CiBRAI gives smaller organisations a practical operating layer for detection, investigation, response and security management โ in one secure, isolated workspace. Deploy a guided agent to Windows, macOS or Linux machines, and start building visibility today.
Use code EARLYBIRD for 50% off any self-service plan. The discounted rate stays in place while your subscription remains continuously active.
CiBRAI connects detection, investigation, response and management activities so the evidence collected at the start of an incident remains available through containment, closure and reporting.
Live SIEM alerts, endpoint activity, anomaly scoring and a prioritised threat queue.
Cases, threat intelligence, MITRE ATT&CK context, email analysis, timeline and evidence review.
Tasks, approvals, playbooks, containment recommendations, remediation tracking and closure evidence.
Essential Eight reporting, risk and posture views, executive summaries and trend reporting.
Most organisations can connect the first supported machine quickly. Coverage expands as you tune and add devices.
Your isolated tenant is provisioned. Confirm the primary administrator, notification address and basic workspace settings.
Deploy the agent to initial Windows, macOS or Linux machines. Security events and asset context begin to arrive.
Review the first alerts, validate expected activity, invite additional users and establish initial notification rules.
Tune detections, confirm case workflows, review the first posture summary and decide which machines to add next.
Core = available in plan. Enhanced = more automation, context or scale. Advanced = broader correlation and customisation. Scoped = defined in Enterprise order form.
| Capability | SME | Growth | Business | Enterprise |
|---|---|---|---|---|
| Monthly standard price | $1,990 | $3,990 | $6,990 | Quoted |
| Early-bird monthly price | $995 | $1,995 | $3,495 | Quoted |
| Monitored machines | Up to 10 | Up to 25 | Up to 50 | 51โ250 standard scope |
| Windows, macOS and Linux agents | โ Included | โ Included | โ Included | โ Included |
| Isolated customer workspace | โ Included | โ Included | โ Included | Dedicated or on-premise |
| Live SIEM alerts and event monitoring | Core | Core | Enhanced | Advanced / tailored |
| Agentic AI alert explanation | Core | Enhanced | Advanced | Custom workflows |
| Case and incident management | Core | Core | Enhanced | Advanced / tailored |
| Guided forensic investigation | Core | Enhanced | Advanced | Tailored |
| Core threat intelligence context | โ Included | โ Included | โ Included | โ Included |
| Human approval and action audit trail | โ Included | โ Included | โ Included | Tailored RBAC |
| Support | Email + in-app | Priority | Priority + onboarding | Named engineer |
| Cancellation | Anytime | Anytime | Anytime | Order form |
| Capability | SME | Growth | Business | Enterprise |
|---|---|---|---|---|
| Automated threat intelligence enrichment | On demand | โ Included | Advanced | Private or custom feeds |
| MITRE ATT&CK mapping | Guided | โ Included | Advanced | Tailored |
| Essential Eight reporting | Not included | โ Included | โ Included | Tailored compliance scope |
| Scheduled multi-agent reviews | Limited | โ Included | Advanced | Custom schedules |
| AI-generated executive summaries | Core | Enhanced | Advanced | Tailored |
| Automated response playbooks | Not included | Guided | โ Included | Custom |
| Custom detection rules | Not included | Standard library | โ Included | Custom engineering |
| SSO and SAML | Not included | Not included | Optional | โ Included / scoped |
| Dedicated tenancy or on-premise | Not included | Not included | Not included | โ Available |
| Named security engineer | Not included | Not included | Onboarding session | โ Included |
| Custom connectors and integrations | Add-on | Add-on | Add-on | โ Included / scoped |
| Managed monitoring or DFIR service | Add-on | Add-on | Add-on | Scoped |
Everything you need to know before getting started.
No. SME, Growth and Business are primarily self-service subscriptions. Managed monitoring, co-managed operations, incident response and DFIR services can be scoped separately.
One supported Windows, macOS or Linux endpoint or server with an active CiBRAI agent connected to your tenant. Final treatment of offline or retired machines is defined in the subscription terms.
Not necessarily. CiBRAI provides monitoring, event correlation, investigation, cases, intelligence and response workflows. It is designed to work alongside existing endpoint protection and other security controls.
Agents analyse the evidence and permissions available to your tenant, then explain findings and recommend next steps. High-impact actions are held for an authorised human decision and recorded in the audit trail.
Operational investigation, evidence linkage, timelines, case notes, endpoint and log context, indicator enrichment and report export. Specialist acquisition, legal chain-of-custody and expert witness services are separate.
The self-service plans are designed for isolated Australian-hosted tenancy. Enterprise customers can discuss dedicated and on-premise deployment. The final order form defines data location, retention and subprocessors.
Yes. Start with the machine count and capability level that fits today, then move to a larger plan as your environment, compliance obligations or response needs grow.
SME, Growth and Business are proposed as cancel-anytime subscriptions, subject to the final billing and cancellation terms. Enterprise arrangements are governed by the applicable order form.
Choose the plan that fits your current machine count, use code EARLYBIRD, deploy the first agent and start building visibility. For more complex environments, contact CiBRAI for a short scoping conversation.
Dedicated and on-premise options โ contact us to discuss