Predictable pricing. EU-grade guarantees.
From 3 devices to unlimited. Every plan ships with the NetSenX Math Guarantee (a split-conformal false-positive bound, reported at the level your own calibration data supports), EU data residency, and signed releases. Seats from 1 on Free to unlimited on Enterprise, no telemetry tax.
Annual billing = two months free. Cancel anytime. Prices exclude VAT.
Choose your plan
Every plan includes the NetSenX Math Guarantee, EU data residency, AES-256-GCM at rest, and Sigstore-signed releases. Upgrade or downgrade at any time.
Free
Start free — up to 3 devices
Core behavioural detection
- Up to 1 user
- 30-day alert history
- NQCI crypto inventory — previewUpgrade to unlock
Starter
Small teams — up to 10 devices
Extended behavioural detection
- Up to 5 users
- 60-day alert history
- PDF compliance reports
- Manual response actions
- NQCI crypto inventory — previewUpgrade to unlock
Pro
Growing SMB — up to 25 devices
Advanced behavioural detection + OT/ICS
- Up to 15 users
- 90-day alert history
- Automatic response recommendations
- REST API access
- OT/ICS coverage
- NQCI crypto inventory & PQC readiness
Business
Mid-market & multi-site — up to 100 devices
Everything in Pro + cryptographic attack detection
- Up to 50 users
- 365-day alert history
- SIEM export
- Breach & attack simulation
- NQCI crypto inventory & PQC readiness
Enterprise
MSSP & large networks — unlimited devices
Full behavioural detection suite
- Unlimited users
- Unlimited alert history
- Custom detection policies
- White-label & on-premise deployment
- NQCI crypto inventory & PQC readiness
All prices in EUR, exclude VAT. Annual plans are billed once per year and equal 10× the monthly rate (two months free).
A device is a host running the NetSenX agent. One agent on a SPAN or TAP port monitors a whole network segment and counts as one device.
Compare every feature
The full matrix. No asterisks, no “contact us for details” on standard plans. Scroll horizontally on small screens.
| Feature | Free | Starter | Pro | Business | Enterprise |
|---|---|---|---|---|---|
| Detection | |||||
| Devices | 3 | 10 | 25 | 100 | Unlimited |
| Alert history | 30-day alert history | 60-day alert history | 90-day alert history | 365-day alert history | Unlimited alert history |
| Detection level | Core behavioural detection | Extended behavioural detection | Advanced behavioural detection + OT/ICS | Everything in Pro + cryptographic attack detection | Full behavioural detection suite |
| NetSenX Layer 3 Graph Intelligence | |||||
| NetSenX TLS Fingerprint Engine | |||||
| NetSenX FastStart (privacy-preserving cold-start) | |||||
| NetSenX AI Analyst Core | |||||
| NetSenX Math Guarantee (conformal false-positive bound) | |||||
| Rogue Agent Detection | |||||
| Operations | |||||
| Alert channels | Email, Slack & webhook | Email, Slack & webhook | Email, Slack & webhook | ||
| Dashboard access | |||||
| REST API access | |||||
| Manual response actions | |||||
| Automatic response recommendations; host isolation via approval | |||||
| Custom integrations | Limited | Full | |||
| Custom detection policies | |||||
| White-label, on-premise & perpetual license | |||||
| Security & data | |||||
| Audit log retention | 90 days | 180 days | 1 year | 2 years | 3 years |
| SIEM export | |||||
| OT/ICS coverage | |||||
| EU data residency | |||||
| AES-256-GCM at rest | |||||
| SSO / SAML | |||||
| Sigstore signed releases | |||||
| Compliance | |||||
| PDF compliance reports | |||||
| GDPR, NIS2, CRA & AI Act evidence | |||||
| Compliance reports cadence | Quarterly | Monthly | Real-time + audit pack | ||
| Triple Crown evidence pack (SOC 2 + ISO 42001 + ISO 27001) | |||||
| DPA + sub-processors list | |||||
| Support | |||||
| Support | Community | Email + Chat | Priority | Dedicated CSM | |
| SLA | 99.9% target | 99.9% target | 99.9% target | ||
| Onboarding | Self-serve | Self-serve | Self-serve + guide | Onboarding call | Dedicated implementation |
Enterprise, regulated industries, or more than 100 devices?
We support EU CISOs in finance, healthcare, public sector, and critical infrastructure with custom commercial terms and the same detection engine on every tier. Every Enterprise engagement ships with a dedicated CSM and an audit-pack ready for your next ISO, NIS2, or DORA review.
Response time: within 1 business day. EU-based account team.
Custom contracts
MSA, DPA, EU SCC, and procurement workflows tailored to your legal team.
Dedicated CSM
Named customer success manager, quarterly reviews, and direct engineering escalation.
Audit-pack-ready compliance
Triple Crown evidence pack (SOC 2 + ISO 42001 + ISO 27001) and real-time auditor exports.
Frequently asked questions
Short, factual answers. Need something specific? Ask our team.
You choose the deployment: a single SPAN/TAP port on your switch watches a whole network segment and counts as one device, or install the NetSenX agent on the specific hosts you choose. Both are documented; no kernel modules. On Linux the installer only installs a package whose signature matches the NetSenX release key, and refuses anything else; Windows and macOS agents are set up together with NetSenX support.
Customer telemetry and alerts are stored exclusively in the EU — EU-region object storage and EU-region Postgres, encrypted at rest with AES-256-GCM. Some sub-processors (Stripe for payments, Resend for transactional email) operate in the USA under EU Standard Contractual Clauses. Some AI Analyst capabilities may use a provider outside the EU only with your explicit consent. A full sub-processor list is published with our DPA.
There is no separate trial period. Every new account starts on the Free plan — up to 3 devices, no credit card required, no time limit. Upgrade to a paid plan whenever you need more capacity; plan changes apply immediately.
On Business and Enterprise tiers, you can register an AWS KMS or HashiCorp Vault key with your tenant through our BYOK API.
It guarantees a method, applied to your data, and full visibility into what that method currently supports. A split-conformal layer derives a false-positive bound on the alerts the engine surfaces, at a configurable confidence level, from analyst-labelled benign traffic in your own tenant. A finite calibration set can only resolve a bound so tight, so the dashboard shows the bound your data supports — and states that it supports none yet, together with what would close the gap, rather than displaying a figure we cannot back. The methodology is documented in our Trust Center and is independently reviewable.
Enterprise customers receive evidence mapped to SOC 2 Type I (in progress), ISO 42001 (AI management), and ISO 27001. Each control includes timestamped artifacts, sub-processor attestations, and an exportable auditor view, refreshed on a real-time cadence.
Yes. The Business and Enterprise onboarding includes a structured cut-over: parallel running for two weeks, alert taxonomy mapping, and analyst playbook migration.
Yes. Verified non-profits, universities, and accredited research labs receive 50% off Starter and Pro tiers, or extended Free-tier device caps. Email [email protected] with verification.
Credit and debit cards (Visa, Mastercard, AmEx), SEPA Direct Debit on annual plans, and bank transfer for Business and Enterprise contracts. All processed through EU payment providers that hold PCI-DSS certification; the certification is the provider's, not NetSenX's.
Annual plans on Business and Enterprise can be invoiced with Net-30 terms. Starter and Pro annual plans can request manual invoicing on approval. Every payment generates a VAT-compliant invoice automatically.