Best Cyber Solutions Request service

FAQ

Straight answers to the questions people actually ask.

Don't see yours? Ask it, and it may end up here.

The service

What happens if something is detected at 3am?

The response policy you agreed at onboarding acts immediately: The process is suspended, the file quarantined or the address blocked, within seconds. A person reviews it at the start of the next business day, or sooner if it happens during business hours. Automated containment is what makes the overnight hours covered; we won't pretend someone is awake.

Do you run a 24/7 security operations center?

No, and we'll never describe ourselves as one. Automated detection and response run continuously. Human triage, investigation and judgment happen 8am–6pm Eastern, Monday to Friday. The contract says exactly the same thing.

Can we turn automated response off?

Yes, whenever you want it off. Say the word and we change it, usually within the hour, and we confirm what changed. You also sign off on the response policy itself during onboarding, and again after any significant change, so you always know what the software is allowed to do. The controls sit with us on purpose: You are paying for the service to hold them, and a monitored machine whose protection can be switched off from that machine is not really monitored. You can watch everything it does from the console on your own machines.

What if automated response blocks something legitimate?

It can happen. Every automated action is reversible, and we roll response out in stages during onboarding precisely to find those cases before they matter. If something legitimate is caught, we release it and tune the policy so it doesn't happen again.

What do we get in a month when nothing happens?

A month without incidents is the goal, and it isn't a month without work. We hunt in your environment every month for threats that no detection has caught yet, starting from that month's research on Mac and Linux attacks. Your monthly report lists every hunt: What we looked for, why, how we looked, and what we found, including when the answer was nothing. How we hunt.

How do you roll out to our machines?

In stages. The agent starts by watching only, then we turn on response for a few machines, then the rest. It's slower than flipping everything on at once, and it's how you avoid breaking someone's workday.

Coverage

Which systems do you cover?

macOS, plus Linux servers and workstations running Debian or Ubuntu. Cloud Linux instances are fine as long as they run one of those.

Do you cover Windows?

Not yet. A Windows agent is in active development, but we won't put a date in your contract until it ships. If you have a few Windows machines, we'll tell you honestly what that means and what we'd suggest in the meantime.

Is there a minimum size?

No. One machine is enough, and the Solo plan starts at $49 a month for up to three. The service is built for Mac- and Linux-first teams up to about 50 people, and that includes the one-person shop: A founder with a MacBook full of customer data needs the same containment as a team of thirty, and gets the same service.

Why no kernel driver? Isn't that less capable?

It trades some deep visibility for something we think matters more at your size: A bad update can't blue-screen or boot-loop your fleet. On macOS, Apple's own Endpoint Security framework runs in user space anyway. The threats your team actually faces, like infostealers, malicious installers and credential theft, are well within reach of a user-space agent.

Privacy & data

Is this employee monitoring?

No. We look for attackers, not productivity: No screenshots, no keystrokes, no browsing history, no time tracking. What the agent collects is documented, and we'll walk anyone on your team through exactly what leaves their machine.

Can we see what you see?

Yes, on your own machines. Every machine we monitor runs Scouter's own console, and it is the same interface we work in: Processes and what launched them, network connections, persistence, logins, every alert, every detection that fired and every action taken. It answers only to that machine, so nobody else on your network or ours can open it. Most teams never do, and that is fine — the point is that checking our work doesn't require taking our word for it. The fleet console we run across customers stays on our side, so there is nothing new for you to learn or to expose.

Where is our data stored?

Detailed history stays on each machine. Our console receives summaries of alerts and machine health, and pulls detail only when an investigation needs it. Retention is set out in your agreement, and 90 days is our default.

Do you use AI on our data?

Only if you want it. The AI layer is off by default or runs on a local model. If you choose a commercial model, you pick the provider and use your own account, and data is redacted before any prompt is built.

Pricing & contracts

How long is the contract?

Month to month, with 30 days' notice either way and your data exported when you leave. Paying annually gets you two months free and waives the onboarding fee.

Why do you publish starting prices?

Because small teams shouldn't have to sit through a sales call to find out whether something is in their budget. The plan prices and the per-machine rates past the included count are on the services page, so you can work out your own number before you speak to us.

Can you help with our security questionnaire?

Yes. It's part of Contain+. For many small companies, that questionnaire is the reason they start looking at all.

We already have an IT provider. Do we need to switch?

No. We don't do helpdesk work and aren't trying to replace your IT provider. We'd rather work alongside them; see partners.

Find out what is already on your machines.

We recommend starting with a one-week Compromise Assessment. $500 of it is credited if you continue into monitoring.