Security isn't a pricing tier
· 2 min read
Every Foundry Cyber tier gets the same security baseline. Bronze is not Silver with the security turned down. What changes between tiers is scope, cadence and proof. Never the strength of the controls.
That sounds obvious. In this industry, it isn’t.
The habit we won’t copy
Read a few security pricing pages and a pattern appears. Single sign-on, on the expensive plan. Audit logs, on the expensive plan. Stronger authentication, enforced policies, faster response: expensive plan. The features that keep customers safe get repackaged as the reason to upgrade.
The message underneath is that safety scales with spend. Attackers disagree. A five-person firm gets phished the same way a five-thousand-person firm does, with the same tricks, on the same day. Nobody price-checks your subscription before they target you.
What actually changes between our tiers
Our three tiers differ in five ways:
- Scope. How much of your estate we assess: one cloud on Bronze, more as you move up.
- Cadence. Monthly assessment on Bronze, weekly on Silver, weekly plus on-demand on Gold.
- Proof. Which standards we render reports against, from our own benchmark on Bronze up to Cyber Essentials, NIST CSF, ISO 27001 and NCSC CAF. The posture is the same; what changes is how many audiences we can prove it to.
- Retention. How long your evidence is kept: 12, 36 or 60 months.
- Attention. Quarterly reviews on Silver, a named engineer and monthly briefings on Gold.
The hardening itself, the checks we run, the way findings are triaged and fixed: identical. The benchmark does not know what you pay.
Why we price it this way
Our costs scale with breadth, frequency and evidence. More clouds means more assessment. Weekly means more checks and more triage. Audit-grade reports against several frameworks take more rendering and more review than one report against our own benchmark. So that is what the price tracks.
What our costs do not scale with is whether your MFA policy is enforced properly. Making the baseline weaker on cheaper tiers wouldn’t save us much, and it would cost you everything on the day it mattered. A sole trader on Bronze needs fewer reports than a regulated firm on Gold. They do not need weaker controls.
Three questions for any vendor, including us
- Which security features sit behind a higher plan?
- Do MFA, SSO or audit logs cost extra?
- What does the cheapest tier not get, and are those things conveniences or controls?
If the honest answer is that safety is the upsell, keep walking. If you want to see where you’d land with us, the tier recommender takes about a minute.