The pay-as-you-go (postpaid) mode of Security Center bills based on actual daily usage, and generates a bill on the next day (T+1). Pay-as-you-go services include unified sales features and standalone sales features.
Overview
Security Center features are available through unified sales and standalone sales. You can choose flexibly based on your business needs.
Unified sales: Purchase all-in-one on the Security Center buy page. The fees include base service fees and feature usage fees.
Standalone sales: Certain features can only be purchased separately, with dedicated buy pages and independent billing rules. However, once enabled, these features are still integrated into the Security Center console for unified management.
Unified sales features
Unified sales features are pay-as-you-go services purchased on the Security Center buy page, including base service fees and feature usage fees.
Billing formula
Total usage fees of enabled paid features + base service fee.
The system generates a bill on the next day (T+1) based on actual daily usage.
Base service fee
When you enable any pay-as-you-go feature on the Security Center unified sales page, the system charges an additional base service fee. The billing rules are as follows:
After activation, DingTalk chatbot, security reports, and task center (requires vulnerability fix to be enabled or purchased first) are supported by default.
Billing method: Billing is based on the duration that the pay-as-you-go service is enabled.
ImportantThe minimum billing unit is one hour. If the enabled duration is less than 1 hour, it is billed as 1 hour.
Billing cycle: Settled on a daily basis.
Price: .
Feature usage fees
The following table lists the features that can be enabled in pay-as-you-go mode and their billing details:
Host and Container Security
Billing method: Billing is based on the protection level, the number of bound servers, and the actual protection duration (seconds). The actual protection duration is calculated based on the client online duration.
Billing cycle: Settled on a daily basis.
Price: The prices for different protection levels are shown in the following table.
Protection level
Price
Monthly cost (30-day reference)
Antivirus
USD 0.000000578/core/second
USD 1.5/core/month
Advanced
USD 0.000005497/server/second
USD 14.25/server/month
Comprehensive Host Protection
USD 0.000013599/server/second
USD 35.25/server/month
Hosts and Container Protection
USD 0.000013599/server/second+USD 0.000000578/core/second
USD 35.25/server/month+USD 1.5/core/month
Vulnerability Fixing
Billing method: Billing is based on the number of vulnerability fixes. Fixing one vulnerability announcement on a single server counts as 1 time. Failed fixes do not consume quota. For more information, see Overview.
Billing cycle: Settled on a daily basis.
Price: USD 0.3/time.
Container Image Scan
Billing method: Billing is based on the number of scanned images.
Billing cycle: Settled on a daily basis.
Price: USD 0.15/time.
Agentic SOC (Legacy)
Billing method:
Agentic SOC (Legacy): Billing is based on the daily ingested log traffic (GB) using tiered pricing. The daily fee is the sum of fees across all tiers. The minimum billing unit is GB. Fractions less than 1 GB are billed as 1 GB.
Security Operations Agent: In addition to tiered pricing based on daily ingested log traffic (GB), the following billing items are also included:
Intelligent Usage Analysis: Billing is based on the analysis volume (GB) consumed by AI security digital analysts for alert investigation, incident investigation, tracing, attribution, and security report generation.
Number of Managed Instances: Billing is based on the number of agent instances invoked. ECS, WAF, ALB, cross-cloud products, and on-premises security vendor products are all counted as instances. The same instance is counted only once with automatic deduplication.
Billing cycle: Settled on a daily basis.
Price:
Log Ingestion Traffic: Tiered pricing based on daily ingested log traffic (GB).
Log ingestion traffic tier
Price
Fee calculation formula (Y = daily ingested traffic in GB)
1~10 (GB/day)
USD 2.2/GB
2.2×Y (USD)
11~50 (GB/day)
USD 1.6/GB
2.2×10+1.6×(Y-10) (USD)
51~100 (GB/day)
USD 1.4/GB
2.2×10+1.6×40+1.4×(Y-50) (USD)
>100 (GB/day)
USD 1.2/GB
2.2×10+1.6×40+1.4×50+1.2×(Y-100) (USD)
Intelligent Usage Analysis: USD 0.144/GB/day.
Number of Managed Instances: USD 2.15/instance/month.
Log Storage Capacity
Billing method: Billing is based on the daily cumulative log storage volume (GB). The minimum billing unit is 1,000 GB. Fractions less than 1,000 GB are billed as 1,000 GB. For example, if the daily usage is 1,900 GB, it is billed as 2,000 GB.
Billing cycle: Settled on a daily basis.
Price: USD 7.2/1,000 GB.
Agentic Cloud Platform Configuration Check
Billing method: Billing is based on the number of billable cloud service instances scanned, verified, and remediated. For more information about authorization consumption rules, see Authorization (postpaid) consumption description.
Billing cycle: Settled on a daily basis.
Price: USD 0.0732/instance/day. Multiple scans, verifications, and remediations within a single billing cycle do not incur additional charges.
Agentless Detection
Billing method: Billing is based on the volume of data scanned (GB).
Billing cycle: Settled on a daily basis.
Price: USD 0.03/GB.
Serverless Assets
Billing method: Billing is based on the number of authorized server cores × actual protection duration (seconds). The actual protection duration is calculated based on the client online duration.
Billing cycle: Settled on a daily basis.
Price: Tiered pricing based on monthly cumulative usage.
Monthly cumulative usage description:
Daily cumulative usage for the current month = Monthly cumulative usage up to the previous day (0 on the first day) + Daily usage for the current day.
NoteIn the first month of activation, the statistics period is from the activation date to the end of the current month. Starting from the second month, the statistics period is a calendar month (from the 1st to the end of each month).
Example: Day 1 monthly cumulative usage = Day 1 usage. Day 2 monthly cumulative usage = Day 1 usage + Day 2 usage. Day 3 monthly cumulative usage = Day 1 usage + Day 2 usage + Day 3 usage, and so on.
Tier pricing:
Monthly cumulative usage
Price
Fee calculation formula (U = daily usage, unit: core/second)
Tier 1: 0~200,000,000 core/second
USD 0.000003/core/second
0.000003×U (USD)
Tier 2: 200,000,001~1,000,000,000 core/second
USD 0.000002/core/second
First day entering this tier:
0.000003×200,000,000+0.000002×(U-200,000,000) (USD)
Subsequent days: 0.000002×U (USD)
Tier 3: 1,000,000,001~9,999,999,999,999 core/second
USD 0.0000015/core/second
First day entering this tier:
0.000003×200,000,000+0.000002×800,000,000
+0.0000015×(U-1,000,000,000) (USD)
Subsequent days: 0.0000015×U (USD).
Billing example:
Scenario: Serverless assets have a total of 20,000 cores, running 24 hours (86,400 seconds) per day. Daily usage (U) = 20,000 cores × 86,400 seconds/day = 1,728,000,000 core/second.
First day fee:
Usage description: Day 1 monthly cumulative usage = Day 1 usage = 1,728,000,000 core/second. The monthly cumulative usage has reached Tier 3, and is billed based on the first-day-entering-Tier-3 rules (cross-tier).
Fee calculation: First day fee = 0.000003 (Tier 1 unit price) ×200,000,000+0.000002 (Tier 2 unit price) ×800,000,000+0.0000015 (Tier 3 unit price) ×(1,728,000,000-1,000,000,000)=3,292 (USD).
Second day and subsequent fees:
Usage description: Since the Day 1 monthly cumulative usage has already reached Tier 3, from Day 2 to the end of the month, the monthly cumulative usage remains in Tier 3, and daily fees are billed at the Tier 3 unit price.
Fee calculation: Daily fee = 0.0000015 (Tier 3 unit price) ×(20,000×86,400)=2,592 (USD).
Malicious File Detection
Billing method: Billing is based on the number of file detections (number of files detected).
Billing cycle: Settled on a daily basis.
Price: USD 0.0002/time.
Application Protection(RASP)
Billing method: Billing is based on the number of online instances per minute (0~60 seconds).
Billing cycle: Settled on a daily basis.
Price: USD 0.0002/instance/minute.
Anti-ransomware
Billing method: Billing is based on the backup file size (GB) and storage duration (hours).
Billing cycle: Cumulative hourly usage, settled on a daily basis.
Price: USD 0.00013/GB/hour.
File Tamper-Proofing
Billing method:
Billing formula: Actual protection duration (seconds) × Number of protected servers.
Protected server count rules: Servers that meet any of the following conditions are counted as protected servers:
Servers bound to interception protection rules.
Servers bound to alert protection rules where the host protection edition is below Enterprise Edition, or the protection level is below Comprehensive Host Protection.
Billing cycle: Settled on a daily basis.
Price: USD 0.286705/server/hour.
Standalone sales features
Standalone pay-as-you-go services do not charge a base service fee.
Agentic EDR
Billing method: Billing is based on the number of seats × usage duration. Binding one server consumes one seat license. Servers without policy configuration are automatically excluded from billing.
Billing cycle: Billed hourly, settled on a daily basis.
Price: USD 0.014325/seat/hour.
Attack Management
Billing method: Billing is based on the number of protected assets and the Credits consumed by scanning.
NoteCredits are the scanning quota unit for attack surface management. Each scan consumes a certain number of Credits, which are used for attack path mapping of exposed assets, intelligent risk details, and generation of intelligent risk remediation suggestions. The actual number of Credits consumed is subject to the system's actual usage.
Billing cycle: Settled on a daily basis.
Price:
Assets: USD 0.5/day/asset. Each asset includes 200 Credits by default.
Excess Credits: USD 0.15/100 Credits.
Overdue payments or service deactivation
Scenarios:
Overdue payment: Pay-as-you-go bills are generated on T+1. If the account balance is insufficient at the time of settlement, an overdue payment occurs. To avoid service disruption, top up your account promptly.
Service deactivation: The account manually deactivates the pay-as-you-go service. After deactivation, no new fees are generated.
NoteOn the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the relevant service switches. Or click the Deactivate button above to deactivate all pay-as-you-go services.
Subsequent impact: The corresponding pay-as-you-go features are unavailable, and the related detection and protection capabilities are lost.
Data retention:
Unified sales
Overdue payment: After an overdue payment, there is a 15-day data retention period. After 15 days, data is cleaned according to the rules in the following table.
Service deactivation: No data retention period. Data is cleaned immediately according to the rules in the table.
Scenario
Data cleanup description
Overdue - within data retention period
During the retention period, all service authorization information, configuration policies, and pay-as-you-go service data are retained.
Overdue - after data retention period
The following authorization information is immediately purged:
Container Protection - Image security scan.
Container Protection - CI/CD integration settings.
The following Agentic SOC data is immediately purged:
ImportantIf the data retention period for an overdue payment is longer than 15 days, Agentic SOC does not wait for the retention period to end. Instead, it starts the data purge immediately after the 15th day of the overdue payment.
Security alerts: All alert information except for alerts under CWPP.
Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).
NoteSecurity events generated from alerts under CWPP (CWPP security events) are retained.
Response orchestration: Custom playbooks and custom response rules.
Log Management: Standardized integration logs and Security Center logs.
Rule management: Custom rules.
Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.
Agentic SOC - Response Center: Response policy and response task data is automatically purged by the system 90 days after it expires. This is not affected by overdue payments or service shutdowns.
Cloud Security Posture Management:
Cloud product configuration check:
After the cloud product configuration check is disabled, the check result data is not deleted.
Periodic scan policies, allowlist policies, and custom check items are not deleted.
System baseline:
Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.
NoteIf your subscription service (Advanced, Enterprise, or Ultimate) has not expired and has not been unsubscribed, the check results for the corresponding edition are continuously retained. After the service expires or you unsubscribe, the data is retained in the backend for 30 days and then automatically deleted.
Scan policies are immediately deleted. Allowlist policies are not deleted.
Service deactivation
Standalone sales
Agentic EDR
-
Policies and baseline retention: Existing policies and host baselines are retained but no longer updated.
-
Historical alert retention: Existing host abnormal behavior alerts are retained, but no new alerts are generated.