TFTHREATFADE
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
GitHub
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
HomeCommercial paths

Open at the detection core. Premium where operational value begins.

ThreatFade is not packaged as generic SaaS. The commercial ladder follows the buyer's progression from technical adoption to evidence, pilot, enterprise operation and managed expertise.

Community
$0
forever

Researchers, developers and security practitioners

The open-core detection engine and reproducible technical evaluation surface.

  • Core detection engine
  • Offline / local analysis
  • PCAP analysis
  • Core detection packs
  • Evidence and ATT&CK context
  • CLI / API and documentation
Run the source
Pro
$49
/month · $490/year

Individual practitioners

A low-friction commercial step for people who need a private, repeatable ThreatFade workflow.

  • Private workspace
  • Saved investigations
  • Evidence export
  • Commercial usage allowance
  • Priority product guidance
Ask about Pro
TeamCore commercial tier
$299
/month · $2,990/year

Small security teams

Shared investigation and governance foundations for teams operationalizing behavioral-fade detection.

  • Shared organization workspace
  • RBAC and tenant boundary
  • Investigation workflow
  • Audit history
  • Evidence and disposition workflow
  • Documented integration paths
Discuss Team
Enterprise
$25k+
/year · scoped

Mid-market and enterprise security programs

Annual platform commitment for deployment, governance, integrations and operational requirements.

  • Enterprise identity / SSO
  • Advanced RBAC and tenancy
  • Audit and governance
  • Deployment architecture
  • Enterprise integration scope
  • Contracted support / SLA options
Start evaluation
Value ladder
01

Community

$0

Adopt and challenge the engine.

02

Pro

$49/mo

Turn repeat usage into a private workflow.

03

Team

$299/mo

Operationalize shared investigations.

04

Assessment

$5k+

Find evidence-backed detection gaps.

05

Paid Pilot

$7.5k–$15k

Validate value in a defined environment.

06

Enterprise

$25k+/yr

Operationalize at organizational scale.

07

Managed

$3.5k–$15k+/mo

Buy ongoing detection expertise.

High-intent path

Assessment → Pilot → Enterprise

For organizations that need evidence before committing to a platform, the commercial wedge is a scoped Detection Gap Assessment. A successful assessment produces the acceptance criteria for a paid pilot; the pilot ends with a measured enterprise decision.

Detection Gap AssessmentPaid pilot
Trust boundary

Evidence, not invented proof.

  • Open-source capability — inspectable in the repositories.
  • Validated capability — backed by repository tests and documented validation scope.
  • Experimental capability — clearly labelled research or optional layers.
  • Professional services — assessment, pilot, managed operations and custom engineering are scoped separately.

Frequently asked

Is ThreatFade open source?

Yes. The open-core detection engine remains the technical trust and distribution layer. Commercial packaging adds operationalization, governance, deployment and expertise rather than crippling the core detection thesis.

Is Enterprise pricing per seat?

No. The intended model is an annual platform commitment shaped by deployment scope, analysis requirements, integrations, support and security requirements rather than arbitrary seat counts.

What does the $5,000+ assessment buy?

A scoped Detection Gap Assessment covering the agreed telemetry and architecture, ThreatFade analysis, evidence examples, coverage gaps, prioritized recommendations and a pilot design. Larger environments are quoted above the starting price.

Are the prices contractual?

No. Public prices are starting standards for planning. Final quotes reflect scope, deployment, usage, support and integration complexity.

Does ThreatFade replace a SIEM or SOAR?

No. ThreatFade is positioned as a specialized detection and investigation layer that can hand structured results to existing security operations systems.

Need a technical evaluation?

Start with the question, not a generic demo.

Bring a detection scenario, evidence question or deployment constraint. We can scope the appropriate commercial path without representing unvalidated capabilities as production guarantees.

Request evaluationEnterprise architecture
THREATFADE / TINLANCE LIMITEDSource on GitHub