Cloud Sentry
Plans

Start with the check. Grow into the function.

Start on whichever platform you already run, with a fixed-fee inspection and a flat monthly package that keeps it in order. Every price on this page is published, and you can start the first one on your own.

Every platform we run

Start on the platform you already run

We operate five platforms, all five expertly managed. For the three where your identity, email, and infrastructure actually live, there is a fixed-fee inspection to start and a flat monthly package that keeps it in order.

Microsoft 365

Start online today

Hygiene Check

$1,500 one-time
What it inspects
  • Tenant configuration, setting by setting
  • Entra Conditional Access, including the gaps between policies
  • Licensing hygiene and mail security posture

Findings land in your own workspace on our platform, queued as work items with the first evidence filed. We walk it with you, and if you continue you keep the workspace.

Microsoft 365 Upkeep

$795/mo
What we do
  • Conditional Access kept current as Microsoft moves its defaults
  • Tenant configuration corrected
  • Licensing reviewed, and unused licenses cut

Flat per tenant to about 25 users, then $28 each. Month to month, with 30 minutes of CISO time. The check fee credits into your first 90 days.

AWS

Start online today

Hygiene Check

$1,500 one-time
What it inspects
  • Account and organization structure, and IAM posture
  • Public exposure across S3 and security groups
  • GuardDuty coverage, logging baseline, backups, cost flags

You get the results in a working session with our team: what we found, what it means, and what we would fix first.

AWS Upkeep

$795/mo
What we do
  • IAM posture corrected: root usage, MFA, stale keys and roles
  • Public exposure closed across S3 and security groups
  • Logging, GuardDuty coverage, and backups kept on

Guardrails only. Alert and finding triage starts at Resilience. Flat per account, month to month, with 30 minutes of CISO time.

Google Workspace

Hygiene Check

$1,500 one-time
What it inspects
  • Super-admin hygiene and 2SV enforcement
  • Sharing defaults, Drive exposure, and OAuth grants
  • Gmail security posture: SPF, DKIM, DMARC, routing

You get the results in a working session with our team: what we found, what it means, and what we would fix first.

Google Workspace Upkeep

$795/mo
What we do
  • Admin roles and 2SV enforcement held where they belong
  • Sharing defaults corrected and stale OAuth grants removed
  • Gmail security posture maintained

Flat per tenant to about 25 users, then $28 each. Month to month, with 30 minutes of CISO time. The check fee credits into your first 90 days.

Three things a Hygiene Check leaves to other engagements

  • A penetration test. We read configuration only, and a test is scoped with a testing partner when you need one.
  • An audit. Certification comes from an independent audit firm. The check tells you what we found, plainly.
  • An incident response. This is a scheduled inspection. If something is actively wrong, you need a different engagement and we will say so.

The three tiers

Three tiers, all priced the same way

Every tier prices the same way: a base operations fee for the company, plus a per-user rate for the work that scales with seats. The pricing is published here; enrollment runs through a short configure-and-confirm call. Every tier has a seat minimum, printed on the card. Below it, start on the entry rung; the check fee credits forward when you grow into a tier.

Foundations Tier

Managed IT and the service desk, run on the platform.

10-user minimum

Base operations fee

$1,250/mo

Plus, for seat-scaled work

$85/user/mo

What it covers

  • One front door for every request: 13 topics covering 15 workflows, from IT support to buyer security reviews
  • A staffed service desk: each kind of request has its own queue and resolves against SLAs you can see
  • Approvals routed to the people you name, with multi-party sign-off where a single denial stops the request
  • An inventory of your devices, identities, licenses, systems, and SaaS applications, built from your connected platforms
  • A monthly service report, with your change requests and service commitments tracked in the Portal
  • Service health for every connected platform, in one view your whole team can read
Recommended starting point

Resilience

The Foundations Tier, plus security operations.

15-user minimum

Base operations fee

$2,500/mo

Plus, for seat-scaled work

$140/user/mo

Everything in the Foundations Tier, plus

  • Managed detection on Microsoft Defender for Business and cloud-native signals, triaged by our team
  • Security incidents run to a close by our CISO, with a post-incident report of root cause and corrective actions
  • Reported phishing triaged by an operator, and the person who reported it hears the outcome
  • Access lifecycle: requests, provisioning verified in Microsoft 365 and Google Workspace, and joiners, movers, and leavers run per person
  • Email and domain trust: your domains monitored, and DMARC taken from monitor to quarantine to reject
  • Coverage visibility, so you know who is watching and when

Assurance Tier

The Resilience Tier, plus compliance operations.

20-user minimum

Base operations fee

$3,500/mo

Plus, for seat-scaled work

$165/user/mo

Everything in the Resilience Tier, plus

  • A compliance calendar of recurring activities, each one reviewed by our CISO and closed with your sign-off
  • Evidence assembled for every activity and mapped to the controls in your framework, with a readiness roll-up
  • Access review campaigns for staff, guest and external, and vendor access, with every revocation carried out
  • An evidence vault with time-bound, watermarked access for your auditor, plus tracking of the observation window and every auditor request
  • A risk register reviewed by our CISO, on a set cadence
  • Threat hunting by our team across your connected platforms

One workflow at a time

Buy one workflow, run properly

Some companies need one thing run properly and already have the rest handled. Each of these is a single operated workflow on the same platform, priced the same way the tiers are: a base fee for the company plus a rate for the work that scales with seats.

People lifecycle

$650/moplus $22/user/mo

Joiners, movers, and leavers run end to end, including access to every third-party application, so every login ends on the person's last day.

Service desk

$850/moplus $45/user/mo

One front door for any request, staffed by named people, resolving against SLAs you can watch.

Evidence vault and questionnaires

$750/moplus $12/user/mo

A living record of your controls and evidence, plus four customer security questionnaires a quarter answered by our team.

Risk register

$600/moone flat fee

An operated risk register reviewed on a set cadence, with an owner on every open item and a history you can hand an auditor.

Policy program

$550/moplus $6/user/mo

Your policy set kept current, with acknowledgements tracked to completion and the gaps visible before an assessor finds them.

Vendor governance

$500/moone flat fee

Know what you run and who runs it: third-party inventory, risk review, and the evidence that you looked.

  • Security operations starts at the Resilience Tier. That is where we also run identity and devices, so every alert has someone with the access to act on it.
  • Compliance workflows bought alone give you the documentation. You get the artifacts and the tracking, and your team runs the access reviews and the alert triage, so the evidence records your team's work.

Anything outside the catalogue gets its own scope.

Scoped projectPriced per statement of work
Remediation, migrations, and buildouts run as fixed-fee work with a written scope before anything starts.
Time and materials$275 per hour
Hourly, for work outside everything above. We will usually suggest a fixed-fee shape where one fits.

Attach to any tier

Add-ons

Two things some companies need. They attach to any tier on the same agreement, and each is priced on its own, so you pay only for the one you add.

Additional compliance framework

$1,000/mo per framework

The Assurance Tier carries one framework. Each additional one runs as its own program on the same evidence, with its own control mapping and its own audit support. We run SOC 2, ISO 27001, CMMC, HIPAA, and HITRUST.

Managed backup and disaster recovery

From $750/mo

Backup and recovery run as an operated cadence rather than a setting somebody switched on once: cutover tested, restores exercised, and the evidence filed. From $750 a month, scaling with the size of the estate. The one-time buildout scopes separately.

Fixed fee, one time

Where you stand, and when you will be finished

A consultant hands you a list of problems and an invoice. Every assessment we sell tells you three things instead: what is wrong, the date it will be fixed by, and the fixed price to get there. If we do the work, the assessment fee comes off the bill in full.

Risk assessment

$2,500 one-time

A structured read of where your real risk sits: the systems, the identities, the access, and the gaps, ranked by what to fix first. You leave with a completed risk register, and you keep working it in the platform for six months.

AI Governance Assessment

$2,500 one-time

Whether your organisation can actually govern AI, judged against how you make decisions, hold data, and grant access today. Governance outlasts whichever tool your team picked, so this looks at the things that survive changing tools.

Assessment Readiness Path

$5,500 one-time

Where you stand against SOC 2, ISO 27001, CMMC, HIPAA, and HITRUST, and then a roadmap in four bands. The quick wins we close straight away, then the fast wins the platform carries for you, which is the honest option and what you can do yourself for free. Below those sit the project work that gets scoped and priced on its own, and the ongoing operation if you want it run for you.

Fixed fee, one subject at a time

One subject, one fixed fee

Small, scoped reads on a single part of your estate. Each one is a fixed fee with a number on it before you start, and each credits in full if you carry on with us.

Policy Analysis

$1,500 per framework

Send us your policy set. We read it against one framework, name every gap, and hand back drafted recommendations with the reasoning behind each one. Analysing against a second framework is another $1,500, and so on. We run SOC 2, ISO 27001, CMMC, HIPAA, and HITRUST.

Access Review

$1,500 per platform

Every orphaned account, over-privileged user, stale key, and unreviewed admin on one cloud platform: Microsoft 365, AWS, or Google Workspace. The most common finding in a first audit, answered before the auditor asks. Reviewing more than one platform is another $1,500 each, and if your footprint is small we will scope the whole estate together for less.

Vendor Inventory Snapshot

$1,500 one-time

Every third-party application holding an OAuth grant against your tenant, what data it can reach, and what access it was given, ranked by risk. Anything bought on a card with no connection to your tenant is invisible to discovery, and the snapshot says so.

Incident Readiness Check

$2,000 one-time

A read on whether you could actually run a bad day: the plan, the contacts, the backups, the evidence trail. You leave with the gaps named and a response plan you can hand to your team.

Coverage by tier

What each tier watches, and when

01

Resilience tier

Standard business-hours signal triage by our operators.

02

Detection & Response module

Extended coverage with sev-1 page-out, threat hunting, and incident run.

03

Enterprise uplift

Staffed around-the-clock coverage, scoped for enterprise engagements only.

Each rung says exactly what it covers. You know who is watching and when.

Before you call

Common questions

What happens after the Hygiene Check?

On Microsoft 365, your findings land in your own workspace on our platform, queued as work items with a seeded risk register and the first evidence filed, and we walk them with you in a working session. On AWS and Google Workspace we walk the findings with you directly today. Some companies take the list and fix things internally, and that is a fine outcome. Enroll in Upkeep within 90 days and the check fee credits into the package.

Can we move between tiers?

Yes, on a quarterly true-forward. When you outgrow a tier, the next quarter starts on the new one; your history, your operators, and the platform come with you.

What does the escalator cap mean?

Annual increases are capped in writing in the agreement, so you know the ceiling on renewal pricing before you sign anything.

Do plans require multi-year terms?

The three tiers are annual agreements, with multi-year options if you want to hold the structure longer. The entry rung is monthly.

Which platform should we start on?

Whichever one holds the risk you are worried about. There is a check and an Upkeep package for Microsoft 365, AWS, and Google Workspace, all at the same price. The Microsoft 365 and AWS checks you can start online today, and the Google Workspace check begins with a short call. The tiers above run wider still, covering Azure and GCP alongside these three.

Is AWS Upkeep the same thing as monitoring?

They are two different services. AWS Upkeep holds your account guardrails in place: IAM posture, public exposure, logging, GuardDuty coverage, backups, cost hygiene. Triaging the alerts and findings your account produces is a separate job, because an AWS account generates those continuously and the volume depends on what your engineers ship. Triage starts at the Resilience Tier.

Some companies need the whole function run for them.

The tiers run a lot. The operated partnership runs the whole function: IT, security, and compliance end to end, with named modules and one accountable lead. That work starts with a conversation, and the conversation is free.

Tell us what you run today and where it hurts. The partnership is configured around the full function, with named modules and a roadmap one accountable lead owns. Bring your own cloud if you have one; single-tenant BYOC deployment is available for qualified engagements.

Read how the partnership is structured, module by module, and where the tiers hand off to it.