OpenText vs Sapphire
OpenText is a Pure-play MDR that works with your existing tools. Sapphire is a Services firm that works with your existing tools. OpenText targets SMB and Mid-market organizations; Sapphire serves SMB, Mid-market, and Enterprise.
Buyer brief
OpenText is a Pure-play MDR that works with your existing tools. Sapphire is a Services firm that works with your existing tools. OpenText targets SMB and Mid-market organizations; Sapphire serves SMB, Mid-market, and Enterprise.
OpenText (Pure-play MDR) and Sapphire (Services firm) serve different buyer profiles. Your decision depends on whether you prioritize OpenText's sensible fit for smaller it teams that want opentext's threat intelligence and a 24/7 soc layered... or Sapphire's sapphire mdr is strongest for uk buyers that value local ownership, a crest-accredited uk soc and....
At a glance
| FIELD | ||
|---|---|---|
| Best fit | SMB and lower mid-market organizations that want a SOC layer over their existing endpoint stack | UK organisations that want MDR from a UK-owned provider with a UK-based CREST-accredited SOC |
| Price | Custom quote | Custom quote |
| Response authority | 1/6 actions · Approval required | 1/6 actions · Configurable |
| Stack | Works with existing stack | Works with existing stack |
| Data access | Dashboards | Dashboards |
| Warranty | None listed | None listed |
- Best fit
- SMB and lower mid-market organizations that want a SOC layer over their existing endpoint stack
- Price
- Custom quote
- Response authority
- 1/6 actions · Approval required
- Stack
- Works with existing stack
- Data access
- Dashboards
- Warranty
- None listed
- Best fit
- UK organisations that want MDR from a UK-owned provider with a UK-based CREST-accredited SOC
- Price
- Custom quote
- Response authority
- 1/6 actions · Configurable
- Stack
- Works with existing stack
- Data access
- Dashboards
- Warranty
- None listed
›› Detailed comparison
| FIELD | OpenTextTECH-AGNOSTIC | SapphireTECH-AGNOSTIC |
|---|---|---|
| ›› Fit | ||
| Target size | SMB, Mid-market | SMB, Mid-market, Enterprise |
| Sentiment | Mixed | Mixed |
| ›› Your stack | ||
| Approach | Works with your tools | Works with your tools |
| EDR integrations | CrowdStrikeMicrosoft DefenderSentinelOneSophosCarbon BlackBitdefender | EDR toolsMicrosoft technologies |
| SIEM integrations | Microsoft SentinelSplunk | ExabeamSIEM tools |
| Coverage | EPEndpoint: CoveredCloudCloud: CoveredIDIdentity: LimitedSaaSSaaS: CoveredNetNetwork: CoveredOTOT/IoT: Not covered | EPEndpoint: CoveredCloudCloud: CoveredIDIdentity: LimitedSaaSSaaS: CoveredNetNetwork: CoveredOTOT/IoT: Optional add-on |
| ›› Response | ||
| Response type | Guided Response | Active Remediation |
| Approval policy | Approval Required | Configurable |
| Response actions | Custom playbooks | Custom playbooks |
| IR included | Separate | ✓ Included |
| ›› Cost | ||
| Price range | Not published | Not published |
| Minimum seats | None | None |
| Breach warranty | – | – |
| ›› More details | ||
| Requires own agent | No | No |
| Endpoints | ✓ Included | ✓ Included |
| Cloud workloads | ✓ Included | ✓ Included |
| Identity | ~ Limited | ~ Limited |
| SaaS apps | ✓ Included | ✓ Included |
| Network | ✓ Included | ✓ Included |
| OT/ICS | Not offered | + Optional |
| Threat hunting | ✓ Included | ✓ Included |
| Response SLA | Not disclosed | Not disclosed |
| 24/7 coverage | ✓ | ✓ |
| Pricing model | Custom quote, not published. Sold direct and through OpenText partner channel. | Custom quote. Sapphire does not publish MDR package pricing. |
| Hidden cost warnings | Co-managed model means the customer's team still does the actual containment work. No published SLA, contractual response commitments must be negotiated. Headline detection metrics come from a 2021 launch announcement and have not been independently verified | Public pages do not publish response SLAs or exact response-authority rules.. MDR, MXDR and OT SOC scope can differ materially, so buyers should define monitored surfaces in the order form.. The page publishes vendor-reported comparative metrics without independent methodology.. IR hours are included as standard, but buyers should confirm number of hours, coverage triggers and overage rates. |
| Data portability | Partial | Partial |
| Contract terms | Annual | Custom |
| Channels | EmailPortalPhone | PortalEmailPhone |
| Data access | Dashboards | Dashboards |
| Dedicated analyst | – | – |
| SOC regions | North America | Europe |
| Onboarding | Not published | Sapphire references onboarding and implementation that can be shorter than expected, but no standard public MDR onboarding timeline was found. |
| Industry focus | SMBHealthcareFinancial ServicesPublic Sector | Public SectorDefenceFinancial ServicesProfessional ServicesIndustrialsManufacturingOperational TechnologyHealthcare |
| MTTD | Less than 30 minutes (vendor-published, 2021 launch claim) | Not published |
| MTTR | Not published | Not published |
| Community view | Public review coverage of OpenText Core MDR is thin. Capterra lists the product with zero reviews, and there is no Gartner Peer Insights MDR profile or G2 page with a meaningful review base. Practitioner discussion mostly references the broader OpenText Cybersecurity portfolio and the Webroot heritage rather than the MDR service itself. | Sapphire has limited MDR-specific community review volume. The public buyer case is strongest for UK ownership, UK-based SOC delivery, CREST SOC accreditation and IT/OT services depth. Buyers should validate response authority, price, metrics and the exact split between MDR, MXDR, OT SOC and incident-response work. |
| Compliance | Not published | ISO 27001NISTHIPAADORACyber Essentials PlusCRESTGDPRPCI DSS |
| Certifications | Not published | CREST SOCCREST Penetration TestingCyber Essentials PlusISO 27001 |
| Founded | 1991 | 1996 |
| Data retention | Not published | Not published as a standard MDR retention period. |
| API available | ✓ | – |
| Website | Visit → | Visit → |
›› FAQ
What is the main difference between OpenText and Sapphire?
OpenText is a Pure-play MDR that is technology-agnostic (works with your existing tools). Sapphire is a Services firm that is technology-agnostic (works with your existing tools).
How do OpenText and Sapphire differ in response capabilities?
OpenText supports 1 autonomous actions (custom playbooks) and requires approval before acting. Sapphire supports 1 autonomous actions (custom playbooks) and approval is configurable. Incident response is not included with OpenText and included with Sapphire.
How does OpenText pricing compare to Sapphire?
OpenText pricing: Not published. Sapphire pricing: Not published. Watch for with OpenText: Co-managed model means the customer's team still does the actual containment work; No published SLA, contractual response commitments must be negotiated. Watch for with Sapphire: Public pages do not publish response SLAs or exact response-authority rules.; MDR, MXDR and OT SOC scope can differ materially, so buyers should define monitored surfaces in the order form..
Should I choose OpenText or Sapphire?
Choose OpenText if: sMB and lower mid-market organizations that want a SOC layer over their existing endpoint stack. Choose Sapphire if: uK organisations that want MDR from a UK-owned provider with a UK-based CREST-accredited SOC. OpenText is not ideal for buyers who need analysts to isolate endpoints or kill processes without customer approval. Sapphire is not ideal for buyers that need public MDR pricing or contractual response SLAs before sales engagement.
Daylight Security
AI-native MDR for buyers comparing active remediation across endpoint, cloud, identity, and SaaS. Daylight works with existing EDR/SIEM stacks and uses ChatOps-native collaboration, so it can be a useful third reference point in this comparison.