Pricing
Simple pricing for serious cloud security teams.
Pay by analyst seat, not by the alert. 14-day free trial on all plans. No credit card required to start.
Pricing tiers
Starter
$149
/month
Up to 2 analyst seats, 500K events/day
- Core alert correlation engine
- AWS Security Hub + CloudTrail ingestion
- MITRE ATT&CK technique tagging
- Auto-close with reasoning log
- Slack alert notifications
- 30-day event retention
- Email support
14-day free trial, no credit card
Most Popular
Team
$399
/month
Up to 8 analyst seats, 5M events/day
- Everything in Starter
- SIEM integrations: Splunk, Elastic, Sentinel, Datadog
- Custom Sigma-compatible detection rules
- Multi-cloud: AWS + Azure + GCP
- Role-based access control (RBAC)
- SAML 2.0 SSO
- 90-day event retention
- Audit log export (JSON/CSV)
- Priority support + onboarding session
Enterprise
Custom
Unlimited analysts, custom event volume
- Everything in Team
- On-premises connector option
- Dedicated security review
- Custom data retention policy
- SOC2 compliance documentation support
- Dedicated Customer Success Manager
- 99.9% uptime SLA guarantee
- Custom contracts (annual, multi-year)
The ROI Math
What you're paying for alert noise right now
Current cost of false positives
1 analyst shift/day on triage work x $55/hr fully loaded x 22 work days = $1,210/month in analyst time spent on noise.
Cloakmint Team plan
Covers up to 8 analysts for $399/month. That's $811/month net savings on analyst time alone, before factoring in faster incident response.
Conservative estimate. Based on transparent inputs: $55/hr fully loaded analyst cost x 1 shift/day of triage overhead x 22 days. Your actual savings depend on team size and current alert volume.
FAQ
Common pricing questions
An analyst seat is any user account with login access to the Cloakmint dashboard. Read-only audit accounts (for compliance reviewers) do not count against seat limits. API-only service accounts also do not consume a seat.
We don't drop events or disable correlation when you exceed your daily cap. Instead, you'll receive an in-app notification and can choose to upgrade your plan or add a burst allocation. We'll never let real incidents go unprocessed because of a volume overage.
Starter and Team plans are month-to-month with no minimum commitment. Enterprise plans are annual by default but we can discuss multi-year contracts. Cancel anytime from your account settings.
Event log data is stored in-region (US-East for most customers, configurable for Enterprise). Starter plan: 30-day retention. Team plan: 90-day retention. Enterprise: custom retention policy. Data is encrypted at rest (AES-256) and in transit (TLS 1.3). You can request deletion of all your data at any time.
Need unlimited analysts and custom event volume?
Enterprise plans include dedicated security review, on-premises connector options, and a CSM who knows your environment.