Defence Pods
One team, one monthly fee, no surprise invoices.
Every engagement is delivered by a pod — a named group of engineers assigned to your account, sized by what you run rather than by how noisy a month turned out to be.
Sentinel
Continuous cover for a growing team.
- Best for
- Companies establishing their first real security function.
- Scope
- Up to 250 endpoints & identities
- Response
- 30-minute critical triage, business-hours advisory
- 24×7 managed detection & response
- Endpoint management and hardening baselines
- Identity hardening: SSO and MFA rollout
- Monthly posture review with your leadership
- Quarterly posture review against your cloud and endpoint baseline
- Incident response hours included
Vanguard
The full grid, for companies selling to enterprises.
- Best for
- Teams with certification deadlines and enterprise customers.
- Scope
- Up to 1,000 endpoints & identities
- Response
- 15-minute critical triage, 24×7 advisory
- Everything in Sentinel
- Cloud posture management across all accounts
- Zero trust access and privileged access management
- Compliance programme: ISO 27001, SOC 2 or DPDP
- Continuous API discovery and posture monitoring
- Security automation and playbook engineering
- Named security lead in your leadership meetings
Citadel
Regulated, high-consequence environments.
- Best for
- Financial services, healthcare and critical operations.
- Scope
- Unlimited scope, dedicated pod
- Response
- 15-minute critical triage, dedicated on-call bridge
- Everything in Vanguard
- Dedicated analyst pod assigned to your account only
- Threat hunting on a fixed monthly cadence
- Supply-chain and third-party risk programme
- Regulatory reporting workflows (RBI, SEBI, CERT-In)
- Third-party and supply chain risk programme
- Board-level reporting and audit representation
Every pod includes incident response hours — we do not sell you the fire and then invoice the extinguisher. AI process automation is scoped and quoted separately, and you see the full figure before anything is signed.
Onboarding
From signed order to full coverage in under thirty days
The same engineers who onboard you are the ones who defend you afterwards. There is no handover to a stranger in month two.
- Week 1
Discovery
Telemetry connected, estate enumerated, quick wins identified.
- Week 2
Baseline
Detections deployed and tuned against your environment, not a default pack.
- Week 3
Runbook
Containment authority agreed in writing, escalation paths tested.
- Week 4
Live
Full 24×7 coverage, dashboards handed over, first tabletop scheduled.
Pods
What clients ask about pods
01What exactly is a pod?
A named group of engineers — analysts, a detection engineer and a security lead — assigned to your account. They onboard you, they run your detections, and they are the people on the bridge during an incident. You will know their names.
02Why price by endpoints instead of by data volume?
Because volume-based pricing punishes you for the one thing we want you to do: send us more telemetry. Sizing by endpoints and identities keeps the incentive pointing the right way and makes the invoice predictable.
03Can we move between pods?
Yes, and most clients do as they grow. Moving up takes effect the following month with no re-onboarding, because the same pod stays with you.
04What is the contract length?
Twelve months is standard, with a thirty-day exit if we miss our committed SLAs two months running. We would rather earn the renewal than trap it.
Sizing
Which pod fits is usually obvious after one call.
Tell us your endpoint and identity counts and what you are being asked to prove. We will tell you which pod, and what it costs.