Security Center provides a variety of features ranging from basic protection to value-added services to meet security requirements in different scenarios. This topic helps you understand the billing modes, billing rules, and cost structure of Security Center so that you can make the best purchase decision based on your business requirements.
Billing modes and billable items
Security Center supports two billing modes: subscription and pay-as-you-go. The billing mode defines the settlement method of Alibaba Cloud, and different modes support different features.
Regardless of the billing mode you select, you can use the features of the free edition. For more information, see Enable Security Center Basic.
Comparison item | Subscription (prepaid) | Pay-as-you-go (post-paid) | Hybrid billing |
Billing characteristics | One-time payment by month or year, with fixed costs for easy budget management. | Pay based on actual usage, flexible and convenient, with no upfront costs required. | Based on subscription, excess usage is billed on a pay-as-you-go basis, balancing cost control and elastic scaling. |
Billable items | Fee = Edition fee + Value-added service fee (optional).
| Fee = Base service fee + Feature usage fee.
| Fee = Subscription fee + Burstable protection fee.
|
Feature support description
Subscription
Edition service:
Anti-virus: Provides capabilities such as detection and removal of common host viruses.
Advanced Edition: Provides capabilities such as host virus detection, virus removal, vulnerability detection and fix, and security reports.
Enterprise: Meets the requirements for host security intrusion prevention, identity authentication, and security auditing.
Ultimate: Provides full-stack security protection capabilities that cover hosts, containers, and intelligent computing Lingjun servers, including K8s threat detection, container asset panorama, security alerts, virus removal, vulnerability detection, asset fingerprint identification, and attack chain analysis.
Value-added services: You can simultaneously purchase Vulnerability Fixing, Agentic SOC (Legacy), Anti-ransomware, Agentic CSPM, and other features.
Pay-as-you-go
Basic features: DingTalk bot, security report, and task center (requires vulnerability fix to be enabled or purchased first) are supported by default.
Paid features: You can individually purchase post-paid features such as Host and Container Security, Vulnerability Fixing, Serverless Assets, Agentic SOC (Log Storage Capacity), and Agentic SOC (Legacy).
Hybrid billing: Users who enable the subscription service have Burstable Protection enabled by default, which activates the hybrid billing mode. Features that support this mode include edition service, Agentic EDR, Attack Management, and Anti-ransomware.
For more feature descriptions, see Subscription, Pay-as-you-go, and Hybrid billing (burstable protection).
Billing code
Security Center involves multiple products in Expenses and Costs. When you query orders in Expenses and Costs, you can locate the feature activation records by using the product names and billing modes in the following table.
Product category | Product name | Billing code | Description |
Unified sales | Security Center |
| Subscription service. |
Security Center (pay-as-you-go) |
| None | |
Standalone sales | Attack surface management |
| Subscription service. |
Attack surface management (pay-as-you-go) |
| None | |
Agentic BAS basic service |
| Subscription service. | |
Agentic BAS (pay-as-you-go) |
| None | |
Intelligent host detection and response |
| Subscription service. | |
Intelligent host detection and response (post-paid) |
| None | |
Security Operations Agent subscription |
| Subscription service. | |
Security Operations Agent (pay-as-you-go) |
| None | |
Agentic SOC (pay-as-you-go) |
| None | |
Agentic SOC subscription |
| The subscription service of the latest version of Agentic SOC. Note The legacy version of Agentic SOC is a unified sales service, and its product code is |
FAQ
Can I enable both pay-as-you-go and subscription at the same time?
Yes, but only for different feature modules. For example, you can select subscription for "Vulnerability Fix" and pay-as-you-go for "Agentic SOC".
You can only select one of the subscription editions (Anti-virus, Advanced, Enterprise, Ultimate) and the Host and Container Security service under pay-as-you-go. You cannot purchase both at the same time or stack them.
You cannot simultaneously purchase subscription value-added features (such as Agentic SOC (Legacy)) and the same features under pay-as-you-go.
Why was I unexpectedly charged for pay-as-you-go?
If you find unexpected pay-as-you-go charges for Security Center, the charges may be caused by the following reasons:
Resource plan exhausted: If you used a resource plan (such as a vulnerability fix resource plan or an ECS free trial package), the system automatically switches to pay-as-you-go billing after the plan quota is exhausted or expires. The service does not stop automatically. For more information, see the What is the relationship between resource plans and pay-as-you-go? section below.
Accidental activation: Pay-as-you-go features may have been enabled unintentionally during console operations.
To identify when pay-as-you-go was activated, use one of the following methods:
Check order records: Go to the My Orders page in Expenses and Costs to view the activation time and order records for Security Center pay-as-you-go services.
Query operation records: Log on to ActionTrail and query the operation records of Security Center to identify when and how pay-as-you-go features were enabled.
To stop subsequent charges, go to the Overview page of the Security Center console. In the Enable Pay-as-You-Go Service section, turn off the relevant service switches, or click Deactivate to disable all pay-as-you-go services at once. After you disable the services, fees incurred on the same day are settled the next day (T+1). No new bills are generated after that.
How do I disable the pay-as-you-go service?
On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the relevant service switches. Or click the Deactivate button to disable all post-paid services.
ImportantIf your account has overdue payments and services are suspended, we recommend that you use the Deactivate feature to avoid incurring new fees when services are automatically enabled after you top up your account.
Fees incurred on the day you disable the services will be settled the next day and a final bill will be generated.
Which fees in the pay-as-you-go bill are continuously incurred? What is the billing logic?
Some features of Security Center use a "pay-as-you-go + resource reservation" mode. As long as the feature switch is enabled, the system reserves the corresponding computing resources, storage space, or executes preset security policies, which generates corresponding base service fees or storage fees. This is not an abnormal charge, but to ensure that your security protection is always available. The following describes the logic of each fee and how to stop billing:
Base service fee is continuously charged: As long as any pay-as-you-go feature is enabled under your account, regardless of whether any assets are connected or security alerts are generated, the system charges a base service fee hourly (USD 0.0072/hour). To stop billing, turn off all pay-as-you-go feature switches.
Log storage fee is continuously generated: If the log storage feature is enabled, fees may be incurred due to occupied storage space even if no new logs are written. The minimum billing unit for Agentic SOC (Log Storage Capacity) is 1,000 GB. If the storage is less than 1,000 GB, you are still billed for 1,000 GB.
Agentic CSPM periodic scanning fee: If you configure an Agentic CSPM periodic automatic scanning policy, the system will execute scheduled scans and generate fees. If the trial quota is used up, a post-paid bill will be generated the next day.
What is the relationship between resource plans and pay-as-you-go?
Some features support resource plans (such as vulnerability fix resource plans and ECS security free trial packages) that use prepaid quotas to offset fees. Note the following rules:
Deduction scope: Resource plans only offset the quotas for specific billable items and do not apply to the base service fee or other uncovered feature fees.
Billing after a resource plan is exhausted or expires: After the resource plan quota is exhausted or the validity period expires, if the corresponding pay-as-you-go feature switch is not turned off, the system automatically switches to the pay-as-you-go billing mode and continues billing. The service is not automatically stopped.
No unsubscription required for resource plans: Resource plans automatically become invalid after expiration. Manual unsubscription is not required.
How to stop subsequent billing: To stop incurring fees after a resource plan is exhausted, you must manually go to the Overview page of the Security Center console, turn off the switch for the corresponding feature in the Enable Pay-as-You-Go Service section, or click the Deactivate button to disable all pay-as-you-go services.
How do I avoid service suspension due to overdue payments?
Optimize resource configuration
Select the scope of assets to be protected based on actual requirements to avoid paying for unnecessary resources.
Available credit alert
Log on to Billing Management and set Available Credit Alert on the Account Overview page. When the available credit of your account falls below the alert threshold, the system automatically triggers a reminder.
Will Security Center pay-as-you-go continue to be charged after I unsubscribe from Elastic Compute Service (ECS)?
Yes. Security Center pay-as-you-go billing is independent of ECS instances. Unsubscribing from ECS does not automatically disable Security Center pay-as-you-go services. To stop billing, go to the Overview page of the Security Center console. In the Enable Pay-as-You-Go Service section, turn off the relevant service switches, or click Deactivate to disable all pay-as-you-go services. Fees incurred on the day you disable the services are settled the next day (T+1), and no new fees are generated afterward.