Skip to content
Veteran-Owned. Built by engineers who've actually done the work.
¶ 01

Three tiers. Published.

No "request a quote" gate, no per-user re-license trick. Pick the tier whose obligations match your regulatory exposure. The price you see is the price on your invoice.

Tier 01 Guardian
$ 15 / ep / mo$13/ep on annual

Core MDR with 24/7 monitoring, structured-reasoning investigation on every alert, and human-approved verdicts.

  • 24/7/365 detection & triage
  • Named-engineer verdicts
  • 1,100+ MITRE-mapped rules
  • 90-day log retention
  • 2-hr emergency IR / critical incident
25-endpoint min · $500/mo floor See full Guardian spec ↓
Tier 03 Aegis
Custom scoped engagement

Federal SDVOSB engagements, multi-site enterprises, and Fortune-1000 detection programs requiring a dedicated engineering seat.

  • Everything in Fortress
  • Dedicated detection engineer
  • Quarterly purple-team exercise
  • Forensics retainer included
  • Annual program-of-record audit
  • SAM.gov · CMMC · NIST 800-171
Federal & enterprise Scope an engagement →

Market context: the public US managed-detection market typically ranges $15–$50 per endpoint per month. Sophos and Arctic Wolf both gate per-endpoint price behind a sales call. We publish ours so you can do the math before the call, not during it.

Service Tiers & Pricing

Monitoring that acts.
Response that doesn't wait.

You run a business. We run your security operations. 24/7 monitoring, AI-enriched threat investigation, and managed response from a veteran-owned team. So you are never the last to know and never handling an incident alone. Built for industries with compliance obligations. Available to any organization that takes security seriously.

What a breach actually costs your organization
$10.22M
Average cost of a U.S. data breach in 2025. A new all-time record. Healthcare leads all industries for the 14th consecutive year at $7.42M average.
IBM Cost of a Data Breach 2025
$5.08M
Average cost of a ransomware or extortion incident. 63% of organizations now refuse to pay. Average recovery still takes over 100 days.
IBM Cost of a Data Breach 2025
$51,744
FTC Safeguards Rule penalty per violation per day. Every CPA firm without a compliant WISP faces this exposure.
FTC 2025 inflation-adjusted rate
Organizations that take security seriously don't wait for a breach to act. The practices, firms, and agencies we work with don't see MDR as a cost. They see it as the difference between a contained incident and a seven-figure crisis. If you're reading this, you're already thinking the right way.
Annual · 12-month
10% off
Onboarding fee waived
3-year
25% off
Rate locked for full term
Guardian
Core MDR
For organizations with IT staff who are able to act on guidance. We monitor and alert. You decide what happens next.
$15/endpoint/mo
$500/mo minimum  ·  25 ep min  ·  $13/ep annual
Without MDR, the average breach goes undetected for 241 days. IBM 2025
Monitoring
  • 24/7 behavioral endpoint monitoring
  • Automated threat containment. Platform isolates in seconds.
  • Documented investigation on every alert in plain English
  • Automated forensic collection at critical thresholds
  • Microsoft 365 email security monitoring
  • Removable media monitoring
Reporting
  • Monthly security report
  • Quarterly vulnerability scan
  • 90-day log retention
Emergency response. Confirmed critical events only.
TriggerConfirmed ransomware or active breach
Included2 hours per incident
Quarterly cap2 incidents
Additional hours$275/hr on demand
Human responseUnder 30 minutes
Aegis
Professional Services
Add to either tier. Analyst time and specialist engagements beyond the platform. Scoped per engagement.
Priced per service  ·  Contact for quote
55% of HIPAA penalties fall on small practices. Most had no IR plan. HHS enforcement data 2025
Advanced incident response
  • Full response retainer with unlimited confirmed incidents
  • Ransomware investigation, eradication, and recovery
  • Breach notification drafting and regulatory filing
  • HIPAA 60-day and state 30-day deadline management
  • Annual tabletop exercise using DHS and CISA methodology
  • Digital and mobile forensics
Advisory
  • Virtual security officer retainer. $2,500 to $5,000/mo
  • Penetration testing via certified partner. $5K to $15K/yr
  • Compliance audit preparation. $5K to $25K
  • Security attestation report. $2K to $2,500/yr
  • Executive and board security briefings
Extended monitoring
  • Cloud security monitoring for AWS, M365, and GCP. $300 to $500/mo
  • Brand and typosquatting monitoring
  • Vendor and supply chain risk assessment. $1,500 to $3,500/yr
  • Regulatory change monitoring. $150/mo

Same detection engine. Same engineers. The tier you pick changes scope, documentation, and warranty — not capability. Hover any feature for definition.

Capability Guardian $15 / ep / mo Most popular Fortress $22 / ep / mo Aegis Custom
Detection & response
24/7/365 monitored detectioni Included Included Included
Named-engineer verdict on every alerti Included Included Included
Structured-reasoning investigation pipeline Included Included Included
Automated containment (isolate / quarantine) Included Included Included
Continuous threat huntingi Quarterly Weekly Continuous + dedicated engineer
Incident response
Critical-incident response time < 30 min human < 15 min on-call Dedicated engineer
IR retainer included 2 hr / incident
2 incidents / qtr cap
10 hr / mo
rolls forward
Unlimited confirmed
Additional IR hours $275 / hr $250 / hr Bundled
Digital forensics retainer Not included Available add-on Included
Compliance & documentation
Log retention 90 days 365 days Custom
Vertical compliance packagei Not included All four verticals All + federal
Annual program-of-record audit Not included Add-on Included
Risk & warranty
Breach warranty Not included $250,000
underwritten by Cysurance
Custom limit
Quarterly purple-team exercise Not included Not included Included
Federal scope (SAM.gov / CMMC / NIST 800-171) Not included Not included Included
  Choose Guardian Choose Fortress Scope Aegis

All tiers: $500/mo floor · 25-endpoint minimum · quarterly billing. No upper endpoint ceiling on any tier.

What MDR costs you. What a breach costs you. Side by side.

Set your endpoint count and vertical. We show your annualized Carbynix spend next to the published average cost of a breach in your industry. The math is the math.

Your annualized Carbynix spend
$18,000
$1,500/mo · 100 endpoints · Guardian · monthly
vs.
Average cost of a breach in your industry
$5,090,000
Legal services · IBM Cost of a Data Breach 2024 (avg)
A breach in your industry costs ~283× what one year of Guardian costs you.

Sources: IBM Cost of a Data Breach Report 2024 · Sophos State of Ransomware 2024. Industry breach averages include forensics, notification, regulatory response, and downtime — not legal settlements or class-action exposure.

Included on every tier

The artifact your auditor reads.

Every alert closed by Carbynix — on Guardian, Fortress, or Aegis — produces an investigation record. Named engineer. Counterfactuals ruled out. Evidence chain preserved for the duration your regulator requires. The tier changes scope; it does not change whether the record exists.

See an example record →
What our clients stopped paying for
"The verdict on every alert is signed by the engineer who closed it. If the auditor asks why we believed it was benign, we hand them the record — not a marketing slide."
M. Reyes · Lead Detection Engineer · 8 years federal IR (DHS / CISA)
"97.5% less in breach-related loss. Not because you got lucky. Because we were watching before the attacker finished planning."
Sophos data · 282 organizations analyzed
"The Wacks Law Group took 5 months to detect a breach. The class action is still running. Their MDR subscription was $550 a month."
Real case. Real cost. The math is not complicated.
"When the regulator, the auditor, or your client's diligence team asks for evidence, you hand them the record. Not a marketing slide."
The artifact your audit chain reads
Included in Fortress
Dark Web Monitoring
Included in Fortress  ·  $50/mo add-on for Guardian
Continuous monitoring of breach communities and criminal marketplaces for your organization's exposed credentials and domains. By the time attackers use stolen credentials, the average dwell time is 146 days. We find it first.
High Value
Ransomware Early Warning
Passive tripwires deployed across your environment. The difference between a contained incident and a $4 million ransom demand is detection at the staging phase. This is that detection.
High Value
Security Awareness Training
Managed employee training with compliance-mapped curriculum. Satisfies ABA 483, HIPAA, WISP, and PIDSA training documentation requirements. Monthly phishing simulation included with Fortress.
97.5%
Less in breach-related loss for MDR users vs endpoint-only
Sophos · 282 organizations analyzed · 2025
60%
Of breaches involve a human element — phishing, social engineering, or insider action
Verizon DBIR · 2025
279
Average days to identify and contain a healthcare breach. Five weeks longer than any other industry.
IBM Cost of a Data Breach · 2025
15-25%
Cyber insurance premium reduction with active MDR
Coalition · Cowbell · Sophos · 2025
Veteran
Owned
Our founder spent years at DHS, CISA, NIH, and Google hunting the same threats that now target law firms, CPA practices, and healthcare organizations. We built Carbynix because those organizations deserve the same level of protection that federal agencies and Fortune 500 companies receive. Most of them are paying far less than the cost of a single breach for a year of MDR. That math should not be this simple. But it is.