Buyer fit
Good fit when
- ✓SMBs and MSPs wanting affordable MDR with published per-user pricing
- ✓Canadian organizations needing domestic data hosting and PIPEDA compliance
- ✓Organizations that value MITRE-validated detection quality
Watch out when
- ×Organizations with existing CrowdStrike/SentinelOne/Defender deployments (requires proprietary agent)
- ×Teams needing raw log query access or broad third-party integrations
Coverage
4 of 6 attack surfaces in the base price; the rest are separately priced.
Platform
Additional capabilities
Incident response
Pricing
Per-user, per-month.
Checked Jun 2026
How pricing works+−
MDR Core: $3-$20/user/month (volume discounts apply). MDR Complete: custom pricing.
Cost caveats
- –MDR Core excludes network monitoring, DNS firewall, and dark web monitoring
- –Exact MDR Core price depends on volume and discounting within the published range
- –Requires proprietary Field Effect agent, cannot use existing EDR
What costs extra (3)+−
- –IR retainer packages (two options, separate from MDR)
- –Extended log retention beyond 90 days
- –MDR Core excludes network monitoring, DNS firewall, dark web monitoring
Figures from named sources only (vendor pages, marketplaces, resellers, public procurement records, buyer reports), each dated. Nothing here is our estimate.
Team and access
Reputation
PeerSpot 9.2/10 (Jan 2026). SoftwareReviews 9.5/10 composite (423 verified reviews, +98 Net Emotional Footprint, Data Quadrant Leader four consecutive years 2022-2025). G2 Highest ROI in MDR, Winter 2026. Praised for easy setup, noise reduction, and MSP value. Main criticisms: limited third-party integrations and no raw log visibility.
What customers praise
- ✓Fast setup (hours, not weeks) with vendor-claimed 99.9% noise reduction
- ✓Published per-user pricing range ($3-$20/user/month) rare in the MDR market
- ✓MITRE-validated detection (11-min MTTD, detected every measured step)
Common complaints
- ×Limited third-party integrations compared to enterprise MDR providers
- ×No raw log query access, dashboard-level visibility only
- ×MDR Core excludes network monitoring, making Complete the real product for most buyers
Limited Reddit discussion. Less discussed than CrowdStrike, SentinelOne, or Huntress on r/msp. Generally positive in MSP community for SMB market segment.
Questions to ask
- 1.
What specific response actions does each Active Response policy level take, and can we customize beyond the four presets?
- 2.
What is the price delta between MDR Core and MDR Complete, and what does the upgrade path look like?
- 3.
What level of raw log access do we get through the portal and API?
- 4.
How does your single-SOC model in Ottawa handle surge capacity or regional outages?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
