Unsubscribe from a subscription

Updated at:

If you no longer need the security protection features provided by Security Center, you can unsubscribe from your purchased Security Center instance through a refund. This topic describes the refund rules and operations for Security Center under different billing methods and scenarios.

Confirm the sales type and unsubscription path

Depending on the feature, Security Center uses the following unified-sales and standalone-sales paths. The unsubscription process also differs. Before unsubscribing, confirm whether the feature is sold as a unified-sales or standalone-sales item:

  • Unified sales:

    • Unified-sales features share the same subscription resource instance ID. If you unsubscribe from this instance, you will lose all unified-sales features.

    • Unified-sales features mainly include edition services and value-added services. For more information, see Subscription - Feature and Service Details.

  • Standalone sales: In Expenses and Costs, each standalone-sales feature has a separate subscription resource instance ID. Unsubscribing from a single feature instance does not affect other instances.

    Note

    Standalone-sales features that support unsubscription include Agentic EDR, Attack Management, and more. For more information, see Purchase separately on dedicated pages Feature Details.

Unsubscription rules

Security Center supports five-day unconditional full refund, partial refund, and unsubscription for unactivated renewal periods three unsubscription types. Before unsubscribing from a Security Center instance, make sure you understand the unsubscription rules, notes, and case examples. For details, see Unsubscription rules.

Note
  • Each Alibaba Cloud account can use the five-day unconditional full refund only once per calendar year (January 1 to December 31).

  • After a refund, all complimentary benefits associated with the order will be voided and cleared to zero.

Unsubscribe unified-sales features

Unsubscribe a single value-added service

  1. Access the Security Center console - Asset Center - Asset Overview. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Overview page Subscription region, clickChange Configuration > Downgrade On the order upgrade and downgrade page, on the Order Downgrade tab, set Purchase or Not to No for the relevant service. For the detailed procedure, see Upgrades and downgrades.

Important

Unsubscribe the entire instance

Self-service unsubscription steps in the console

Purchased Security Center subscription instances support self-service unsubscription through the console.

  1. Query the instance ID:

    1. Log on to the Expenses and Costs console, and go to the My Orders page.

    2. Configure the search conditions as described below, and then click Search.

      • Product Name: select Security Center.

      • Commodity Name: select Security Center.

        Important

        Do not select "Security Center (Pay-As-You-Go)".

    3. In the order list, in the Asset/Resource Instance ID column, copy the Asset/Resource Instance ID of the target instance.

      Note

      Usually, you can take the latest record.

  2. Unsubscribe the resource:

    1. Go to the Unsubscription Management page.

    2. On the Unsubscribe Resource tab, enter the instance ID queried in the previous step, and then click Search.

    3. On the 5-day Money-back Guarantee or Partial Refund tab, select the resource to unsubscribe.

      Important

      If no relevant resources are found, check the Nonrefundable tab, which indicates that the instance can no longer be unsubscribed.

      1. In the Actions column of the resource to unsubscribe, click Unsubscribe Resource.

      2. On the Unsubscribe Resource page, carefully read the unsubscription agreement and related instructions, and then select the check boxes for I have carefully read the "Unsubscription Rules" and confirmed the refund amount and I have confirmed that the instance data to be unsubscribed has been backed up and migrated.

      3. Click Unsubscribe , and then confirm the content of the Confirm Unsubscription Information dialog box, confirm the resource information, set the Reason for Unsubscription, and then click OK.

  3. After the unsubscription request is successfully submitted, click Unsubscribe Order Details above the list to view the unsubscription processing details.

Impact of unsubscription

  • Elastic Protection: Elastic Protection immediately becomes invalid and stops billing. The elastic authorizations and credits consumed on the current day will be billed on the next day.

  • Data retention:

    Scenario

    Data clearance description

    On the day of unsubscription

    • The following authorization information is immediately purged:

      • Container Protection - Image security scan.

      • Container Protection - CI/CD integration settings.

    • Log analysis: The data in the `sas-log` Logstore is immediately purged. This Logstore belongs to the Project that Security Center creates in Simple Log Service (SLS). The Project is named `sas-log-<Alibaba Cloud account ID>-<region ID>`.

    • Host Protection - Anti-ransomware: All backup policies and backup data are immediately purged.

    • Cloud Security Posture Management:

      • Cloud product configuration check:

        • Only the check results of free edition items are retained. The check results of paid edition items are immediately purged.

        • Periodic scan policies, allowlist policies, and custom check items are not deleted.

      • System baseline:

        • Baseline check results cannot be viewed in the frontend. Backend data is retained for 30 days and then automatically deleted after the retention period expires.

        • Scan policies are immediately deleted. Allowlist policies are not deleted.

    • Anti-ransomware: 1 day after the instance is released, the protection capabilities and generated backup data of this service are removed.

    15 days after unsubscription/expiration

    • The following Agentic SOC data is immediately purged:

      • Security alerts: All alert information except for alerts under CWPP.

      • Security event handling: Event information generated by Agentic SOC predefined rules and custom rules (Agentic SOC security events).

        Note

        Security events generated from alerts under CWPP (CWPP security events) are retained.

      • Response orchestration: Custom playbooks and custom response rules.

      • Log Management: Standardized integration logs and Security Center logs.

      • Rule management: Custom rules.

      • Integration Center: Custom items such as standardized integration rules, data sources, watchlists, and integration policies.

    • Agentic SOC - Response Center: Response policies and response tasks are automatically purged by the system 90 days after they expire. This is not affected by unsubscription.

Unsubscribe standalone-sales features

Unsubscription scope

  • Features that do not support unsubscription: AgenticBAS, SecOpsAgent do not currently support unsubscription.

    Note

    If needed, contact your account manager for manual unsubscription.

  • Features that support unsubscription: Agentic EDR, Attack Management.

Unsubscription steps

  1. Query the instance ID:

    1. Log on to the Expenses and CostsExpenses and Costs console, and go to the My Orders page.

    2. Configure the search conditions as described below, and then click Search.

      • Product Name: select Security Center.

      • Commodity Name: select the corresponding standalone-sales feature name, such as Agentic EDR, Attack Management.

    3. In the order list, in the Asset/Resource Instance ID column, copy the Asset/Resource Instance ID of the target instance.

      Note

      Usually, you can take the latest record.

  2. Unsubscribe the resource:

    1. Go to the Unsubscription Management page.

    2. On the Unsubscribe Resource tab, enter the instance ID queried in the previous step, and then click Search.

    3. On the 5-day Money-back Guarantee or Partial Refund tab, select the resource to unsubscribe.

      Important

      If no relevant resources are found, check the Nonrefundable tab, which indicates that the instance can no longer be unsubscribed.

      1. In the Actions column of the resource to unsubscribe, click Unsubscribe Resource.

      2. On the Unsubscribe Resource page, carefully read the unsubscription agreement and related instructions, and then select the check boxes for I have carefully read the "Unsubscription Rules" and confirmed the refund amount and I have confirmed that the instance data to be unsubscribed has been backed up and migrated.

      3. Click Unsubscribe , and then confirm the content of the Confirm Unsubscription Information dialog box, confirm the resource information, set the Reason for Unsubscription, and then click OK.

  3. After the unsubscription request is successfully submitted, click Unsubscribe Order Details above the list to view the unsubscription processing details.

Impact of unsubscription

Agentic EDR

  • Instance status: The instance is immediately released, and Agentic EDR immediately stops service.

  • Elastic Protection: Elastic Protection immediately becomes invalid and stops billing. The elastic authorizations and credits consumed on the current day will be billed on the next day.

  • Data retention:

    • Policy and baseline retention: Original policies and host baselines will be retained but no longer updated.

    • Historical alert retention: Host anomaly alerts that have already been generated will be retained, but no new alerts will be generated.

Attack Management

  • Instance status: The instance is immediately released, and the Attack Management protection capability stops simultaneously.

  • Elastic Protection: Elastic Protection immediately becomes invalid and stops billing. The elastic authorizations and credits consumed on the current day will be billed on the next day.

  • Data retention:

    • Feature policy configuration data will be retained indefinitely.

    • Asset and attack path scan task data will be retained for only 7 days, after which it will be permanently released.

Troubleshooting

  • "Failed to obtain unsubscription resource information" error: This typically indicates that the resource is in an abnormal state (for example, the instance is in arrears, security-locked, or undergoing an upgrade or downgrade operation), and cannot be unsubscribed through the console self-service.

  • Page status not updated after unsubscription or closure: After unsubscribing from or closing a service, the expiration time or instance status displayed in the console may have a brief delay. If the page status is not updated in a timely manner, we recommend that you refresh the page or wait a few minutes before checking again.

  • Activation or charges caused by someone else's operation: If you did not actively activate Security Center but find related charges, you can use ActionTrail to identify the specific operator:

    1. Log on to the ActionTrail console.

    2. On the Event Query page, filter the service name to Sas.

    3. Filter the event name to ModifyPostPayModuleSwitch.

    4. Review the matching event records to confirm the operation time and the operator identity (such as a RAM user or another authorized account).

Refund destination

  • After a successful unsubscription, the refund is typically processed within two business days.

  • Refunds generally follow the original payment method principle. If the original payment method refund fails, the refund is typically automatically credited to your Alibaba Cloud account balance.

  • If an arrears adjustment is involved, the adjusted amount will be credited to your account balance instead of the original payment method after the adjustment is completed.

  • After a successful refund, the system automatically reduces the invoiceable amount for the corresponding order. If an invoice has already been issued, the original invoice remains valid after the unsubscription, but the refunded amount can no longer be applied for an invoice.

  • For more refund information, see Initiate unsubscription and Refund destinations.

FAQ

Can I get a refund for accidental activation or unexpected charges on a pay-as-you-go instance?

Bills already generated for pay-as-you-go (postpaid) usage generally cannot be directly refunded or reversed through a balance adjustment.

For the following non-malicious scenarios, you can contact customer service to apply for a general-purpose cloud product coupon as compensation:

  • Accidental activation of pay-as-you-go service due to non-malicious error.

  • No notification received before the trial period expired, resulting in unexpected charges.

Coupon description:

Item

Description

Amount

CNY 20, CNY 50, CNY 100, or other amounts (depending on the situation)

Validity period

Typically 90 to 180 days

Applicable scope

Can be used to offset subsequent prepaid orders or postpaid bills (excluding specific products such as domain names and cloud communications)

If you have a dispute about charges, we recommend that you submit an appeal through the ticket system. A specialist will review the operation records (such as ActionTrail logs) and then process your request.