← All services MONTHLY

WAF + Vulnerability Retainer

Someone owns your edge and your exposure every month.

Business-hours co-management of your WAF and monthly vulnerability review: tuning, exception decisions, scan review, unlimited retests of previously reported findings, one advisory session and a quarterly plain-language report. Priced per application and per WAF, not per gigabyte. For clients who need 24/7 response, we add a disclosed partner SOC on top.

$1,500 - $3,500 per month

Up to $3,500 depending on scope.

Built for: Any client after a first engagement; MSPs on behalf of their clients

Ask about this service Start with the free snapshot

Prices in CAD before tax. Scope confirmed in writing before any work starts.

What you get

  • Monthly WAF rule review and tuning with decision records
  • monthly vulnerability scan review and prioritization
  • unlimited retests of previously reported findings
  • one advisory session per month
  • quarterly report and roadmap for leadership
  • defined response windows during business hours
  • optional disclosed 24/7 partner priced per user.

Start tiers

TierStarts withinPriceNotes
Core On request List $1,500 per month: one application, one WAF, monthly review and retests.
Plus On request List $2,500 per month: up to three applications, one WAF, monthly review, quarterly roadmap.
Scale On request List $3,500 per month: up to six applications, two WAFs, two advisory sessions, quarterly report to leadership.

When people buy this

After any review or sprint; an insurer asking for continuous management; the question "who is watching this?"

How the agents help

Triage clusters the raw findings, Warden drafts WAF exceptions with expiry and rollback, Scribe drafts the report and attestation from validated evidence. A practitioner validates every finding, approves every change and signs every letter. How the human gates work