Three editions. Six add-ons. Zero meters.
You are buying a decision layer, not renting a pipe. Every edition runs on your own infrastructure under a signed licence that says plainly what you are entitled to and when it expires. Nothing is billed per gigabyte, per endpoint or per tenant-month — so the day your telemetry doubles is not the day your bill does.
The core Decision Center for teams running Wazuh. Real cases, a real queue, real SLA clocks — on your own box, at no cost, for as long as you like.
- Wazuh as the single source
- Alerts, cases, analyst screens, notifications
- Decision queue and SLA clocks
- 72 MITRE-mapped detection packs, importable from a screen
- SSO, MFA, role-based access, tamper-evident audit trail
- No correlation engine (one alert, one case)
- No vendor connectors, no threat intel
The full Decision Center for one organisation, sitting above whatever detection stack you already run, with add-ons à la carte.
- The Correlation Engine: nine strategies vote on one explained verdict, with readable decision traces and attack storylines
- Plug in what you have: open-source stacks (Wazuh, OpenSearch, Elastic, ClickHouse) and market platforms (Splunk, Sentinel, CrowdStrike, Defender, SentinelOne, Cortex XDR, Okta, Entra, AWS, Azure…) — 23 connectors, push webhooks, passive tailing of your SIEM, and custom connectors built on request
- Burst absorption: hundreds of low-severity repeats become one correctly rated case
- Response workbooks with approval gates; destructive actions always need a person
- Vulnerability Operations Centre
- Signed updates that roll back on a failed health check
- Any add-on module below, individually
Client plus the multi-client bundle: run every customer from one deployment without one customer ever seeing another.
- Everything in Client
- One case space per client, enforced at several independent layers
- Client attribution with a quarantine queue — an alert we cannot place waits, it is never guessed — and an onboarding wizard per client
- Per-client scope on reports, vulnerability operations and the AI analyst
- Cross-client roll-up for your own view of the estate
- White-label: your logo, your colours, your name on the product
- You bill your clients. We never bill your volume.
Licensed individually. Pay for what you switch on.
Six modules, each quoted on its own. Start with the Decision Center, add the capabilities your estate — or your clients — actually ask for, and nothing else.
Advanced AI · SIROC
An AI analyst that lists its hypotheses and evidence before its verdict — and is downgraded in front of your analyst when that evidence is not in the case. A local open-licence model on CPU by default; your own cloud key per task by choice; secrets and personal data redacted before any cloud call, every such call recorded in a tamper-proof ledger, spend capped. Includes the governed gateway that lets an external AI agent work your queue.
Shows its workIntelligence
Threat feeds and indicator hunting across your own alerts, qualification of what a feed is actually telling you, CVE enrichment, campaign clustering, and indicator exchange with peers over standard formats (STIX/TAXII, MISP) under sharing rules you set.
Context on every caseSOC Reporting
Case and client reports, scorecards for NIST CSF, ISO 27001, GDPR, DORA and NIS2, scheduled delivery, and evidence packs that state their own methodology and coverage. Every number carries the evidence behind it; a metric that cannot be computed says so.
Board-ready, regulator-readyAutomations
Workbooks and runbooks with approval gates, remote response agents that keep vendor credentials on your own hosts, and ticket push to ServiceNow, Jira and TheHive. Destructive actions such as isolating a host always require a person.
Bounded autonomyAdvanced Wazuh · Fleet Analytics
Endpoint-fleet health, telemetry coverage scoring and the vulnerability lifecycle for estates that run Wazuh agents — so you learn which hosts have gone quiet before an incident tells you.
Coverage you can proveExternal Attack Surface
Watch your domains from the outside: newly issued certificates, forgotten subdomains and look-alike domains that could carry a phishing campaign against your brand or your clients'.
Your estate as an attacker sees itOne signed file per deployment. No meter anywhere.
- A signed licence names your edition, your add-ons, your allowances and its expiry. Your deployment checks it; it cannot issue one.
- Quoted per deployment and per year. Not per gigabyte, per endpoint, per tenant or per seat-month. Your ingest volume is your business.
- Expiry is loud, not silent. You are warned ahead of time, there is a grace period, and past it the platform says so plainly instead of quietly degrading.
- Seat and asset allowances are part of the quote, so growth is a conversation before renewal, never a surprise invoice.
- Updates are signed, applied when your admin chooses, and roll back automatically on a failed health check. An offline path exists for air-gapped sites.
One box. The people who run it. The decision layer.
Infrastructure: one self-hosted host, VPS or on-prem, Debian or Ubuntu, Docker or bare metal, no GPU required — it installs in minutes. Operations: the detection stack you already run and your analysts' time, which is exactly the labour the product gives back. The licence is the only line item Seculogik adds, and it is quoted per deployment and per year.
We are an early-stage vendor with a design-partner programme rather than a published rate card. Every quote comes with the same offer: a thirty-minute session on your own telemetry before you sign anything.
Request a quoteWhere the meter is.
| Platform | Ingest pricing basis | Self-hostable | Documented multi-tenant | Local AI option |
|---|---|---|---|---|
| Seculogik | None — no per-GB meter | Yes, one box | Yes, MSSP edition | Yes, by default |
| Microsoft Sentinel | Per GB ($4.30 PAYG, commit tiers lower) | No | Lighthouse | No |
| CrowdStrike NG-SIEM | Per GB for third-party data ($5.95 on AWS Marketplace) | No | Flight Control | No |
| Splunk Enterprise Security | Not published (per GB or workload) | Yes | Not documented for ES | No |
| IBM QRadar | Not published (EPS) | Yes | Yes | No AI-analyst layer |
| Elastic Security | From $0.09 per GB (cloud) | Yes | Spaces | Bring your own |
Competitor figures are public list rates as of September 2026 and are indicative only; several vendors do not publish. Multi-tenancy and self-hosting columns reflect vendor documentation reviewed in our market benchmark. Gartner, on the record: “SIEM buyers have grown increasingly frustrated by SIEM cost bloat.”
Tell us about your estate. We reply with a scoped quote.
How many clients, which sources you run today, and whether you want the AI analyst on-box or with your own cloud key. That is all a quote needs.