What changed between published versions of the pricing catalog, and why. Each version is a live page on media.sevenai.com; earlier versions stay up so you can compare side by side.
This log covers structural and naming changes to packaging. It does not track the earlier v1→v2 pass (bug fixes and the first services rebuild); it begins where the catalog started diverging into named versions.
Driven by the July 23 pricing follow-up and competitive benchmarking (Microsoft Sentinel, Google SecOps, Splunk). Four changes: (1) enter real per-GB prices on the four Federated SIEM SKUs; (2) strip the out-of-date customer-voiced intro copy from the product pages since this is an internal tool; (3) make service platform-dependencies explicit as Required / Prerequisites; and (4) present the quote in annual terms (ARR) rather than monthly. This version resolves v4's "prices are conjecture / TBD" flag and reverses two v4 decisions (see the "why" cells).
The four SIEM SKUs are now priced flat per GB. Benchmarking: Microsoft Sentinel meters ingestion per GB ingested ($2.46–$5.59 pay-as-you-go, ~$1.10–$1.23 at commitment tiers); Google SecOps is per-employee with an included GB allowance; Splunk's ingest license normalizes to roughly $1–$2 / GB. $1–$2 / GB lands in the competitive band.
| Was (v4) | Now (v5) | Why | |
|---|---|---|---|
| Ingestion: TBD, metered per GB / day | → | Ingestion: $2 / GB (flat) | Reverses v4's per-GB/day meter — that was an error. Ingestion is a throughput charge billed per GB ingested (as Microsoft does), not a daily retention meter. $2 / GB sits below Sentinel pay-as-you-go and just above its commitment rate. |
| Federated Detection Engine: TBD (per GB) | → | Federated Detection Engine: $1 / GB | Unit unchanged (per GB, incl. data kept in the customer's own SIEM); real rate entered. |
| Detection Optimization: TBD, per endpoint / mo (one rate in both placements) | → | Detection Optimization: $1 / GB under Federated SIEM; per endpoint / yr (TBD) under AI SOC | Under Federated SIEM it's priced per GB like the other SIEM SKUs (reverses v4's per-endpoint stance). The AI SOC add-on stays a per-endpoint upcharge but annual (per endpoint / yr, TBD). So the two placements now price differently despite the shared name — intentional. (v4 had floated $1.50 per endpoint.) |
| Storage: $1 / GB / day (≈ $30 / GB / mo) | → | Storage: $1 / GB (flat) | Reverses the per-day meter. $1 / GB / day annualized to ~1000× real storage economics; flat per GB brings it back to earth. "No storage cost if you bring your own" retained. |
| Was (v4) | Now (v5) | Why | |
|---|---|---|---|
| Each product's left page opened with a customer-voiced intro paragraph (AI SOC, Threat Hunting, Federated SIEM, PLAID ELITE) | → | Intro paragraphs removed from all four product left pages | The copy was out of date and addressed an external customer; this is an internal sales-enablement tool. Partially resolves v4's flag on customer-facing prose — the "Metered by / The SKUs" reference callouts were kept (their pricing text was updated to the new per-GB model). |
| Was (v4) | Now (v5) | Why | |
|---|---|---|---|
| PLAID ELITE listed no explicit platform prerequisite; "The Foundation" opened with "All services require the 7AI platform…" | → | A caveat directly under the PLAID ELITE entry: "Requires AI SOC — the platform PLAID ELITE operates on." (No price shown — AI SOC is quoted on its own page.) The "all services require the 7AI platform" framing was removed as redundant. | Keeps AI SOC (a priced product) present in every PLAID ELITE deal, but as a caveat on the entry rather than its own section — it's implied that PLAID ELITE is the foundation and runs on AI SOC. (The withdrawn idea of removing Case Management / Workflow from PLAID's Included list was dropped — those stay.) |
| Managed Threat Hunting & Co-Managed SIEM: dependency implied in prose only | → | A required-prerequisite line under each: Managed Threat Hunting requires the Threat Hunting product; Co-Managed SIEM requires Federated SIEM | Names the specific product that must be purchased for each service to function. Only these two services (plus PLAID ELITE) were called out this round; the other a-la-carte services are unchanged. |
| Was (v4) | Now (v5) | Why | |
|---|---|---|---|
| Quote calculator showed "Estimated Monthly"; CSV exported monthly figures | → | Quote shows "Estimated Annual"; every line total, subtotal, grand total, and CSV amount is 12 × monthly | We evaluate deals in ARR, not MRR. Per-unit rate descriptors (e.g. "$10 / asset / mo," "$2 / GB") stay monthly; only extended amounts and totals are annualized, so rates still read in familiar units. Ledger margins are unchanged (both cost and revenue scale by 12). |
Also in v5: the Rate Card and CSV export show the four SIEM SKUs at their per-GB rates; the live calculator was rewired off the ×30 daily meter to flat per-GB — Ingestion now computes (routing GB × $2) instead of showing "Quoted," and Storage no longer multiplies by 30. Verified end-to-end with a headless jsdom run (Estimated Monthly total, per-line amounts, Order Review sync, zero script errors).
Driven by the July 22 pricing and competitive-benchmarking session with Lior and the team. Two themes: make per-asset the primary AI SOC model, and restructure Federated SIEM into simple, seller-legible SKUs priced on data volume. All new prices are directional and marked TBD pending competitive quotes.
| Was (v3) | Now (v4) | Why | |
|---|---|---|---|
| Per investigation and per asset presented as equal choices | → | Per asset is the primary model; per investigation tagged "land / pilot" | Per-investigation invites customers to suppress usage and shrink the deal. It is a land/pilot tool; per-asset is the real motion. |
| $10 / asset / mo · $20 / asset / mo | → | $10 / asset / mo · $120 / yr | $20 · $240 / yr | Annual equivalents added to line up against Red Canary's list ($120 endpoint / $240 cloud on AWS Marketplace). |
| Federated Search: Always-On, included free | → | Federated Search: priced add-on, standard 100% discount | Lior: never give value away for nothing. Keeping it a priced SKU (discounted to $0) preserves a negotiation lever — "I can remove the federated search." |
| — | → | New add-on: Detection Analysis & Optimization (per endpoint / mo) | The AI detection-engineering work, surfaced in AI SOC as well as Federated SIEM. Same SKU in both places, bundleable. |
| Per-asset cap note only | → | Cap note + "includes 7AI detection control and tuning on covered assets" | Lior: don't ask permission to tune — state that we control detection on covered assets (opt-out available). Protects unit economics. |
v3's layered "Intelligence / Compute / Storage" model was replaced with the seller-facing story data moving → data stored → data detection, plus detection engineering as its own SKU.
| Was (v3) | Now (v4) | Why | |
|---|---|---|---|
| Page title: "Decoupled Storage, Compute & Intelligence" | → | "Ingestion, Storage & Federated Detection" | Names the actual SKUs a seller quotes, not abstract layers. |
| Compute (ingestion, querying, detection execution) | → | Ingestion (data moving) — always priced, never zero | Detection execution pulled out into its own SKU; ingestion is now purely the pipeline. Confirmed it must carry a price even on customer pipelines. |
| Intelligence layer (detection engineering + coverage, unit TBD) | → | Federated Detection Engine (per GB) | Running detections is compute that scales with data volume — priced per GB/day, including data that stays in the customer's own SIEM. Data grows; employee counts don't. |
| (folded into the intelligence layer) | → | Detection Optimization — its own SKU (per endpoint / mo), bundleable | Optimizing detections is near-zero compute (token cost) and distinct from running them. Its own line item, bundleable into SIEM or AI SOC or sold standalone. Sub-items: Detection Analysis, and Context-Aware Optimization & Tuning. Named "Detection Optimization" (not "Detection Engineering") to reserve "Detection Engineering" for the human PLAID service — resolving the earlier name collision. |
| Storage: "$1 / GB / day" | → | Storage kept as its own lever; "no storage cost if you bring your own" | Storage stays a separate priced lever (not bundled into ingestion), for Microsoft-style parity and negotiation room. |
Also in v4: rate card and CSV export updated to the four SIEM SKUs; the stray "SaaS, OT, Custom" rate-card use-case list corrected to the canonical set.
| Was | Now | Why | |
|---|---|---|---|
| Ingestion listed "Querying" as a component | → | Querying removed from Ingestion | Ingestion is purely data moving; querying isn't part of that SKU. |
| Fed SIEM SKU "Detection Engineering"; sub-items "Detection Analysis & Optimization" + "Detection creation & editing" | → | "Detection Optimization"; sub-items "Detection Analysis" + "Context-Aware Optimization & Tuning" | Renamed to free up "Detection Engineering" for the human PLAID service. The AI SOC cross-listed add-on took the same new name so one SKU carries one name. PLAID ELITE's "Detection Engineering" is unchanged. |
| Section headers: small (0.58rem), gray, thin rule | → | Section headers: bold, larger (0.9rem), ink-black, full rule underneath — every page | Each section should clearly read as the start of a section across the whole catalog. |
| "Always On · Platform Foundation" headers styled as small gray eyebrows | → | Same bold section-header treatment as every other section | Consistency — the always-on foundation blocks now read as full sections like the rest. |
| Threat Hunting left pane showed pricing ($20 / hunt run, $10 / endpoint / mo) | → | Pricing callout removed from the Threat Hunting left pane | The left-pane figures were internally inconsistent with the actual rates on the right (Ad Hoc $30, Emerging Threat $20, per-asset $15/$10). Removed rather than restated to avoid a second source of truth. |
| Threat Hunting "Hunt types" still listed "Automated" | → | "Emerging Threat" | Leftover from before the v3 rename; now consistent with the rest of the catalog. |
| Federated Detection Engine row: "Detection execution against live data" | → | "Detection execution" | July 23 review: "against live data" was extra words; the engine runs detections wherever data lives. |
| Federated SIEM feature grid included "Fraction of SIEM Cost" | → | Removed | No longer true once each SKU is priced separately against the market; struck to avoid a claim we can't stand behind. |
| Federated Search not listed under Federated SIEM foundation | → | Always-On under Federated SIEM | If you have the SIEM you have Federated Search. Intentional asymmetry: on AI SOC it stays a priced-and-discounted line item (a lever); on Federated SIEM it's simply included. |
| Section headers at 0.9rem | → | Section headers at 1.15rem — the most prominent recurring header | July 23 review: make section titles unmistakably the start of a section. Enlarged further (kept below the product/page title). |
These July 23 refinements were applied in place on v4 (same review cycle, not a new version). The meeting's three headline decisions — remove querying from Ingestion, rename the Fed SIEM SKU to Detection Optimization, and its sub-items (Detection Analysis; Context-Aware Optimization & Tuning) — were already in v4 from the prior pass, so they are not relisted here.
Driven by the July 21 naming and application-alignment meeting (Nate, Erika, Evelyn, Carolyn, Ryan). The goal was to make the catalog's language match what the product actually calls things, and to clean up items that didn't exist or were mislabeled.
| Was (v2) | Now (v3) | Why | |
|---|---|---|---|
| Automated Hunts | → | Emerging Threat Hunts | "Automated" was confusing — ad hoc hunts will also be automatable soon. "Emerging Threat" names what it actually hunts. |
| 7AI Threat Feed | → | 7AI Threat Intelligence | Matches the feed name in the product. |
| Simple Automation | → | Remediation Actions | "Simple Automation" meant nothing to anyone; it's remediation. |
| Unified Chat & Voice | → | Unified Chat | The product only ever called it Unified Chat. |
| Email / Phishing | → | Phishing is one alert type feeding the Email category; the product category is just Email. | |
| Chat with Investigations (listed) | → | Removed as a line item | Chat is being introduced everywhere; calling it out once was arbitrary. |
| Was (v2) | Now (v3) | Why | |
|---|---|---|---|
| Federated Search: paid AI SOC add-on (+10%) | → | Always-On under AI SOC | Everyone on the platform already gets it — the SIEM "Trojan horse." (Note: reversed again in v4 — see above.) |
| Hunt Workspace, Bring Your Own Feed (listed) | → | Removed | Neither adds value as a line item; one didn't exist as a real feature. |
| Unlimited Connectors (AI SOC + Threat Hunting) | → | Removed everywhere | "Unlimited" is a dangerous word for sales, and it conflicted with the billable custom-connector idea for services. |
| Mobile Apps on every product | → | AI SOC only | Mobile only really works for cases (AI SOC). |
| Fed SIEM: Intelligence / Routing & Compute / Storage layers | → | Storage · Retention, Compute, Intelligence (reordered, "$10/employee" unit removed) | "Employee" was never a real unit; the layers were carrying fake "Included" chips. (Restructured again in v4.) |
| "7AI Detection Execution" | → | Detection Execution (under Compute) | Dropped the "7AI" brand prefix; moved to Compute where it belongs. |
| Was (v2) | Now (v3) | Why | |
|---|---|---|---|
| "AI investigation on every alert" led the included list | → | "24/7 analyst coverage · defined SLAs" leads; "every alert" removed | 24/7 human coverage is the reason customers buy a managed service — it belongs first. |
| Platform requirement implied in prose | → | "All services require the 7AI platform; cannot be quoted standalone" — called out in bold | Sellers were at risk of quoting a service without the platform. |
| Rate card "Included with every purchase" text block | → | Removed — list & price only | The rate card is an internal quick-reference for reps; it just needs the list and the number. |
| Book width 500px | → | 580px | Right-hand pages were too cramped. |
| Bundles as a bullet list | → | Comparison table (added late in v3) | A table makes what's in each bundle scannable at a glance. |
A post-v3 fix also corrected the Federated SIEM quote math: storage metered "$1 / GB / day" now multiplies by 30 for the monthly estimate (50 GB/day → $1,500/mo, not $50).