Detection, blocking and the way out of a false positive are free. To keep receiving the threat address database and binary updates, and to see the deeper views: US$59 per server per year — subscribe for one if you only have one. No other plans, no hidden fees.
⭐ This section has no Free/Pro split. Detection and blocking are free, so every source below is read — and acted on — on a host with no subscription too.
| Source | What is read | Notes |
|---|---|---|
| Apache | access log + error log | Defaults to /var/log/apache2; both the directory and the filename patterns are configurable |
| nginx | access log + error log | Opt-in: name a directory or it is not touched at all, so an Apache-only host never gets a warning about a directory it never asked us to read |
| SSH (sshd) | /var/log/auth.log or /var/log/secure | The name differs per distribution, so the file is identified by reading it rather than by guessing; both native sshd and PAM formats are understood (appliances such as Synology use the latter) |
| FTP (vsftpd, proftpd, …) | the same authentication log | The PAM message family, sharing one file with SSH |
| Feature | Free | Pro |
|---|---|---|
| Built-in rule detection + automatic blocking (nftables / ipset / iptables) | ✅ | ✅ |
| Unblocking and the whitelist (the way out of a false positive) | ✅ | ✅ |
| Blocklist, IP management, live dashboard status | ✅ | ✅ |
| Alerts: email, syslog, the console's notification log (daily digest included) | ✅ | ✅ |
| Shared threat address database (the daily signed list of attacking sources) | ❌ | ✅ |
| OTA auto-update | ❌ manual reinstall | ✅ |
| Resource alerts (CPU / memory / disk over threshold) | ❌ | ✅ |
| Resource charts (history) | ❌ | ✅ |
| Site analytics | ❌ | ✅ |
| The detection rules page: read, change and reset the thresholds (after expiry the thresholds stay in force and detection is unchanged) | ❌ | ✅ |
| Scanning historical logs | ❌ | ✅ |
| Extra scan directories (the built-in ones are always scanned) | ❌ | ✅ |
| Log sources page (which files this host is reading, and how far) | ❌ | ✅ |
| Data export, notification-log export | ❌ | ✅ |
| Feature | Free | Pro |
|---|---|---|
| Bind to your account + see every one of your hosts in the fleet list (with version and 24-hour event count) | ✅ | ✅ |
| Per-host detail, event history, IP lookup | ❌ | ✅ |
| Cross-host event and block data export | ❌ | ✅ |
| Fleet charts (24-hour event distribution, daily blocking trend) | ❌ | ✅ |
Payments are handled by Paddle (credit card / PayPal, taxes and invoices included) — your card number never touches our systems. When a subscription lapses, core protection keeps running — detection and blocking do not stop. The Pro pages close, and the console says plainly how many days that host has gone without updates: nothing is taken away quietly.
What happens when a subscription expires, how cancelling and refunds work, how coordinated protection works — see the FAQ.