Four things you can buy from 7AI. Pick a product to see its three packages, from a focused start to full scope. Every package runs on the same platform foundation.
MSSPs and MDRs run these same products multi-tenant and deliver them to their own customers.
AI investigates your alerts end to end. Start with one use case, then expand coverage and capabilities as you grow. Every package includes dedicated PLAID AI Security Engineering and unlimited connectors, and is metered by investigation volume (with caps) or by asset count. Response and case management come in from Core.
| What's included | FoundationAutonomous investigation for your first use case | CoreAdds response and case management across more use cases | ExtendedFull use-case coverage across all six |
|---|---|---|---|
| Coverage | |||
| Use Cases | 1 use case | Up to 3 | All 6 |
Choose fromPhishingEndpointIdentityCloudInsider ThreatNetwork | |||
| Metered by | Investigation volume with caps, or per-asset proxy | ||
| Modules | |||
| Agentic Investigations | |||
IncludesTriageEnrichmentEnd-to-end investigationsDeterminationsRemediation recommendationsAgentic reportTicket system integrationInvestigation chatTimeline & root cause | |||
| Agentic Response | |||
IncludesWorkflowsRunbooksAuthorized response actionsOrchestrationNotifications | |||
| Case Management | |||
IncludesCasesBidirectional ITSM syncAI case summaries & titlesAuto-assignCase notifications | |||
| Platform foundation · included in every package | |||
| Unlimited connectors | |||
| Enterprise Insights | |||
| Reporting & dashboards | |||
| Skills (library & custom authoring) | |||
| Unified Chat & Voice | |||
| Pulse | |||
| Mobile apps | |||
| Human layer | |||
| PLAID AI Security Engineering | |||
| Operated by | You | You | You |
Layer any of these onto any package.
Replace an outsourced SOC, or fill a coverage gap, with a fully managed service. The same AI Security Engineers who tune your environment operate it for you. Case management is included in every package. Packages step up by coverage and by the depth of expert services.
| What's included | Elite FoundationFully managed, one use case | Elite CoreMultiple use cases, with hunting and 7AI Threat Intel | Elite ExtendedFull environment, with DFIR and exposure management |
|---|---|---|---|
| Coverage | |||
| Use Cases covered | 1 use case | Multiple | Full environment |
CoversPhishingEndpointIdentityCloudInsider ThreatNetwork | |||
| Managed capabilities | |||
| Agentic AI investigation on every alert | |||
IncludesTriageEnrichmentEnd-to-end investigationsDeterminationsRemediation recommendationsAgentic reportInvestigation chat | |||
| Elite analyst overwatchHumans on the loop | |||
| Authorized response actions | |||
| Case Management · included | |||
IncludesCasesBidirectional ITSM syncAI case summaries & titlesAuto-assign | |||
| Reporting & continuous tuning | |||
| Proactive threat hunting | |||
| 7AI Threat Intel | |||
| Security posture analysis | |||
| Expert services | |||
| DFIR retainer | |||
| Exposure Management | |||
| Co-managed SIEM | |||
| Platform foundation · included in every package | |||
| Unlimited connectors | |||
| Enterprise Insights | |||
| Reporting & dashboards | |||
| Unified Chat & Voice | |||
| Pulse | |||
| Skills (library & custom authoring) | |||
| Mobile apps | |||
| Delivery | |||
| Operated by | 7AI | 7AI | 7AI |
Extend the managed service with deeper expert engagements.
A managed log store with federated search and detection built in. Every capability is included in all three packages. The packages differ only by how much you ingest and how long you retain it.
| What's included | FoundationStandard ingestion and retention | CoreHigher ingestion, extended retention | ExtendedCustom ingestion and retention |
|---|---|---|---|
| Volume & retention · what changes across packages | |||
| Included ingestion volume | Standard | Higher | Custom |
| Log retention | Standard | Extended | Custom |
| Metered by | Ingestion volume (GB) + retention | ||
| Store | |||
| Log ingestion | |||
| Hot storage | |||
| Cold / archive storage | |||
| Source health monitoring | |||
| Federated search | |||
| Federated search across sources | |||
| Saved searches & scheduling | |||
| Search across investigations & hunts | |||
| Detection | |||
| Detection Intelligence | |||
| Detection routing | |||
| Alert aggregation | |||
| Coverage analysis & optimization | |||
| MITRE ATT&CK coverage | |||
| Detection engineering | |||
| Prebuilt rule packages | |||
| Platform foundation · included in every package | |||
| Unlimited connectors | |||
| Reporting & dashboards | |||
| Unified Chat & Voice | |||
| Pulse | |||
| Mobile apps | |||
| Human layer | |||
| PLAID AI Security Engineering | |||
| Operated by | You | You | You |
Layer any of these onto any package.
Proactively find risk before alerts fire, without ingesting a single alert. A different job, for a different buyer. Runs with zero investigations connected: hunt manually or against threat intel. Packages add hunt types as your program matures.
| What's included | FoundationManual and interactive hunting to get started | CoreAdds IOC and threat-intel-driven hunts | ExtendedEvery hunt type, scheduled and continuous |
|---|---|---|---|
| Coverage | |||
| Environments covered | Selected | Multiple | All connected data |
| Metered by | Hunt volume / seats | ||
| Hunt types | |||
| Ad-hoc & interactive hunts | |||
| IOC hunts | |||
| Threat-intel-driven hunts | |||
| Hunt on Threat Intel | |||
| CVE-driven hunts | |||
| Scheduled & continuous hunts | |||
| Hunt workspace | |||
| Hunt workspace | |||
IncludesHunt chatFindings & pivotsHand-off to investigationSaved hunts | |||
| 7AI Threat Intel | |||
| Platform foundation · included in every package | |||
| Unlimited connectors | |||
| Enterprise Insights | |||
| Reporting & dashboards | |||
| Unified Chat & Voice | |||
| Pulse | |||
| Skills (library & custom authoring) | |||
| Mobile apps | |||
| Human layer | |||
| PLAID AI Security Engineering | |||
| Operated by | You | You | You or 7AI |
Layer any of these onto any package.