Skip to content

Service Tiers

KYRA AI MDR offers four service tiers designed to meet the security needs of organizations from solo developers to enterprises.

Tier Overview

TierPricingTarget MarketKey Value Proposition
FREE$0/moSmall (1-30 employees)Security posture check, basic monitoring
MDR$230/moSMB (10-100 employees)24/7 AI-powered detection + auto-response
PRO$600/moMid-market (30-300 employees)Full MDR + dedicated analyst + compliance
CUSTOMNegotiatedEnterprise (300+)Tailored MDR with on-site support

Annual Pricing

TierMonthlyAnnualSavings
MDR$230/mo$1,380/yr ($115/mo effective)50% off

MDR Annual ($1,380/yr) offers 50% savings compared to monthly billing.

Service Capabilities

CapabilityFREEMDRPROCUSTOM
24/7 Threat DetectionYesYesYesYes
MITRE ATT&CK MappingYesYesYesYes
AI Alert TriageSummary onlyFull (99% FP filter)Full (99% FP filter)Full (99% FP filter)
Auto-ResponseNoStandard SOARCustom SOARCustom playbooks
Proactive Threat HuntingNoNoMonthlyWeekly
Custom Detection RulesNoNoLimitedUnlimited
DashboardRead-onlyFull interactiveFull + customFully custom
ReportsMonthly score emailMonthly threat briefWeekly + complianceCustom cadence
ComplianceNoBasic ISMS-P checklistISMS-P + SOC 2Multi-framework
Dedicated AnalystNoNoSharedAssigned
On-site SupportNoNoNoYes
EASM ScanMonthlyWeeklyDailyReal-time
SupportCommunity/docsEmail (24hr)Dedicated (4hr SLA)Dedicated (1hr SLA)
OnboardingSelf-serveGuided (1-click)White-gloveOn-site

Ingestion Quotas

TierMax EPSDaily IngestionCollectorsEndpointsUsers
FREE50500 MB1403
MDR5005 GB112025
PRO2,00020 GB535050
CUSTOMUnlimitedUnlimitedUnlimitedUnlimitedUnlimited

Overage

TierOverage Policy
FREEHard cap (logs stop ingesting)
MDR$0.02/GB beyond daily limit
PRO$0.015/GB beyond daily limit
CUSTOMNegotiated

Log Retention

TierLog Retention
FREE7 days
MDR90 days
PRO180 days
CUSTOM365+ days

Legal hold override: All retention periods extended indefinitely during active legal proceedings.


Incident Severity Matrix (SEV1-SEV4)

SEV1 — Critical (Active Compromise with Business Impact)

Indicators: Active ransomware, real-time data exfiltration (>1GB), domain admin compromise, critical infrastructure breach, public data exposure, active C2 communication.

Business Impact: Service disruption >50% of users, financial loss >$100K, regulatory breach requiring immediate notification.

Response: Detection to acknowledgment <15 minutes (all tiers), war room activation immediate, executive notification within 30 minutes, customer notification within 1 hour.

SEV2 — High (Confirmed Compromise, Limited Immediate Impact)

Indicators: Confirmed malware execution, lateral movement, non-privileged credential compromise, successful privilege escalation, persistent backdoor deployment.

Response Times:

  • FREE: Acknowledged within 4 hours, contained within 8 hours
  • MDR: Acknowledged within 1 hour, contained within 8 hours
  • PRO/CUSTOM: Acknowledged within 30 minutes, contained within 4 hours

SEV3 — Medium (Suspicious Activity Requiring Investigation)

Indicators: Policy violations, authentication anomalies, network reconnaissance, suspicious downloads, phishing attempts, unsuccessful exploitation.

Response Times:

  • FREE: Documented analysis within 24 hours
  • MDR: Investigation within 4 hours
  • PRO/CUSTOM: Investigation within 2 hours

SEV4 — Low (Informational/Routine)

Indicators: Routine vulnerability scan findings, expected security tool alerts, minor configuration drift, certificate expiration warnings.

Response Times:

  • FREE: Analysis within 72 hours
  • MDR: Batch processing within 24 hours
  • PRO/CUSTOM: Analysis within 8 hours

Severity Escalation Rules

EscalationTrigger
SEV4 → SEV3>5 related events from same asset within 24 hours
SEV3 → SEV2IOC match confirmed or successful exploitation evidence
SEV2 → SEV1Lateral movement detected or business-critical system affected
Any → SEV1Customer declares business impact or regulatory trigger

SLA Response Times

SeverityFREEMDRPRO / CUSTOM
SEV115 min15 min15 min
SEV24 hours1 hour30 min
SEV324 hours4 hours2 hours
SEV472 hours24 hours8 hours

SLA Resolution Times

SeverityFREEMDRPRO / CUSTOM
SEV18 hours*4 hours2 hours
SEV216 hours*8 hours4 hours
SEV33 days*24 hours12 hours
SEV45 days*3 days2 days

FREE tier resolution = comprehensive analysis and recommendations (no active containment)

Containment SLAs (MDR, PRO, CUSTOM Only)

SeverityMDRPRO / CUSTOM
SEV12 hours1 hour
SEV26 hours3 hours
SEV312 hours6 hours
SEV424 hours12 hours

Platform Availability

ComponentFREEMDRPRO / CUSTOM
Event Ingestion99.5%99.9%99.99%
Management Console99.0%99.5%99.9%
REST API99.0%99.5%99.9%
Alert Notifications99.5%99.9%99.99%

SLA Credits

Availability BreachCreditMax Monthly
Below PRO/CUSTOM SLA (99.99%)5%25%
Below MDR SLA (99.9%)10%50%
Below FREE SLA (99.5%)10%50%
Below 99.0% (any tier)25%100%

Feature Access by Tier

CategoryFeatureFREEMDRPROCUSTOM
DetectionBasic Rule LibraryYesYesYesYes
DetectionAdvanced ML ModelsNoYesYesYes
DetectionCustom Rule BuilderNoNoLimitedYes
DetectionThreat Intel FeedsBasicPremiumPremium + PrivatePremium + Private
InvestigationAutomated TriageSummary onlyFull (99% FP filter)Full (99% FP filter)Full (99% FP filter)
InvestigationForensics ToolsNoBasicAdvancedAdvanced
InvestigationCase ManagementNoYesYesYes
ResponseAlert NotificationsYesYesYesYes
ResponseAutomated ContainmentNoStandard SOARCustom SOARCustom playbooks
ResponsePlaybook ExecutionNoStandardCustomCustom
ReportingStandard DashboardsRead-onlyFull interactiveFull + customFully custom
ReportingExecutive ReportsNoMonthly threat briefWeekly + complianceCustom cadence
ReportingCompliance ReportsNoBasic ISMS-PISMS-P + SOC 2Multi-framework
ReportingCustom ReportsNoNoYesYes
APIRead-only APIYesYesYesYes
APIWrite APINoLimitedYesYes
APIWebhooksNoYesYesYes

Tier Migration

Customers can upgrade or downgrade their service tier at any time:

  • Upgrades: New features and quotas are activated immediately
  • Downgrades: Features are adjusted at the end of the current billing period
  • Data Retention: On downgrade, existing data remains accessible until the original retention period expires; new data follows the new tier’s retention schedule