Core
The full watchfloor, self-deployed.
- All six modules, all five agents
- 27 live feeds + your commercial subscriptions
- Self-hosted via Docker Compose, single environment
- TAXII 2.1 server + all notification channels
- Business-hours support
Enterprise
For SOCs that run around the clock.
- Everything in Core
- Deployment assistance (Docker Compose or Helm/Kubernetes)
- Multiple environments — production + staging
- Onboarding: feed tuning, brand corpus, BIN registry setup
- Priority support with contractually agreed response times
- A named engineering contact
Sovereign
For regulated and national environments.
- Everything in Enterprise
- Air-gapped / sovereign-cloud deployment patterns
- Self-hosted LLM bridge setup — zero outbound calls
- Custom crawler-target onboarding
- Compliance documentation support for regional frameworks
- Dedicated engineering support
Compare plans
| Core | Enterprise | Sovereign | |
|---|---|---|---|
| Attack surface management (EASM) | |||
| Brand & domain protection + takedowns | |||
| Dark web monitoring (Tor, I2P, Telegram, Matrix) | |||
| Data leakage & fraud detection | |||
| Email security (DMARC360) | |||
| Threat intelligence — 27 feeds, TAXII 2.1 | |||
| Five autonomous agents | |||
| Self-hosted, your VPC, your Postgres | |||
| Deployment assistance | |||
| Environments | 1 | Multiple | Multiple |
| Onboarding & tuning services | |||
| Support | Business hours | Priority, contracted SLA | Priority, dedicated |
| Air-gapped deployment pattern | |||
| Self-hosted LLM bridge setup | |||
| Compliance documentation support |
Questions, answered straight
Why is there no price on this page?
Because the honest number depends on your environment — how many brands and BIN ranges you're protecting, how many environments you run, and how much deployment and onboarding help you want. A 30-minute call gets you a real quote instead of a misleading anchor.
Where does CTP247 run?
In your infrastructure. The platform ships as a Docker Compose stack (Postgres, Redis, MinIO, worker, API — with the dashboard served alongside by start.sh) that you run in your own VPC or data center. Your data never lives on our servers.
What about LLM costs?
The agents call whichever model you configure — Ollama fully local, Anthropic, or any OpenAI-compatible endpoint. The API bill lands on your account, and you can cap or swap models with an environment variable.
Can we trial it?
Yes — the standard motion is a guided proof of value: we deploy against your real feeds, run a triage on yesterday's entries, and walk one alert end to end. Ask for it on the demo call.
Do commercial feeds cost extra?
Your existing commercial feed subscriptions (paid with your vendors) plug into the same pipeline at no extra platform charge. The 27 bundled feeds are included.
Get a number shaped to your environment.
Thirty minutes, your real feeds, a real quote. No newsletter, no drip campaign.
Book the call