Pay-as-you-go

Updated at:

Security Center pay-as-you-go (postpaid) billing charges you based on actual daily usage, and generates a bill on the next day (T+1). Pay-as-you-go services include two types: unified sales features and standalone sales features.

Billing overview

Security Center features are available through two sales models: unified sales and standalone sales. You can choose based on your business needs.

  • Unified sales: Purchase on the Security Center buy page in one stop, all features share the same pay-as-you-go instance ID. Charges include a base service fee and feature usage fees.

  • Standalone sales: Certain features are available only as standalone purchases, with dedicated buy pages , independent billing rules and dedicated resource instance ID. After activation, these features are still managed from the Security Center console.

Unified sales

Unified sales features are pay-as-you-go services purchased on the Security Center buy page. Charges include a base service fee and feature usage fees.

Billing formula

Sum of usage fees for all enabled paid features + base service fee.

Note

The system generates a bill on the next day (T+1) based on actual daily usage. For details on how to view your bill, see View bills.

Base service fee

When you enable any pay-as-you-go feature on the Security Center unified sales page, the system charges an additional base service fee. The billing rules are as follows:

Note

After activation, DingTalk chatbot, security reports, and task center (requires Vulnerability Fixing to be enabled or purchased first) are available by default.

  • Billing method: Metered by the duration that pay-as-you-go service is enabled.

    Important

    The minimum billing unit is one hour. Enabled duration shorter than one hour is billed as one hour.

  • Billing cycle: Settled daily.

  • Price: CNY 0.05/hour.

Feature usage fees

The following describes the pay-as-you-go features supported by Security Center and their billing rules:

Host and Container Security

  • Billing method: Metered by protection level, number of bound servers, and actual protection duration (in seconds). Actual protection duration is measured from client online time.

  • Billing cycle: Settled daily.

  • Price: Varies by protection level. See the following table.

    Protection level

    Price

    Monthly cost (30-day reference)

    Antivirus

    CNY 0.00000289/core/second

    CNY 7.5/core/month

    Advanced

    CNY 0.000034722/server/second

    CNY 90/server/month

    Comprehensive Host Protection

    CNY 0.000086806/server/second

    CNY 225/server/month

    Hosts and Container Protection

    CNY 0.000086806/server/second+CNY 0.00000289/core/second

    CNY 225/server/month+CNY 7.5/core/month

Vulnerability Fixing

  • Billing method: Metered by the number of vulnerability fixes. Fixing one vulnerability announcement on a single server counts as one fix. Failed fixes do not consume quota. For more information, see Overview.

  • Billing cycle: Settled daily.

  • Price: CNY 2/fix.

Container Image Scan

  • Billing method: Metered by the number of scanned images.

  • Billing cycle: Settled daily.

  • Price: CNY 0.75/scan.

Agentic SOC

Billing method

Agentic SOC is billed separately based on three items: Intelligent Operations, Managed Instances, and Log Ingestion.

  • Intelligent Operations: Metered in near real-time by actual Credits consumed.

  • Managed Instances: Metered by the number of target instances that receive response and remediation actions during security operations, calculated per calendar month.

  • Log Ingestion: Metered by actual daily log ingestion volume. For the entitlement conversion and tiered billing logic, see the "Price" subsection below.

    Billing cycle: Settled daily.

Price
  • Intelligent Operations: CNY 0.015/Credit.

  • Managed Instances: CNY 15/seat/month.

  • Log Ingestion Traffic: The entitlement converted from Credits is deducted first. Ingestion exceeding the entitlement is billed at tiered prices based on daily excess volume. Settlement rules are as follows:

    1. Entitlement conversion: Credits accumulate per calendar day. Every 24,000 Credits consumed converts to 1 GB/day of log ingestion entitlement.

    2. Deduction order: When generating the daily log ingestion bill, the day's converted entitlement is deducted first.

    3. Tiered billing for excess: Ingestion exceeding the entitlement is billed at tiered prices per the table below, with each tier cumulated separately.

Daily log ingestion exceeding entitlement

Tiered price

Fee formula (Y = daily log ingestion exceeding entitlement, unit: GB)

1-10 GB/day

CNY 15/GB

15×Y (CNY)

11-50 GB/day

CNY 10/GB

15×10+10×(Y-10) (CNY)

51-100 GB/day

CNY 9/GB

15×10+10×40+9×(Y-50) (CNY)

>100 GB/day

CNY 8/GB

15×10+10×40+9×50+8×(Y-100) (CNY)

For example, if the daily excess after entitlement deduction is 60 GB, the fee is 10 GB × CNY 15/GB + 40 GB × CNY 10/GB + 10 GB × CNY 9/GB.

Important

Actual fees are subject to the buy page, metering results, and Billing Center bills.

Agentic SOC (Log Storage Capacity)

  • Billing method: Metered by daily cumulative log storage volume (GB). The minimum billing unit is 1,000 GB. Fractions of 1,000 GB are billed as 1,000 GB. For example, 1,900 GB of daily usage is billed as 2,000 GB.

  • Billing cycle: Settled daily.

  • Price: CNY 50/1,000 GB.

Note

The log storage capacity purchased on the buy page and the capacity displayed and used in the log module are the same single entitlement, not two separate capacities.

Agentic Cloud Platform Configuration Check

  • Billing method: Metered by the number of billable cloud service instances scanned, verified, and remediated. For authorization consumption rules, see Authorization (postpaid) consumption description.

  • Billing cycle: Settled daily.

  • Price: CNY 0.5/instance/day. Multiple scans, verifications, and remediations within one billing cycle do not incur additional charges.

Agentless Detection

  • Billing method: Metered by scanned data volume (GB).

  • Billing cycle: Settled daily.

  • Price: CNY 0.2/GB.

Serverless Assets

  • Billing method: Metered by number of authorized server cores × actual protection duration (seconds). Actual protection duration is measured from client online time.

  • Billing cycle: Settled daily.

  • Price: Tiered pricing based on monthly cumulative usage.

  • Monthly cumulative usage description:

    • Daily monthly cumulative usage = monthly cumulative usage up to the previous day (0 on the first day) + current day's daily usage.

      Note

      In the first month of activation, the statistics period runs from the activation date to the end of that month. Starting from the second month, the statistics period is a calendar month (from the 1st to the end of the month).

    • Example: Day 1 monthly cumulative usage = Day 1 usage. Day 2 monthly cumulative usage = Day 1 usage + Day 2 usage. Day 3 monthly cumulative usage = Day 1 usage + Day 2 usage + Day 3 usage, and so on.

  • Tier pricing:

    Monthly cumulative usage

    Price

    Fee formula (U = daily usage, unit: core/second)

    Tier 1: 0-200,000,000 core/second

    CNY 0.00002/core/second

    0.00002×U (CNY)

    Tier 2: 200,000,001-1,000,000,000 core/second

    CNY 0.000015/core/second

    • First day entering this tier:

      0.00002×200,000,000+0.000015×(U-200,000,000) (CNY)

    • Subsequent days: 0.000015×U (CNY)

    Tier 3: 1,000,000,001-9,999,999,999,999 core/second

    CNY 0.00001/core/second

    • First day entering this tier:

      0.00002×200,000,000+0.000015×800,000,000

      +0.00001×(U-1,000,000,000) (CNY)

    • Subsequent days: 0.00001×U (CNY).

  • Billing example:

    • Scenario: Serverless assets have 20,000 cores running 24 hours (86,400 seconds) per day. Daily usage (U) = 20,000 cores × 86,400 seconds/day = 1,728,000,000 core/second.

    • Day 1 fee:

      • Usage description: Day 1 monthly cumulative usage = Day 1 usage = 1,728,000,000 core/second. The monthly cumulative usage has reached Tier 3, so it is billed using the cross-tier "first day entering Tier 3" formula.

      • Fee calculation: Day 1 fee = 0.00002 (Tier 1 unit price)×200,000,000+0.000015 (Tier 2 unit price)×800,000,000+0.00001 (Tier 3 unit price)×(1,728,000,000-1,000,000,000)=23,280 (CNY).

    • Day 2 and subsequent fees:

      • Usage description: Since the Day 1 monthly cumulative usage has already reached Tier 3, from Day 2 to the end of the month, the monthly cumulative usage remains in Tier 3 and daily fees are billed at the Tier 3 unit price.

      • Fee calculation: Daily fee = 0.00001 (Tier 3 unit price)×(20,000×86,400)=17,280 (CNY).

Agentic Malicious File Detection

  • Billing method: Metered by the number of files detected.

  • Billing cycle: Settled daily.

  • Price: CNY 0.009 per file.

RASP

  • Billing method: Metered by the number of online instances per minute (0-60 seconds).

  • Billing cycle: Settled daily.

  • Price: CNY 0.0014/instance/minute.

Anti-ransomware

  • Billing method: Metered by backup file size (GB) and storage duration (hours).

  • Billing cycle: Metered hourly and settled daily.

  • Price: CNY 0.0009/GB/hour.

File Tamper-Proofing

  • Billing method:

    • Billing formula: Actual protection duration (seconds) × number of protected servers.

    • Protected server count rules: A server is counted as a protected server if it meets any of the following conditions:

      • The server is bound to interception protection rules.

      • The server is bound to alert protection rules, and the host protection edition is below Enterprise Edition, or the protection level is below Comprehensive Host Protection.

  • Billing cycle: Settled daily.

  • Price: CNY 2/server/hour.

Standalone sales

Important

Standalone pay-as-you-go services do not charge a base service fee.

Agentic EDR

  • Billing method: Metered by number of seats × usage duration. Binding one server consumes one seat license. Servers without policy configuration are automatically excluded from billing.

  • Billing cycle: Billed hourly and settled daily.

  • Price: CNY 0.104167/seat/hour.

Attack Management

  • Billing method: Metered by number of protected assets and the Credits consumed by scanning.

    Note

    Credits are the scanning quota unit for attack surface management. Each scan consumes a certain number of Credits, which are used for attack path mapping of exposed assets, intelligent risk details, and generation of intelligent risk remediation suggestions. Actual Credits consumed are subject to the system's actual usage.

  • Billing cycle: Settled daily.

  • Price:

    • Assets: CNY 3/day/asset. Each asset includes 200 Credits by default.

    • Excess Credits: CNY 1/100 Credits.

Overdue payments and service deactivation

  • Scenario description:

    • Overdue payment: Pay-as-you-go bills are generated on T+1. If the account balance is insufficient at the time of settlement, the account enters an overdue state. To avoid service disruption, top up the account promptly. For the specific steps, see Online top-up.

    • Service deactivation: The account owner manually deactivates the pay-as-you-go service. After deactivation, no new fees are generated.

      Note

      In the Overview page of the Security Center console, turn off the relevant service switches in the Enable Pay-as-You-Go Service area. Or click the Deactivate button above the area to deactivate all pay-as-you-go services at once.

  • Impact: The corresponding pay-as-you-go features become unavailable, and their detection and protection capabilities are lost.

  • Data retention:

    Unified sales features

    • Overdue payment: After an overdue payment, a 15-day data retention period is provided.

      Important

      Alibaba Cloud offers a service suspension extension that can extend the data retention period for cloud products. For more information, see Service suspension protection for overdue payments. For example, if you are granted a 10-day service suspension extension, the data retention period for Security Center is extended to 25 days (10 + 15).

    • Manual service shutdown/Forced service shutdown: No data retention period. Data is immediately purged according to the rules.

    Scenario

    Data purge description

    Overdue payment - Within the data retention period

    During the retention period, all service authorization information, configuration policies, and pay-as-you-go service data are retained.

    Overdue payment - After the data retention period

    • The following authorization information is immediately purged:

      • Container Protection - Image security scan.

      • Container Protection - CI/CD integration settings.

    • The following Agentic SOC data is immediately purged:

      Important

      If the data retention period for an overdue payment is longer than 15 days, Agentic SOC does not wait for the retention period to end. Instead, it starts the data purge immediately after the 15th day of the overdue payment.

      • Security alerts: All alert information except for alerts under CWPP.

      • Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).

        Note

        Security events generated from alerts under CWPP (CWPP security events) are retained.

      • Response orchestration: Custom playbooks and custom response rules.

      • Log Management: Standardized integration logs and Security Center logs.

      • Rule management: Custom rules.

      • Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.

    • Agentic SOC - Response Center: Response policy and response task data is automatically purged by the system 90 days after it expires. This is not affected by overdue payments or service shutdowns.

    • Cloud Security Posture Management:

      • Cloud product configuration check:

        • After the cloud product configuration check is disabled, the check result data is not deleted.

        • Periodic scan policies, allowlist policies, and custom check items are not deleted.

      • System baseline:

        • Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.

          Note

          If your subscription service (Advanced, Enterprise, or Ultimate) has not expired and has not been unsubscribed, the check results for the corresponding edition are continuously retained. After the service expires or you unsubscribe, the data is retained in the backend for 30 days and then automatically deleted.

        • Scan policies are immediately deleted. Allowlist policies are not deleted.

    • Anti-ransomware: 1 day after the instance is released, the protection capabilities and generated backup data of this service are removed.

    Manual service shutdown

    Forced service shutdown

    Independent sales features

    Agentic EDR

    • Elastic protection: Elastic protection immediately becomes invalid and billing stops. The elastic authorizations and credits consumed on the current day are billed the next day.

    • Data retention:

      • Policy and baseline retention: Existing policies and host baselines are retained but no longer updated.

      • Historical alert retention: Existing host anomaly alerts are retained, but no new alerts are generated.

    Attack Management

    • Feature policy configuration data is retained permanently.

    • Asset and attack path scanning task data is retained for only 7 days and then permanently released.