Pricing
Choose a plan that matches your mission
Cyber Defence combines threat intelligence search, dark web and credential-leak visibility, and external attack surface monitoring in one place. It blends Hedgehog Security’s SOC intelligence with curated phishing feeds, deception infrastructure, and adversary tracking to surface meaningful signals. Everything is exposed through a powerful API so you can plug data straight into SIEM, SOAR, and your wider security tooling.
Free public indicator lookup and a sandbox API key (one lookup every 10 seconds) are available for experimentation. The paid plans below remove those limits and add continuous monitoring.
Detect
£149 / month ex VAT
For smaller security teams, consultants, and early adopters who need a bridge between free lookups and a serious subscription.
- Full access to the threat intelligence dataset (IPs, domains, hashes, email addresses).
- Dark web and credential-leak searching for a small number of monitored domains.
- Basic attack surface monitoring for a modest estate (for example, a limited number of domains and IP ranges).
- Unthrottled API access on a fair-use basis.
- Suitable for solo analysts, boutique consultancies, and very small firms.
Defend
£399 / month ex VAT
For SMEs and mid-sized organisations in legal, financial services, banking, logistics, and research — the main plan most customers should choose.
- Everything in Detect.
- Larger allowance of monitored domains and IP ranges for attack surface monitoring.
- Dark web and credential monitoring across all monitored domains.
- Multiple named users (for example, a small security or IT team) plus API/service accounts.
- Designed to integrate with SIEM/SOAR, ticketing systems, and SOC workflows.
- Priority support compared with Detect.
Disrupt
From £1,250 / month ex VAT
For larger, multi-site or highly regulated organisations and partners where pricing scales with asset count, business units, or multi-tenant needs.
- Everything in Defend.
- Significantly higher limits on monitored domains, IP ranges, and brands.
- Support for complex estates or partner use (for example MSSPs or group structures).
- Bespoke onboarding, tuning, and integration assistance.
- Strongest SLAs and access to expert analysts for threat-led use-cases.
What’s included
Operational intelligence without extra tooling
Realtime coverage
Malware telemetry, dark web leaks, and phishing domains refreshed continuously to keep detections current.
Analyst expertise
Human-led curation on critical threats, plus escalation paths for Pro customers.
Simple integration
Bootstrap-styled portal, documented API, and CSV exports for quick SOC workflows.
Need enterprise or MSP terms?
Talk with our team about private ingestion pipelines, dedicated analyst hours, and bespoke exports.