| Defender | Responder | Ultimate | |
|---|---|---|---|
| Pricing |
starts at 200 assets $ 799 $ 8629 |
starts at 800 assets $ 2,299 $ 24,829 |
starts at 2500 assets $ Custom $ Custom Talk to an Expert |
| Features | |||
| AIR Core Comprehensive Evidence Acquisition (700+ evidence types), Advanced Threat Hunting with YARA, Sigma, osquery, interACT — Cross-Platform Remote Shell, Case Management, Investigation Hub, Advanced Timelining |
|||
| Business Email Compromise Cross-platform evidence acquisition from Google Workspace and Microsoft 365. |
|||
| Fleet AI Multi-Expert Agent System |
|||
| Integrations The type of platforms you can integrate AIR with. |
|||
| #Connections The number of platforms you can connect AIR to. |
|||
| Evidence Retention The duration data is stored making it available for real-time investigations before being moved to cold storage. |
|||
| SOC2 Compliant | |||
| Automation Hub (Coming soon) |
|||
| SSO This is a great place to add a bit of extra information about the feature. |
|||
| On-prem & Air-gapped Supports on-prem, and air-gapped deployment options for military, and government customers. |
|||
The Boost your SOC needs. Right Here!
Scale investigations without complexity or hidden costs.
Trusted by Enterprises and Incident Responders Worldwide
Enterprise Pricing FAQs
-
What packages can I purchase online?
You can buy two packages directly from our website after a free trial:
- Defender – starts at $799/month for up to 200 assets; additional capacity can be purchased in bands of 200 (with volume discounts) up until 1000 assets.
- Responder – starts at $2,299/month for up to 800 assets; additional capacity can be purchased in bands of 250 (with volume discounts) up until 1750 assets. For additional capacity beyond this please contact our sales team for custom quotes.
In all cases annual payment options are available, offering an additional discount.
-
How does the free trial work?
The free trial gives you full access to the features of our Responder package for up to 50 assets. The trial duration is 14 days and no credit card is required. At the end of the trial, you can convert to a paid plan instantly via Stripe (credit card).
-
Who are these packages best suited for?
- Defender – Ideal for smaller teams with earlier-stage SOCs or limited IR capabilities. If you have fewer than 800 assets, or want to begin with fewer than 800 assets and simpler use cases requiring just one integration, Defender is the right choice.
- Responder – Designed for organizations with more complex environments, requiring more automation, broader integration, and a greater volume of assets (between 800 and 5000).
- Ultimate – For enterprises managing 2500+ assets or requiring enterprise-grade automation. Contact our sales team for details.
-
Is on-premise or air-gapped deployment available in Defender or Responder?
No. On-premise and air-gapped support are only available with the Ultimate package. Please contact sales for details.
-
How does deploying Binalyze to more assets work?
You can add additional tiers of asset coverage at any time via the purchase portal or through our sales team:
-
Defender – Entry level includes up to 200 assets. Can be increased in increments of 200, up to 1000 assets (via website).
-
Responder – Entry level includes up to 800 assets. Additional increments of 200-250 can be purchased directly via the website up until 1750. To add further capacity beyond this (the Responder package can be expanded up until 5000 assets) please contact sales for custom quotes.
-
Ultimate – Starts at 2500 assets (sales only). No upper limit.
-
-
What’s the minimum purchase?
The minimum online purchase is 200 assets (Defender). Smaller packages are not available.
-
What payment methods are supported?
Monthly credit card payments are accepted via Stripe for Defender and Responder.
-
Can I cancel at any time?
Yes. Monthly Defender and Responder plans can be cancelled at any time through the website purchase portal. Your subscription remains active until the end of the billing cycle.
-
Where can I read the full Terms and Conditions?
You can review our full Terms and Conditions here for details on billing, cancellation, and acceptable use.
-
Are discounts available?
Yes. Annual payments receive a 10% discount. Additional volume discounts apply for higher asset tiers.
-
Can I switch from Defender to Responder or to Ultimate?
Yes. You can upgrade at any time.
-
Is Binalyze compliant with SOC 2, ISO 27001, and GDPR?
Yes. Binalyze AIR SaaS is certified or aligned with:
- SOC 2 Type II
- ISO 27001
- GDPR
You can read more on our Trust & Data Protection page.
-
What happens to my data after the trial ends?
If you don’t convert to a paid plan, all trial data is securely and permanently deleted in line with our data retention and privacy policies. If you do intend to convert to a paid plan, we have a 7-day grace period during which data is retained to be migrated over to your paid plan, after which it is securely and permanently deleted from the trial instance.
-
What happens when my paid subscription ends?
You have 14 days to export your data. After this grace period, we permanently delete the data from our systems.
-
Where is my data stored and processed?
By default, Binalyze AIR SaaS is hosted on Amazon Web Services (AWS) in the us-east-2 (Ohio) region. For customers with data residency requirements, we can provision tenants across 30 different countries. For details, please speak to our sales teams.
We do not replicate or transfer forensic data outside your tenant’s region. Customers requiring on-premise or air-gapped deployment should contact sales to discuss the Ultimate package.
-
Do you back up my data across regions?
No. All forensic data remains in your tenant’s assigned region. Backup, failover, and disaster recovery are provided within that same AWS region.
-
Does Binalyze have access to my forensic data?
No. Your forensic evidence is encrypted and isolated within your tenant’s region. Binalyze cannot access or use this data unless you explicitly grant temporary access for troubleshooting. Any such access is time-limited and revoked as soon as the issue is resolved.
-
Can I run Binalyze in my own environment?
Yes. On-premise and fully air-gapped deployments are available through the Ultimate package. Please contact sales for details.
What our customers say about us...
Hear from the front-line defenders.
If I were to go anywhere and build a new security stack and defensive layer methodology, I know Binalyze AIR is going to be part of it.
Dane Zielinski
Information Security Manager at Transam
With AIR, when an incident happens, we get the answers.It’s as simple as that. We’re not just throwing alerts over the fence. AIR lets us deliver clarity.
Andrew Haslett
Director of Security Services at Novawatch
With AIR, we get the full picture—what executed, what moved, what was accessed—and that’s what helps us close investigations with confidence.
Christopher Clark
Incident Response Team Manager at Thrive
Cut weeks off your IR workflow.
Start your free trial today.
From signup to investigation in less
than 2 minutes.








