Plans.

Two offerings. One mission.

ThreatLens Core helps security teams investigate threats faster. AI Governance Platform enables secure AI adoption and governance.

Enterprise licensing is available for Public Cloud, Private Cloud, and On-Premises deployments.

FAQ

Questions before you commit?

The most common things procurement, security architects, and analysts ask us, answered honestly.

No, and that's deliberate. ThreatLens is an investigation intelligence layer that sits on top of your existing stack, not a replacement for it. Your SIEM continues to be the system of record for logs and alerts. ThreatLens connects to it (and to your EDR, XDR, identity, cloud, and threat intelligence sources), correlates the evidence across those tools, and produces investigation-ready verdicts for your analysts to act on.

Think of it as the layer between detection and response, the part that today lives in analyst heads and browser tabs. We automate the investigation grunt-work; your SIEM keeps doing what it was built to do.

Available with any ThreatLens Core or AI Governance Platform enterprise license, on-premise deployment means the product runs entirely within your own infrastructure, your data never leaves your environment. We ship a containerised deployment package (Kubernetes-based) with a documented runbook and assisted setup. Your team handles the underlying compute; we manage the application lifecycle, update delivery, and provide a dedicated support channel for operational issues.

Minimum requirements: 16 vCPU / 64 GB RAM / 1 TB SSD for a standard deployment. Final sizing is scoped with our team during onboarding. Air-gapped deployments (no outbound internet) are also supported.

ThreatLens Core and the AI Governance Platform are licensed per environment under an enterprise agreement, scoped to your deployment model, telemetry volume, and team, not metered by alert, agent invocation, or LLM token. That keeps budgeting predictable no matter how noisy your stack gets.

Licensing is finalised on a scoping call with our team, where we right-size the agreement to your actual environment and growth plans.

We don't offer a self-serve free trial, SOC tooling that touches live telemetry benefits from a guided start. Instead, we run a structured 30-day proof of concept with your team, connected to one real data source, with a dedicated onboarding specialist and defined success criteria agreed upfront.

The PoC is free of charge and gives you a production-representative read on ThreatLens performance against your actual alert environment. Request a demo to start the conversation, we typically scope and kick off PoCs within two weeks of the first call.

ThreatLens Core ships with native connectors for the most common SOC stack, Splunk, Microsoft Sentinel, CrowdStrike Falcon, SentinelOne, Palo Alto Cortex XDR, Elastic SIEM, QRadar, Okta, Azure AD, AWS CloudTrail, GCP Security Command Center, VirusTotal, and Shodan, plus a webhook API for pushing findings into ticketing systems like ServiceNow and Jira.

Enterprise license customers can request custom connectors built to their specification, we typically deliver custom integrations within a 6–8 week build cycle included in the enterprise agreement. A full, up-to-date integration catalogue is available in the security & compliance section.

Get started

Ready to see it in action?

Book a 45-minute demo with our team. We'll connect ThreatLens to a sample of your alert data and show you what investigation intelligence looks like in your environment.

No commitment required · PoC scoped within 2 weeks · Your data stays in your environment