SKU Proposal

Product
Packaging

Modern security operations demand coordinated, autonomous entry points—purpose-built for both enterprise SOCs and security service providers to augment human-led operations at scale.

Agentic Investigations

AI-native investigation platform — autonomously investigates alerts, builds contextual knowledge graphs, and delivers analyst-ready findings across your security stack.

  • Investigation
  • Knowledge Graph
  • Alert Triage
  • Custom Reporting
Agentic Detection

AI-native detection that autonomously ingests, correlates, and triages security events — elevating high-confidence threats for analyst review while eliminating manual alert queues.

  • Log Store (add-on)
  • Detection Engine
  • Detection Tuning
  • Federated Search
  • Recommended to include Agentic Investigations
Agentic Response

Orchestrates automated investigation and response workflows across your security stack — keeping humans in the loop while reducing manual effort at machine speed.

  • Case Management
  • Response
  • Orchestration
  • Workflow Designer
  • Recommended to include Agentic Investigations
Agentic Risk Mitigation

Proactive risk reduction platform — continuous threat hunting, adversarial simulation, security hardening to find exposures before they become incidents.

  • Threat Hunt
  • Vulnerability AssessmentComing Soon
  • Purple TeamComing Soon
  • Attack Surface ManagementComing Soon
  • Recommended to include Agentic Investigations
01
SKU Proposal

PLAID
Services

Human Experts — All PLAID Services

Managed practitioners embedded in your workflow to extend platform capability and security coverage.

PLAID Platform specialists who accelerate time-to-value through hands-on implementation, tuning, and continuous optimization.
PLAID Elite Senior practitioners delivering active monitoring & response, threat hunting, co-managed detection operations, and on-demand incident response.
PLAID
Onboarding
Guided deployment and initial configuration
Platform Connectivity
Integrating data sources and connectors
Tuning
Alert fidelity improvement and noise reduction
Optimization
Continuous platform and workflow improvement
24/7 Monitoring & Response

Senior analysts on shift around the clock, supervising every escalated case that requires human judgment.

  • Round-the-clock 7AI agent oversight
  • Incident triage and escalation
  • Active response coordination
  • Threat intelligence-led response
Threat Hunt

Proactive adversary discovery through intelligence-driven and hypothesis-based hunts before incidents occur.

  • Ad hoc hypothesis-driven hunts
  • 7AI curated threat intelligence
  • Proactive emerging threat coverage
  • Hunt findings and reporting
Co-Managed Detection OperationsComing Soon

We author, tune, and operate detection content as an extension of your team.

  • Detection rule authoring and tuning
  • 7AI Log Store or 3rd party SIEM management
  • Content lifecycle management
  • Custom use case development
Data Forensics + Incident Response (DFIR)Coming Soon

Pre-purchased IR hours that activate within hours for forensics, root cause analysis, and containment.

  • On-demand IR support
  • Threat intelligence expertise
  • Deep data forensics and root cause analysis
  • Post-incident reporting
02
SKU Proposal

Packaging
Option

Agentic Investigations

  • Investigation
  • Knowledge Graph
  • Alert Triage
  • Custom Reporting

Agentic Detection

  • Log Store (add-on)
  • Detection Engine
  • Detection Tuning
  • Federated Search

Agentic Response

  • Case Management
  • Response
  • Orchestration
  • Workflow Designer

Agentic Risk Mitigation

  • Threat Hunt
  • Vulnerability AssessmentSoon
  • Purple TeamSoon
  • Attack Surface ManagementSoon

Requirements Matrix

Each PLAID Elite service requires the corresponding platform module to be purchased and active. A ✓ below means that module is a prerequisite — not an option.

Platform Module Required to Unlock
PLAID Elite Service
Agentic
Investigations
Agentic
Detection
Agentic
Response
Agentic
Risk Mitigation
PLAID Services Add-On
PLAID
Any module qualifies
PLAID Elite 24/7 Monitoring & Response
PLAID Elite Threat Hunt
PLAID Elite Co-Managed Detection Operations
PLAID Elite Data Forensics + Incident Response (DFIR)
Key
Required — must own this module
Not applicable for this service
Any module qualifies
03
SKU Proposal

PLAID Elite
Packaged
Bundles

Human Experts — All PLAID Elite Bundles

Pre-packaged PLAID Elite tiers designed around operational scale — each bundle stacks on the previous, so customers grow into coverage without re-negotiating scope.

Growth Continuous monitoring and proactive hunting for teams below 10K endpoints.
Complete Adds co-managed detection operations for teams exceeding 10K endpoints.
+ DFIR Retainer Add-on to any bundle — pre-committed IR hours available at all endpoint tiers.
Growth
Under 10K Endpoints Includes
  • 24/7 Monitoring & Response
  • Threat Hunt
Complete
Over 10K Endpoints Includes
  • 24/7 Monitoring & Response
  • Threat Hunt
  • Co-Managed Detection Operations
DFIR Retainer
Add-On · Any Bundle · Any Tier Pricing
  • Starter $16K/yr · 40 hrs
  • Standard $40K/yr · 100 hrs
  • Custom Contact sales
  • Pre-committed hours activate within hours for forensics, root cause analysis & containment
04
GTM

ICP
Segments

Three distinct buyer profiles — each with a different primary motion. Lead with the right entry point to shorten sales cycles and build trust faster.

SOC Transformation Internal teams using 7AI to replace underperforming SIEM, SOAR, XDR, or EDR — platform is the product.
Outsource SOC (MDR) Buyers replacing or supplementing a managed service — PLAID Elite is the product.
3rd Party Providers MSSPs and service firms embedding 7AI into their delivery model.
ICP1
SOC Transformation
Lead with Platform

Mid-market security teams replacing underperforming SIEM, SOAR, XDR, or EDR with an agentic AI platform that investigates, responds, and hunts autonomously.

Buying Signals
  • Alert fatigue and analyst burnout
  • Mid-market SIEM or SOAR delivering poor ROI
  • EDR or XDR generating noise without investigation depth
  • Pressure to do more without adding headcount
ICP2
Outsource SOC (MDR)
Lead with PLAID Elite

Organizations evaluating or replacing a managed detection and response provider who want analyst-quality oversight backed by AI-native investigation.

Buying Signals
  • Dissatisfied with current MDR quality or SLAs
  • Want faster escalation and clearer analyst accountability
  • Trust is the primary buying decision — not features
  • Contract renewal window approaching
ICP3
3rd Party Service Providers
Lead with Platform

MSSPs and consulting firms embedding 7AI into their service delivery to scale capacity, reduce analyst cost per client, and differentiate their offering.

Buying Signals
  • Multi-tenant operational model
  • Margin pressure on analyst-heavy service lines
  • Clients demanding faster investigation turnaround
  • Looking to expand service portfolio without headcount
05
Pricing Context

Market
Bench­mark

Two buying motions mapped to the three ICPs. SOC Transformation and 3rd Party Providers (ICP 1 & 3) buy platform. Outsource SOC (ICP 2) buys PLAID Elite. 7AI prices below market in both lanes.

$62–$185 Platform XDR/SOAR per endpoint/year — market range across CrowdStrike, SentinelOne, Palo Alto, Microsoft
$120–$250 MDR all-in (24/7 SOC included) per endpoint/year — market range across top MDR providers
14–30% Average buyer discount achieved in competitive evaluations — use this as your floor, not ceiling
Vendor / Tier Relative Price — Scale: $0 ————————————————————————— $300/ep/yr Est. $/ep/yr
ICP 1 · SOC Transformation + ICP 3 · 3rd Party Providers — Platform XDR / SOAR, Technology Only
CrowdStrike
Falcon Enterprise (XDR)
$185per ep / yr
SentinelOne
Singularity Complete
$160per ep / yr
Palo Alto
Cortex XDR Pro
$81per ep / yr
Microsoft
Defender Endpoint P2
$62per ep / yr
ICP 2 · Outsource SOC (MDR) — Managed Service, Platform Included, 24/7 SOC
ReliaQuest
GreyMatter MDR
$175–250per ep / yr
SentinelOne
Singularity Complete + Vigilance MDR
$161–215per ep / yr
Arctic Wolf
SOC as a Service
$120–216per ep / yr
Expel
MDR (endpoint coverage)
$120–180per ep / yr
CrowdStrike
Falcon Complete MDR
$125–150per ep / yr
7AI Platform
Agentic Investigations + Module · 1K–5K endpoints
from $45per ep / yr
7AI PLAID Elite Growth
24/7 Monitoring + Threat Hunt · 1K–5K endpoints
from $150per ep / yr
7AI PLAID Elite Complete
Full MDR Suite · 10K+ endpoints
from $120per ep / yr
06
SKU Proposal

Proposed
Pricing

AI-native efficiency drives real margin advantage. 7AI prices to win on value — not volume — while maintaining deal economics that grow with the customer.

Agentic Investigations + Module (per endpoint / year · annual contract) 250–999
endpts
1K–4,999
endpts
5K–9,999
endpts
10K+
endpts
Agentic Investigations
Investigation · Knowledge Graph · Alert Triage
$65
$55
$45
Custom
Agentic Detection
Detection Engine · Detection Tuning · Federated Search
$55
$45
$38
Custom
Agentic Response
Case Management · Response · Orchestration · Workflow Designer
$55
$45
$38
Custom
Agentic Risk Mitigation
Threat Hunt · Vulnerability Assessment · Purple Team · ASM (coming soon)
$55
$45
$38
Custom
Log Store Add-on: +$8/ep (250–999) · +$7/ep (1K–5K) · +$6/ep (5K–10K) —— PLAID: 20% of Platform ACV · min $20,000/yr —— Min contract: $20K ARR
PLAID Elite Bundles (per endpoint / year · platform included · annual contract) 250–999
endpts
1K–5K
endpts
5K–10K
endpts
10K–25K
endpts
Growth
24/7 Monitoring & Response + Threat Hunt
$175
$150
$130
$100
Complete
Growth + Co-Managed Detection Operations
$210
$180
$155
$120
DFIR Retainer
Add-on to any bundle · flat fee · all endpoint tiers
Starter $16K/yr 40 hrs · Standard $40K/yr 100 hrs · Custom contact sales
Co-Managed Det Ops (standalone add-on to Growth): +$35/ep (250–999) · +$30/ep (1K–5K) · +$25/ep (5K–10K) · +$20/ep (10K+) —— Min bundle: 250 endpoints · 25K+ endpoints: Custom
07
Sales Enablement

Sales
Quick
Ref

Four competitive displacement scenarios. Match the buyer's pain before leading with price — the right narrative shortens every sales cycle.

vs. Arctic Wolf / Expel
Platform-first: customer owns the technology, not locked into a black-box service. Transparency on escalation logic. AI automation means fewer gaps between analyst shifts.
vs. Mid-Market SIEM / SOAR / XDR / EDR
Total replacement narrative. Investigation + response + detection + threat hunt using the agentic AI approach. Target is LogRhythm, Rapid7, IBM QRadar, Secureworks, SentinelOne mid-market.
vs. Renewal Inertia
Run a parallel POC during the incumbent's contract window. Side-by-side investigation speed comparison closes faster than feature sheets. Focus on analyst-hours saved per quarter, not roadmaps.
vs. Dropzone AI / Prophet Security
Pricing comparison pending. If you encounter either in a deal, send details to Product Management for competitive analysis.
SOC Transformation
Primary Entry SKU
Agentic Investigations + Detection Agentic Investigations + Response + PLAID
$45K–$380K typical first-year ACV
1K–10K endpoints
Mid-Market Displacement Target
  • LogRhythm, Rapid7 InsightIDR, IBM QRadar
  • Secureworks Taegis XDR
  • SentinelOne mid-market / Cortex XDR mid-market
  • Self-managed EDR + SOAR combinations
Outsource SOC (MDR)
Primary Entry SKU
PLAID Elite Growth or Complete Bundle
$150K–$1.3M typical first-year ACV
1K–10K endpoints
Displacement Target
  • CrowdStrike Falcon Complete MDR
  • Expel MDR (contract renewal window)
  • Arctic Wolf SOC as a Service
  • ReliaQuest GreyMatter
3rd Party Providers
Primary Entry SKU
Platform Licensing Agentic Detection Agentic Response
$500K+ custom structure
10K+ endpoints (multi-tenant)
Displacement Target
  • Custom MSSP SOC toolchain
  • Secureworks Taegis MXDR
  • Legacy SIEM + SOAR combinations
  • In-house analyst headcount
08

Pricing Model · The Unit of Value

What is
a credit?

1 Credit = 1 Investigated Alert
The anchor —
everything else
prices off of this

A credit is the unified unit of measurement across every 7AI module — one simple currency that reflects the work the platform performs on your behalf.

09

Consumption Model

How customers consume 7AI

01 Buy Access

Purchase the modules your team needs

01 Agentic
Investigations
Required base
02 Agentic
Detection
03 Agentic
Response
04 Agentic
Risk Mit.
02 Burn Credits

Not every action burns credits — here’s the tier spectrum

Included
0 credits
Unmetered
Raw alert ingestion, remediation API calls
0.1 credits
Infrastructure
Log storage, deduplicated events
1.0 credit
Core Actions
Investigated alerts, federated search, detection tuning, response, attack-surface scan
2–3 credits
Premium Actions
Threat hunts, coverage analysis, custom reports
10