage gaps | Not included | Included | Included |
| Policy-as-code drift detection — Git repository, GitHub or Azure DevOps | Not included | Included | Included |
| Scheduled repository-versus-tenant comparison, with history | Not included | Included | Included |
| Baseline capture — a tenant’s live policy into the repository, as a pull request | Not included | Included | Included |
| Approval-gated policy write-back to your tenant | Not included | Not included | Included |
| Deploy repository policy into your tenant, approval-gated | Not included | Not included | Included |
Governance reads, Automation writes, and the line between them is the whole ladder. Everything on Governance — the baselines, the repository comparison, the schedule, even the capture — leaves your directory exactly as it found it. Capture writes only to your Git repository, on a new branch, as a pull request somebody has to merge; it never pushes to the branch we read. Automation is the one rung that changes your tenant, and even there the deliberate decision is per change, not per contract: a deployment is approved by somebody other than the person who requested it, and nothing is written without a separate connector consent you grant yourself. Nothing is ever deleted — a policy your tenant has and the repository does not is reported, never removed.
Not released yet. Built, running and close — the price is published so it is not a surprise when it ships, not because you can buy it today. What it does, and what it does not.
Per monitored site, per month
| Freeon every tenant | Prokept and scheduled | |
|---|---|---|
| List | $0 | $20 |
| 5 sites | $0 | $100 |
| 25 sites | $0 | $500 |
One paid licence, not a ladder — keeping a scan and scheduling it were separate tiers, and that sold a distinction nobody makes: a saved site nobody re-scans is a stale record, and a schedule that keeps nothing is a cron job with no output.
A tenant that arrived through a free scan is one we would not otherwise have, and putting a minimum in front of them would eat the funnel it sits downstream of. Nothing is added when a second product applies from that point.
Pro looks for hostnames under a site you already pay for and lists what it finds — the name, whether it still resolves, where it last pointed. That costs nothing and is never billed, however many turn up. They are listed, not scanned. Promoting one to a monitored site is a button you press, and only then does it get the full check suite and only then does it count. Nothing here can raise your bill on its own, which is deliberate: an estate that grows on a timer would be an invoice that grows on a timer. Coverage is partial and improving — the limits page says how.
Scanning is never counted — only sites you chose to keep, once per billing period each, however often they run..
| Capability | Freeon every tenant | Proper monitored site |
|---|---|---|
| Price | ||
| Per monitored site, per month | $0 | $20 |
| Five sites | $0 | $100 |
| The scan itself | ||
| On-demand scan, whenever you want one | Included | Included |
| The complete check set | Included | Included |
| Scan a site you have not onboarded | Not included | Included |
| Subdomain and asset discovery | Included | Included |
| Certificate transparency lookup | Included | Included |
| Certificate expiry, checked on every scan | Included | Included |
| Graded score with the four result states kept apart | Included | Included |
| Standard and RFC references on every check | Included | Included |
| Why it matters, and the fix, on every failure | Included | Included |
| Sites you may keep | — | Unlimited |
| What happens afterwards | ||
| Results kept once you close the page | Not included | Included |
| Scan history and trend over time | Not included | Included |
| Findings, waivers and an audit trail | Not included | Included |
| Control-reference tags, feeding CompliancePortal as evidence | Not included | Included |
| Fleet view across sites and managed tenants | Not included | Included |
| Watched on a clock, between scans | ||
| Certificate expiry warned before it lapses, not after | Not included | Included |
| Certificate transparency monitoring — alerting on new issuance | Not included | Included |
| Alerting when discovery turns up a new asset | Not included | Included |
| Alerting when a passing check regresses | Not included | Included |
| Running without you | ||
| Scheduled scans, on a cadence you set | Not included | Included |
| Write access | ||
| Write access to your DNS or web server | Not included | Not included |
Two licences, not a ladder, and the reason is that the ladder sold a distinction nobody makes. Keeping a scan and running it on a schedule were separate tiers; but a saved site nobody re-scans is a stale record, and a schedule that keeps nothing is a cron job with no output. Pro grants both.
The free tier is the whole scanner, and that is deliberate. Every check, the same severity-weighted score a paid run produces. What it does not do is remember: one URL at a time, fire and forget, nothing written down when the scan finishes. That is what makes it free to give away rather than a trial with an expiry date — and it is auto-granted to every tenant rather than sold.
Counted per site rather than per domain, because a site is what gets scanned: one domain can front several, and each is its own configuration to grade. Nothing caps how many sites you may add; the count is trued up, never a hard stop.
Pro is $20 against a category that starts an order of magnitude higher. The nearest paid comparables run from roughly $60 per asset per month to several hundred, and they include active vulnerability testing that WebScan does not do. At the other end the free graders charge nothing and retain nothing. The gap between those two is where this sits, and it was empty.
WebScan never writes anywhere — DNS write-back belongs to MailTrust, which also owns SPF, DKIM and DMARC; those are mail authentication rather than web surface and are not duplicated here.
Per domain, per month
| Visibilitysee it | Governancegovern it | Automationact on it | |
|---|---|---|---|
| Sending domain | $15 | $30 | $40 |
| Parked domain | $3 | $3 | $3 |
| 3 sending, 40 parked | $120 | $165 | $195 |
Five parked domains included with every sending domain — the example above prices the remaining 25.
Most organisations own far more domains than they send from: acquisitions, retired brands, defensive and typo registrations. Those are exactly the ones worth spoofing — no real mail flows, so nothing breaks and nobody notices.
Charging full rate for them makes the rational decision protect fewer domains, which is the behaviour this product exists to prevent. The classification is measured, not asserted: a domain is parked when it has produced no DMARC report volume and no DKIM signing for a full period, and it reclassifies itself the moment you start sending from it.
The list price above is a retail price, and a provider is not a retail buyer. MSP-focused DMARC platforms sell partners a wholesale rate precisely because the partner does the onboarding, the sender inventory and the support conversation, then sets their own retail. Charging a reseller list would ask them to buy at several times what a competitor charges them, which is not a price either.
| Visibilitysee it | Governancegovern it | Automationact on it | |
|---|---|---|---|
| Sending domain, across your whole book | $5 | $10 | $13 |
| Parked domain | $1 | $1 | $1 |
A third of list, rounded to the dollar. Minimum ten managed tenants, on a provider agreement — the same bar as pooled compliance, and for the same reason: below it the arithmetic stops describing wholesale and starts describing a discount. Five parked domains still included with every sending domain, and domains pool across your managed tenants.
Sixty clients averaging three sending domains each is 180 domains. On Governance that is $1,800 a month against $5,400 at list. Resold at a typical managed-DMARC rate it is the highest-margin line in the stack — which is the point: you are buying the platform, not the retail price of it.
DNS write-back is live for Azure DNS and DNSimple. Anywhere else, Automation gives you a staged rollout and the exact records to apply yourself — guidance, not automation. That is why the tier is $40 rather than the $50 the capability would be worth if it wrote everywhere. Cloudflare and Route 53 are next, and the price moves when they ship, not before.
| Capability | Visibilitysee it | Governancegovern it | Automationact on it |
|---|---|---|---|
| Price | |||
| Per sending domain, per month | $15 | $30 | $40 |
| Per parked domain, per month | $3 | $3 | $3 |
| Parked domains included, per sending domain | 5 | 5 | 5 |
| Cadence | |||
| On-demand scan, whenever you want one | Included | Included | Included |
| Scheduled scan cadence | Daily | Every 6 hours | Hourly |
| Assessment | |||
| SPF, DKIM, DMARC, BIMI and MTA-STS posture | Included | Included | Included |
| DMARC aggregate report ingestion and sender analysis | Included | Included | Included |
| Findings history and reports | Included | Included | Included |
| Unlimited domains on every tier | Included | Included | Included |
| Parked domains watched for silent record changes | Included | Included | Included |
| Governance | |||
| Guided staged rollout toward enforcement | Not included | Included | Included |
| Deliverability and authentication alerting | Not included | Included | Included |
| Multi-domain fleet view | Not included | Included | Included |
| Write access | |||
| DNS write-back for supported providers | Not included | Not included | Included |
A parked domain is not priced like a sending one. Most organisations own far more domains than they send from — acquisitions, retired brands, defensive and typo registrations — and those are exactly the ones worth spoofing, because no real mail flows so nothing breaks and nobody notices. Charging full rate for them would make the rational decision protect fewer domains, which is the behaviour this product exists to prevent. So a parked domain is $3, five come with every sending domain, and the classification is measured rather than asserted: a domain is parked when it has produced no DMARC report volume and no DKIM signing for a full period. Start sending from it and it reclassifies itself.
Report volume carries an allowance. Ingesting, parsing and storing DMARC aggregate reports is a real cost that scales with how much mail a domain sends, not with how many domains you have — so each domain includes an allowance sized to normal sending volume, and unusually high-volume domains buy additional blocks. Same test as the deliverability allowance: a genuine external cost, optional, and bursty. Posture, findings and reports stay uncapped.
No tier caps how many domains you may add — the count is a commercial measurement, trued up on the next invoice, never a hard stop. Ingesting DMARC reports needs a mailbox to receive them; that is part of onboarding.
Automation is priced at $40 rather than higher, and the reason is honest: DNS write-back is live for Azure DNS and DNSimple only. If your DNS is anywhere else, that tier gives you a staged rollout and guided records to apply yourself, not automation — so it is not priced as though it wrote them for you. Cloudflare and Route 53 are the next two, and the price goes up when they land rather than before.
Per tenant, per month · banded by frameworks in scope · not released yet
| 1 frameworksingle regime | 3 frameworksthe usual mix | Unlimitedevery regime | |
|---|---|---|---|
| Evidence | $300 | $600 | $900 |
| Attested | $450 | $900 | $1,350 |
Priced per tenant rather than per user, because a framework is the same amount of work to prove whether you have forty people or four hundred.
How many frameworks you need is scope. Whether you want sign-off and automatic capture is depth. Those used to share one number, which meant a company doing SOC 2 alone had to buy every framework in the catalogue to reach attestation — paying for twenty-three regimes it would never open, to get one capability.
Evidence is the catalogue, the crosswalk, automated probes, assessments, the evidence repository and time-boxed auditor access. Attested adds attestation and sign-off with four-eyes and expiry, control ownership, and automated evidence capture — at half again the band price, whichever band you are on.
Per-tenant compliance pricing does not survive a fleet. Sixty clients on the entry band would be $18,000 a month, which is not a price, it is a decline. So for providers the two cost drivers are separated and charged for individually.
| Priceper month | |
|---|---|
| Framework licence, across your whole book | $750 |
| — or every framework, across your whole book | $3,000 |
| Per managed tenant — Evidence | $50 |
| Per managed tenant — Attested | $75 |
| Retention | 36 months included · 84 months +$10 / tenant |
Minimum ten managed tenants, on a provider agreement. Below that the arithmetic stops describing pooling and starts describing a discount.
Sixty tenants on one framework with sign-off: $750 + 60 × $75 = $5,250 a month, about $88 a client. Thirty tenants on two frameworks without sign-off: $1,500 + 30 × $50 = $3,000, $100 a client. Compare the first with the $27,000 the same book would cost at per-tenant rates — that gap is not a discount, it is what happens when you stop charging sixty times for one crosswalk.
Provider-scoped licences are not built. Entitlements in this platform resolve per tenant. A licence saying "this provider may assess SOC 2 against any client in its book" is granted at the provider and enforced at the tenant, and that shape does not exist in the catalogue today. The prices above are what you will be quoted; the gate behind them is work in progress.
Assessments do not run on a schedule yet. You raise one when you want one. What is continuous is the evidence underneath — SecurityPortal, ShareCare, WebScan and MailTrust scan on their own schedules, and their control-tagged findings are what an assessment reuses.
| Capability | 1 frameworksingle regime | 3 frameworksthe usual mix | Unlimitedevery regime |
|---|---|---|---|
| Price | |||
| Evidence — per tenant, per month | $300 | $600 | $900 |
| Attested — per tenant, per month | $450 | $900 | $1,350 |
| In every band | |||
| On-demand assessment, whenever you want one | Included | Included | Included |
| Recurring scheduled assessments | Not included | Not included | Not included |
| Framework and benchmark catalog | Included | Included | Included |
| Multi-framework crosswalk — one piece of evidence, many controls | Included | Included | Included |
| Automated control probes across the connected planes | Included | Included | Included |
| Google Cloud and AWS coverage via read-only connectors | Included | Included | Included |
| Evidence reuse from SecurityPortal, ShareCare and MailTrust | Included | Included | Included |
| Assessment workflow and immutable snapshot trail | Included | Included | Included |
| Evidence repository and provided-by-client requests | Included | Included | Included |
| Time-boxed auditor access | Included | Included | Included |
| Scales with the band | |||
| Frameworks in scope | 1 | 3 | Unlimited |
| Evidence retention | 12 months | 36 months | 84 months |
| Attested adds, at any band | |||
| Attestation and sign-off, with four-eyes and expiry | Included | Included | Included |
| Automated evidence capture | Included | Included | Included |
| Control ownership and remediation tasks | Included | Included | Included |
Two questions, two axes, so neither answer is bought to get the other. How many frameworks you need is scope. Whether you want sign-off and automatic capture is depth. Until now those shared one number, which meant a company doing SOC 2 alone had to buy every framework in the catalogue to reach attestation — paying for twenty-three regimes it would never open, to get one capability. Attested is half again the band price at any band instead.
Not called Automation, and not an accident. On the ladder products that word is the tier that writes to your tenant. CompliancePortal writes nothing — it maps, scores, evidences and attests. Automated evidence capture reads from the estate; it does not act on it.
Assessments do not yet run on a schedule. They are raised on demand and the product has no recurring cadence to sell, which is why that row is empty in all three bands rather than quietly ticked. What is continuous is the evidence underneath: SecurityPortal, ShareCare, WebScan and MailTrust scan on their own schedules, and their control-tagged findings are what an assessment reuses. The scope still holds either way — this proves the technical controls on the platforms SeQontrol connects to, not a whole-company compliance programme.
One quoted, one not yet priced
Dredd is still in development, and quoted rather than listed when it lands. Its unit is monitored configuration scope, which is the metric this model understands least, and it is being set against real estates rather than guessed.
PosturePortal carries no price at all, because it is still in development. It will not be a separate line when it arrives — it connects to nothing and reads the shared findings store — but exactly how it is packaged is unsettled, and a price against something still being built is how a price list stops being worth reading.
Everything else on this page is listed in full.
Dredd runs; its licence shape is still being set. The product is built and the governance, remediation and bulk-heal paths are live — what is not settled is the unit it should be counted on. It is the metric we understand least, and rather than guess a shape and reprice it six months later, it is being set against real configuration scopes first. Ask and you will get a number. The full capability set is on the Dredd section.
| Capability | Includedone tier |
|---|---|
| Cross-product findings aggregation | Included |
| Posture scores, top risks and trends | Included |
| Connector health and coverage visibility | Included |
| Saved views and annotations | Included |
| Fleet overview across managed tenants | Included |
| Write access to your tenant | Not included |
Still in development, and deliberately not on the price list. PosturePortal connects to nothing itself — it reads the shared findings store — so it costs almost nothing to run and will not be sold as a separate line. Exactly how it is packaged is not settled, and putting a number against something still being built is how a price list stops being trusted. The capabilities below describe what it does; none of them is something you can buy today.
There is no platform minimum. You pay for the products you hold, in the unit each one counts, at any size. The tenancy, auth, audit trail, findings store, reporting and scheduling that every product runs on are included rather than charged separately. A 30-user tenant on ShareCare Visibility computes $60 and pays $60.
$50 a month, every product, every tier, on the tenant you run your own business from. The same estate computes somewhere between $260 and $640 at list, so this is not a discount and is not described as one — it is deliberately below what a tenant costs to run, which means it costs us money and is meant to.
The reasoning is plain enough to publish: a provider who runs this on themselves every day can demonstrate it from a live tenant instead of a slide, and will find our mistakes before your clients do. That is worth more to us than the margin on one small tenant.
The rule we hold ourselves to: never meter the thing we want you to do more of. Metered scanning teaches you to scan less, discover less and get less value — and then to conclude the product never found anything.
Scan hourly or nightly; it costs the same. Per-scan pricing would make you widen your schedule to save money, which defeats the entire point of continuous assurance.
"The worse your posture, the more you pay to learn about it" is the most perverse metric in this category. Findings are free. Fixing is free.
Users, domains, tenants or monitored scope — depending on the product. Each one correlates with our cost and your value, and each is a number you already know at quote time.
| Situation | What happens | Why |
|---|---|---|
| Not entitled to a product or capability | The capability is refused outright | An entitlement is a capability gate. If you have not bought write-back, nothing writes back. |
| Over your unit count | Warning at 100%, a banner at 110%, trued up on the next invoice | Units are a commercial measurement, not a kill switch. Growing past your estimate is a billing conversation. |
| Drifting over it quietly | We review overage monthly and come to you | A soft cap only works if somebody reads it. The review is ours to run, so the first you hear of a mismatch is a conversation — not a surprise line on a renewal. |
| Any commercial dispute at all | Your scans keep running | Hard-capping a security scan mid-incident is a security failure. We do not do it. |
Two things carry a real external cost per use, are optional, and are bursty. They get an included allowance rather than being folded into the base price. Everything else — scans, remediation actions, findings, evidence exports — is uncapped.
| Allowance | Included | Beyond that |
|---|---|---|
| Deliverability tests | 50 per month, per domain | Charged per test — we send and receive real mail |
| DMARC aggregate report volume | An allowance per domain, sized to normal sending volume | Additional blocks — ingesting, parsing and storing reports scales with how much mail you send, not with how many domains you have |
| AI remediation guidance and report narratives | Fair use | Add-on packs — there is a real per-call model cost |
How many products you take. There is no suite discount. Each product is priced on its own and adding one costs what that product costs — no bundle, no package, no number that only appears if you buy everything. What running more than one does get you is structural rather than promotional: one tenancy, one identity, one audit trail across the account, and findings that land somewhere they are already useful.
How often you scan, how many findings you have, how much you remediate, or how much evidence you export. None of those are metered, deliberately — charging for them would teach you to look less often, which is the one behaviour this product exists to prevent.
Nor does how you pay. A year costs twelve months. Annual and monthly are a cash-flow decision, not a lever: there is no discount for committing and no penalty for not. If you would rather pay yearly because it is one invoice instead of twelve, do that — it will not change the number, and nobody here will pretend it should.
WebScan takes that further: every tenant scans at no cost, indefinitely, one URL at a time. The licence buys what happens after the scan — the history, the schedule, the audit trail and the evidence. A scan you do not keep cannot prove anything, and the one you do keep is the one we charge for.
Tell us the size of the estate. You will get a real figure back, not a discovery call.
Some browsers and webmail setups cannot hand off to a mail app. Nothing is lost — copy the message below and send it to jeff@jeffops.com.
It landed. You will get a reply from a person, usually the same working day.