Modern pricing for modern scale
Only pay for the data you store. No ingest fees. No query limits.
No surprises.
Powering security teams of the future
Our Plans
SaaS
Fully managed by RunReveal. You get instant access to new features as we ship them, with no infrastructure to maintain or upgrade cycles to plan around. Get up and running in minutes.
100+ first-party source integrations
550-day retention by default
AI investigations
Unlimited Ingest
Built-in detections & BYO as code
SOC II compliant
$10k-$150k
depending on stored data volume
RunReveal in Your Cloud
RunReveal deploys into your AWS, GCP, or Azure account. You own the infrastructure; we handle the platform. Built for large and growing organizations with high data volumes or data residency requirements.
Full data residency
Custom integrations
AWS | GCP | Azure
Enterprise SLAs
$75k+
depending on stored data volume
Self-Hosted
Deploy on any Kubernetes cluster — on-prem, air-gapped, or cloud. Full control over compute, storage, and networking. Bring your own ClickHouse or use RunReveal's managed distribution.
Air-gapped environments
GovCloud
Helm + GitOps deploy
Enterprise SLAs & support
On-prem or Cloud
EKS, GKE, AKS, or bare metal
Custom
based on config
Or try some of our other plans
Community Edition
$0
/month
20 GB
/monthly storage
Use the forever-free SaaS Community Edition of RunReveal.
5 data sources
30-day data retention
Bring-your-own API AI keys
Teams
$200
/month
100 GB
/monthly storage
Ideal for security conscious startups who use cloud services.
15 data sources
90-day data retention
Custom integrations
Everything included in one price
No hidden fees. No caps. No trade-offs between visibility and budget.
Why Teams Choose RunReveal
Before RunReveal
Before RunReveal
Investigation Speed
Manual log correlation and analysis takes 3+ hours per investigation
AI-powered investigations cut investigation time to minutes with automated context gathering
Detection Engineering
Writing custom detection rules for each threat requires ongoing engineering time
Built-in detection library covers common threats out-of-the-box with 70% less custom work
Time-To-Value
Weeks or months to fully integrate log sources and build detection coverage
Up and running in hours with immediate security visibility across all sources
Cost Efficiency
High operational costs from data engineering overhead and ingest-based SIEM pricing models
Transparent pricing with no data engineering team needed—unlimited ingest and pay only for what you use
Pipeline Management
Engineers spend hours building and maintaining custom data pipelines for each log source
Built-in data pipelines that supports data transformation, routing, enrichment, and normalization
Tool Sprawl
Juggling multiple tools and vendor contracts for data storage, pipelines, and SOC
Single platform for data ingestion, filtering, enrichment, search, investigations, and analytics
FAQs