Pricing keyed to your attack surface, not a seat count.
ShadowMap is priced by asset-surface size and capability footprint, not by analyst seats. Pick the SKU that matches how your team wants to operate; we'll quote precisely after a 30-minute scoping call. The published figure is a floor, not a band — larger estates and vendor portfolios quote above it.
The two SKUs
Pick how you want to operate
Same platform, two operating models. Choose Platform + Support if your team has bandwidth to run continuous exposure operations directly. Choose Platform + Managed Service if you'd rather have ShadowMap analysts run the console alongside your team.
Platform + Support
You operate · we support
from $25,000per year, keyed to asset-surface size
The full ShadowMap platform delivered as SaaS, with standard support. Your security team operates the console, triages alerts, and runs the workflows. Right-sized for teams with the bandwidth to run continuous-exposure operations themselves.
- Every capability — Attack Surface, Brand Protection, Data Exposure, Dark Web, Threat Intelligence, Threat Feeds, CART, Vendor Risk Management, Unified Console
- 24-hour re-scan cadence across your attributed inventory
- 86 native integrations (SIEM / SOAR / EDR / ticketing / IdP / cloud / secrets / CASB)
- RBAC + SSO (SAML / OIDC) + audit log
- Read + write API and webhooks
- Standard support: email + ticketing, business-hours response
- Onboarding programme with a ShadowMap engineer
- Audit-ready evidence trail
Platform + Support + Managed Service
We operate alongside your team
Everything in Platform plus a managed-service team running the console for you — triaging findings, orchestrating takedowns, validating exposures, delivering executive briefings. Three operating-model flavours below.
- Everything in Platform + Support, plus:
- Daily / weekly finding triage by a ShadowMap analyst
- Brand-protection takedowns coordinated under a contractual SLA, with response and completion targets set per abuse class
- SLA penalty clause: one additional unit of service per day the SLA is exceeded
- CART campaigns scoped + executed against high-priority exposures
- Quarterly threat-landscape briefings keyed to your sector
- Custom dashboards and executive-level monthly reports
- Direct escalation to Security Brigade red team for incidents
- Steering-committee cadence with named ShadowMap leads
Managed Service · Operating models
Three ways our analysts plug in
When you choose Platform + Managed Service, the analyst delivery model is yours to pick. All three carry the same SLA structure, the same evidence trail, and the same backing intelligence team — they differ on continuity, co-location, and economics.
MS-A1
Dedicated On-site
Embedded in your SOC
A named ShadowMap analyst (or analyst team) physically embedded with your security operations centre. Same workspace, same standups, same culture — with the full backing of the ShadowMap intelligence team behind them. Right for organisations that need 24/7 coverage co-located with the rest of the SOC.
Best for
Large enterprises · regulated industries · sensitive operating contexts
MS-A2
Dedicated Remote
A named analyst, working from SB
A named ShadowMap analyst — yours by name, calendar, and Slack — operating from a Security Brigade office. Same accountability and continuity as on-site without the seat-cost of an embedded resource. The default choice for most enterprise customers.
Best for
Mid-market and enterprise · teams that want named accountability without on-site overhead
MS-A3
Shared Resource
Pooled analyst, SME-sized customers only
A pooled analyst supporting multiple SME customers in parallel, with deterministic SLAs and a clear escalation path. Available only for SME tiers — not appropriate where dedicated continuity is required, but a strong fit for smaller security teams that want managed-service rigour at SME economics.
Best for
SMEs · small security teams · regulated SMBs that need formal evidence trails
SME tiers only. Not available for enterprise contracts.
What sets your price
The variables we ask about in scoping
- External asset count (apex domains, subdomains, hosts, mobile apps, cloud accounts)
- Number of brands monitored (each registered brand counts independently)
- Vendor portfolio size (if Vendor Risk Management module is in scope)
- Module footprint (the platform is modular — take all of it or a subset)
- Managed-service flavour and analyst hours (if applicable)
- Integrations + custom workflows (most native integrations are included)
- Deployment topology (multi-tenant SaaS, regional, or VPC-isolated)
- Contract length and start date
Public pricing is bespoke. We'll send a written pricing letter within one business day of the scoping call.
Still deciding what to scope? The platform overview covers the modules, integrations lists what is native and included, and vendor risk management is the module the vendor-portfolio line refers to.
The takedown line in the Managed Service tier covers two different filings, and which one applies is a scoping question rather than a pricing one. A domain takedown is filed against the registration; a website takedown is filed against the provider holding the files. The provider directory sets out which counterparty can act in each case, and what each one will accept as evidence.
The 30-minute scoping call is also the demo.
One call: we map your apex domain live, walk you through what we find, then quote based on what we saw. You leave with a draft of your attributed inventory and a written pricing letter either way.