- $ / week
- —
- $ / month
- —
- Tokens / wk
- —
- Cases / day
- —
- Hardware
- —
—
Cost transparency · no hidden math
The subscription is one number. The AI inference behind your Guild is another. We don't bundle them — you choose your lane (your hardware, frontier APIs, or a mix) and you see the math. Pick a preset for your situation, switch lanes, swap models, watch the numbers move. Nobody else in SOC tooling shows this; we think they should.
Pricing data: public-list as of 2026-05-26. Token estimates: from CyberCLI's calibration harness + prefilter telemetry on design-partner traces. Refreshed quarterly. Your real workload will vary; use this as a starting point, not an SLA.
—
—
—
Each cell: $/wk on top · model + per-1M list price underneath · click a role to read its full charter.
Endpoints × events-per-day → raw event volume. CyberCLI's dedupe + prefilter typically compresses that into a 5-10% case ratio (one case per 10-20 related signals). Of those cases, the engine routes ~30-40% to Knight for verification — verification fires only on candidate true-positives, not every signal. ~50% of Knight-verified cases get a Marshal-sequenced plan + Paladin execution.
Warden handles every event — that's 95%+ of total token volume. Putting Warden on local Ollama (~$0) instead of frontier ($15/1M+) is where the savings come from. Knight, Marshal, and Scribe fire per case, which is 1-2 orders of magnitude lower volume. Spending frontier dollars on their judgment is cheap. The Hybrid lane keeps high-volume cheap roles local and frontier-grade reasoning where it actually matters.
Perfectly balanced, as all things should be.
You don't have local GPU and don't want to buy one. You'd rather pay $200-$2000/mo for inference than rack a $4000 workstation. Pick a cheap-tier frontier model (Claude Haiku, DeepSeek V3) and the math gets very friendly. All-Frontier on Haiku at 50-endpoint Business often lands under $300/mo — comparable to Wazuh cloud pricing and less than a single SaaS SOC seat.
You own GPU you'd otherwise be paying for anyway (a Mac Studio, a homelab rig, a workstation idle overnight). Marginal inference cost is electricity. The tradeoff is judgment quality on Knight/Marshal/Scribe — frontier models are still measurably better on multi-step reasoning. For threat-hunting MSPs running their own AI lane, this is the only architecture that scales to hundreds of tenants without an inference bill.
v5.6 · cost calculator · pricing data refreshed 2026-05-26 · token estimates from CyberCLI calibration harness (rough; quarterly refresh)
It's a simple calculus.