Buyer fit
Good fit when
- ✓Organizations with existing EDR investments (CrowdStrike, Microsoft, SentinelOne, Carbon Black, Cortex XDR, Trend Micro, Jamf) wanting MDR layered on top
- ✓Linux-heavy environments needing purpose-built Linux EDR for containers and Kubernetes
- ✓Security teams wanting Slack-native SOC communication with configurable automated response playbooks
Watch out when
- ×Global organizations needing follow-the-sun SOC coverage, only Denver SOC confirmed
- ×Organizations wanting included incident response, IR is via partner network and not part of base service
- ×Buyers concerned about long-term vendor-agnostic independence under Zscaler ownership, elevated churn disclosed Feb 2026
Coverage
5 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Resource-based subscription priced per endpoint, per user, and per cloud resource.
Checked Jul 2026
Sourced figures
Per-12-month list rates for endpoint, user/identity, cloud resource and network…
AWS Marketplace · checked Jul 2026
Aggregated anonymized buyer contract data, post-acquisition. 100-500 endpoints…
Vendr · 2026-02
Pre-acquisition estimate attributing the $120/$100/$250/$20 annual rates to the…
UnderDefense · 2025-03-21
How pricing works+−
Resource-based subscription: per-endpoint + per-identity/user + per-cloud-resource (plus a per-network unit on the AWS Marketplace listing). Three tiers: Core (24x7 detection and response), Complete (identity, endpoint and cloud, most popular), Enterprise (custom, dedicated support). Sold annual or multi-year (12/24/36 month terms).
Cost caveats
- –Overage fees when unit counts exceed the contract (AWS overage: $10.00/endpoint, $8.33/account, $20.83/cloud resource, $1.66/network per unit)
- –Adding cloud, identity or network coverage mid-contract typically prices higher than bundling it up front (Vendr, Feb 2026)
- –Annual price escalators of 3 to 5% typical, negotiable to cap or remove on multi-year deals (Vendr, Feb 2026)
3 more+−
- –Three separate meters (endpoint + user + cloud) mean cost can scale faster than a flat per-endpoint model as identity and cloud footprints grow
- –Vendor pricing page no longer prints per-unit figures; concrete rates come from the AWS Marketplace listing or a custom quote
- –Zscaler acquisition (completed Aug 2025): no packaging or contract changes published yet, but Forrester flags risk to vendor-agnostic partnerships and no public integration timeline
What costs extra (8)+−
- –Complete tier for multi-domain MDR, API access, Red Canary Copilot, configurable data exporter, detection and response advisory
- –Enterprise tier for dedicated technical support, custom intelligence briefings, threat hunter collaboration, unlimited integrations
- –Per-user identity coverage ($100/user/yr list on AWS; $5 to $15/user negotiated per Vendr)
- –Per-cloud-resource coverage ($250/resource/yr list on AWS; 60 to 80% of endpoint rate per Vendr)
- –Per-network coverage ($20/network/yr list on AWS)
- –Add-on services: Active Remediation, Managed Phishing Response, Security Data Lake, Training and Tabletops, SIEM Jumpstart
- –Incident response retainer (via partner network, not in base service)
- –OT/ICS monitoring via Dragos integration
Warranty conditions+−
No breach protection warranty published. Proof-of-value / proof-of-concept engagement available, deploys in minutes; not a free trial.
Figures from named sources only (vendor pages, marketplaces, resellers, public procurement records, buyer reports), each dated. Nothing here is our estimate.
Team and access
Reputation
Forrester Wave MDR Leader Q1 2025. G2 4.7/5 (127 reviews, #1 customer satisfaction). Gartner Peer Insights 4.6/5 (131+ reviews). PeerSpot 9.0/10. Product quality remains strong post-Zscaler acquisition, but Zscaler disclosed elevated customer churn in Feb 2026 earnings with market mindshare declining from 4.2% to 2.9% year-over-year.
What customers praise
- ✓Broadest EDR integration in MDR (9 platforms) with vendor-agnostic approach maintained post-acquisition
- ✓Detection-as-code methodology with all detections mapped to MITRE ATT&CK
- ✓Slack-native SOC communication with responsive Threat Response Engineers
Common complaints
- ×Elevated customer churn post-Zscaler acquisition, market mindshare declined 4.2% to 2.9% (Zscaler Q2 FY2026 earnings, Feb 2026)
- ×Single Denver SOC with no follow-the-sun model for global organizations
- ×Vendor site no longer prints per-unit rates (AWS Marketplace publishes them), and the resource-based model can scale unexpectedly
Limited direct Reddit discussion. Generally mentioned favorably alongside Expel and CrowdStrike Falcon Complete as a top-tier MDR option in cybersecurity communities.
Questions to ask
- 1.
Given the elevated customer churn Zscaler disclosed in Feb 2026 earnings, what commitments can you provide about maintaining vendor-agnostic EDR partnerships over our contract term?
- 2.
What is the total cost for our environment including per-endpoint, per-user, and per-cloud-resource charges?
- 3.
With a single SOC in Denver, how do you provide 24/7 coverage and what is the overnight staffing model?
- 4.
What happens to our detection rules and SOAR playbooks if we leave Red Canary?
- 5.
Is the Palo Alto Managed XSIAM partnership still active under Zscaler ownership?
- 6.
What is the FedRAMP certification timeline for government sector customers?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
