Pricing

Simple pricing for serious cloud security teams.

Pay by analyst seat, not by the alert. 14-day free trial on all plans. No credit card required to start.

Pricing tiers

Starter
$149 /month
Up to 2 analyst seats, 500K events/day
  • Core alert correlation engine
  • AWS Security Hub + CloudTrail ingestion
  • MITRE ATT&CK technique tagging
  • Auto-close with reasoning log
  • Slack alert notifications
  • 30-day event retention
  • Email support
Start Free Trial

14-day free trial, no credit card

Most Popular
Team
$399 /month
Up to 8 analyst seats, 5M events/day
  • Everything in Starter
  • SIEM integrations: Splunk, Elastic, Sentinel, Datadog
  • Custom Sigma-compatible detection rules
  • Multi-cloud: AWS + Azure + GCP
  • Role-based access control (RBAC)
  • SAML 2.0 SSO
  • 90-day event retention
  • Audit log export (JSON/CSV)
  • Priority support + onboarding session
Start Free Trial
Enterprise
Custom
Unlimited analysts, custom event volume
  • Everything in Team
  • On-premises connector option
  • Dedicated security review
  • Custom data retention policy
  • SOC2 compliance documentation support
  • Dedicated Customer Success Manager
  • 99.9% uptime SLA guarantee
  • Custom contracts (annual, multi-year)
Contact Sales

What you're paying for alert noise right now

Current cost of false positives

1 analyst shift/day on triage work x $55/hr fully loaded x 22 work days = $1,210/month in analyst time spent on noise.

Cloakmint Team plan

Covers up to 8 analysts for $399/month. That's $811/month net savings on analyst time alone, before factoring in faster incident response.

Conservative estimate. Based on transparent inputs: $55/hr fully loaded analyst cost x 1 shift/day of triage overhead x 22 days. Your actual savings depend on team size and current alert volume.

Common pricing questions

An analyst seat is any user account with login access to the Cloakmint dashboard. Read-only audit accounts (for compliance reviewers) do not count against seat limits. API-only service accounts also do not consume a seat.
We don't drop events or disable correlation when you exceed your daily cap. Instead, you'll receive an in-app notification and can choose to upgrade your plan or add a burst allocation. We'll never let real incidents go unprocessed because of a volume overage.
Starter and Team plans are month-to-month with no minimum commitment. Enterprise plans are annual by default but we can discuss multi-year contracts. Cancel anytime from your account settings.
Event log data is stored in-region (US-East for most customers, configurable for Enterprise). Starter plan: 30-day retention. Team plan: 90-day retention. Enterprise: custom retention policy. Data is encrypted at rest (AES-256) and in transit (TLS 1.3). You can request deletion of all your data at any time.

Need unlimited analysts and custom event volume?

Enterprise plans include dedicated security review, on-premises connector options, and a CSM who knows your environment.

Contact Sales View Security Practices