Subscription is the prepaid billing method of Security Center. It offers two modes: unified sales and independent sales, depending on the edition and value-added feature combination that you select.
Overview
Security Center provides unified sales and independent sales modes. You can select a mode based on your business requirements.
Unified sales: You can purchase services on the Security Center buy page in a one-stop manner. The fees include the edition service fee and value-added feature fees.
Independent sales: Some specific features can only be purchased separately. These features have dedicated buy pages and independent billing rules. After these features are enabled, they are integrated into the Security Center console for unified management.
Unified sales
Unified sales refers to subscription services that you purchase on the Security Center buy page. The fees include the edition service fee and value-added feature fees. The billable items of Security Center vary based on the edition and the value-added features that you select. The following prices are for reference only. For more information, go to the buy page.
After new users purchase some subscription services of unified sales (such as edition services and anti-ransomware services, Agentic EDR, Attack Management, Agentic CSPM), Burstable Protection is enabled by default. After the subscription quota is exceeded, the excess is billed on a pay-as-you-go basis. For more information, see Hybrid billing (burstable protection).
Edition service fee
Edition | Billing method | Fee |
Anti-virus | (Number of cores × Edition fee + Value-added feature fees) × Duration Note The number of cores is the total number of vCPUs of all servers in your assets. | USD 1/core/month |
Advanced Edition | (Number of protected servers × Edition fee + Value-added feature fees) × Duration Note The number of protected servers is the total number of servers protected by Security Center. Both Alibaba Cloud ECS instances and non-Alibaba Cloud servers on which the Security Center agent is installed can be protected. | USD 9.5/server/month |
Enterprise | USD 23.5/server/month | |
Ultimate | (Number of protected servers × Edition fee + Number of cores × Edition fee + Value-added feature fees) × Duration Note The Ultimate edition provides full-stack security protection capabilities that cover hosts, containers, and intelligent computing Lingjun servers, including K8s threat detection, container asset panorama, security alerts, virus removal, vulnerability detection, asset fingerprint identification, and attack chain analysis. | USD 23.5/server/month + USD 1/core/month |
Value-added Plan | Value-added feature fees × Duration. | No base feature is purchased. No fee is charged. |
Value-added feature service fees
Vulnerability Fixing
Billing method: You are billed based on the number of purchased vulnerability fix times. A successful fix of a vulnerability bulletin on a single server counts as 1 time. Failed fixes do not consume times.
Billing rules:
Anti-virus: USD 0.3/time/month (minimum of 20 times).
Advanced Edition, Enterprise, Ultimate: No additional fee is required. You can use this feature for unlimited times.
Value-added Plan: USD 0.3/time/month (minimum of 20 times).
Agentic CSPM
Billing method: You are billed based on the number of cloud service instances that are scanned, verified, and fixed.
NoteAn "instance" refers to a specific network device or application entity (such as an OSS bucket or an ECS instance). Based on whether charges are incurred, instances are classified into two types:
Billable instances: such as buckets in Object Storage Service (OSS) and ECS instances.
Non-billable instances: such as ECS security groups.
Billing rules:
Standard billing: Multiple scans, verifications, and fixes within a single billing cycle do not incur additional fees. The price is USD 1.46/instance/month.
Existing and paid users: Within the validity period of the current order, you can continue to use the service under the original billing mode and prices, without being affected by the billing mode adjustment. You can also switch to the new billing mode. For more information, see Billing adjustment for CSPM in Security Center.
RASP (RASP)
Billing method: You are billed based on the number of purchased quotas. The number of quotas is the number of instances protected by the RASP feature. For example, in Application Protection, one protected application process (Pod) counts as one quota.
Billing rules: All editions are billed based on the number of purchased quotas. The more quotas you purchase, the lower the unit price.
Quotas ≤ 50: USD 6/quota/month.
50 < quotas ≤ 200: USD 4.5/quota/month.
quotas > 200: USD 3/quota/month.
File Tamper-Proofing
Billing method: You are billed based on the number of purchased anti-tamper services (servers that need to be protected).
Billing rules: All editions are billed at the same rate: USD 165/server/month.
Agentic SOC (Legacy)
Billing method: The billable items vary based on the purchase options.
Agentic SOC (Legacy): You are billed based on the purchased Log Ingestion Traffic and Log Storage Capacity.
Security Operations Agent: In addition to purchasing the Log Ingestion Traffic and Log Storage Capacity, you must also purchase the Intelligent Usage Analysis and Number of Managed Instances.
Billing rules: All editions are billed at the same rate. The following table describes the fee details:
Log Ingestion Traffic: Tiered pricing is applied. The minimum purchase quantity is 100 GB/day, and the purchase increment is 100 GB/day. The following table describes the specific pricing (X is the amount of traffic ingested in a day):
X = 100 GB: USD 0.45/GB/day.
200 GB ≤ X < 9,999,999,999 GB: USD 0.42/GB/day.
Log Storage Capacity: USD 100/1,000 GB/month (minimum of 1,000 GB, in increments of 1,000 GB).
Intelligent Usage Analysis:
The minimum purchase quantity is 100 GB/day. The purchase quantity cannot be automatically filled in and must be consistent with the Log Ingestion Traffic.
Price: USD 9.6/100 GB/day.
NoteThe usage is reset to zero at midnight every day. If the limit is exceeded, the system automatically throttles the traffic.
Number of Managed Instances:
The minimum purchase quantity is 10 instances/month, and the purchase increment is 10 instances/month.
USD 1.434/instance/month.
Each instance is counted only once. Automatic deduplication is applied.
Anti-ransomware
Billing method: You are billed based on the purchased anti-ransomware capacity.
Billing rules: All editions are billed at the same rate: USD 0.045/GB/month.
Log Analysis
Billing method: You are billed based on the purchased log storage capacity.
Billing rules:
Anti-virus, Advanced Edition, Enterprise, Ultimate: USD 0.1/GB/month.
Value-added Plan: Not supported.
Container Image Scan
Billing method: You are billed based on the number of purchased quotas (based on the number of image digests).
Billing rules:
Anti-virus: Not supported.
Advanced Edition, Enterprise, Ultimate, Value-added Plan: USD 0.1/image/month.
Cloud Honeypot
Billing method: You are billed based on the number of purchased cloud honeypot probes.
Billing rules: All editions are billed at the same rate: USD 333.33/probe/month (minimum of 20 probes).
Malicious File Detection
Billing method: You are billed based on the number of purchased file detection times.
Billing rules: All editions are billed at the same rate: USD 1.5/10,000 times/month (minimum of 100,000 times).
Independent sales
The independently sold features use an independent sales system with dedicated buy pages and billing rules, and are decoupled from the main Security Center product. However, for daily use, you do not need to switch platforms. The management and control of related features are still integrated in Security Center, ensuring a consistent and convenient operation experience.
After new users purchase some subscription services of independent sales (such as Agentic EDR and Attack Management), Burstable Protection is enabled by default. After the subscription quota is exceeded, the excess is billed on a pay-as-you-go basis. For more information, see Hybrid billing (burstable protection).
Agentic EDR
Billing method: You are billed based on the number of purchased seat quotas. Binding one host consumes one seat quota.
Billing rules: USD 6.876066/quota/month.
Attack Management
Billing method: You are billed based on the number of protected asset quotas. Each quota includes a certain number of credits.
NoteCredits are the scanning quota units of Attack Surface Management. Each scan consumes a certain number of credits, which are used to draw attack paths of exposed assets, perform intelligent risk analysis, and generate intelligent risk remediation suggestions. The actual number of credits consumed depends on the system usage.
Billing rules: USD 5/quota/month. Each quota includes 6,000 credits.
AgenticBAS
Billing method: Base service subscription fee + excess Credits fee (pay-as-you-go).
ImportantThe base service subscription fee includes 1,000,000 credits (expire monthly). After the credits are used up, the pay-as-you-go mode is automatically enabled for credits.
The pay-as-you-go mode of AgenticBAS cannot be disabled separately (that is, it is not affected by the Burstable Protection switch). After the subscription expires or is unsubscribed, the pay-as-you-go mode is automatically disabled.
Billing rules:
Base service subscription fee: USD 6,000/month.
Credits pay-as-you-go: USD 0.002/credit.
SecOpsAgent
Billing method: Base service subscription fee + excess Credits fee (pay-as-you-go).
ImportantThe base service subscription fee includes 30,000 credits (expire monthly). After the credits are used up, the pay-as-you-go mode is automatically enabled for credits.
The pay-as-you-go mode of SecOpsAgent cannot be disabled separately (that is, it is not affected by the Burstable Protection switch). After the subscription expires or is unsubscribed, the pay-as-you-go mode is automatically disabled.
Billing rules:
Base service subscription fee: USD 68.76/month.
Credits pay-as-you-go: USD 0.002/credit.
Expiration or unsubscription
Scenario description:
Expiration: The subscription service naturally expires and is not renewed in time, which is considered service expiration.
Unsubscription: Unsubscribe from the entire Security Center instance. For more information about the unsubscription procedure, see Refund policy.
Data retention:
Unified sales
After expiration or unsubscription, the Security Center service instance is released, and the paid edition is downgraded to the free edition. Servers lose the corresponding protection capabilities, which increases the risk of malicious intrusions or data leaks. We recommend that you renew or purchase a new edition in time.
Expiration: The system reserves a 7-day buffer period. After 7 days, the service instance is released, and data is cleared based on the rules in the following table.
NoteSeven days before the service expires, the system sends renewal reminders through emails, or internal messages.
Unsubscription: The service instance is immediately released, and data is cleared based on the rules in the following table.
Scenario
Data clearing description
Expiration - within 7 days
The service authorization information, configuration policies, and service data for all features are retained.
Expiration - after 7 days
The following authorization information is immediately purged:
Container Protection - Image security scan.
Container Protection - CI/CD integration settings.
Log analysis: The data in the `sas-log` Logstore is immediately purged. This Logstore belongs to the Project that Security Center creates in Simple Log Service (SLS). The Project is named `sas-log-<Alibaba Cloud account ID>-<region ID>`.
Host Protection - Anti-ransomware: All backup policies and backup data are immediately purged.
Cloud Security Posture Management:
Cloud product configuration check:
Only the check results of free edition items are retained. The check results of paid edition items are immediately purged.
Periodic scan policies, allowlist policies, and custom check items are not deleted.
System baseline:
Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.
Scan policies are immediately deleted. Allowlist policies are not deleted.
Unsubscription
Unsubscription/Expiration - after 15 days
The following Agentic SOC data is immediately purged:
Security alerts: All alert information except for alerts under CWPP.
Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).
NoteSecurity events generated from alerts under CWPP (CWPP security events) are retained.
Response orchestration: Custom playbooks and custom response rules.
Log Management: Standardized integration logs and Security Center logs.
Rule management: Custom rules.
Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.
Agentic SOC - Response Center: Response policies and response tasks are automatically purged by the system 90 days after they expire. This is not affected by unsubscription.
Independent sales
Agentic EDR
After an EDR instance expires or is unsubscribed, the instance is immediately released, and Agentic EDR immediately stops service.
Elastic protection: Elastic protection immediately becomes invalid and billing stops. The elastic authorizations and credits consumed on the current day are billed the next day.
Data retention:
Policy and baseline retention: Existing policies and host baselines are retained but no longer updated.
Historical alert retention: Existing host anomaly alerts are retained, but no new alerts are generated.
Attack Management
After an Attack Surface Management instance expires or is unsubscribed, the instance is immediately released, and protection capabilities stop.
Elastic protection: Elastic protection immediately becomes invalid and billing stops. The elastic authorizations and Credits consumed on the current day are billed the next day.
Data retention:
Feature policy configuration data is retained indefinitely.
Asset and attack path scan task data is retained for 7 days, after which it is permanently released.
AgenticBAS
Expiration: Penetration test task data is retained for 15 days. After 15 days, the instance is released and historical data is purged. If you repurchase within 15 days, historical penetration test task data can be restored.
Unsubscription: Online unsubscription unavailable. Please contact your business representative for manual processing.
SecOpsAgent
Expiration: After the service expires, you can no longer use the features of Security Agent.
The instance and data are retained for 30 days. If you reactivate the service within the retention period, you can continue to use the existing data.
If you do not renew the service within 30 days, the instance is released and the historical data is permanently purged and cannot be recovered.
Unsubscription: Online unsubscription unavailable. Please contact your business representative for manual processing.