Packages
One package, the whole platform
There are no tiers to compare and nothing held back for a higher one. Everything Seraph CTI does is in the package; what it costs is scoped to your organisation and quoted in writing.
One package with the whole platform in it — intelligence, human risk, exposure monitoring, reporting and the security controls a review will ask about.
- The simulation engine
- Courses, quizzes and completion tracking
- The Outlook and Gmail Report add-in
- Per-department resilience reporting
- Threat intelligence & technology watches
- Breach & leak monitoring for your domains
- Analyst Threat Inbox
- Priority support
- SAML SSO & enforced MFA policy
- Audit log exports & API access
- Dedicated onboarding & success
- Vulnerability Assessment and Penetration Testing
We scope it with you — people in scope, domains monitored, how you want to start — and send a written quote. No obligation, and no seat count needed to have the conversation.
No surprises
What is included whatever the scope
The things a comparison usually finds hidden behind a higher tier are simply in it.
- A written quote before anything is signed
- One agreement covering the whole platform
- Scoped to your organisation, not to a tier
- Invoiced in arrears against that agreement
- Per-tenant SAML SSO and enforced MFA
- Audit log export and org-scoped API keys
- A security review we expect to pass
- Dedicated onboarding
Before you ask
What your security review will want
You are choosing a custodian for how your people respond to attack. The documents that govern that are linked here rather than buried, and they say what is true today.
Seraph Cyber is a Kenyan company and the platform is operated from Nairobi. Some sub-processors sit outside Kenya; they are named in the Privacy Notice, and transfers rely on the safeguards in section 49 of the Data Protection Act.
Privacy Notice and sub-processorsA Data Processing Addendum is published in full, not held back for negotiation. It covers instructions, confidentiality, breach notice, sub-processors, audit and deletion — and we answer a security questionnaire once a year at no charge.
Read the DPAYour data is exportable throughout, including while an account is suspended for non-payment. Erasing a staff member anonymises their records after a 30-day grace period; invoices and the tax records attached to them are kept because the law requires it.
Trust & security in fullThe other lane
Some organisations should start with an assessment instead
A running programme is the right shape when you know that is what you want. If the question is still where are we exposed, an assessment answers that first and usually decides the programme afterwards.