Stop billing and unsubscribe
Security Center supports three billing methods: subscription, pay-as-you-go, and hybrid billing (elastic protection). The entry point and the procedure for stopping billing differ by billing method. This topic helps you quickly identify the billing sources that are in effect and complete the operations to stop billing and unsubscribe in the correct order, so that no overlooked configuration continues to incur charges.
Process
To stop billing for Security Center, complete the following three steps in order:
Identify the billing sources: Check which billing items are in effect for your account.
Stop billing by billing method: You must unsubscribe from subscription services. For pay-as-you-go services and elastic protection, you must turn off the switches in the Security Center console.
Verify the result: Check the switch status in the console and review the bills delivered over the next two days.
Multiple billing methods can coexist under the same account. For example, you may have purchased subscription services and also activated pay-as-you-go services. If you unsubscribe from only the subscription services, the pay-as-you-go billing items continue to be charged and appear on your bills. Check each item one by one.
Step 1: Identify the billing sources
Go to the Security Center console - Overview page.
On the Overview page, use the following table to confirm the billing items that are in effect and the corresponding operation that you must perform.
NoteFor the activation source of each service, see Query entries for activation records.
You can go to the Expenses and Costs - Bill Details page and check the actual charged items by commodity name. For more information, see View orders and instance IDs.
For the rule differences among the three billing methods, see Billing method.
Billing method
Console location and criteria
Corresponding operation
Subscription
The Subscription area displays the purchased edition services and value-added services, and the instance has not expired.
Pay-as-you-go
The Enable Pay-as-You-Go Service area contains feature switches that are turned on.
Hybrid billing (elastic protection)
Above the Subscription area, the Elastic Protection switch is turned on, and the used quota displayed on the right of a service module exceeds the subscription quota.
Above the Attack Management area, the Full Protection switch is turned on.
Step 2: Stop billing by billing method
Perform the corresponding operation based on the result of Step 1. If multiple billing items exist, complete the operation for each of them.
If you only want to reduce costs instead of stopping the use of Security Center completely, you can control costs by downgrading the configuration or adjusting the protection edition, without unsubscribing. For more information, see Upgrades and downgrades.
Unsubscribe from subscription services
Scenario: You have purchased a subscription instance and no longer need to use the related services.
Confirm the following before you proceed:
Sale type: Features that are sold in a bundle share the same subscription instance ID. If you unsubscribe from that instance, you lose all bundled features at the same time. Features that are sold separately, such as Agentic EDR and Attack Management, have independent instance IDs. Unsubscribing from one instance does not affect other instances.
Unsubscribe rules: Each Alibaba Cloud account can use the five-day unconditional full refund only once per calendar year (January 1 to December 31). After the refund, the complimentary benefits associated with the order become void and are cleared.
Procedure: For the unsubscribe path, the unsubscribe procedure, and the refund calculation rules, see Unsubscribe from a subscription.
Turn off elastic protection
Scenario: You have purchased subscription services, your actual usage exceeds the subscription quota, and elastic protection is automatically triggered and generates pay-as-you-go bills.
Confirm the following before you proceed:
You must release or upgrade the quota first: Make sure that the used quota does not exceed the subscription quota. Otherwise, the system does not allow you to turn off the Elastic Protection switch.
Scope of the switch-off:
Protected Servers (edition service), Agentic EDR, Anti-Ransomware, and Agentic Cloud Platform Configuration Check are controlled by the same switch and cannot be turned off individually.
Attack Management uses an independent switch and must be turned off separately.
Applicable scope: Elastic protection applies only to Subscription. Separately purchased pay-as-you-go services are not affected.
Procedure: For the quota release methods and the procedure to turn off elastic protection, see Disable elastic protection.
ImportantIf you unsubscribe from the corresponding subscription instance, the corresponding elastic protection is also turned off. You do not need to perform a separate operation.
Turn off pay-as-you-go services
Scenario: You have activated pay-as-you-go features, or the Security Center trial resource plan that you claimed when you purchased ECS has been used up and is automatically converted to pay-as-you-go billing.
Confirm the following before you proceed:
Entry point: Pay-as-you-go (postpaid) instances cannot be unsubscribed directly on the Unsubscribe Management page. You must turn off the switches in the Enable Pay-as-You-Go Service area of the Security Center console. You can turn off only some of the services, or click Deactivate to turn off all pay-as-you-go services at a time.
Overdue status: If a pay-as-you-go instance is suspended because of an overdue payment, you must first go to Expenses and Costs to top up your account and settle the outstanding amount. You can perform the turn-off operation only after the account returns to the normal state.
Basic service fee: After you turn on any bundled pay-as-you-go feature, the system automatically charges a basic service fee. This fee cannot be canceled separately. The fee stops being charged only after you turn off all bundled pay-as-you-go services.
Procedure: For the procedure to turn off the services and answers to common billing questions, see Disable pay-as-you-go services.
Step 3: Verify the result
Check the console status: On the Overview page, confirm the following: all switches in the Enable Pay-as-You-Go Service area are turned off, the Elastic Protection switch is turned off, and the unsubscribed subscription instances are no longer displayed.
Check subsequent bills: Check the bill delivery against the following expectations.
On the day of the operation: The related services immediately stop being charged, and protection stops immediately.
The next day (T+1): You still receive one bill, which covers the usage consumed before the turn-off operation. This is normal.
From the third day on: No related bills are delivered.
If you continue to receive Security Center bills after the third day, billing items that are not turned off still exist. Return to Step 1: Identify the billing sources to check each item one by one, or see FAQ.
Data handling after billing is stopped
After billing is stopped or you unsubscribe, the data retention and clearing time differs by feature module: some data is cleared immediately, and other data is retained in the background for a period of time and then automatically deleted. For the data retention period and the clearing rules of each feature module, see Data purge rules.
Cleared data cannot be recovered. Complete the necessary data export and backup before you unsubscribe or turn off any service.