Cloud Sentry
Plans

Start with the check. Grow into the function.

Start on whichever platform you already run, with a fixed-fee inspection and a flat monthly package that keeps it in order. Every price on this page is published, and you can start the first one without talking to us.

Every platform we run

Start on the platform you already run

We operate five platforms and we turn down work on anything else. For the three where your identity, email, and infrastructure actually live, there is a fixed-fee inspection to start and a flat monthly package that keeps it in order.

Microsoft 365

Start online today

Hygiene Check

$1,500 one-time
What it inspects
  • Tenant configuration, setting by setting
  • Entra Conditional Access, including the gaps between policies
  • Licensing hygiene and mail security posture

Findings land in your own workspace on our platform, queued as work items with the first evidence filed. We walk it with you, and if you continue you keep the workspace.

Microsoft 365 Upkeep

$795/mo
What we do
  • Conditional Access kept current as Microsoft moves its defaults
  • Tenant configuration corrected, not just reported
  • Licensing reviewed, and what nobody uses cut

Flat per tenant to about 25 users, then $28 each. Month to month, with 30 minutes of CISO time. The check fee credits into your first 90 days.

AWS

Start online today

Hygiene Check

$1,500 one-time
What it inspects
  • Account and organization structure, and IAM posture
  • Public exposure across S3 and security groups
  • GuardDuty coverage, logging baseline, backups, cost flags

You get the results in a working session with our team: what we found, what it means, and what we would fix first.

AWS Upkeep

$795/mo
What we do
  • IAM posture corrected: root usage, MFA, stale keys and roles
  • Public exposure closed across S3 and security groups
  • Logging, GuardDuty coverage, and backups kept on

Guardrails only. Alert and finding triage starts at Resilience. Flat per account, month to month, with 30 minutes of CISO time.

Google Workspace

Hygiene Check

$1,500 one-time
What it inspects
  • Super-admin hygiene and 2SV enforcement
  • Sharing defaults, Drive exposure, and OAuth grants
  • Gmail security posture: SPF, DKIM, DMARC, routing

You get the results in a working session with our team: what we found, what it means, and what we would fix first.

Google Workspace Upkeep

$795/mo
What we do
  • Admin roles and 2SV enforcement held where they belong
  • Sharing defaults corrected and stale OAuth grants removed
  • Gmail security posture maintained

Flat per tenant to about 25 users, then $28 each. Month to month, with 30 minutes of CISO time. The check fee credits into your first 90 days.

What a Hygiene Check is not

  • A penetration test. Nobody attacks anything. We read configuration; we do not probe defenses.
  • An audit. It certifies nothing and satisfies no framework requirement. It tells you what we found, plainly.
  • An incident response. This is a scheduled inspection. If something is actively wrong, you need a different engagement and we will say so.

The three tiers

Three tiers, all priced the same way

Every tier prices the same way: a base operations fee for the company, plus a per-user rate for the work that scales with seats. The pricing is published here; enrollment runs through a short configure-and-confirm call. Every tier has a seat minimum, printed on the card. Below it, start on the entry rung; the check fee credits forward when you grow into a tier.

Foundations Tier

Managed IT and the service desk, run on the platform.

10-user minimum

Base operations fee

$1,250/mo

Plus, for seat-scaled work

$85/user/mo

What it covers

  • A staffed service desk: requests land with a person and resolve against SLAs you can see
  • An asset register: every device and license with an owner, a location, and where it sits in its life
  • CSAT captured on resolved requests, visible to you
  • A knowledge base kept current as answers repeat
  • Service health in one view your whole team can read
  • A team console for the people who run your side

The honest part. The Foundations Tier is IT and the desk. Detection, access lifecycle, and compliance operations live in the two tiers above it.

Recommended starting point

Resilience

The Foundations Tier, plus security operations.

15-user minimum

Base operations fee

$2,500/mo

Plus, for seat-scaled work

$140/user/mo

Everything in the Foundations Tier, plus

  • Security operations run by our team
  • Managed detection via Microsoft Defender for Business and cloud-native signals
  • Access lifecycle: requests, provisioning, and joiner-mover-leaver
  • Coverage visibility, so you know who is watching and when

The honest part. Detection runs on Microsoft Defender for Business and cloud-native signals. If your estate sits outside that footprint, we will say so on the configure call.

Assurance Tier

The Resilience Tier, plus compliance operations.

20-user minimum

Base operations fee

$3,500/mo

Plus, for seat-scaled work

$165/user/mo

Everything in the Resilience Tier, plus

  • An evidence vault your auditor can actually read
  • A risk register reviewed by an operator, on a set cadence
  • Policy acknowledgements tracked to completion
  • A questionnaire-response allotment for customer security reviews
  • A quarterly advisory review with our team

The honest part. One framework to start; each additional one is $1,000 a month. The audit itself comes from an independent firm, and we will not pretend otherwise.

One workflow at a time

Buy one workflow instead of the whole function

Some companies need one thing run properly and already have the rest handled. Each of these is a single operated workflow on the same platform, priced the same way the tiers are: a base fee for the company plus a rate for the work that scales with seats.

People lifecycle

$650/moplus $22/user/mo

Joiners, movers, and leavers run end to end, including access to every third-party application, so nobody keeps a login after their last day.

Service desk

$850/moplus $45/user/mo

One front door for any request, staffed by named people, resolving against SLAs you can watch.

Evidence vault and questionnaires

$750/moplus $12/user/mo

A living record of your controls and evidence, plus four customer security questionnaires a quarter answered by our team.

Risk register

$600/moone flat fee

An operated risk register reviewed on a set cadence, with an owner on every open item and a history you can hand an auditor.

Policy program

$550/moplus $6/user/mo

Your policy set kept current, with acknowledgements tracked to completion and the gaps visible before an assessor finds them.

Vendor governance

$500/moone flat fee

Know what you run and who runs it: third-party inventory, risk review, and the evidence that you looked.

  • Security operations is not sold on its own. Detection without control of identity and devices is alerting nobody can act on, which is the thing we exist to replace. It starts at the Resilience Tier.
  • Compliance workflows bought alone are documentation, not operations. You get the artifacts and the tracking. You do not get operators executing your access reviews or triaging your alerts, so the evidence is of your work, not ours.

And when it does not fit any of this

Scoped projectPriced per statement of work
Remediation, migrations, and buildouts run as fixed-fee work with a written scope before anything starts.
Time and materials$275 per hour
Hourly, for work outside everything above. We would usually rather find you a shape that is not hourly, and we will say so.

Attach to any tier

Add-ons

Two things that some companies need and most do not. They attach to any tier on the same agreement, and neither is bundled into a price you pay whether you use it or not.

Additional compliance framework

$1,000/mo per framework

The Assurance Tier carries one framework. Each additional one runs as its own program on the same evidence, with its own control mapping and its own audit support. We run SOC 2, ISO 27001, CMMC, HIPAA, and HITRUST, and we will tell you plainly if you are asking for one we do not.

Managed backup and disaster recovery

From $750/mo

Backup and recovery run as an operated cadence rather than a setting somebody switched on once: cutover tested, restores exercised, and the evidence filed. From $750 a month, scaling with the size of the estate. The one-time buildout scopes separately.

Fixed fee, one time

Where you stand, and when you will be finished

A consultant hands you a list of problems and an invoice. Every assessment we sell tells you three things instead: what is wrong, the date it will be fixed by, and the fixed price to get there. If we do the work, the assessment fee comes off the bill in full.

Risk assessment

$2,500 one-time

A structured read of where your real risk sits: the systems, the identities, the access, and the gaps, ranked by what to fix first. You leave with a completed risk register, and you keep working it in the platform for six months.

AI Governance Assessment

$2,500 one-time

Whether your organisation can actually govern AI, judged against how you make decisions, hold data, and grant access today. Governance does not live inside whichever tool your team picked, so this looks at the things that survive changing tools.

Assessment Readiness Path

$5,500 one-time

Where you stand against SOC 2, ISO 27001, CMMC, HIPAA, and HITRUST, and then the part nobody else gives you: a roadmap in four bands. The quick wins we close straight away, then the fast wins the platform carries for you, which is the honest option and what you can do yourself for nothing. Below those sit the project work that gets scoped and priced on its own, and the ongoing operation if you want it run for you.

Fixed fee, one subject at a time

One subject, one fixed fee

Small, scoped reads on a single part of your estate. Each one is a fixed fee with a number on it before you start, and each credits in full if you carry on with us.

Policy Analysis

$1,500 per framework

Send us your policy set. We read it against one framework, name every gap, and hand back drafted recommendations with the reasoning behind each one. Analysing against a second framework is another $1,500, and so on. We run SOC 2, ISO 27001, CMMC, HIPAA, and HITRUST.

Access Review

$1,500 per platform

Every orphaned account, over-privileged user, stale key, and unreviewed admin on one cloud platform: Microsoft 365, AWS, or Google Workspace. The most common finding in a first audit, answered before the auditor asks. Reviewing more than one platform is another $1,500 each, and if your footprint is small we will scope the whole estate together for less.

Vendor Inventory Snapshot

$1,500 one-time

Every third-party application holding an OAuth grant against your tenant, what data it can reach, and what access it was given, ranked by risk. Anything bought on a card with no connection to your tenant is invisible to discovery, and we say so rather than imply otherwise.

Incident Readiness Check

$2,000 one-time

A read on whether you could actually run a bad day: the plan, the contacts, the backups, the evidence trail. You leave with the gaps named and a response plan you can hand to your team.

Coverage by tier

What each tier watches, and when

01

Resilience tier

Standard business-hours signal triage by our operators.

02

Detection & Response module

Extended coverage with sev-1 page-out, threat hunting, and incident run.

03

Enterprise uplift

Staffed around-the-clock coverage, scoped for enterprise engagements only.

No rung oversells the one above it. You know exactly who is watching and when.

Before you call

Common questions

What happens after the Hygiene Check?

On Microsoft 365, your findings land in your own workspace on our platform, queued as work items with a seeded risk register and the first evidence filed, and we walk them with you in a working session. On AWS and Google Workspace we walk the findings with you directly today. Some companies take the list and fix things internally, and that is a fine outcome. Enroll in Upkeep within 90 days and the check fee credits into the package.

Can we move between tiers?

Yes, on a quarterly true-forward. When you outgrow a tier, the next quarter starts on the new one; your history, your operators, and the platform come with you.

What does the escalator cap mean?

Annual increases are capped in writing in the agreement, so you know the ceiling on renewal pricing before you sign anything.

Do plans require multi-year terms?

The three tiers are annual agreements, with multi-year options if you want to hold the structure longer. The entry rung is monthly.

Which platform should we start on?

Whichever one holds the risk you are worried about. There is a check and an Upkeep package for Microsoft 365, AWS, and Google Workspace, all at the same price. The Microsoft 365 and AWS checks you can start online today, and the Google Workspace check begins with a short call. The tiers above run wider still, covering Azure and GCP alongside these three.

Is AWS Upkeep the same thing as monitoring?

No, and we would rather say so here than have you find out later. AWS Upkeep holds your account guardrails in place: IAM posture, public exposure, logging, GuardDuty coverage, backups, cost hygiene. It does not include triaging the alerts and findings your account produces, because an AWS account generates those continuously and the volume depends on what your engineers ship. Triage starts at the Resilience Tier.

Some companies need the bigger door.

The tiers run a lot. The operated partnership runs the whole function: IT, security, and compliance end to end, with named modules and one accountable lead. That work starts with a conversation, and the conversation is free.

Tell us what you run today and where it hurts. The partnership is configured around the full function, with named modules and a roadmap one accountable lead owns. Bring your own cloud if you have one; single-tenant BYOC deployment is available for qualified engagements.

Read how the partnership is structured, module by module, and where the tiers hand off to it.