How does the free trial work?+
Sign up, connect your first data source, and you get 14 days of full access at your chosen tier — no credit card required. At day 14 you'll be prompted to enter payment to continue. If you don't upgrade, your dashboard access is paused (your data is retained for 30 days so you can reactivate without starting over).
What's the difference between Starter and Professional?+
Starter ($2,000/mo) is one data source integration and up to 500 alerts/day — right for smaller teams just getting AI-triage on their EDR or SIEM feed. Professional ($3,500/mo) adds up to 5 integrations, 5,000 alerts/day, threat hunting, Slack alerting, and a weekly executive briefing. Most mid-market teams (50-200 employees) land on Professional.
What's the contract length?+
Starter and Professional are month-to-month — cancel any time with no penalty. Enterprise contracts are annual (negotiated 1-3 years with volume discounting), billed monthly.
Do you handle our existing SIEM, or do we have to switch?+
Sentinel ingests from the tools you already run: SentinelOne, CrowdStrike, Stellar Cyber, Adlumin, Proofpoint, and Generic Syslog (any syslog-capable device). If you don't have a SIEM, we run vendor-direct adapters. You don't need to rip and replace anything.
Is this MDR or co-managed SOC?+
Starter is AI-augmented monitoring — you get the triage queue and alerts, you respond. Professional is co-managed — we share on-call for high-severity alerts and you have incident response support. Enterprise can be fully managed including vCISO services.
Can we white-label Sentinel for our own customers?+
Yes — that's the MSP-partner option under Enterprise. Multi-tenant rollup, per-tenant RBAC, per-tenant billing rollup, and a co-branded or fully white-labeled portal. Book a call to discuss MSP pricing.
What compliance frameworks do you map to?+
Out of the box: HIPAA, PCI DSS 4.0, SOC 2, NIST CSF v2. Custom mappings (FedRAMP Moderate, ISO 27001, NYDFS) are part of Enterprise. Monthly compliance report ships with every tier.
Where does our data live?+
Your alert data is processed in your GCP or cloud boundary — we never replicate raw event data out. Operational metadata (rule definitions, playbook configs, audit logs) lives in our GCP tenant under SOC 2 controls.