Pick how you want to run security operations. See what comes in each package, expand any capability to see the full scope, then the optional add-ons you can layer on.
Keep your analysts, hand the platform the Tier 1 and Tier 2 grind. Start with one use case, then expand coverage and capabilities as you grow. Every package includes dedicated PLAID AI Security Engineering and unlimited connectors, and is metered by investigation volume (with caps) or by asset count. Higher tiers add modules and use-case coverage; anything not included is available as an add-on.
| What's included | FoundationAutonomous investigation for your first use case | CoreAdds response, threat hunting, and case management across more use cases | ExtendedAdds detection engineering and full use-case coverage |
|---|---|---|---|
| Coverage | |||
| Use Cases | 1 use case | Up to 3 | All 6 |
Choose fromPhishingEndpointIdentityCloudInsider ThreatNetwork | |||
| Metered by | Investigation volume with caps, or per-asset proxy | ||
| Modules | |||
| Agentic Investigations | |||
IncludesTriageEnrichmentEnd-to-end investigationsDeterminationsRemediation recommendationsAgentic reportTicket system integrationInvestigation chatTimeline & root cause | |||
| Agentic Response | |||
IncludesWorkflowsRunbooksAuthorized response actionsOrchestrationNotifications | |||
| Agentic Threat Hunt | |||
IncludesAd-hoc & interactive huntsIOC huntsCVE-driven huntsThreat-intel-driven huntsHunt on Threat Intel | |||
| Case Management | |||
IncludesCasesBidirectional ITSM syncAI case summaries & titlesAuto-assignCase notifications | |||
| Agentic Detection | |||
IncludesDetection IntelligenceDetection engineeringCoverage analysis & optimizationDetection routingAlert aggregationPrebuilt rule packagesMITRE ATT&CK coverage | |||
| Platform foundation · included in every package | |||
| Unlimited connectors | |||
| Enterprise Insights | |||
| Reporting & dashboards | |||
| Skills (library & custom authoring) | |||
| Unified Chat & Voice | |||
| Pulse | |||
| Mobile apps | |||
| Human layer | |||
| PLAID AI Security Engineering | |||
| Operated by | You | You | You |
Layer any of these onto any package.
Replace an outsourced SOC, or fill a coverage gap, with a fully managed service. The same AI Security Engineers who tune your environment operate it for you, around the clock. Case management is included in every tier. Tiers step up by coverage and by the depth of expert services, and deeper engagements stay available as add-ons.
| What's included | Elite FoundationFully managed, one use case | Elite CoreMultiple use cases, with hunting and 7AI Threat Intel | Elite ExtendedFull environment, with DFIR and exposure management |
|---|---|---|---|
| Coverage | |||
| Use Cases covered | 1 use case | Multiple | Full environment |
CoversPhishingEndpointIdentityCloudInsider ThreatNetwork | |||
| Managed capabilities | |||
| Agentic AI investigation on every alert | |||
IncludesTriageEnrichmentEnd-to-end investigationsDeterminationsRemediation recommendationsAgentic reportInvestigation chat | |||
| Elite analyst overwatchHumans on the loop | |||
| Authorized response actions | |||
| Case Management · included | |||
IncludesCasesBidirectional ITSM syncAI case summaries & titlesAuto-assign | |||
| Reporting & continuous tuning | |||
| Enterprise Insights | |||
| Proactive threat hunting | |||
| 7AI Threat Intel | |||
| Security posture analysis | |||
| Expert services | |||
| DFIR retainer | |||
| Exposure Management | |||
| Co-managed SIEM | |||
| Foundation & delivery | |||
| Unlimited connectors | |||
| Reporting, Chat & Voice, Pulse, Skills, Mobile | |||
| Operated by | 7AI | 7AI | 7AI |
Extend the managed service with deeper expert engagements.
Run your MDR or MSSP on 7AI as your underlying platform. Multi-tenant from day one, so you deliver to every customer from one place. Start with a single use case and expand to your full service as you grow. Every package includes dedicated PLAID AI Security Engineering and unlimited connectors, and is metered by investigation volume or by asset count. Higher tiers add modules and use-case coverage; anything not included is available as an add-on.
| What's included | FoundationRun one use case for your customers on 7AI | CoreRun multiple use cases across your customer base | ExtendedRun your entire MDR / MSSP on 7AI |
|---|---|---|---|
| Coverage | |||
| Use Cases | 1 use case | Up to 3 | All 6 |
Choose fromPhishingEndpointIdentityCloudInsider ThreatNetwork | |||
| Metered by | Investigation volume across tenants, or per-asset proxy | ||
| Modules | |||
| Agentic Investigations | |||
IncludesTriageEnrichmentEnd-to-end investigationsDeterminationsRemediation recommendationsAgentic reportTicket system integrationInvestigation chatTimeline & root cause | |||
| Agentic Response | |||
IncludesWorkflowsRunbooksAuthorized response actionsOrchestrationNotifications | |||
| Agentic Threat Hunt | |||
IncludesAd-hoc & interactive huntsIOC huntsCVE-driven huntsThreat-intel-driven huntsHunt on Threat Intel | |||
| Case Management | |||
IncludesCasesBidirectional ITSM syncAI case summaries & titlesAuto-assignCase notifications | |||
| Agentic Detection | |||
IncludesDetection IntelligenceDetection engineeringCoverage analysis & optimizationDetection routingAlert aggregationPrebuilt rule packagesMITRE ATT&CK coverage | |||
| Platform foundation · included in every package | |||
| Multi-tenant management | |||
| Unlimited connectors | |||
| Enterprise Insights | |||
| Reporting & dashboards | |||
| Skills (library & custom authoring) | |||
| Unified Chat & Voice | |||
| Pulse | |||
| Mobile apps | |||
| Human layer | |||
| PLAID AI Security Engineering | |||
| Operated by | You | You | You |
Layer any of these onto any package.