Our three packages
Essential
Automated coverage of your external exposure
- Continuous detection and reports
- Attack surface, credentials, brand
- Threat intelligence as a feed
- Full self-service
Core
Investigate and test, with a dedicated expert
Everything in Essential:
+ Enriched analysis
+ Deeper data on each finding
+ On-demand active testing
+ First vendor visibility
+ A dedicated CSM on demand
Elite
Anticipation, run by your dedicated analyst
Everything in Core:
+ Predictive threat intelligence
+ Active testing included
+ Full vendor & dark-web coverage
+ Expert support with a dedicated analyst
On every package
The package sets the depth of analysis and the level of expert support, never what you are allowed to see.
- Daily scanning
We scan your external surface every day, on every package. - Automatic inventory
Your exposed assets, shadow IT and vulnerabilities, found and listed for you. - Credentials and domains
Leaked credentials and lookalike domains, detected as they appear. - Threat intelligence
Threat intelligence and Threat Note, included as standard. - Reports and integrations
Dashboards, exports and API access, so findings reach the tools you already use. - Takedowns and support
Domain and fileserver takedowns, standard support and an Executive Business Review.
The six questions we answer
We group everything we monitor under six questions security teams face. All three packages answer all questions; what changes is how deep the analysis goes and how much expert support comes with it.
Govern Can I prove my posture to my board?
Reports, dashboards, exports and an Executive Business Review, so the board slide is a byproduct of the work rather than a separate project.
Identify Am I exposed without knowing it?
Unknown assets, shadow IT and vulnerabilities, scanned daily on every package, with depth of analysis and expert review varying by package.
Discover Have my data leaked or my identity been faked?
Credentials, documents and source code outside your perimeter, plus lookalike domains and fake accounts impersonating you and your executives.
Discover Do my vendors weaken me?
The exposure and compromise of your critical vendors, monitored continuously, so a breach at one of your suppliers does not become yours.
Anticipate Am I about to be attacked?
Attack claims, threat actors targeting your sector and vulnerability intelligence, connected to what is actually exposed about you rather than a feed to filter.
Mobilize Can I test my weak spots and react fast?
Passive detection shows what is exposed, active testing checks whether it can be exploited, and our experts help you.
-
API security testing
Executive risk assessment
Vendor security testing
Application discoveryTest what is exposed, don't just look at it
Passive detection shows what is exposed. Our active testing checks whether that exposure can actually be exploited, so you know what to fix first.
Available on demand with Core and included with Elite. With Elite, we also test your exfiltrated credentials.
Expert support on every package
Every package includes support from our team, because a finding you cannot act on is not much use. What changes is how much of that expertise is dedicated to you.
- Standard support: our team and our documentation are there on every package, at no extra cost.
- Onboarding: self-service with Essential, on demand with Core, and a premium workshop with your CSM and analyst with Elite.
- A dedicated CSM: on demand with Core, included with Elite. A Customer Success Manager who knows your organization, reviews your exposure with you and prepares your Executive Business Review.
- A managed service: on demand with Core, included with Elite. A CybelAngel analyst investigates your findings with you rather than handing them over.
- Add-ons on credits: investigations, phishing and data breach analysis, threat actor profiling and crisis monitoring are available on any package, so you can bring in our experts when you need them, without a retainer.
Frequently Asked Questions
Essential fits when you want detection to run automatically and act on findings yourself. Core fits when you want to investigate and test what we find, with expert accompaniment available on demand. Elite fits when you want the whole loop run with you, with maximum depth and an analyst alongside your team.
Yes. Essential is a complete program, not a trial: the same questions covered, continuous detection scanned daily, takedowns, reporting and standard support included.
Detection runs continuously, with daily scanning, on every package. What changes between the packages is the depth of the analysis and the level of expert review, not how often we look.
No. We do not sell features in isolation: every package answers all the questions above. Add-ons then let us compose around your specific needs.
Nothing changes on your side today, and there is no migration to plan. Your Customer Success Manager will walk you through what the packages mean for your setup.
Passive detection shows what is exposed. Active testing checks whether an exposure can actually be exploited, so you can prioritise what to fix first. It is available on demand with Core and included with Elite.
Yes, from Core, which alerts you when a critical vendor is targeted or compromised and maps their exposure. Elite adds your vendors’ exposed credentials and data, and dark web monitoring on them.
Pricing is built with you. Talk to our team, or to your Customer Success Manager if you are already a customer, and we will put together the breakdown that matches your scope.
Every customer gets support from our team. Essential comes with standard support, self-service onboarding and a yearly Executive Business Review. Core adds a quarterly review, with onboarding assistance, a dedicated Customer Success Manager and a managed service available on demand. Elite includes a premium onboarding workshop, a dedicated Customer Success Manager, a managed service with a dedicated analyst and a monthly review. Investigations and complex takedowns are available on any package as add-ons on credits.
Yes. CybelAngel’s platform API supports integration with SIEM, SOAR and ITSM tools, and CybelAngel Connect, our no-code automation studio, folds alerts and remediation directly into platforms like Splunk, ServiceNow, Jira, Slack, Cortex XSOAR, IBM Security SOAR and Azure Sentinel. API access is included on every package: one key with Essential, multiple access with Core, and custom access with Elite. For the full technical reference, visit our API documentation.