Pricing
Priced by what we watch, not by what we find.
Three tiers, one platform. Your scope is the brands and domains you want covered and the external assets we track for you. A loud month never turns into a bigger bill.
Essential
For a single brand and a small security team
$1,200
/month, billed annually
Continuous external monitoring with the alerts that matter most — leaked credentials and unknown exposed assets.
- 1 primary domain
- Up to 500 tracked assets
- 5 platform users
What you get
- Dark web and paste-site monitoring
- Leaked credential alerts with breach context
- Automated external asset discovery
- Weekly exposure digest by email
- Email support, next business day
Professional
RecommendedFor security teams protecting several brands or subsidiaries
$3,400
/month, billed annually
Everything in Essential, plus brand protection with managed takedowns, deeper enrichment and workflow integrations.
- Up to 5 domains or brands
- Up to 5,000 tracked assets
- 25 platform users
What you get
- Everything in Essential
- Lookalike domain and impersonation detection
- Managed takedown requests, tracked to closure
- Jira, ServiceNow, Slack and SIEM integrations (see roadmap status)
- Executive and VIP exposure monitoring
- Monthly analyst review call
Enterprise
For large or regulated organisations with complex estates
Custom
Quoted against your scope
Scoped to your environment, with the deployment, data-residency and reporting commitments a regulated programme needs.
- Unlimited domains and brands
- Unlimited assets and users
- Custom data residency
What you get
- Everything in Professional
- Supply-chain and third-party monitoring
- Assigned intelligence analyst at general availability
- Custom collection requests and RFIs
- SSO/SAML, SCIM and audit logging
- Contractual SLAs and quarterly reviews
These prices are indicative. Final scope — which brands and domains we cover, how many external assets we track, how many people need a seat — is agreed with you before anything is signed, and the quote follows that scope. Figures are in US dollars, billed annually, and exclude local taxes.
Compare
Every capability, tier by tier
The whole list, including what we hold back from the entry tier. If one thing you need sits a tier up, say so on the call — scope is negotiable and we would rather fit the plan to the programme.
| Capability | Essential | Professional | Enterprise |
|---|---|---|---|
| Dark Web Monitoring | |||
| Credential leak monitoringCorporate email addresses found in breach dumps and combolists | Included | Included | Included |
| Marketplace and forum coverage | Core sources | Extended sources | Extended + custom |
| Ransomware leak-site tracking | Included | Included | Included |
| Telegram and closed-channel collection | Not included | Included | Included |
| Analyst-validated alertsA human confirms severity before the alert reaches you | Not included | Included | Included |
| Custom collection requests (RFIs) | Not included | Not included | Included |
| Attack Surface Management | |||
| Automated asset discoveryDomains, subdomains, IP ranges, cloud services and certificates | Included | Included | Included |
| Discovery frequency | Weekly | Daily | Continuous |
| Exposed service and misconfiguration checks | Included | Included | Included |
| Risk scoring and prioritisation | Standard | Standard | Tuned to your estate |
| Shadow IT and forgotten-asset flagging | Not included | Included | Included |
| Supply-chain and subsidiary monitoring | Not included | Not included | Included |
| Brand Protection | |||
| Lookalike and typosquat domain detection | Alerts only | Included | Included |
| Phishing page detection and evidence capture | Not included | Included | Included |
| Managed takedownsWe file, chase and evidence the request on your behalf | Not included | Included | Included, with contractual reporting commitments |
| Rogue mobile app and social account monitoring | Not included | Included | Included |
| Executive and VIP impersonation monitoring | Not included | Included | Included |
| Platform and delivery | |||
| Alert routing to email and Slack | Included | Included | Included |
| Jira, ServiceNow and SIEM integrations | Not included | Included | Included |
| REST API and webhooks | Read-only | Included | Included |
| SSO/SAML and SCIM provisioning | Not included | SSO/SAML | SSO/SAML + SCIM |
| Role-based access and audit logging | Not included | Included | Included |
| Data residency options | Not included | Not included | Included |
| Support | Email, next business day | Priority + monthly analyst call | Dedicated analyst + SLA |
Integration rows describe planned tier entitlements. Ask which connectors are live for your stack before you sign.
Pricing model
What actually drives the cost
Three inputs set your tier. None of them is the number of alerts we raise, so a bad month for findings is never a bad month for the invoice.
- Per brand
Brands and domains in scope
Each brand brings its own domain family to watch — subdomains, certificates, and every lookalike registered against it. Naming the brands is most of the scoping conversation.
- Per asset
External assets we track
Hosts, IP ranges, certificates, storage buckets and cloud services attributed to you. Discovery finds them from your domain; the resulting count is what the tier is scoped against.
- Per seat
People who need access
Seats for the analysts, engineers and fraud investigators who work findings day to day. Stakeholders who only read the monthly report do not need one.
What we never meter
- Alerts raised, however noisy the month
- Findings sitting in your queue
- Managed takedown requests on Professional and Enterprise
- API calls, webhook deliveries and SIEM forwarding
- Reports, exports and evidence packages
Charging per alert would bill you most in the weeks you need the tool most, and it quietly pushes teams to turn sources off. We would rather you ran every source your tier entitles you to.
- Primary domain
- yourbrand.example
- Additional brands
- 3
- Assets discovered
- 1,284
- Platform users
- 18
- Alerts last quarter
- not metered
- Takedowns filed
- not metered
This scope lands inside Professional. Growing within the limit costs nothing extra, and crossing it starts a conversation rather than an invoice.
Questions
Pricing questions, answered
If yours is not here, ask us directly — we will give you a straight answer rather than a follow-up call.
By the size of what we monitor rather than by alert volume — the number of brands and domains in scope, and the number of external assets we track. That keeps the bill predictable, and it means a noisy month never costs you more.
Essential and Professional are billed annually. Enterprise agreements are usually multi-year, and we are happy to start with a shorter initial term while you validate the coverage.
Nothing breaks and nothing stops being monitored. We flag it, show you what pushed you over, and talk about the right tier. We do not meter you by surprise.
No. Managed takedowns are included on Professional and Enterprise, with no per-request fee. Enterprise adds contractual commitments on how fast we file, chase and report — not on how fast a third party removes the content, which was never ours to promise.
Yes. Yes — an evaluation runs against your own domains, so you see real findings from your own estate rather than a canned demo dataset. Book a demo and we will set the scope with you.
Often, but not always. 0DaySecure is built to be the external-facing half of your programme and to push findings into the tools you already run. If you have a feed you value, we integrate rather than duplicate.
Get a quote against your real scope.
Bring your domains. We map what is exposed, show you exactly what we would be monitoring, and price it from there.
- Scope agreed before anything is signed
- No per-alert or per-takedown fees
- Findings are yours to keep