Pay-as-you-go

Updated at:

The pay-as-you-go (postpaid) mode of Security Center bills based on actual daily usage, and generates a bill on the next day (T+1). Pay-as-you-go services include unified sales features and standalone sales features.

Overview

Security Center features are available through unified sales and standalone sales. You can choose flexibly based on your business needs.

  • Unified sales: Purchase all-in-one on the Security Center buy page. The fees include base service fees and feature usage fees.

  • Standalone sales: Certain features can only be purchased separately, with dedicated buy pages and independent billing rules. However, once enabled, these features are still integrated into the Security Center console for unified management.

Unified sales features

Unified sales features are pay-as-you-go services purchased on the Security Center buy page, including base service fees and feature usage fees.

Billing formula

Total usage fees of enabled paid features + base service fee.

Note

The system generates a bill on the next day (T+1) based on actual daily usage. For more information about how to view bills, see View bills.

Base service fee

When you enable any pay-as-you-go feature on the Security Center unified sales page, the system charges an additional base service fee. The billing rules are as follows:

Note

After activation, DingTalk chatbot, security reports, and task center (requires vulnerability fix to be enabled or purchased first) are supported by default.

  • Billing method: Billing is based on the duration that the pay-as-you-go service is enabled.

    Important

    The minimum billing unit is one hour. If the enabled duration is less than 1 hour, it is billed as 1 hour.

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.0072/hour.

Feature usage fees

The following table lists the features that can be enabled in pay-as-you-go mode and their billing details:

Host and Container Security

  • Billing method: Billing is based on the protection level, the number of bound servers, and the actual protection duration (seconds). The actual protection duration is calculated based on the client online duration.

  • Billing cycle: Settled on a daily basis.

  • Price: The prices for different protection levels are shown in the following table.

    Protection level

    Price

    Monthly cost (30-day reference)

    Antivirus

    USD 0.00000289/core/second

    USD 1.5/core/month

    Advanced

    USD 0.000034722/server/second

    USD 14.25/server/month

    Comprehensive Host Protection

    USD 0.000086806/server/second

    USD 35.25/server/month

    Hosts and Container Protection

    USD 0.000086806/server/second+USD 0.00000289/core/second

    USD 35.25/server/month+USD 1.5/core/month

Vulnerability Fixing

  • Billing method: Billing is based on the number of vulnerability fixes. Fixing one vulnerability announcement on a single server counts as 1 time. Failed fixes do not consume quota. For more information, see Overview.

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.3/time.

Container Image Scan

  • Billing method: Billing is based on the number of scanned images.

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.15/time.

Agentic SOC (Legacy)

  • Billing method:

    • Agentic SOC (Legacy): Billing is based on the daily ingested log traffic (GB) using tiered pricing. The daily fee is the sum of fees across all tiers. The minimum billing unit is GB. Fractions less than 1 GB are billed as 1 GB.

    • Security Operations Agent: In addition to tiered pricing based on daily ingested log traffic (GB), the following billing items are also included:

      • Intelligent Usage Analysis: Billing is based on the analysis volume (GB) consumed by AI security digital analysts for alert investigation, incident investigation, tracing, attribution, and security report generation.

      • Number of Managed Instances: Billing is based on the number of agent instances invoked. ECS, WAF, ALB, cross-cloud products, and on-premises security vendor products are all counted as instances. The same instance is counted only once with automatic deduplication.

  • Billing cycle: Settled on a daily basis.

  • Price:

    • Log Ingestion Traffic: Tiered pricing based on daily ingested log traffic (GB).

      Log ingestion traffic tier

      Price

      Fee calculation formula (Y = daily ingested traffic in GB)

      1~10 (GB/day)

      USD 2.2/GB

      2.2×Y (USD)

      11~50 (GB/day)

      USD 1.6/GB

      2.2×10+1.6×(Y-10) (USD)

      51~100 (GB/day)

      USD 1.4/GB

      2.2×10+1.6×40+1.4×(Y-50) (USD)

      >100 (GB/day)

      USD 1.2/GB

      2.2×10+1.6×40+1.4×50+1.2×(Y-100) (USD)

    • Intelligent Usage Analysis: USD 0.144/GB/day.

    • Number of Managed Instances: USD 2.15/instance/month.

Log Storage Capacity

  • Billing method: Billing is based on the daily cumulative log storage volume (GB). The minimum billing unit is 1,000 GB. Fractions less than 1,000 GB are billed as 1,000 GB. For example, if the daily usage is 1,900 GB, it is billed as 2,000 GB.

  • Billing cycle: Settled on a daily basis.

  • Price: USD 7.2/1,000 GB.

Agentic Cloud Platform Configuration Check

  • Billing method: Billing is based on the number of billable cloud service instances scanned, verified, and remediated. For more information about authorization consumption rules, see Authorization (postpaid) consumption description.

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.0732/instance/day. Multiple scans, verifications, and remediations within a single billing cycle do not incur additional charges.

Agentless Detection

  • Billing method: Billing is based on the volume of data scanned (GB).

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.03/GB.

Serverless Assets

  • Billing method: Billing is based on the number of authorized server cores × actual protection duration (seconds). The actual protection duration is calculated based on the client online duration.

  • Billing cycle: Settled on a daily basis.

  • Price: Tiered pricing based on monthly cumulative usage.

  • Monthly cumulative usage description:

    • Daily cumulative usage for the current month = Monthly cumulative usage up to the previous day (0 on the first day) + Daily usage for the current day.

      Note

      In the first month of activation, the statistics period is from the activation date to the end of the current month. Starting from the second month, the statistics period is a calendar month (from the 1st to the end of each month).

    • Example: Day 1 monthly cumulative usage = Day 1 usage. Day 2 monthly cumulative usage = Day 1 usage + Day 2 usage. Day 3 monthly cumulative usage = Day 1 usage + Day 2 usage + Day 3 usage, and so on.

  • Tier pricing:

    Monthly cumulative usage

    Price

    Fee calculation formula (U = daily usage, unit: core/second)

    Tier 1: 0~200,000,000 core/second

    USD 0.000003/core/second

    0.000003×U (USD)

    Tier 2: 200,000,001~1,000,000,000 core/second

    USD 0.000002/core/second

    • First day entering this tier:

      0.000003×200,000,000+0.000002×(U-200,000,000) (USD)

    • Subsequent days: 0.000002×U (USD)

    Tier 3: 1,000,000,001~9,999,999,999,999 core/second

    USD 0.0000015/core/second

    • First day entering this tier:

      0.000003×200,000,000+0.000002×800,000,000

      +0.0000015×(U-1,000,000,000) (USD)

    • Subsequent days: 0.0000015×U (USD).

  • Billing example:

    • Scenario: Serverless assets have a total of 20,000 cores, running 24 hours (86,400 seconds) per day. Daily usage (U) = 20,000 cores × 86,400 seconds/day = 1,728,000,000 core/second.

    • First day fee:

      • Usage description: Day 1 monthly cumulative usage = Day 1 usage = 1,728,000,000 core/second. The monthly cumulative usage has reached Tier 3, and is billed based on the first-day-entering-Tier-3 rules (cross-tier).

      • Fee calculation: First day fee = 0.000003 (Tier 1 unit price) ×200,000,000+0.000002 (Tier 2 unit price) ×800,000,000+0.0000015 (Tier 3 unit price) ×(1,728,000,000-1,000,000,000)=3,292 (USD).

    • Second day and subsequent fees:

      • Usage description: Since the Day 1 monthly cumulative usage has already reached Tier 3, from Day 2 to the end of the month, the monthly cumulative usage remains in Tier 3, and daily fees are billed at the Tier 3 unit price.

      • Fee calculation: Daily fee = 0.0000015 (Tier 3 unit price) ×(20,000×86,400)=2,592 (USD).

Malicious File Detection

  • Billing method: Billing is based on the number of file detections (number of files detected).

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.0002/time.

Application Protection(RASP)

  • Billing method: Billing is based on the number of online instances per minute (0~60 seconds).

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.0002/instance/minute.

Anti-ransomware

  • Billing method: Billing is based on the backup file size (GB) and storage duration (hours).

  • Billing cycle: Cumulative hourly usage, settled on a daily basis.

  • Price: USD 0.00013/GB/hour.

File Tamper-Proofing

  • Billing method:

    • Billing formula: Actual protection duration (seconds) × Number of protected servers.

    • Protected server count rules: Servers that meet any of the following conditions are counted as protected servers:

      • Servers bound to interception protection rules.

      • Servers bound to alert protection rules where the host protection edition is below Enterprise Edition, or the protection level is below Comprehensive Host Protection.

  • Billing cycle: Settled on a daily basis.

  • Price: USD 0.286705/server/hour.

Standalone sales features

Important

Standalone pay-as-you-go services do not charge a base service fee.

Agentic EDR

  • Billing method: Billing is based on the number of seats × usage duration. Binding one server consumes one seat license. Servers without policy configuration are automatically excluded from billing.

  • Billing cycle: Billed hourly, settled on a daily basis.

  • Price: USD 0.014325/seat/hour.

Attack Management

  • Billing method: Billing is based on the number of protected assets and the Credits consumed by scanning.

    Note

    Credits are the scanning quota unit for attack surface management. Each scan consumes a certain number of Credits, which are used for attack path mapping of exposed assets, intelligent risk details, and generation of intelligent risk remediation suggestions. The actual number of Credits consumed is subject to the system's actual usage.

  • Billing cycle: Settled on a daily basis.

  • Price:

    • Assets: USD 0.5/day/asset. Each asset includes 200 Credits by default.

    • Excess Credits: USD 0.15/100 Credits.

Overdue payments or service deactivation

  • Scenarios:

    • Overdue payment: Pay-as-you-go bills are generated on T+1. If the account balance is insufficient at the time of settlement, an overdue payment occurs. To avoid service disruption, top up your account promptly. For more information, see Online top-up.

    • Service deactivation: The account manually deactivates the pay-as-you-go service. After deactivation, no new fees are generated.

      Note

      On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the relevant service switches. Or click the Deactivate button above to deactivate all pay-as-you-go services.

  • Subsequent impact: The corresponding pay-as-you-go features are unavailable, and the related detection and protection capabilities are lost.

  • Data retention:

    Unified sales

    • Overdue payment: After an overdue payment, there is a 15-day data retention period. After 15 days, data is cleaned according to the rules in the following table.

      Important

      Alibaba Cloud provides a grace period service that can extend the data retention period for cloud services. For more information, see Service suspension protection for overdue payments. For example, if the grace period benefit is 10 days, the data retention period for Security Center is 10+15=25 days.

    • Service deactivation: No data retention period. Data is cleaned immediately according to the rules in the table.

    Scenario

    Data cleanup description

    Overdue - within data retention period

    During the retention period, all service authorization information, configuration policies, and pay-as-you-go service data are retained.

    Overdue - after data retention period

    • The following authorization information is immediately purged:

      • Container Protection - Image security scan.

      • Container Protection - CI/CD integration settings.

    • The following Agentic SOC data is immediately purged:

      Important

      If the data retention period for an overdue payment is longer than 15 days, Agentic SOC does not wait for the retention period to end. Instead, it starts the data purge immediately after the 15th day of the overdue payment.

      • Security alerts: All alert information except for alerts under CWPP.

      • Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).

        Note

        Security events generated from alerts under CWPP (CWPP security events) are retained.

      • Response orchestration: Custom playbooks and custom response rules.

      • Log Management: Standardized integration logs and Security Center logs.

      • Rule management: Custom rules.

      • Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.

    • Agentic SOC - Response Center: Response policy and response task data is automatically purged by the system 90 days after it expires. This is not affected by overdue payments or service shutdowns.

    • Cloud Security Posture Management:

      • Cloud product configuration check:

        • After the cloud product configuration check is disabled, the check result data is not deleted.

        • Periodic scan policies, allowlist policies, and custom check items are not deleted.

      • System baseline:

        • Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.

          Note

          If your subscription service (Advanced, Enterprise, or Ultimate) has not expired and has not been unsubscribed, the check results for the corresponding edition are continuously retained. After the service expires or you unsubscribe, the data is retained in the backend for 30 days and then automatically deleted.

        • Scan policies are immediately deleted. Allowlist policies are not deleted.

    Service deactivation

    Standalone sales

    Agentic EDR

    • Policies and baseline retention: Existing policies and host baselines are retained but no longer updated.

    • Historical alert retention: Existing host abnormal behavior alerts are retained, but no new alerts are generated.