Detection, blocking and the way out of a false positive are free. To keep receiving the threat address database and binary updates, and to see the deeper views: US$59 per server per year — subscribe for one if you only have one. No other plans, no hidden fees.
Payments are handled by Paddle (credit card / PayPal, taxes and invoices included) — your card number never touches our systems. When a subscription lapses, Pro features sleep quietly and core protection keeps running (fail-open).
| Feature | Free | Pro |
|---|---|---|
| 15-rule detection + automatic blocking (nftables / ipset / iptables) | ✅ | ✅ |
| Unblocking and the whitelist (the way out of a false positive) | ✅ | ✅ |
| Blocklist, IP management, live dashboard status | ✅ | ✅ |
| Alerts: email, syslog, the console's notification log (daily digest included) | ✅ | ✅ |
| Reading the detection rules (every threshold visible) | ✅ | ✅ |
| Bind to your account + see every one of your hosts in the fleet list | ✅ | ✅ |
| Hosts you can install and join to the Hub | Unlimited | Unlimited |
| Hosts that keep receiving updates | None | = subscriptions held (one per host) |
| Threat address database (the daily signed list of attacking sources) | ❌ | ✅ |
| Binary updates | Manual reinstall | ✅ OTA auto-update |
| Resource alerts (CPU / memory / disk over threshold) | ❌ | ✅ |
| Resource charts (history) | ❌ | ✅ |
| Site analytics | ❌ | ✅ |
| Changing detection thresholds and resetting them (existing ones stay in force) | ❌ | ✅ |
| Scanning historical logs | ❌ | ✅ |
| Extra scan directories (the built-in ones are always scanned) | ❌ | ✅ |
| Data export, notification-log export | ❌ | ✅ |
| Per-host detail, event history, IP lookup and fleet-wide commands on the Hub | ❌ | ✅ |
| Support | Community forum | Priority forum replies |
On a host without a subscription, four things always hold: it still blocks, you can still see what it blocked, you can still get an address back, and you are still told when something happens. Detection and blocking run as usual, the blocklist is readable, unblocking and the whitelist are free forever, and attack notifications still go out. A subscription buys the supply of new data (the threat address database, binary updates) and the deeper views (analytics, history, export, per-host detail on the Hub) — not the protection itself, and not the right to join the Hub. Expiry does not change detection: the thresholds you set stay in force; what changes is whether you can still adjust them.
Whichever host a subscription is assigned to is the one that keeps receiving updates. Binding to your account needs no subscription — a host without one still binds and still shows in the fleet list. Reinstalling the same machine (same fingerprint) never needs another one.
No proration, no part-months — a subscription costs US$59 and runs for a year from the day you buy it. Each keeps its own expiry date: it is not pulled forward to match the others, and buying mid-year does not shorten it. Renewing extends the one you have rather than adding another.
A subscription can be transferred to another machine at any time, as often as you like, and the expiry date does not change. To retire a server: bind the new one, transfer the subscription, then unbind the old one. A host with a live subscription is never unbound, so a subscription can never go missing between the two steps.
No. This is a hard design rule: licensing only gates the supply of new data (the threat address database, OTA) and the deeper views. Detection and blocking never stop over a licensing problem, and the thresholds you set stay in force — expiry does not change detection, only whether you can still adjust it. The way out of a false positive (unblocking, the whitelist) is free forever, and attack notifications still go out. Nor is the host unbound: renew and supply resumes immediately, with nothing to reassign.
Cancel the ones you no longer need; each lapses on its own expiry date and works normally until then, with no refund for the current term. Because every subscription expires on its own date, you can drop some and keep others.
Usually not. Free-tier detection and blocking are complete. The main reason single-server users upgrade is automatic threat address database updates.
Full refund within 14 days of your first purchase; after that you cancel instead and the service runs to its expiry date. See the Refund Policy.