Offer review · 2026

Three editions. Six add-ons. Zero meters.

You are buying a decision layer, not renting a pipe. Every edition runs on your own infrastructure under a signed licence that says plainly what you are entitled to and when it expires. Nothing is billed per gigabyte, per endpoint or per tenant-month — so the day your telemetry doubles is not the day your bill does.

Free
€0 forever · self-hosted

The core Decision Center for teams running Wazuh. Real cases, a real queue, real SLA clocks — on your own box, at no cost, for as long as you like.

  • Wazuh as the single source
  • Alerts, cases, analyst screens, notifications
  • Decision queue and SLA clocks
  • 72 MITRE-mapped detection packs, importable from a screen
  • SSO, MFA, role-based access, tamper-evident audit trail
  • No correlation engine (one alert, one case)
  • No vendor connectors, no threat intel
Start free
Commercial entry
Client
Per deployment · quoted annually

The full Decision Center for one organisation, sitting above whatever detection stack you already run, with add-ons à la carte.

  • The Correlation Engine: nine strategies vote on one explained verdict, with readable decision traces and attack storylines
  • Plug in what you have: open-source stacks (Wazuh, OpenSearch, Elastic, ClickHouse) and market platforms (Splunk, Sentinel, CrowdStrike, Defender, SentinelOne, Cortex XDR, Okta, Entra, AWS, Azure…) — 23 connectors, push webhooks, passive tailing of your SIEM, and custom connectors built on request
  • Burst absorption: hundreds of low-severity repeats become one correctly rated case
  • Response workbooks with approval gates; destructive actions always need a person
  • Vulnerability Operations Centre
  • Signed updates that roll back on a failed health check
  • Any add-on module below, individually
Request a quote
MSSP
Per deployment · quoted annually

Client plus the multi-client bundle: run every customer from one deployment without one customer ever seeing another.

  • Everything in Client
  • One case space per client, enforced at several independent layers
  • Client attribution with a quarantine queue — an alert we cannot place waits, it is never guessed — and an onboarding wizard per client
  • Per-client scope on reports, vulnerability operations and the AI analyst
  • Cross-client roll-up for your own view of the estate
  • White-label: your logo, your colours, your name on the product
  • You bill your clients. We never bill your volume.
Talk to us about MSSP
Add-on modules

Licensed individually. Pay for what you switch on.

Six modules, each quoted on its own. Start with the Decision Center, add the capabilities your estate — or your clients — actually ask for, and nothing else.

AI

Advanced AI · SIROC

An AI analyst that lists its hypotheses and evidence before its verdict — and is downgraded in front of your analyst when that evidence is not in the case. A local open-licence model on CPU by default; your own cloud key per task by choice; secrets and personal data redacted before any cloud call, every such call recorded in a tamper-proof ledger, spend capped. Includes the governed gateway that lets an external AI agent work your queue.

Shows its work
TI

Intelligence

Threat feeds and indicator hunting across your own alerts, qualification of what a feed is actually telling you, CVE enrichment, campaign clustering, and indicator exchange with peers over standard formats (STIX/TAXII, MISP) under sharing rules you set.

Context on every case
RP

SOC Reporting

Case and client reports, scorecards for NIST CSF, ISO 27001, GDPR, DORA and NIS2, scheduled delivery, and evidence packs that state their own methodology and coverage. Every number carries the evidence behind it; a metric that cannot be computed says so.

Board-ready, regulator-ready
AU

Automations

Workbooks and runbooks with approval gates, remote response agents that keep vendor credentials on your own hosts, and ticket push to ServiceNow, Jira and TheHive. Destructive actions such as isolating a host always require a person.

Bounded autonomy
FA

Advanced Wazuh · Fleet Analytics

Endpoint-fleet health, telemetry coverage scoring and the vulnerability lifecycle for estates that run Wazuh agents — so you learn which hosts have gone quiet before an incident tells you.

Coverage you can prove
EA

External Attack Surface

Watch your domains from the outside: newly issued certificates, forgotten subdomains and look-alike domains that could carry a phishing campaign against your brand or your clients'.

Your estate as an attacker sees it
How the licence works

One signed file per deployment. No meter anywhere.

  • A signed licence names your edition, your add-ons, your allowances and its expiry. Your deployment checks it; it cannot issue one.
  • Quoted per deployment and per year. Not per gigabyte, per endpoint, per tenant or per seat-month. Your ingest volume is your business.
  • Expiry is loud, not silent. You are warned ahead of time, there is a grace period, and past it the platform says so plainly instead of quietly degrading.
  • Seat and asset allowances are part of the quote, so growth is a conversation before renewal, never a surprise invoice.
  • Updates are signed, applied when your admin chooses, and roll back automatically on a failed health check. An offline path exists for air-gapped sites.
What you pay for, honestly

One box. The people who run it. The decision layer.

Infrastructure: one self-hosted host, VPS or on-prem, Debian or Ubuntu, Docker or bare metal, no GPU required — it installs in minutes. Operations: the detection stack you already run and your analysts' time, which is exactly the labour the product gives back. The licence is the only line item Seculogik adds, and it is quoted per deployment and per year.

We are an early-stage vendor with a design-partner programme rather than a published rate card. Every quote comes with the same offer: a thirty-minute session on your own telemetry before you sign anything.

Request a quote
Compared

Where the meter is.

PlatformIngest pricing basisSelf-hostableDocumented multi-tenantLocal AI option
SeculogikNone — no per-GB meterYes, one boxYes, MSSP editionYes, by default
Microsoft SentinelPer GB ($4.30 PAYG, commit tiers lower)NoLighthouseNo
CrowdStrike NG-SIEMPer GB for third-party data ($5.95 on AWS Marketplace)NoFlight ControlNo
Splunk Enterprise SecurityNot published (per GB or workload)YesNot documented for ESNo
IBM QRadarNot published (EPS)YesYesNo AI-analyst layer
Elastic SecurityFrom $0.09 per GB (cloud)YesSpacesBring your own

Competitor figures are public list rates as of September 2026 and are indicative only; several vendors do not publish. Multi-tenancy and self-hosting columns reflect vendor documentation reviewed in our market benchmark. Gartner, on the record: “SIEM buyers have grown increasingly frustrated by SIEM cost bloat.”

Next step

Tell us about your estate. We reply with a scoped quote.

How many clients, which sources you run today, and whether you want the AI analyst on-box or with your own cloud key. That is all a quote needs.