Threat memory priced to stay defensible.

Self-serve for individual analysts, annual contracts for SOC teams, and scoped capacity for MSSPs.

→ Try the recall surface first — no signup

Researcher and Pro are self-serve — checkout is live. Team and Enterprise are annual contracts.

Individual Researcher

$49

/ month · billed monthly

Solo researchers and independent analysts. One seat, fast recall, no overhead. Hard cap: writing stops when you hit 2,000 records.

Start free trial
Most popular

Pro

$499

/ month · annual option $4,800/yr

Independent teams that need the full retrieval stack, knowledge graph, MCP server, and LangChain adapter with bounded usage.

Start Pro
Sales-assisted

Team

$30K

/ year · sales-assisted

SOC and CTI teams that need SSO planning, audit exports, onboarding, and a capacity schedule instead of surprise overage.

Scope Team →

Enterprise

$90K+

/ year · dedicated from $120K/yr

MSSPs, regulated teams, and dedicated deployments. Scope seats, client workspaces, data boundary, support, and evidence needs before contract.

See pricing dimensions →
Value calculator

How much analyst time are you leaving on the table?

Adjust the inputs below to see your team's recoverable capacity — instantly, no form, no sales call required.

1200
150
0.25h8h
$40$300
Hours recovered / year
analyst-hours
Recovered capacity
FTE-equivalents
Dollar value recovered
per year
Net first-year value
recovered − pilot cost

Estimates only. Real value depends on your investigation mix and integration depth. Pilot teams measure their own baseline in week 1. Assumes ThreatRecall eliminates ~70% of context-rebuild time (re-reading old tickets, re-querying SIEM, asking teammates "did we see this IOC before?"). Pilot cost used for net value: Pro annual baseline = $4,800/yr.

See it on your data → Apply for the pilot

Pricing FAQ

How much does ThreatRecall cost?

ThreatRecall has four pricing tiers: Individual Researcher at $49/month (self-serve), Pro at $499/month or $4,800/year, Team at approximately $30,000/year (sales-assisted), and Enterprise starting at $90,000/year with dedicated deployments from $120,000/year.

Does ThreatRecall have a self-serve plan, or do I need to talk to sales?

The Individual Researcher plan at $49/month is fully self-serve with checkout through Stripe. Pro is $499/month or $4,800/year. Team and Enterprise are sales-assisted annual contracts scoped with the team.

What's included in the Pro plan?

The Pro plan ($499/month or $4,800/year) includes 5 seats, a 50,000-record cap, the full MCP server for Claude Code and LangChain, a LangChain adapter, and the knowledge graph UI. It is ThreatRecall’s most popular plan.

What does the ThreatRecall ROI calculator estimate?

The pricing page includes an ROI calculator. You enter analyst headcount, investigations per week, hours lost per investigation to context-rebuilding, and hourly rate. For an example team of 8 analysts running 5 investigations per week at 1.5 hours lost each and a $95/hour rate, it estimates about 2,200 recovered analyst-hours per year, roughly $207,000 in recovered value, and about $203,000 net after the Pro plan’s $4,800 annual cost.

Security & compliance FAQ
What's included in the FedRAMP control reporting?
Full NIST 800-53 Rev 5 Moderate baseline coverage — 20 control families, 36+ findings tracked and remediated. Pre-answered CAIQ-Lite v4 and SIG-Lite questionnaire available at /security/questionnaire.
Is the security questionnaire downloadable as PDF?
Yes — Download the full CAIQ-Lite v4 + SIG-Lite PDF (v1.0, 2026-05-29, EIN: 42-2096618). Pre-answered for SOC/MSSP procurement — no login required.
Can I self-host ThreatRecall inside my FedRAMP-authorized environment?
Yes — self-hosted deployment is available for Enterprise. Deploy on your own FedRAMP-authorized CSP (AWS GovCloud, Azure Government). Air-gapped mode available (LLAMA_BASE_URL). Contact security@threatrecall.ai.
When will FedRAMP authorization be complete?
Phase 4 (Authorization to Operate) is in progress. Target: post-Seed funding. We are not authorized today — do not represent us that way to your CISO. See the full posture statement at /security.