Billing & pricing
:::note Mobius is in beta We are not billing during the beta. You can add a card, but nothing is charged automatically — any charge is reviewed and approved by us manually, and only after your free credit is used up. :::
Mobius is fully usage-based: you pay for the AI work performed on your alerts and incidents. Every triage, investigation, incident analysis, and report has a cost, and your bill is the sum of that work. No per-agent fee, no monthly minimum, no quotas, no overage shock — you pay only for what you analyse.
Billing is at the organization level, on the shared Wazuh Labs billing profile — the same customer record your organization uses for the other Labs services, managed through the Wazuh Hub.
What you are billed for
| Unit | What it covers |
|---|---|
| Alert triage | Every new alert analysed |
| Deep investigations | Escalations that need a closer look |
| Incident analysis | Correlation and expert review of incidents |
| Reports | Incident and scheduled reports |
Each unit is priced to match the model it runs: a fast, low-cost model for triage, a more thorough model for deeper investigation and incident analysis. Your own Wazuh costs (manager, indexer, dashboard) are billed by your Wazuh Cloud subscription or self-hosted stack and are out of scope for Mobius.
The dedup window and noise filters keep billed volume honest: the same alert re-seen across polling cycles is never re-triaged or re-billed.
Start with $40 of free credit
Every new tenant gets $40 of free credit — no credit card, no agent cap, no feature gating. The credit meter at the top of the billing page shows how much is left. When it runs out, the paid pipeline pauses until you add a payment method.
Add a payment method
Click Add payment method on the credit meter (or open Manage in Wazuh Hub) to enter a card. The card lives in the Wazuh Hub and covers every Wazuh service your organization uses, so you enter it once. The Hub uses Stripe's hosted form — your card data never touches our servers. During the beta, adding a card never triggers an automatic charge.
Watch your usage in real time
- The Billed usage card shows today and month-to-date billed cost in dollars, with a 60-day cost chart below it that makes anomalies easy to spot (for example, a suddenly chatty rule firing thousands of alerts).
- The Your usage breakdown card shows what Mobius did for you over the last 60 days and what each part cost — alert triage, deep investigations, incident analysis, and reports, each with its run count and dollar cost. This is exactly the usage your bill is computed from.
- Estimated invoice shows month-to-date plus a naive projection of where the bill will land at month-end if usage continues at the current daily rate.
Cap your monthly spend
From Settings → Budget limits you can set a monthly budget. New tenants start at $100/month; an admin can raise it up to $200 (above that, contact us through the console). You are notified at 85%, 90%, and 100% — and at 100% Mobius pauses workflow launches and alert ingestion until the next billing month. No data is deleted; everything resumes when the new month starts or you raise the limit.
Two more cost controls work per environment:
- Ingest pause stops new triage (and its cost) instantly — the connector stays up.
- EPS caps bound how much a runaway environment can ingest per cycle.
Invoices
Once Stripe finalises an invoice (the day the billing period closes), it shows up in the Invoices table at the bottom of the billing page. Click any row to download the PDF, or open the Wazuh Hub for the full history.
What happens if my card fails
Stripe retries automatically and your billing status moves to past_due;
we notify the billing email on file. If retries fail, the tenant moves to
paused — workflows stop running until a valid card is added. No data is
deleted; everything resumes the moment payment succeeds.
Only users in the admins group can view the billing page. Ask an admin if you need access. Route billing notifications to the org admin in notification settings.