Skip to content

Simple annual pricing

Price deployed coverage.
Not data exhaust.

stickysweet is priced around the security program you deploy—companies, personas, and sensors—not the number of adversary interactions you collect.

Unlimited interaction telemetry No ingest fees

Three tiers

Start focused. Scale the observation network.

Every tier includes the core sensor family, persona correlation, and alerting. The SOC tier adds the analysis and integration layer most operating teams need.

01

Starter

$9,000/ year

$750/mo equivalent

A focused deployment for a security team proving the model.

Company / cluster1
Sensor instances5
Active personas100
SOC users5
Retention90 days
Start with Starter
03

Enterprise

$60,000/ year

$5,000/mo equivalent

Large, multi-business, and distributed deception programs.

Companies / clustersCustom
Sensor instances50+
Active personasUnlimited
SOC usersUnlimited
Retention2+ years
Talk Enterprise
Need more coverage?Add sensor capacity without jumping tiers.

+$500–$750/year per additional sensor instance, depending on deployment requirements.

Included capability

One platform. More depth as you scale.

Scale from focused deployment to multi-business coverage with deeper integrations, tailored identities, controls, and support.

CapabilityStarterSOCEnterprise
Email / SSO / Sales / Voice sensors
Persona correlation
Alerts
Unlimited interaction telemetry
Hunting
Analytics
API / SIEM export
Tailored edge corporate identities
Enterprise SSO / RBAC
SupportStandardPriority + SLA

All plans are annual. Deployment details, support scope, and additional capacity are confirmed in the order form.

Founding beta

Move earlier. Lock in a lower first year.

For a limited group of design partners, founding pricing is locked for 12 months in exchange for direct product feedback and participation in the beta program.

Under founding program terms, participation may also include permission to develop anonymized aggregate threat intelligence from program telemetry.

12-month founding pricing
Starter$5K
SOC$12K
Enterprise$30K
Apply for founding access

FAQ

Built around deployed value.

The customer is buying proprietary threat telemetry generated against their environment—not another meter on top of existing logs.

01What are we actually paying for?

Deployed value: companies or clusters, synthetic personas, sensor capacity, retention, and operating features. stickysweet is intentionally not priced by log volume, event count, or gigabytes ingested.

02Are there ingest fees?

No. Interaction telemetry is unlimited within the deployment. We want teams generating more useful adversary data, not rationing collection because every event has a meter attached to it.

03Why are personas generous?

Personas create coverage. More believable synthetic identities across finance, IT, recruiting, executives, developers, contractors, and other roles create more opportunities to observe adversary behavior. Starter includes 100, SOC includes 500, and Enterprise is unlimited.

04What counts as a sensor instance?

A sensor instance is a deployed collection or exposure point—such as Email, SSO, Sales, or Voice—connected to the stickysweet environment. Additional sensor capacity can be added without immediately forcing a tier upgrade.

05Can we add sensors to a tier?

Yes. Additional sensor capacity is expected to be available at roughly $500–$750 per sensor instance per year, depending on deployment requirements.

06Why is SOC the recommended tier?

SOC is designed to be the obvious operating tier: up to three clusters, 20 sensors, 500 personas, unlimited SOC users, one year of retention, full Hunting and Analytics, plus API and SIEM export for $24,000 per year.

07What is the founding beta program?

Founding customers can access lower 12-month beta pricing in exchange for direct product feedback and, under the applicable program terms, permission to develop anonymized aggregate threat intelligence from resulting telemetry.

The recommended operating tier

$24K/year.
Build your own threat telemetry.

Deploy synthetic identities where attackers operate. See who engages with them, how they move between channels, and what infrastructure they reuse.