CyberCLI

Cost transparency · no hidden math

What will the Guild
actually cost to run?

The subscription is one number. The AI inference behind your Guild is another. We don't bundle them — you choose your lane (your hardware, frontier APIs, or a mix) and you see the math. Pick a preset for your situation, switch lanes, swap models, watch the numbers move. Nobody else in SOC tooling shows this; we think they should.

Pricing data: public-list as of 2026-05-26. Token estimates: from CyberCLI's calibration harness + prefilter telemetry on design-partner traces. Refreshed quarterly. Your real workload will vary; use this as a starting point, not an SLA.

Start with a scenario

10100250500

Estimated AI inference cost · all three lanes side-by-side

Your hardware · $0 ongoing
All-Local
$ / week
$ / month
Tokens / wk
Cases / day
Hardware

Cheap roles local, judgment cloud
Hybrid
$ / week
$ / month
Tokens / wk
Cases / day
Hardware

No hardware needed · highest cost
All-Frontier
$ / week
$ / month
Tokens / wk
Cases / day
Hardware

Per-role token breakdown · audit our math

Each cell: $/wk on top · model + per-1M list price underneath · click a role to read its full charter.

How the math works.

Volume → cases

Endpoints × events-per-day → raw event volume. CyberCLI's dedupe + prefilter typically compresses that into a 5-10% case ratio (one case per 10-20 related signals). Of those cases, the engine routes ~30-40% to Knight for verification — verification fires only on candidate true-positives, not every signal. ~50% of Knight-verified cases get a Marshal-sequenced plan + Paladin execution.

Why Hybrid is the sweet spot

Warden handles every event — that's 95%+ of total token volume. Putting Warden on local Ollama (~$0) instead of frontier ($15/1M+) is where the savings come from. Knight, Marshal, and Scribe fire per case, which is 1-2 orders of magnitude lower volume. Spending frontier dollars on their judgment is cheap. The Hybrid lane keeps high-volume cheap roles local and frontier-grade reasoning where it actually matters.

Perfectly balanced, as all things should be.

When All-Frontier makes sense

You don't have local GPU and don't want to buy one. You'd rather pay $200-$2000/mo for inference than rack a $4000 workstation. Pick a cheap-tier frontier model (Claude Haiku, DeepSeek V3) and the math gets very friendly. All-Frontier on Haiku at 50-endpoint Business often lands under $300/mo — comparable to Wazuh cloud pricing and less than a single SaaS SOC seat.

When All-Local makes sense

You own GPU you'd otherwise be paying for anyway (a Mac Studio, a homelab rig, a workstation idle overnight). Marginal inference cost is electricity. The tradeoff is judgment quality on Knight/Marshal/Scribe — frontier models are still measurably better on multi-step reasoning. For threat-hunting MSPs running their own AI lane, this is the only architecture that scales to hundreds of tenants without an inference bill.

v5.6 · cost calculator · pricing data refreshed 2026-05-26 · token estimates from CyberCLI calibration harness (rough; quarterly refresh)

It's a simple calculus.