Service Packages
Five packages, so you can qualify yourself before you talk to us
Every AST product and service is available individually. They are also bundled into four tiers that build on one another, each including annual service and maintenance covering platform updates, threat intelligence refreshes, and technical support, plus one capability-specific package for organisations whose immediate driver is AI risk and regulatory exposure.
Tier names and inclusions are published here deliberately. Pricing is quoted per engagement, because scope, site count, and regulatory requirements vary too much for a list price to be honest.
At a glance
| Package | Built for |
|---|---|
| Core | Organisations beginning their preemptive defence journey |
| Advanced | Organisations with complex IT environments needing custom deception |
| Elite | Enterprises requiring maximum coverage and production-embedded traps |
| Sovereign | Government agencies, critical national infrastructure, and high-security environments |
| AI Risk & Compliance | Organisations that must evidence AI Act, GDPR, and NIS2 obligations for their own AI usage |
Core
Essential deception and threat intelligence, for organisations beginning their preemptive defence journey.
- Standard deception mesh — multi-service deception plus pre-built device and interface clone traps
- CATIS predictive threat intelligence — access to the real-time threat intelligence platform
- Firewall crowd intelligence feed delivered to your perimeter
- Annual service and maintenance, platform updates, and technical support
Advanced
Enhanced coverage with custom deception traps, for organisations with complex IT environments.
- Everything in Core, plus an expanded deception mesh including custom-made service clone traps
- Dedicated CATIS tenancy with unlimited user accounts and a private intelligence workspace
- Customer-specific intelligence feeds alongside the crowd feed
- Private threat intelligence reports — isolated targeted-attack reporting, dark web exposure and data leakage monitoring, attack surface tracking, and global threat trends
Elite
Maximum deception coverage with production-embedded traps, for enterprises requiring the highest level of protection.
- Everything in Advanced, plus continuous trap mutation, changing the attack surface on a monthly cycle
- Internal deception mesh deployed inside the production estate
- Interactive AI threat intelligence — natural-language queries over live threat data, external enrichment, behavioural correlation, and analyst decision support
- Incident response team service, including crisis management
- Private intelligence reporting extended with zero-day behavioural signal alerts, employee phishing campaign testing, and penetration testing
Sovereign
Full-spectrum preemptive defence for government agencies, critical national infrastructure, and high-security environments.
- Everything in Elite, plus a selection of the capabilities below
- Sovereign on-premises deployment and national data isolation, with strict segregation between telemetry, intelligence processing, and analytical layers
- National early warning and predictive threat monitoring built on deception telemetry and global intelligence fusion
- National intelligence fusion across government entities, including coordinated-campaign detection and cross-agency sharing
- Elastic deception mesh scaling across ministries, critical infrastructure, and national digital services
- Technology transfer and capability enablement for national CERT teams
- Firmware-level embedded deception within routers, switches, IoT devices, and communication modules
AI Risk & Compliance
Monitoring and evidence for the organisation’s own AI usage — for teams that have to demonstrate a position under the EU AI Act, GDPR, and NIS2, and for teams that need to know their AI agents are still operating inside the boundaries they were given.
- All five ASPEN AI monitoring capabilities — prompt and response DLP, transparency and disclosure assurance, prompt injection and jailbreak detection, AI-linked incident detection with NIS2 clock tracking, and agent action auditing
- AI agent integrity monitoring — retrieval, tool, behavioural and action integrity for your own agents, each evaluated against the boundary the agent was authorised to operate inside. See autonomous AI agent security
- Onboarding and configuration — gateway integration, policy authoring for your own data classes, and disclosure and marking checks configured against your live properties
- Evidence reporting — periodic compliance reports drawn from the audit trail, suitable for presenting an Article 50 and Article 4 posture to a regulator or an auditor, and for evidencing the Article 12 record-keeping duty where a system is high-risk
- Available standalone or as an addition to any tier, for organisations whose immediate driver is AI risk rather than deception coverage
- Annual service and maintenance, platform updates, and technical support
ASPEN produces the monitoring, logging, and evidence infrastructure that a compliance position depends on. It does not, by itself, make an organisation compliant, and AST is not a law firm — confirm with counsel which obligations apply to your systems and to your role as provider or deployer.
Managed and professional services
Any tier can be extended so that AST operates the capability rather than handing it to your team.
| Service | What it covers |
|---|---|
| Managed detection and response | AST-operated detection and response built on managed EDR alongside the AST platform |
| 24×7 SOC monitoring | Round-the-clock monitoring, triage, and escalation |
| Virtual CISO | Security leadership, strategy, and governance capacity without a full-time hire |
| Major incident response (MIRT) | Retainer-backed response with a two-hour remote activation commitment, or engaged on demand |
How engagements are scoped
All packages can be customised, and any AST product can be added to any tier. Sovereign deployments are scoped per engagement to meet the specific regulatory, compliance, and security requirements of government and critical infrastructure organisations.
AST recommends a phased approach for most enterprises: begin with the deception mesh and the CATIS intelligence layer for the fastest time to value and the lowest operational footprint, then expand prevention coverage with NanoFirewall and ShenDNS, then integrate ASPEN as the unified investigation and compliance platform.
Contact us for pricing on any tier, or to discuss a scope that does not fit one of them.