Pricing, risk readout and platform tiers | Artemion
Pricing

Priced against the number itself.

Two steps. See your exposure once, then keep it measured. Platform pricing is a percentage of your Systemic Liability Number, so as the risk comes down, so does what you pay.

Step one Risk Readout

Find out what your identities are worth.

Priced to scope credited to your first platform year

A scoped, read only engagement. We connect, run the engine, and hand you a board ready figure with the cascade behind it. Hours, not a quarter.

Your Systemic and Exploitable Liability Numbers
Exposure cascaded to department and named owner
Board ready brief, printable, yours to keep
A working session to walk your team through it
Credited in full against your first platform year
Step two The platform

Keep the number live.

Continuous quantification, remediation priced in dollar deltas, and an evidence trail your auditors and insurers can read. Annual, as a percentage of your SLN.

Cloud % of SLN, annual

We run it. Fastest path to a number that refreshes itself, with no infrastructure on your side.

Self hosted % of SLN, annual

The full engine inside your perimeter. Air gap friendly, per client isolation, your data never leaves.

Enterprise and embedded Custom

Multi entity rollouts, portfolio scoring across your vendors or insureds, and the number delivered into your own product.

Talk about platform pricing

As your risk falls, so does your price. Negative churn, by design.

Compare

What changes between the readout and the platform.

  Risk Readout Cloud Self hosted
Cadence Point in time Continuous Continuous
Identity coverage People, machines, AI agents People, machines, AI agents People, machines, AI agents
Where it runs Read only, our side Managed by Artemion Inside your perimeter
Remediation guidance Top exposures, ranked Priced dollar deltas per fix Priced dollar deltas per fix
Audit and insurer evidence Single brief Standing evidence ledger Standing evidence ledger
Time to first number Hours Hours Scoped with your team
Commercial One engagement, credited forward % of SLN, annual % of SLN, annual
What actually happens

Your first week, in four moves.

DAY 0

Scope call

Thirty minutes. Which clouds, which entities, who receives the brief. We send the read only permission list up front.

DAY 1

Read only connect

You grant scoped read access. No agents installed, no code shipped, nothing written back to your environment.

DAY 1, SAME SESSION

Engine run

We map the identity graph, price every reachable path, and reconcile the population with your own records.

DAYS 2 TO 5

Readout and walkthrough

You get the number, the cascade, and the ranked exposures, plus a working session so your team can argue with the math.

Data handling

Read only means read only.

You are buying a measurement, not another agent with write access. Every question your security review will ask, answered before you ask it.

Scoped read only credentials

No write permissions requested, ever. You can revoke access in one action and the engagement stops.

No agents, no code in your pipeline

Nothing is installed on hosts and nothing is merged into your repositories.

Metadata, not your data

We read identity, permission, and configuration metadata. We do not read your customer records or file contents.

Self hosted if you prefer

Run the whole engine inside your own perimeter and nothing crosses your boundary at all.

Questions

The ones we get asked first.

How do you set a percentage of a number we have not seen yet?

You do not commit to platform pricing before the readout. The readout produces the number, then the percentage applies to a figure you have already seen and pressure tested with us.

What if the number comes back lower than we expected?

Then you have a defensible figure for your board and a cheaper platform year. We are not incentivised to inflate it, and we will show you the working so you can challenge it.

Do we need to replace our identity or posture tooling?

No. AIRE sits on top of what you already run and adds the layer none of it produces: a dollar figure. Your IdP, CSPM, and ticketing stay exactly where they are.

Who signs off on this internally?

Usually the CISO or head of risk for the readout, because it is read only and scoped. Platform years typically involve procurement, which is why the readout exists first.

Can we run a tabletop exercise against the results?

Yes. We will walk your team through the highest value paths the engine found and run the scenario against your actual environment rather than a generic script. Ask us when you scope the readout.

Start with the number. Decide after.

The readout is scoped, read only, and credited against your first platform year if you continue.

Start a readout Book a 20 minute call
Read only access No agents, no code Revoke access any time