Compromise Assessment
A one-week, read-only engagement that answers one question: Is anything already on your machines that shouldn't be?
From
$2,000 fixed fee
$500 is credited toward your first year if you continue within 60 days.
Managed Detection & Response · macOS and Linux
Security monitoring for Mac- and Linux-first teams, from a single MacBook to about 50 people. Automated containment runs around the clock, and a named analyst, not a ticket queue, reviews every detection during business hours.
Why teams call
Services
Ways to work together, priced for small teams and published up front.
A one-week, read-only engagement that answers one question: Is anything already on your machines that shouldn't be?
From
$2,000 fixed fee
$500 is credited toward your first year if you continue within 60 days.
Continuous monitoring with automated response, business-hours human triage, ongoing threat hunting, a monthly report, and email or Slack escalation.
From
$99 / month
Includes up to 10 endpoints. Just you and a laptop? Solo covers up to three for $49.
Everything in Contain, plus response policy tuning, a quarterly posture review, security-questionnaire help and priority escalation.
From
$149 / month
Includes up to 15 endpoints — just $50 a month more than Contain.
How it works
Hunt for anything that got in before anyone was watching: Persistence, stolen credentials, live connections to attacker infrastructure.
A lightweight agent on each Mac and Linux machine, rolled out in stages so nothing in your day-to-day breaks.
Detections trigger an automated response within seconds. Every one is then reviewed by a person.
We hunt for what no detection has caught yet, and every hunt goes in a monthly report written for the people who ask: Your customers, your insurer, your auditor.
What's different
Detection written for LaunchAgents, TCC abuse, macOS infostealers and Linux persistence, not a Windows product with a Mac port bolted on.
Every detection carries a response: Suspend the process, quarantine the file, block the address. An alert nobody acts on at 3am isn't protection.
The agent runs entirely in user space, so it cannot blue-screen or boot-loop your fleet. After 2024, that's worth asking every vendor about.
We look for attackers, not productivity. What the agent collects is documented, and we'll show you exactly what leaves each machine.
You'll know exactly who is reading your alerts, and that person answers the phone. No tiered queue, no hand-offs, no starting over with someone new.
No minimum, and no bundled helpdesk you don't need. Built for companies with 5 to 50 machines.
Straight answers
Plenty of vendors blur "24/7 protection" into "24/7 staffing". We don't, and the contract says the same thing this page does.

Who picks up
“I spent a decade running detection and response for companies large enough to have a security team. This is for the ones that aren't, and deserve the same care.”Lonnie Best, founder · former Director of Managed Detection & Response at Coalition
We recommend starting with a one-week Compromise Assessment. $500 of it is credited if you continue into monitoring.