CTIF pricing
Every tier ships the full threat intelligence feed and the full enrichment pipeline. What changes is how many requests you may make each day, and whether you get the REST API, STIX 2.1 export and priority support. Subscriptions are paid in USDT (TRC20).
Priced by how much you query.
Plans scale with how many requests your team makes each day. Every tier ships the full feed and enrichment; higher tiers add API access and deeper support.
Base
For focused teams adding global context through the dashboard.
- Global sensor feed
- Full IP enrichment
- MITRE ATT&CK mapping
- Hostility scoring
- Dashboard access
- Email support
Paid in USDT on TRON (TRC20)
SMB
For growing security teams running active detection.
- Everything in Base
- REST API + STIX 2.1
- Extended sighting history
- Priority support
Paid in USDT on TRON (TRC20)
SOC
For MSSPs and 24/7 SOCs operating at scale.
- Everything in SMB
- Highest request volume
- Dedicated support channel
- Onboarding assistance
Paid in USDT on TRON (TRC20)
Start on any plan and upgrade whenever your team needs more. No need to commit to a higher tier up front. Billed monthly or annually (two months free on annual) and exclude VAT. Need a blocklist for your edge devices or a private instance? See more ways to deploy.
Service guarantee: if the API is unavailable for more than 24 consecutive hours we extend your subscription by the affected days, or refund the unused balance if you would rather leave. The response targets and availability commitments per plan are written out on the support page.
Free plan
Every account starts on Free, and it never expires. It is enough to evaluate the data before committing to a paid tier.
- 25 lookups per day
- One sensor source
- Dashboard access
- No API key, no STIX export
Try the full product for 7 days
Free is dashboard-only, which is no way to judge an API. Any free account can activate a one-off 7-day trial from the dashboard: every sensor, the REST API, STIX 2.1 and the firewall blocklist, up to 1,000 requests a day. No payment, no card, and it reverts to Free on its own when the 7 days are up. That is enough to run the feed against a real alert queue for a working week before deciding.
What a request means
A request is any call that returns feed data: an IP lookup, a domain lookup, a STIX export or one blocklist pull. It counts whether it came from your dashboard or from the API. Account, billing and support pages return no feed data and are never metered. The cap resets at 00:00 UTC. Base allows 800 per day, SMB 2,000 and SOC 10,000. Programmatic access starts at SMB: Free and Base are dashboard-only.
More of this sort of question is answered on the FAQ. The API and blocklist pages spell out what each one actually returns.