Skip to main content

Pricing & Engagement Models

Engagements & Platform Licensing

Engagement services. Platform licences. Your tier sets the scope.

Two commercial models. Three customer tiers. Every programme SecureITX delivers is explained before the sales call, scoped in writing within 48 hours, and priced without ambiguity.

2
commercial models: engagement or platform licence
3
customer tiers: SMB, Enterprise, Government & Regulated
30
minutes to scope any engagement at no cost

Understand the model first

Two ways to work with SecureITX. Both start with one call.

The right model depends on whether you need a bounded assessment or a production system running continuously in your environment. Many organisations use both.

Engagement Services

Scoped. Delivered. Closed.

A bounded engagement with defined objectives, methodology, scope, and deliverables. Begins with a scoping call. Closes with exploitation-validated findings and a remediation roadmap. No ongoing commitment required, though most organisations re-engage on a cadence.

  • Penetration Testing
  • Identity & Access Security
  • AI Governance
  • MCP Security
  • Agent AI Security
  • Compliance Automation (assessment)
Entry: 30-minute scoping call → written proposal within 48 hours
Platform Services

Licensed. On-premises. Running continuously.

A production system deployed on your infrastructure. Your data never leaves your environment. Licensed annually and sized to your deployment: employee count, user count, or agent configuration. Begins with a free assessment or live demo before any commercial commitment.

  • Security Awareness Training
  • AI Business Intelligence
  • Secure Enterprise Collaboration
  • Compliance Automation (platform)
Entry: Free assessment or live demo → proposal → deployment

Your tier determines your programme

SMB, Enterprise, or Government & Regulated. Different threats. Different constraints. Different programmes.

Automated threat actor infrastructure does not filter by company size. Your defensive posture, budget, and regulatory obligations are specific to your tier, so every programme we build is specific to it too.

A programme built for SMB realities. Not an enterprise programme scaled down.

Ransomware affiliate programmes scan millions of IP addresses continuously, regardless of headcount. SMBs represent the highest-yield segment because lower defensive maturity means faster compromise and faster payment. Supply chain access compounds this: organisations of 50 to 500 employees routinely hold privileged access into larger enterprise clients, making them primary targets even when they are not the final objective.

SecureITX SMB engagements are scoped to the actual attack paths your environment exposes. Findings are written for a management team without a full-time CISO: plain language, ranked by the risk each remediation actually removes, with implementation steps that do not require translating a technical report into an action plan.

30-minute scoping call → fixed-scope proposal within 48 hours → no obligation
Schedule a scoping call

What an SMB engagement covers

External attack surface assessment Identifies internet-exposed services that automated ransomware affiliate tooling discovers before your team does.
Active Directory and identity security review Privileged account exposure, lateral movement paths, and password-spray resistance: the controls that determine whether one compromised credential becomes a full network takeover.
Backup environment integrity test Confirms recovery backups are network-isolated and cannot be encrypted from your production environment. This is the single control that determines whether you recover without paying.
Business Email Compromise simulation Invoice fraud, payroll redirect, and supplier impersonation scenarios calibrated to the social engineering methods that extract the highest financial losses from SMB finance teams.
ISO 27001 and Cyber Essentials Plus readiness Structured to achieve certification. Not gap analysis that produces a second engagement before anything is remediated.
Third-party vendor access review Identifies the partner and supply chain connections that make SMBs high-value stepping stones into larger enterprise clients.

Platform services

Every platform starts with a free assessment before any commitment.

Platform services are licensed annually and sized to your deployment. Every one has a zero-cost entry point so you can verify fit before a commercial conversation begins.

Start free Free Baseline Assessment → 5 business days → no commitment

Security Awareness Training

Email, SMS, and voice simulation. AI-adaptive difficulty per individual. Micro-training at the moment of failure. Measurable behaviour change.

Licensed by employee count
SMBUp to 250 employees
Growth251 to 1,000 employees
Enterprise1,000+ employees
  • Phishing, smishing, and vishing campaigns from live threat feeds
  • AI-adaptive difficulty on a 1 to 10 Goldilocks scale per employee
  • Compliance evidence for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST CSF
  • Individual risk scores and department benchmarks
See full capabilities →
Live demo Demo on your actual data → 3 real questions answered → no synthetic data

AI Business Intelligence

Four specialist agents — Finance, HR, Projects, Sales — trained on your domain rules and data structures. Answers in under 7 seconds with 4-component explainability.

Licensed by agent configuration
Core1 to 2 domain agents
ProfessionalAll 4 domain agents
EnterpriseCustom agents + integrations
  • Deployed on your infrastructure — data never leaves your network
  • 150+ intent patterns with 79 to 95% confidence scoring
  • Role-based data authorization enforced at the query layer
  • Full audit log of every query, response, and data access event
See full capabilities →
Free assessment Deployment Assessment → DLP configuration review → no commitment

Secure Enterprise Collaboration

AES-256-GCM per-message encryption. 45 DLP patterns across 6 categories. Local AI that never contacts an external service. Built for organisations that cannot afford a data leak.

Licensed by user count
SMBUp to 100 users
Enterprise101 to 1,000 users
Gov / Air-gappedCleared deployment
  • 45 DLP patterns: financial, PII, healthcare, credentials, network secrets, custom
  • 13 named roles, 47 granular permissions, 5 sensitivity classification levels
  • eDiscovery with legal hold, configurable retention (7 days to indefinite)
  • GDPR, SOC 2, and HIPAA controls built in, not bolted on
See full capabilities →
Scoping call 30-minute call → framework selection → deployment proposal

Compliance Automation

2,109 controls. 16 frameworks. 48 AI agents monitoring every 5 minutes. Audit-ready evidence generated automatically with no manual evidence collection.

Licensed by environment size
ProfessionalUp to 5 frameworks
EnterpriseAll 16 frameworks
GovernmentSovereign + national frameworks
  • SOC 2, ISO 27001, PCI DSS, FedRAMP, HIPAA, NCA ECC, ADHICS and more
  • 48 AI agents across 48 integrated security systems
  • Evidence generated automatically with no manual collection
  • Deployed on your infrastructure: no data leaves your environment
See full capabilities →

Transparency on pricing

We do not publish prices. Here is why, and what determines your quote.

Every engagement is scoped to your actual environment. Publishing a price list would mean either overcharging straightforward environments or under-scoping complex ones. Neither outcome serves you well.

Engagement services — what determines your quote

01
ScopeNumber of target types, IP ranges, applications, and environments in scope.
02
Methodology tierBlack Box, Grey Box, White Box, Crystal Box, or Red Team. Each has a different resource requirement.
03
Regulatory frameworkCompliance framework mapping, evidence package production, and submission format requirements add time.
04
Delivery constraintsClassified environments, data sovereignty requirements, and maintenance windows affect scheduling.

Platform services — what determines your licence

01
Deployment sizeEmployee count, user count, or agent configuration depending on the platform.
02
Framework countCompliance Automation is licensed by the number of frameworks actively monitored.
03
Initial deploymentA one-time deployment engagement configures and validates the platform before handover.
04
Support tierStandard support is included in all licences. Priority response SLAs are available for regulated and government deployments.
Written proposal within 48 hours of the scoping call. Scope, methodology, timeline, and a fixed price. No ambiguity.
The scoping call is free and carries no obligation. Your first contact is the engineer who will do the work, not a sales intermediary.
Platform demos are run on your actual data, not a demo environment. You see the real output before any commercial commitment.

Every programme begins with a 30-minute call at no cost.

Tell a senior engineer what you are trying to solve. We will recommend the engagement or platform that fits your tier, sector, and current risk posture, and scope it in writing within 48 hours.

Schedule a scoping call