Pricing that fits in one sentence

Detection, blocking and the way out of a false positive are free. To keep receiving the threat address database and binary updates, and to see the deeper views: US$59 per server per year — subscribe for one if you only have one. No other plans, no hidden fees.

Full feature comparison

Log sources we can analyse

This section has no Free/Pro split. Detection and blocking are free, so every source below is read — and acted on — on a host with no subscription too.

SourceWhat is readNotes
Apacheaccess log + error logDefaults to /var/log/apache2; both the directory and the filename patterns are configurable
nginxaccess log + error logOpt-in: name a directory or it is not touched at all, so an Apache-only host never gets a warning about a directory it never asked us to read
SSH (sshd)/var/log/auth.log or /var/log/secureThe name differs per distribution, so the file is identified by reading it rather than by guessing; both native sshd and PAM formats are understood (appliances such as Synology use the latter)
FTP (vsftpd, proftpd, …)the same authentication logThe PAM message family, sharing one file with SSH

Agent — the one running on each of your hosts

FeatureFreePro
Built-in rule detection + automatic blocking (nftables / ipset / iptables)
Unblocking and the whitelist (the way out of a false positive)
Blocklist, IP management, live dashboard status
Alerts: email, syslog, the console's notification log (daily digest included)
Shared threat address database (the daily signed list of attacking sources)
OTA auto-update❌ manual reinstall
Resource alerts (CPU / memory / disk over threshold)
Resource charts (history)
Site analytics
The detection rules page: read, change and reset the thresholds (after expiry the thresholds stay in force and detection is unchanged)
Scanning historical logs
Extra scan directories (the built-in ones are always scanned)
Log sources page (which files this host is reading, and how far)
Data export, notification-log export

Hub — managing your fleet in one place

FeatureFreePro
Bind to your account + see every one of your hosts in the fleet list (with version and 24-hour event count)
Per-host detail, event history, IP lookup
Cross-host event and block data export
Fleet charts (24-hour event distribution, daily blocking trend)
Free
US$0
Any number of hosts · free forever, not a trial
  • Built-in rule detection + automatic blocking
  • nftables / ipset / iptables, with automatic fallback
  • Unblocking and the whitelist — the way out of a false positive
  • Blocklist, IP management, live dashboard status
  • Email and syslog alerts, plus the console's notification log
  • Bind to your account and see every one of your hosts in the fleet list
  • No threat address database updates over time (detection rules ship with each release)
  • Binary updates by manual reinstall (no OTA)
  • Site analytics, historical log scans, data export
  • The detection rules page (thresholds stay in force and keep detecting, but you can neither read nor change them)
Pro
US$59
per host / per year · from one — one subscription per host
  • Everything in Free
  • Threat address database: the daily signed list of attacking sources
  • OTA binary auto-updates
  • Resource monitoring: threshold alerts and history charts
  • Site analytics, historical log scans, extra scan directories
  • The detection rules page: read the thresholds, change them, reset them
  • Data and notification-log export
  • Per-host detail, event history and IP lookup on the Hub
  • Priority forum support

Payments are handled by Paddle (credit card / PayPal, taxes and invoices included) — your card number never touches our systems. When a subscription lapses, core protection keeps running — detection and blocking do not stop. The Pro pages close, and the console says plainly how many days that host has gone without updates: nothing is taken away quietly.

FAQ

What happens when a subscription expires, how cancelling and refunds work, how coordinated protection works — see the FAQ.