Service Packages

Five packages, so you can qualify yourself before you talk to us

Every AST product and service is available individually. They are also bundled into four tiers that build on one another, each including annual service and maintenance covering platform updates, threat intelligence refreshes, and technical support, plus one capability-specific package for organisations whose immediate driver is AI risk and regulatory exposure.

Tier names and inclusions are published here deliberately. Pricing is quoted per engagement, because scope, site count, and regulatory requirements vary too much for a list price to be honest.

At a glance

Package Built for
Core Organisations beginning their preemptive defence journey
Advanced Organisations with complex IT environments needing custom deception
Elite Enterprises requiring maximum coverage and production-embedded traps
Sovereign Government agencies, critical national infrastructure, and high-security environments
AI Risk & Compliance Organisations that must evidence AI Act, GDPR, and NIS2 obligations for their own AI usage

Core

Essential deception and threat intelligence, for organisations beginning their preemptive defence journey.

  • Standard deception mesh — multi-service deception plus pre-built device and interface clone traps
  • CATIS predictive threat intelligence — access to the real-time threat intelligence platform
  • Firewall crowd intelligence feed delivered to your perimeter
  • Annual service and maintenance, platform updates, and technical support

Advanced

Enhanced coverage with custom deception traps, for organisations with complex IT environments.

  • Everything in Core, plus an expanded deception mesh including custom-made service clone traps
  • Dedicated CATIS tenancy with unlimited user accounts and a private intelligence workspace
  • Customer-specific intelligence feeds alongside the crowd feed
  • Private threat intelligence reports — isolated targeted-attack reporting, dark web exposure and data leakage monitoring, attack surface tracking, and global threat trends

Elite

Maximum deception coverage with production-embedded traps, for enterprises requiring the highest level of protection.

  • Everything in Advanced, plus continuous trap mutation, changing the attack surface on a monthly cycle
  • Internal deception mesh deployed inside the production estate
  • Interactive AI threat intelligence — natural-language queries over live threat data, external enrichment, behavioural correlation, and analyst decision support
  • Incident response team service, including crisis management
  • Private intelligence reporting extended with zero-day behavioural signal alerts, employee phishing campaign testing, and penetration testing

Sovereign

Full-spectrum preemptive defence for government agencies, critical national infrastructure, and high-security environments.

  • Everything in Elite, plus a selection of the capabilities below
  • Sovereign on-premises deployment and national data isolation, with strict segregation between telemetry, intelligence processing, and analytical layers
  • National early warning and predictive threat monitoring built on deception telemetry and global intelligence fusion
  • National intelligence fusion across government entities, including coordinated-campaign detection and cross-agency sharing
  • Elastic deception mesh scaling across ministries, critical infrastructure, and national digital services
  • Technology transfer and capability enablement for national CERT teams
  • Firmware-level embedded deception within routers, switches, IoT devices, and communication modules

AI Risk & Compliance

Monitoring and evidence for the organisation’s own AI usage — for teams that have to demonstrate a position under the EU AI Act, GDPR, and NIS2, and for teams that need to know their AI agents are still operating inside the boundaries they were given.

  • All five ASPEN AI monitoring capabilities — prompt and response DLP, transparency and disclosure assurance, prompt injection and jailbreak detection, AI-linked incident detection with NIS2 clock tracking, and agent action auditing
  • AI agent integrity monitoring — retrieval, tool, behavioural and action integrity for your own agents, each evaluated against the boundary the agent was authorised to operate inside. See autonomous AI agent security
  • Onboarding and configuration — gateway integration, policy authoring for your own data classes, and disclosure and marking checks configured against your live properties
  • Evidence reporting — periodic compliance reports drawn from the audit trail, suitable for presenting an Article 50 and Article 4 posture to a regulator or an auditor, and for evidencing the Article 12 record-keeping duty where a system is high-risk
  • Available standalone or as an addition to any tier, for organisations whose immediate driver is AI risk rather than deception coverage
  • Annual service and maintenance, platform updates, and technical support

ASPEN produces the monitoring, logging, and evidence infrastructure that a compliance position depends on. It does not, by itself, make an organisation compliant, and AST is not a law firm — confirm with counsel which obligations apply to your systems and to your role as provider or deployer.

Managed and professional services

Any tier can be extended so that AST operates the capability rather than handing it to your team.

Service What it covers
Managed detection and response AST-operated detection and response built on managed EDR alongside the AST platform
24×7 SOC monitoring Round-the-clock monitoring, triage, and escalation
Virtual CISO Security leadership, strategy, and governance capacity without a full-time hire
Major incident response (MIRT) Retainer-backed response with a two-hour remote activation commitment, or engaged on demand

How engagements are scoped

All packages can be customised, and any AST product can be added to any tier. Sovereign deployments are scoped per engagement to meet the specific regulatory, compliance, and security requirements of government and critical infrastructure organisations.

AST recommends a phased approach for most enterprises: begin with the deception mesh and the CATIS intelligence layer for the fastest time to value and the lowest operational footprint, then expand prevention coverage with NanoFirewall and ShenDNS, then integrate ASPEN as the unified investigation and compliance platform.

Contact us for pricing on any tier, or to discuss a scope that does not fit one of them.