Purchase and manage Security Center editions and value-added services to protect cloud assets against persistent threats such as viruses, hacker attacks, and ransomware. This topic also covers how to unsubscribe from or disable services when they are no longer needed. Choose subscription for stable, predictable workloads with fixed budgets; choose pay-as-you-go for elastic or short-term needs.
Quick selection guide
Use case | Recommended solution | Core value and features |
First-time use or evaluation | Experience comprehensive host security, including vulnerability management and intrusion prevention. | |
Hybrid cloud host security | Subscription:
| Unified security management that provides consistent protection policies and visual management for cloud and on-premises hosts, enabling centralized governance across environments. |
Container security protection | Subscription:
| Full-stack protection from hosts to container runtime. Adding image scanning enables shift-left security in the CI/CD phase for lifecycle security. |
Major event support | Subscription:
| Beyond comprehensive protection, provides application runtime self-protection (Runtime Application Self-Protection, RASP) and tamper-proofing capabilities—critical for defending against advanced threats and ensuring core business stability. |
Security incident response | Pay-as-you-go: For detailed plans, see Pay-as-you-go boarding policies and billing. | For urgent security intrusions such as servers infected with crypto-miners, viruses, or trojans, or incidents like website defacement and ransomware. |
Billing methods
Security Center supports subscription, pay-as-you-go, and hybrid billing. All billing methods include the Free Edition capabilities. Choose a paid billing method only when you need enhanced features.
Regardless of the billing method you choose, you retain the Free Edition capabilities, which include basic vulnerability scanning, threat detection, and abnormal logon alerts. See Key considerations for guidance on choosing a paid edition.
Item | Subscription | Pay-as-you-go | Hybrid |
Payment model | Single upfront fee for a monthly or yearly term. Fixed cost simplifies budgeting. | Pay only for what you use. No upfront investment. | Package fee is fixed; additional usage beyond the package is billed on a pay-as-you-go basis. The two parts are billed independently. |
Fee breakdown | Fees = Edition fee + Value-added service fee (optional).
Note For subscription fee details, see Subscription. | Fees = Basic service fee + Feature usage fee.
Note For pay-as-you-go fee details, see Pay-as-you-go. |
Note For hybrid billing fee details, see Hybrid billing. |
Best for | Stable, long-term workloads with a fixed budget. | Elastic scaling, short-term projects, or frequently changing demands. | Stable long-term business needs with a fixed budget but occasional incremental demand beyond the purchased quota, where you want to avoid interruption of security protection due to quota exhaustion. |
Purchase options
Security Center features are available through the following purchase methods:
Purchase on the Security Center page: One-stop ordering on the Security Center purchase page.
Subscription: The fee includes the edition service fee and add-on fees.
Pay-as-you-go: Basic service fee plus feature usage fees.
Purchase separately on dedicated pages: Some specific features can only be purchased independently with dedicated purchase pages and billing rules. Once enabled, these features are still managed centrally in the Security Center console.
Purchase on the Security Center page
Subscription
Feature details
Edition services: Select Anti-virus, Advanced Edition, Enterprise, or Ultimate. Each edition provides different integrated protection capabilities.
Add-ons: Purchase add-ons separately based on your business needs, such as Anti-Ransomware and Application Protection (Runtime Application Self-Protection, RASP).
Edition services
Edition | Description | Cost |
Basic | Only basic security detection capabilities (such as detecting abnormal server logins, DDoS, mainstream server vulnerabilities, and configuration security issues for some cloud products), with no active protection features. | Free |
Anti-virus | Provides detection and removal capabilities for common host viruses. | USD 1 per core per month |
Advanced Edition | Provides host virus detection, virus removal, vulnerability detection and remediation, and security reports. | USD 9.5 per instance per month |
Enterprise | Meets host security requirements for intrusion prevention, identity authentication, and security auditing. | USD 23.5 per instance per month |
Ultimate | Provides full-stack security protection covering hosts, containers, and Intelligent Computing Lingjun servers, including Kubernetes (K8s) threat detection, container asset overview, security alerts, virus removal, vulnerability detection, asset fingerprinting, and attack chain analysis. | USD 23.5 per instance per month + USD 1 per core per month |
Comparison of main protection capabilities across editions:
Protection capability | Basic | Anti-virus | Advanced Edition | Enterprise | Ultimate |
Partial malware and cloud product threat detection | |||||
Virus removal and host intrusion detection | |||||
Brute-force attack prevention | |||||
Host behavior defense | Note Supports only malicious MD5 process blocking. | ||||
System vulnerability check and remediation | |||||
Malicious network behavior prevention | |||||
Attack tracing | |||||
Application vulnerability detection | |||||
Baseline check and remediation | Note Supports only weak password checks. | ||||
Container security |
Add-ons
Anti-ransomware
Description: Provides anti-ransomware backup and recovery capabilities. Use backup files to restore servers and databases after a ransomware attack.
Purchase notes:
The purchase quantity represents anti-ransomware capacity, which is related to the size of files to be backed up and the backup retention period, not the number of servers.
Available only in select regions. Set the protected data volume as needed. For supported regions, see Supported regions for anti-ransomware.
If you select Set Recommended Policy, the system automatically performs regular backups of important file paths on existing servers. To adjust the strategy, go to the anti-ransomware page. For details, see Modify server anti-ransomware policies.
CSPM
Description: Provides identity and permission management, automated compliance checks, and cloud product configuration baseline detection for centralized management of multi-cloud configuration risks.
Purchase notes: Billed by the number of cloud product instances scanned, verified, and remediated.
NoteUnused quota is cleared at the end of each month. For more billing details, see CSPM billing overview.
Agentic SOC (Legacy)
Description:
Agentic SOC (Legacy): Supports unified log ingestion across clouds, accounts, and products (such as Web Application Firewall, Cloud Firewall, and VPC) for closed-loop security alert detection, event response, and incident handling. Helps improve security operations efficiency and meet MLPS compliance log audit requirements.
Security Operations Agent: A premium value-added service powered by Agentic AI that integrates deeply with Alibaba Cloud native security data and infrastructure. Uses Agent autonomous perception, reasoning, and execution capabilities to independently evaluate security events and enable rapid incident response.
Purchase notes:
Modular billing: billing items vary based on purchase options. For details, see Agentic SOC - Subscription.
Agentic SOC (Legacy): Billed separately by Log Ingestion Traffic and Log Storage Capacity. Purchase based on your actual needs.
Log ingestion traffic (GB/day)
Use: For real-time threat detection, attack tracing, alert analysis, and other core security operations. After purchase, access most core Agentic SOC features such as threat detection and investigation response.
Estimating capacity:
Based on existing log volume
Daily traffic (GB) = Total log storage capacity (GB) / Log retention days (TTL).
Example: If you currently have 10,000 GB of logs retained for 90 days, daily traffic is approximately 10000 / 90 ≈ 111 GB. We recommend purchasing 200 GB/day.
Based on log generation rate (EPS)
Daily traffic (GB) = EPS (log entries per second) × 86400 × Average log size (KB) / 1024
EPS: Log entries generated per second.Average log size: Typically between 3 KB and 7 KB.
Log storage capacity (GB)
Use: For long-term storage, query, and audit of logs to meet compliance requirements such as the Cybersecurity Law and MLPS 2.0, which require log retention of no less than 180 days. Also supports retrospective analysis of historical events.
Estimating capacity:
By server count: We recommend 120 GB of log storage capacity per server.
By existing log analysis capacity: Set to 3 times the purchased capacity in the Security Center - Log Analysis feature.
Security Operations Agent: In addition to Agentic SOC, you must also purchase Intelligent Usage Analysis and Number of Managed Instances.
Intelligent Usage Analysis: The analysis usage consumed by Security Operations Agent for alert evaluation, event investigation, tracing, attribution, and security report generation. The purchase quantity does not support auto-fill and must match the Log Ingestion Traffic quantity.
NoteIntelligent Usage Analysis is cleared daily. Exceeding the limit results in automatic throttling.
Number of Managed Instances: Security Operations Agent supports cross-instance security operations and automated handling. Billing is based on the number of managed instances. Each invoked instance is charged, including ECS, WAF, ALB, cross-cloud products, and on-premises security vendor products.
NoteCleared monthly. Each instance is counted only once with automatic deduplication.
If you select Access Policy, log sources from your current Alibaba Cloud account for Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail are automatically ingested.
Vulnerability Fixing
Description: Enables one-click remediation of Linux Software Vulnerability and Windows System Vulnerability on servers from the console.
Purchase notes: Enter the number of vulnerability remediation attempts to purchase based on the monthly number of vulnerabilities to be remediated.
NoteThe number of remediation attempts equals the total number of vulnerabilities remediated across all servers. For example, if 10 servers have the same named vulnerability and you use Security Center to remediate it, 10 remediation attempts are consumed.
Image Security Scan
Description: One-click scanning of images for system vulnerabilities, application vulnerabilities, viruses, and malicious samples, with remediation recommendations.
Purchase notes:
Enter the number of scan authorizations to purchase based on your monthly needs.
NoteScan authorization: Consumes 1 authorization when an image digest is scanned for the first time. Subsequent scans of the same digest do not consume authorizations. If the image digest changes, authorization must be consumed again.
Available only when the edition is Advanced Edition, Enterprise Edition, Ultimate Enterprise, or Value-added Plan.
File Tamper-Proofing
Description: File tamper-proofing uses real-time monitoring to comprehensively track file system activities, automatically intercept unauthorized write and delete operations, and log all access behavior to form a complete audit chain, ensuring the integrity of critical files.
Purchase notes: Select the number of servers to protect.
Malicious File Detection
Description: Deep scanning and detection of malicious software, web shells, viruses, and other potential risk files hidden in server file systems.
Purchase notes: Set the purchase quantity to the number of files to be scanned per month.
RASP
Description: Application protection is based on RASP technology, enabling applications to protect themselves at runtime by detecting and blocking attacks in real time.
Purchase notes: We recommend setting the purchase quantity to the total number of Java processes to protect.
NoteExample: If you have 2 servers each running 3 Java applications to protect, purchase 6 authorizations.
Cloud Honeypot
Description: Efficiently captures and traps attacker behavior, enhancing detection and protection of core assets in attack-defense scenarios.
Purchase notes: Cloud honeypots are billed by the number of probes. Minimum purchase: 20 probes. Maximum: 500 probes.
NoteFor more than 500 probes, contact technical support for capacity expansion.
Log Analysis
Description: Aggregates security logs from cloud assets (including hosts and security events), provides powerful SQL search and visual reports for easy event tracing, attack investigation, and compliance auditing.
ImportantIf you also purchase the Log Storage Capacity pay-as-you-go service, Security Center logs are stored twice. To avoid duplicate charges, evaluate your needs and turn off the relevant log delivery switches in the Log Analysis module from the Security Center console.
Purchase notes: Logs must be stored for at least 180 days as required by the Cybersecurity Law. We recommend no less than 50 GB of storage capacity per server.
Purchase steps
Log on and access the purchase page
Use your Alibaba Cloud account to log on and visit the Security Center purchase page.
Select an edition
ImportantIf you have already activated the pay-as-you-go Host and Container Security service, only the Value-added Plan is supported.
Billing Method: Select Subscription.
Protection Scenario: The system automatically recommends an edition and add-on configuration based on your selected protection scenario.
Edition: For the baseline protection capabilities of each edition, see Subscription - Feature Details - Edition Services.
Protected Servers: Specify the total number of servers to protect. By default, this displays all Alibaba Cloud ECS instances and connected non-Alibaba Cloud servers under your account.
NoteThis parameter is not required when the edition is Anti-virus or Ultimate.
Cores: The number of vCPUs across your servers. Defaults to the total vCPU count of all ECS instances and connected non-Alibaba Cloud servers.
NoteThis parameter is required only when the edition is Anti-virus or Ultimate.
Security Authorization
Apply the purchased edition authorization to specific servers for protection to take effect.
Automatic binding (default):
The system automatically assigns authorizations to unbound servers under your account based on the default policy. Unbind or rebind authorizations later; see Bind or unbind authorized assets.
Custom binding:
Click Custom Quota Binding and select the region where the servers are located.
Select the servers from the list and choose the corresponding edition in the Target Version column. For feature details of each edition, see Edition services comparison.
If you select multiple servers, click Update Version below the list to bind the same edition to all selected servers.
(Optional) Select Automatically Add New Servers to Security Center to automatically bind the purchased edition to any new servers added later.
WarningIf not selected, you must manually bind authorizations for new servers; otherwise, they will not receive Security Center protection. For details, see Bind or unbind authorized assets.
Select add-ons
Enable the add-on modules you need by toggling Purchase or Not to Yes and completing the required configuration. For feature details of each add-on, see Subscription - Feature Details - Add-ons.
Confirm and pay
Read and accept the Security Center Terms of Service, then click Order Now to complete payment.
Verify purchased services
After purchase, log on to the Security Center console. Navigate to the Overview page, Subscription section to view your active services.
NoteConfirm the following to verify your purchase was successful:
The displayed edition name matches your selection.
The service status shows as Active.
All purchased add-ons appear in the value-added services list.
Pay-as-you-go
Feature details
Default features: Enabling any pay-as-you-go feature incurs a base service fee. The following features are included by default: DingTalk Chatbot, Security Report, and Task Center.
Billing features: Purchase specific protection features as needed. Each feature is billed independently.
Default features
DingTalk Chatbot: Configure a DingTalk bot to receive real-time threat alerts in a DingTalk group.
Security Report: Customize the security metrics you care about and receive periodic reports via email for real-time asset monitoring.
Task Center: Provides automated response orchestration to streamline security remediation workflows by creating automated policies for repetitive tasks.
NoteRequires the Vulnerability Fix feature to be enabled or purchased.
Billing features
Host and Container Security
If you have already purchased the subscription-based Anti-virus, Advanced, Enterprise, or Ultimate, the pay-as-you-go Host and Container Security service cannot be enabled.
Description: Provides comprehensive detection and protection for host and container assets. After purchase, you must bind a protection level to your assets. Protection levels are described in the following table.
Protection level
Description
Monthly cost (30-day estimate)
Unprotected
Basic security detection capabilities only (e.g., anomalous login detection, DDoS, common server vulnerabilities, and security posture issues for select cloud services). No active protection features.
Free
Antivirus
Detects and removes common viruses on hosts.
USD 1.5/core/month
Advanced
No longer available for new purchases or modifications.
USD 14.25/server/month
Comprehensive Host Protection
Meets classified protection compliance requirements and addresses host intrusion prevention, identity authentication, and security auditing requirements.
USD 35.25/server/month
Hosts and Container Protection
Provides full-stack security protection for hosts, containers, and intelligent computing servers, including Kubernetes (K8s) threat detection, container asset visibility, security alerts, virus detection, vulnerability detection, asset fingerprinting, and attack chain analysis.
USD 35.25/server/month + USD 1.5/core/month
Key protection capabilities by level:
Protection capability
Unprotected
Antivirus
Comprehensive Host Protection
Hosts and Container Protection
Malware and cloud product threat detection
Virus detection and host intrusion detection
Brute-force attack prevention
Host behavior defense
NoteOnly supports blocking malicious MD5 processes.
Malicious network behavior defense
Attack tracing
Application vulnerability detection
Container security
Purchase notes: After enabling this feature, you must authorize it on specific assets for it to take effect. Custom asset binding is supported during purchase.
ImportantDefault binding rules:
Servers running container environments (including Alibaba Cloud ACK cluster nodes, intelligent computing servers, and servers connected via self-managed Kubernetes clusters): Hosts and Container Protection.
Other assets: Comprehensive Host Protection.
Newly added servers: Hosts and Container Protection.
CSPM
Description: Provides identity and permission management, automated compliance checks, and cloud product configuration baseline detection for centralized management of multi-cloud configuration risks.
Purchase notes: Billed by the number of cloud product instances scanned, verified, and remediated.
Vulnerability Fixing
Description: Enables one-click remediation of Linux Software Vulnerability and Windows System Vulnerability on servers from the console.
Purchase notes: Enter the number of vulnerability remediation attempts to purchase based on the monthly number of vulnerabilities to be remediated.
NoteThe number of remediation attempts equals the total number of vulnerabilities remediated across all servers. For example, if 10 servers have the same named vulnerability and you use Security Center to remediate it, 10 remediation attempts are consumed.
Image Security Scan
Description: Scans images for system vulnerabilities, application vulnerabilities, viruses, and malicious samples, and provides remediation recommendations.
Purchase notes: Billed per scan. USD 0.15/scan. The first scan of a unique image digest consumes one authorization; subsequent scans of the same digest are free. If the image digest changes, a new authorization is required.
This feature is available only when the edition is Advanced Edition, Enterprise Edition, Value-added Plan, or Ultimate Enterprise.
Agentic SOC (Legacy)
Description:
Agentic SOC (Legacy): Supports unified log ingestion across clouds, accounts, and products (such as Web Application Firewall, Cloud Firewall, and VPC) for closed-loop security alert detection, event response, and incident handling. Helps improve security operations efficiency and meet MLPS compliance log audit requirements.
Security Operations Agent: A premium value-added service powered by Agentic AI that integrates deeply with Alibaba Cloud native security data and infrastructure. Uses Agent autonomous perception, reasoning, and execution capabilities to independently evaluate security events and enable rapid incident response.
Purchase notes:
Billing items vary based on your selection. For details, see Agentic SOC - Pay-as-you-go.
Agentic SOC (Legacy): Tiered pricing based on Log Ingestion Traffic. The higher the volume, the lower the unit price.
ImportantIn pay-as-you-go mode, Log Storage Capacity is not supported, so query and audit logs cannot be stored.
Security Operations Agent: In addition to the Log Ingestion Traffic base fee for Agentic SOC (Legacy), additional charges for Intelligent Usage Analysis and Number of Managed Instances apply.
Intelligent Usage Analysis: Analysis consumption incurred by Security Operations Agent for alert triage, incident investigation, tracing, attribution, and security report generation.
Number of Managed Instances: Security Operations Agent supports cross-instance security operations and automated remediation. Billing is based on the number of managed instances. Each invoked instance (e.g., ECS, WAF, ALB, cross-cloud products, on-premises security vendor products) is counted.
NoteEach instance is counted only once (deduplicated).
If you select Access Policy, logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under the current Alibaba Cloud account are automatically connected.
Anti-ransomware
Description: Provides anti-ransomware backup and recovery capabilities. Restore servers and databases using backup files after a ransomware attack.
Purchase notes:
Billed based on backup file size and data retention period. For pricing details, see Anti-Ransomware Service - Pay-as-you-go.
Available only in select regions. Configure the protection data volume as needed. For supported regions, see Anti-Ransomware supported regions.
If you select Set Recommended Policy, important file paths on existing servers are automatically backed up on a regular schedule. To adjust, go to the anti-ransomware page and modify the policy; see Modify Server Anti-Ransomware.
File Tamper-Proofing
Description: File tamper-proofing uses real-time monitoring to comprehensively track file system activities, automatically intercept unauthorized write and delete operations, and log all access behavior to form a complete audit chain, ensuring the integrity of critical files.
Purchase notes: Billed based on actual protection duration (seconds) multiplied by the number of protected servers. Servers meeting the following criteria are automatically counted:
Servers bound to interception protection rules.
Servers bound to alerting protection rules where the server protection edition is below Advanced or the protection level is below Comprehensive Host Protection.
Application Protection
Description: Application protection is based on RASP technology, enabling applications to protect themselves at runtime by detecting and blocking attacks in real time.
Purchase notes: Authorize this feature on specific assets after enabling for it to take effect. Custom asset binding is supported during purchase.
ImportantBy default, full protection is enabled with slow-rate connection.
Agentless Detection
Description: Perform vulnerability scanning and comprehensive risk checks without installing an agent on your servers.
Purchase notes: Billed based on the volume of scanned data.
Serverless Assets
Provides intrusion detection and vulnerability scanning for Serverless assets (such as Elastic Container Instances). For more information, see Serverless security - Pay-as-you-go.
Purchase notes: After enabling this feature, you must authorize it on specific assets for it to take effect. Custom asset binding is supported during purchase.
ImportantBy default, Serverless Assets protection is enabled for all Serverless assets.
Malicious File Detection
Description: File tamper-proofing uses real-time monitoring to comprehensively track file system activities, automatically intercept unauthorized write and delete operations, and log all access behavior to form a complete audit chain, ensuring the integrity of critical files.
Purchase notes: Billed based on the number of scanned files. For pricing details, see Malicious File Detection - Pay-as-you-go.
Log Management
Description: Log Management is built on Alibaba Cloud Log Service (SLS) and provides log auditing and analysis capabilities. Leveraging Security Center's detection and defense capabilities and the Agentic SOC module, it offers unified log auditing, built-in security reports, SQL-based analysis and tracing, and flexible storage policies.
ImportantIf you have also purchased the subscription-based Log Analysis service, Security Center logs will be stored twice. To avoid duplicate charges, evaluate your needs and disable the relevant log delivery switches in the Log Analysis module from the Security Center console.
Purchase notes: You must configure a log storage region.
Agentic EDR
Description: Provides hosts with intelligent business profiling, behavior baseline establishment, baseline deviation alerts, intelligent detection/alert analysis, and automated response capabilities.
Purchase notes: Each host binding consumes one seat authorization. No unsubscription required. For pricing details, see Agentic EDR - Pay-as-you-go.
Attack Management
Description: Provides hosts with intelligent business profiling, behavior baseline establishment, baseline deviation alerts, intelligent detection/alert analysis, and automated response capabilities.
Purchase notes: Billed based on the number of protected assets and scanning Credits consumed. For pricing details, see Attack Surface Management - Pay-as-you-go.
Purchase steps
Log on and access the purchase page
Use your Alibaba Cloud account to log on and visit the Security Center purchase page.
Select services
Enable the add-on modules you need by toggling Purchase or Not to Yes and completing the required configuration. For feature details, see Pay-as-you-go - Feature Details - Billing Features.
Authorization and binding
For some services, you must authorize them on specific assets after enabling for them to take effect. Configuration steps:
Host and Container Security: Supports custom binding of host assets. Steps:
ImportantIf not configured, the system binds host assets using default rules:
Servers running container environments (including Alibaba Cloud ACK cluster nodes, intelligent computing servers, and self-managed Kubernetes clusters): Hosts and Container Protection.
Other assets: Comprehensive Host Protection.
Newly added servers: Hosts and Container Protection.
On the purchase page, click Custom Quota Binding and select the server region.
Select the servers from the list and choose the corresponding protection level in the Protection Level column.
After selecting multiple servers, click Change Protection Level to batch modify the protection level.
In the Automatically Add New Servers to Security Center section, set the default protection level for newly added servers.
Serverless Assets: Supports custom binding of assets. Steps:
ImportantIf not configured, the system enables Serverless Assets protection for all Serverless assets by default.
Click Custom Quota Binding, select the server region, and check the corresponding assets.
Select Automatically Add New Assets to automatically enable Serverless Assets protection for newly added Serverless assets.
WarningIf not selected, you must manually bind the authorization; otherwise, newly added Serverless assets will not receive Security Center protection. For details, see Bind or Unbind Authorized Assets.
Application Protection: Supports custom binding of assets. Steps:
ImportantIf not configured, the system enables full protection with slow-rate connection by default.
Configure this after purchase in the console under , in the Access Management section.
Click Custom Quota Binding and select the server region.
Select the corresponding assets and click OK.
Confirm and pay
Read and accept the Security Center Terms of Service, then click Order Now to complete payment.
Verify purchased services
After purchase, log on to the console. Navigate to the Overview page, Enable Pay-as-You-Go Service section to view your active services.
NoteConfirm the following to verify your purchase was successful:
Enabled services match your selections.
Assets are properly bound with the correct protection levels.
Purchase separately on dedicated pages
Agentic EDR
Description: Provides hosts with intelligent business profiling, behavior baseline establishment, baseline deviation alerts, intelligent detection/alert analysis, and automated response capabilities for streamlined security operations.
Purchase notes: Seat authorization is the billing unit. Each host binding consumes one seat authorization. The authorization model is consistent with add-ons such as Anti-Ransomware. For pricing details, see Agentic EDR - Subscription.
Purchase steps:
Subscription
-
Go to the or Agentic EDR buy page and complete the following configurations:
-
Intelligent Host Detection and Response: Select the number of regular authorization seats to purchase.
-
Duration: The service duration.
NoteWe recommend that you select "Auto-renewal upon expiration" to avoid service interruption or resource release due to expiration. After you enable auto-renewal, the renewal cycle is monthly, and the system automatically deducts fees at the real-time price before the instance expires. You can cancel auto-renewal at any time. Configure or cancel auto-renewal.
-
-
After the configuration is complete, click Buy Now.
Pay-as-you-go
-
Go to the Security Center console - Overview page.
-
In the Enable Pay-as-You-Go Service section, turn on the Agentic EDR switch.
-
Attack Management
Description: Provides external attack surface management capabilities. Automatically discovers internet-exposed assets (domains, IPs, certificates), identifies attack paths and critical nodes, helping organizations understand their security exposure and reduce attack risk.
Purchase notes: Protected assets are the billing unit. Each asset authorization includes a certain amount of Credits for attack surface scanning.
ImportantAfter enabling Full Protection, if you exceed the Credits included in the subscription plan, pay-as-you-go mode is automatically enabled for additional Credits. For pricing details, see Attack Surface Management - Hybrid Billing.
Purchase steps:
Subscription
Visit the Attack Surface Management purchase page and complete the following configuration:
Attack Surface Management edition: Only Basic Edition is currently supported.
Assets: The number of authorizations for protected assets. One asset consumes one authorization (includes 6,000 credits).
Duration: Service duration.
After you complete the configuration, click Buy Now.
Pay-as-you-go
Visit the Attack Surface Management purchase page.
Select the Pay-as-you-go billing method and click Create Now.
AgenticBAS
Description: AI Penetration Testing (Agentic BAS) is an intelligent intrusion attack simulation based on multi-agent collaboration. It focuses on validating security effectiveness, continuously evaluating protection capabilities through intelligent means, and driving security operations improvements.
Purchase notes: AgenticBAS uses a hybrid billing model of subscription-based base service (monthly) plus pay-as-you-go Credits. After activation, 1 million Credits are included (expiring monthly). Once the monthly quota is exceeded, pay-as-you-go mode is automatically enabled.
ImportantThe pay-as-you-go mode for AgenticBAS cannot be turned off separately (not affected by the Burstable Protection toggle). It is automatically disabled upon subscription expiration or unsubscription.
Purchase steps:
Visit the purchase page.
Select the subscription duration, then click Buy Now to complete payment.
Enable Burstable Protection (Hybrid Billing)
Applicable scope: Applies to subscription-based services that support elastic protection, including: base edition services, Anti-Ransomware, Agentic EDR (Intelligent Host Detection and Response), Attack Management, and more.
Default state: For eligible services, the system enables elastic protection by default when you activate the subscription-based service.
Impact: When elastic protection is enabled and your actual usage exceeds the subscription quota, the excess is automatically billed at pay-as-you-go rates. This eliminates the need for frequent manual scaling and ensures uninterrupted security protection.
ImportantPay-as-you-go bills for excess usage are pushed the next day. For more billing details, see Billing overview.
Manual configuration:
Non-Attack Management:
Log on to the Security Center console.
On the Overview page, in the Subscription section, turn on or turn off the Burstable Protection switch.
Attack Management:
Log on to the Security Center console.
On the Overview page, in the Attack Surface Management section, turn on or turn off the Full Protection switch.
Unsubscribe from or disable Security Center
If you no longer need Security Center services, follow the guidance below based on your billing model. This section uses the unified sales features as an example.
For unsubscribing from independently sold features, refer to their respective documentation. For example, Agentic SOC - Pay-as-you-go and Attack Surface Management - Pay-as-you-go.
Unsubscribe from subscription services
Unsubscribe from individual add-ons
On the Overview page Subscription region, click On the downgrade page, go to the Order Downgrade tab and toggle the relevant services to No. For detailed steps, see Downgrade or unsubscribe from subscription services.
ImportantRefund amounts are subject to the downgrade page. For fund handling after refunds, see Refund instructions.
Full unsubscribe
Visitrefund management page to apply for a refund. For detailed steps, see Refund instructions.
Disable pay-as-you-go services
If you previously claimed a Security Center trial resource package when purchasing ECS, the system automatically switches to pay-as-you-go and continues billing once the package is exhausted. To avoid unexpected charges, follow the steps below to disable pay-as-you-go services after the package is used up or when you no longer need the service.
After disabling pay-as-you-go services, no further charges will be incurred. Steps to disable:
Visit the Security Center console - Overview page.
In the Enable Pay-as-You-Go Service section, complete the operation as needed:
Disable specific services: Toggle the relevant service switches to the off position to disable only that service.
Disable all services at once: Click Deactivate in the upper-right corner to disable all pay-as-you-go features at once.
After disabling pay-as-you-go services, charges incurred on the current day will be billed the next day. Data is cleared immediately after disabling; there is no data retention period.
Rules and limitations
Billing model limitations
Subscription: Each Alibaba Cloud account can purchase only one edition at a time. Upgrading to a higher edition is supported at any time.
Enable Pay-as-You-Go Service: Select different protection levels for different assets and purchase multiple add-on features simultaneously.
Switching billing models: To change the billing model for a feature, you must first unsubscribe from or disable the current billing service, then activate the other model.
Feature purchase and model limitations
Feature exclusivity
Subscription editions (Anti-virus, Advanced, Enterprise, Ultimate) and the pay-as-you-go Host and Container Security service are mutually exclusive. Select only one; they cannot be purchased or used simultaneously.
Subscription-based add-ons (such as Agentic SOC (Legacy)) and the same features under pay-as-you-go cannot be purchased or used simultaneously.
Cross-module flexibility
A single account supports selecting different billing models across different feature modules.
NoteExample: Select subscription for Vulnerability Fix and pay-as-you-go for Agentic SOC.
Edition purchase limitations (container protection)
Servers running container environments (including ACK cluster nodes, self-managed Kubernetes, and Lingjun assets) require specific editions to access container protection capabilities. Edition limitations:
Subscription: You must purchase the Ultimate and bind the Ultimate to your assets.
Enable Pay-as-You-Go Service: You must purchase Host and Container Security and bind the Hosts and Container Protection protection level to your assets.
Edition change limitations
Effective September 11, 2025, Security Center will no longer support new purchases or changes to the Advanced Edition. Existing Advanced Edition users are not affected.
FAQ
Billing model questions
Will subscription and pay-as-you-go services be billed redundantly?
No. Security Center has built-in anti-redundant billing mechanisms:
Single billing per feature: The same feature supports only one billing model at any time. See Feature purchase and model limitations.
Automatic switching: If the edition services included in your subscription purchase overlap with existing pay-as-you-go services, the system automatically disables the overlapping pay-as-you-go features and uses the subscription service instead.
NoteExample: If you have pay-as-you-go Vulnerability Fix and then purchase the Advanced Edition or above, Security Center automatically disables pay-as-you-go Vulnerability Fix, and subsequent vulnerability fixes will not incur additional charges.
Can pay-as-you-go services be converted to subscription?
No. Pay-as-you-go services cannot be directly converted to subscription. Disable the relevant services first, then follow the subscription purchase steps to purchase a new subscription.
Can subscription and pay-as-you-go be used simultaneously?
Yes. Both billing models can be used under a single account. Combine them based on asset importance and lifecycle.
Why am I still being charged after the trial resource package is exhausted?
The trial resource package covers only specific billing items and quotas. After the package is exhausted, the corresponding pay-as-you-go features continue to run and incur charges. To avoid unexpected charges, we recommend:
Regularly check remaining package quota: Log on to the resource package management page to check remaining quota and expiration time.
Disable pay-as-you-go services promptly if no longer needed after the package is exhausted; see Disable pay-as-you-go services.
Set spending alerts: Configure budget alerts in the Billing Center to receive SMS, email, or in-site notifications when your account balance falls below a threshold.
How do I view Security Center bills?
View Security Center billing details as follows:
Log on to the billing details page.
In the filter conditions, set Product Name to Security Center to view usage and costs for each billing item.
For bills with multiple products, check resource package consumption on the resource package management page; see Query Resource Package Usage.
Why is the actual amount on the purchase page higher than the product pricing?
The final order amount depends on multiple factors. The base price typically refers to the cost for a single server per month. The total is affected by:
Number of protected assets: The final cost is multiplied by the total number of protected servers under your account (including cloud ECS and non-cloud servers with the agent installed).
Add-on selections: The system may preselect add-ons such as Log Analysis and Anti-Ransomware. If not needed, set their capacity to
0before placing your order.
Free services and trials
How do I get free services?
Free Edition: Automatically activated after completing Alibaba Cloud account real-name verification. For more information, see What is Security Center Free Edition.
Enterprise Edition free trial: Activate a 7-day free trial of Enterprise Edition.
What is the difference between the Free Edition and the Enterprise Edition free trial?
Feature
Free Edition
Enterprise Edition free trial
Eligible accounts
All Alibaba Cloud accounts that have completed real-name verification.
Accounts that have not previously trialed or purchased the Enterprise Edition.
Protection capabilities
Provides permanent baseline security capabilities.
Short-term access to the full features of the paid Enterprise Edition.
Duration
Permanent.
7 days.
Core capabilities
Anomalous login detection, mining/DDoS trojan detection, mainstream vulnerability scanning, and more.
All Enterprise Edition capabilities, including virus detection, advanced threat detection, vulnerability fixing, and more.
Eligibility
Automatically activated; no application required.
One trial per account; cannot be repeated.
Can I cancel and reapply for the Enterprise Edition free trial?
Yes. On the Overview page, click Release Trial to cancel the free trial. However, each Alibaba Cloud account has only one free trial opportunity. After cancellation, you cannot apply again.
Are configurations retained after the Enterprise Edition free trial expires?
After the trial expires, configurations and data are retained for 7 days and then automatically cleared.
Why is there no "Free Trial" entry on the Overview page?
Reason 1: The account has already applied for the 7-day free trial.
Reason 2: The account has already purchased a paid edition.