04 / Pricing
Transparent per-seat.
No retainer, no “call us.”
Sourced from the same mission as the landing page: built for the one- or two-person security budget, with a clear upgrade path for teams that outgrow a single cloud. Cancel any month.
Crowmark Starter
Starter — try it free for 7 days.
The self-serve way to bring Crowmark on for a single cloud. 7 days on the house, then billed monthly or annually — no retainer, no commitment past the trial.
- Up to 12 integrations (one cloud · one IdP · endpoint · dark-web · CVE feed)
- 07:00 morning brief, weekdays
- Auto-contained IOC handling · 90-day retention
7-day free trial
After 7 days you'll be charged $49/mo per seat unless you cancel.
Card required at checkout. Cancel from your subscription portal any time during the trial — no charge.
Compare Bronze, Silver, Gold, and Platinum
Year one for a four-person team on Silver runs less than one junior analyst’s fully-loaded cost.
| What you get | Bronze $49per seat / month For the one-person security budget covering a single cloud. | Silver Most teams pick Silver $99per seat / month For the two- to five-person security team over a single cloud. | Gold $199per seat / month For multi-cloud teams with on-call escalation tiers. | Platinum Concierge Concierge coverage for large security teams $299per seat / month For multi-region or 24/7 SOC teams with board-level reporting needs. |
|---|---|---|---|---|
| IntegrationsHow many telemetry sources can stream in | Up to 12 (one cloud · one IdP · endpoint · dark-web · CVE feed) | Up to 25 (multi-cloud · multi-IdP · endpoint · dark-web · CVE · ticketing) | Unlimited (AWS · Azure · GCP · Okta · Entra · Google · Slack · PagerDuty · ticketing) | Unlimited + custom connector engineering |
| Daily brief cadenceWhen the morning brief lands and where it goes | 07:00 inbox, weekdays — one named reader | 07:00 email + Slack push, weekdays | 07:00 multi-channel · digest cadence optional | 07:00 multi-channel + on-demand incident push |
| Response SLAHow quickly Crowmark acknowledges a flagged item | Best-effort — no contractual response window | 4-hour acknowledgement · 30-min on critical | 1-hour acknowledgement · 15-min on critical incidents | 30-min acknowledgement · 5-min on critical incidents |
| Human handoffWhen the AI escalates to a human on your side | Email-only · self-serve remediation guides | Slack escalation · named on-call engineer | Dedicated analyst · quarterly purple-team review | Named 24/7 SOC team + annual red-team engagement |
| Sign up | 1 seat$49/mo total 1 seat · adjust here before checkout. Cancel any month. | 1 seat$99/mo total 1 seat · adjust here before checkout. Cancel any month. | 1 seat$199/mo total 1 seat · adjust here before checkout. Cancel any month. | 1 seat$299/mo total 1 seat · adjust here before checkout. Cancel any month. |
For the one-person security budget covering a single cloud.
- IntegrationsUp to 12 (one cloud · one IdP · endpoint · dark-web · CVE feed)
- Daily brief cadence07:00 inbox, weekdays — one named reader
- Response SLABest-effort — no contractual response window
- Human handoffEmail-only · self-serve remediation guides
- Morning brief, weekday delivery
- Auto-contained IOC handling
- 90-day retention
For the two- to five-person security team over a single cloud.
- IntegrationsUp to 25 (multi-cloud · multi-IdP · endpoint · dark-web · CVE · ticketing)
- Daily brief cadence07:00 email + Slack push, weekdays
- Response SLA4-hour acknowledgement · 30-min on critical
- Human handoffSlack escalation · named on-call engineer
- Morning brief, weekday delivery
- Auto-contained IOC handling
- 90-day retention
For multi-cloud teams with on-call escalation tiers.
- IntegrationsUnlimited (AWS · Azure · GCP · Okta · Entra · Google · Slack · PagerDuty · ticketing)
- Daily brief cadence07:00 multi-channel · digest cadence optional
- Response SLA1-hour acknowledgement · 15-min on critical incidents
- Human handoffDedicated analyst · quarterly purple-team review
- Morning brief, weekday delivery
- Auto-contained IOC handling
- 90-day retention
Concierge coverage for large security teams
For multi-region or 24/7 SOC teams with board-level reporting needs.
- IntegrationsUnlimited + custom connector engineering
- Daily brief cadence07:00 multi-channel + on-demand incident push
- Response SLA30-min acknowledgement · 5-min on critical incidents
- Human handoffNamed 24/7 SOC team + annual red-team engagement
- Morning brief, weekday delivery
- Auto-contained IOC handling
- 90-day retention
All plans include morning-brief delivery, auto-contained handling of IOC egress, and 90-day retention. Annual pricing: Bronze $500/seat, Silver $1,000/seat, Gold $2,000/seat, Platinum $3,000/seat — save ~15% vs. monthly.
Side by side
Feature comparison
See at a glance which capabilities come with each tier.
| Capability | Bronze | Silver Recommended | Gold | Platinum |
|---|---|---|---|---|
| IntegrationsTelemetry sources streaming into Crowmark | Up to 12 (one cloud · one IdP · endpoint · dark-web · CVE feed) | Up to 25 (multi-cloud · multi-IdP · endpoint · dark-web · CVE · ticketing) | Unlimited (AWS · Azure · GCP · Okta · Entra · Google · Slack · PagerDuty · ticketing) | Unlimited + custom connector engineering |
| Monitored surfacesWhich account / identity / app surfaces we watch | 1 cloud · 1 IdP · endpoints · SaaS essentials | + additional IdP · expanded SaaS · ticketing | Multi-cloud · multi-IdP · full SaaS & ticketing | + executive impersonation watch · full app-layer telemetry |
| Dark-web coverageWhat we look for in dark-web and paste-site sources | Identity-only dark-web watch | + credential & paste-site monitoring | + supply-chain & executive impersonation | + supply-chain deep-watch · vendor compromise alerts |
| CVE mappingHow we correlate CVEs against your asset inventory | Vendor-feed correlation, daily | + priority weighting by asset criticality | + custom asset allow/deny list · 30-min SLA on KEV hits | + custom asset allow/deny list · 30-min SLA on KEV hits + custom threat-intel feeds |
| Response SLAAcknowledgement window on a flagged item | Best-effort — no contractual response window | 4-hour acknowledgement · 30-min on critical | 1-hour acknowledgement · 15-min on critical incidents | 30-min acknowledgement · 5-min on critical incidents |
| Dedicated analystNamed humans behind the AI escalation | None — email-only escalation | Named on-call engineer (rotating) | Dedicated analyst · quarterly purple-team review | Global 24/7 named SOC · every-business-day review · annual red-team engagement |
- IntegrationsTelemetry sources streaming into CrowmarkUp to 12 (one cloud · one IdP · endpoint · dark-web · CVE feed)
- Monitored surfacesWhich account / identity / app surfaces we watch1 cloud · 1 IdP · endpoints · SaaS essentials
- Dark-web coverageWhat we look for in dark-web and paste-site sourcesIdentity-only dark-web watch
- CVE mappingHow we correlate CVEs against your asset inventoryVendor-feed correlation, daily
- Response SLAAcknowledgement window on a flagged itemBest-effort — no contractual response window
- Dedicated analystNamed humans behind the AI escalationNone — email-only escalation
- IntegrationsTelemetry sources streaming into CrowmarkUp to 25 (multi-cloud · multi-IdP · endpoint · dark-web · CVE · ticketing)
- Monitored surfacesWhich account / identity / app surfaces we watch+ additional IdP · expanded SaaS · ticketing
- Dark-web coverageWhat we look for in dark-web and paste-site sources+ credential & paste-site monitoring
- CVE mappingHow we correlate CVEs against your asset inventory+ priority weighting by asset criticality
- Response SLAAcknowledgement window on a flagged item4-hour acknowledgement · 30-min on critical
- Dedicated analystNamed humans behind the AI escalationNamed on-call engineer (rotating)
- IntegrationsTelemetry sources streaming into CrowmarkUnlimited (AWS · Azure · GCP · Okta · Entra · Google · Slack · PagerDuty · ticketing)
- Monitored surfacesWhich account / identity / app surfaces we watchMulti-cloud · multi-IdP · full SaaS & ticketing
- Dark-web coverageWhat we look for in dark-web and paste-site sources+ supply-chain & executive impersonation
- CVE mappingHow we correlate CVEs against your asset inventory+ custom asset allow/deny list · 30-min SLA on KEV hits
- Response SLAAcknowledgement window on a flagged item1-hour acknowledgement · 15-min on critical incidents
- Dedicated analystNamed humans behind the AI escalationDedicated analyst · quarterly purple-team review
- IntegrationsTelemetry sources streaming into CrowmarkUnlimited + custom connector engineering
- Monitored surfacesWhich account / identity / app surfaces we watch+ executive impersonation watch · full app-layer telemetry
- Dark-web coverageWhat we look for in dark-web and paste-site sources+ supply-chain deep-watch · vendor compromise alerts
- CVE mappingHow we correlate CVEs against your asset inventory+ custom asset allow/deny list · 30-min SLA on KEV hits + custom threat-intel feeds
- Response SLAAcknowledgement window on a flagged item30-min acknowledgement · 5-min on critical incidents
- Dedicated analystNamed humans behind the AI escalationGlobal 24/7 named SOC · every-business-day review · annual red-team engagement
Notes
Self-serve onboarding
No professional-services engagement. Connectors ship ready-made; SSO and IdP linking can be done by anyone with admin in one afternoon.
Per-seat, not per-asset
Pricing tracks humans covered, not laptops or cloud accounts watched. Adding a contractor costs what adding a hire costs.
Cancel any month
No annual lock-in on Bronze and Silver. The auto-contained items stay on a 30-day tail after cancellation so you can hand off cleanly.
Ready when you are
Start a 14-day pilot. Bring one cloud, two integrations, and a contact.
Quick answers