All Products
Search
Document Center

Security Center:Disable pay-as-you-go services

Last Updated:Aug 20, 2026

Pay-as-you-go services continue to incur charges until they are disabled and cannot be unsubscribed from the Unsubscribe Management page. This topic describes how to disable them in the Security Center console. You can disable individual services or all services at once.

Disabling instructions

Usage suggestions

If you claimed a Security Center trial resource plan when purchasing an Elastic Compute Service (ECS) instance, the system automatically switches to pay-as-you-go billing after the trial plan is exhausted and continues charging. To prevent further charges, disable the pay-as-you-go services after the trial plan is used up or when you confirm that the services are no longer needed.

Disabling methods

Disabling method

Scope

Disable individual services

Only the selected services stop being billed. The remaining services continue to be billed on a pay-as-you-go basis.

Disable all services at once

All enabled pay-as-you-go services are disabled.

Procedure

Important

If the pay-as-you-go instance is suspended due to overdue payments, you must first go to the Billing Center to top up and settle the outstanding balance to restore the account to normal status before you can perform the disabling operation. During the overdue period, the console displays an additional payment entry on the pay-as-you-go card.

  1. Go to the Security Center console - Overview page.

  2. In the Enable Pay-as-You-Go Service section, perform one of the following operations:

    • Disable individual services: Turn off the switch for that service to stop billing for that service only.

    • Disable all services at once: Click Deactivate in the upper-right corner of the page to disable all pay-as-you-go features at once.

  3. In the confirmation dialog box, confirm the disabling operation.

  4. After confirmation, the system displays a success message and automatically refreshes the page. The pay-as-you-go toggle shows the off state.

Impact of disabling (billing and bills)

  • Disabled services stop being billed immediately, and the related services stop protection immediately.

  • Usage consumed on the day of disabling is still billed on the next day (T+1), and a bill is pushed.

    Important

    If you still receive bills after disabling services, these are typically charges incurred before the disabling operation, which is normal.

Data deletion

Unified sales features

There is no data retention period. Data is immediately cleared according to the rules in the following list.

  • The following authorization information is immediately purged:

    • Container Protection - Image security scan.

    • Container Protection - CI/CD integration settings.

  • The following Agentic SOC data is immediately purged:

    Important

    If the data retention period for an overdue payment is longer than 15 days, Agentic SOC does not wait for the retention period to end. Instead, it starts the data purge immediately after the 15th day of the overdue payment.

    • Security alerts: All alert information except for alerts under CWPP.

    • Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).

      Note

      Security events generated from alerts under CWPP (CWPP security events) are retained.

    • Response orchestration: Custom playbooks and custom response rules.

    • Log Management: Standardized integration logs and Security Center logs.

    • Rule management: Custom rules.

    • Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.

  • Agentic SOC - Response Center: Response policy and response task data is automatically purged by the system 90 days after it expires. This is not affected by overdue payments or service shutdowns.

  • Cloud Security Posture Management:

    • Cloud product configuration check:

      • After the cloud product configuration check is disabled, the check result data is not deleted.

      • Periodic scan policies, allowlist policies, and custom check items are not deleted.

    • System baseline:

      • Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.

        Note

        If your subscription service (Advanced, Enterprise, or Ultimate) has not expired and has not been unsubscribed, the check results for the corresponding edition are continuously retained. After the service expires or you unsubscribe, the data is retained in the backend for 30 days and then automatically deleted.

      • Scan policies are immediately deleted. Allowlist policies are not deleted.

  • Anti-ransomware: 1 day after the instance is released, the protection capabilities and generated backup data of this service are removed.

Independent sales features

Agentic EDR

  • Elastic protection: Elastic protection immediately becomes invalid and billing stops. The elastic authorizations and credits consumed on the current day are billed the next day.

  • Data retention:

    • Policy and baseline retention: Existing policies and host baselines are retained but no longer updated.

    • Historical alert retention: Existing host anomaly alerts are retained, but no new alerts are generated.

Attack Management

  • Feature policy configuration data is retained permanently.

  • Asset and attack path scanning task data is retained for only 7 days and then permanently released.

FAQ

  • Why do I still receive bills after I have disabled pay-as-you-go?

    • Usage consumed on the day of disabling is still billed on the next day.

    • If a subscription service you purchased triggers elastic protection, the corresponding pay-as-you-go bill is still pushed. For more information, see Disable elastic protection.

  • I have not enabled pay-as-you-go services. Why do I receive bills?

    1. Confirm whether pay-as-you-go is actually enabled

      1. Go to the Security Center console - Overview.

      2. In the Enable Pay-as-You-Go Service section, check whether any feature has the pay-as-you-go enable switch turned on image.

    2. Check the enablement time

      1. Go to Billing and Cost Management - My Orders to check when the Security Center (pay-as-you-go) instance was enabled.

        Note

        The default query period is 6 months. If no results are found, adjust the Creation Time Range.

      2. If you claimed a Security Center trial resource plan when purchasing an ECS instance, those pay-as-you-go features continue to run and incur charges after the trial plan is exhausted. Go to Billing and Cost Management - Resource Plans to check the enablement time and usage details of the resource plan. For more information, see Explanation of Comprehensive Host Protection Benefits for ECS.

      3. After you enable a pay-as-you-go free trial (savings plan), those pay-as-you-go features continue to run and incur charges when the trial ends or usage exceeds the free quota. Go to the Billing and Cost Management - Savings Plans page to check the View Details. For more information, see Activate the pay-as-you-go free trial.

    3. Disable pay-as-you-go services: Go to the Security Center console - Overview. In the Enable Pay-as-You-Go Service section, click Deactivate in the upper-right corner of the page to disable all pay-as-you-go features at once.

    4. Other postpaid billing scenarios:

      • If a subscription service triggers elastic protection (enabled by default), the corresponding pay-as-you-go bill is also pushed. Release the excess elastic protection quota first, and then turn off the elastic protection switch to stop pay-as-you-go billing. For more information, see Disable elastic protection.

      • Usage consumed on the day you disable pay-as-you-go or elastic protection is still billed on the next day. After the bill is settled, you will no longer receive related bill reminders from the third day.

        Note

        Services stop immediately on the day of disabling and no new charges are incurred. The bill pushed covers unsettled charges for usage already consumed, so there is no need for concern.

  • Why can't I find the pay-as-you-go enablement order?

    • Query time range limit: Billing and Cost Management - My Orders queries the last 6 months by default. If no results are found, manually widen the range by adjusting the Creation Time Range filter.

    • Postpaid instance reuse — no new order generated: If you previously enabled a postpaid service, then disabled it and later re-enabled it, the system reuses the original instance ID and does not generate a new order record.

      Note

      No new order is expected in this scenario. You can view your enabled postpaid features directly on the Security Center console - Overview page.

  • What is the USD 0.0072 base service fee in my pay-as-you-go bill? Can it be canceled?

    • This fee is the basic feature usage fee for pay-as-you-go instances, not an optional value-added service. When you enable any pay-as-you-go feature on the Security Center unified sales page, the system automatically charges the base service fee.

      Important

      Pay-as-you-go services that are sold separately, such as Agentic EDR and Attack Management, are not charged the base service fee.

    • This fee cannot be canceled directly. It stops being charged only after you disable all pay-as-you-go services. For more information, see Pay-as-you-go.