Skip to main content

Billing & pricing

No charge without a human review

Billing is real and usage is metered for real, but nothing is ever collected automatically. When a billing cycle closes the invoice is issued and the card on file is charged, and a human reviews and approves it first. The free credit is spent before any of that applies, and an invoice that looks wrong is corrected before it is collected.

Mobius is fully usage-based. The bill is the AI analysis performed on an organization's alerts and incidents, and nothing else. There is no per-agent fee, no monthly minimum, and no quota to buy up front. Billing is at the organization level and shared with the other Wazuh services the organization uses, managed through the Wazuh Hub.

Beta pricing

Mobius is in closed beta, and every figure on this page is a beta figure. These numbers apply to the organizations testing the service today, and they will change in the near future. The beta bar in the console says the same thing.

What costs money​

Every row below is a piece of AI analysis. Each one costs what that analysis consumed, so a routine triage costs a fraction of a deep investigation, and a quiet month costs less than a busy one.

Billed workWhen it happens
Alert triageOnce for every alert that reaches L1 triage
Deeper investigationWhen triage sends an alert to L2 for a closer look
Incident analysisWhen an incident is written up, and again on every re-analysis
Incident reportEach report generated for an incident
Scheduled reportEach run of each switched-on report, once per selected environment
Threat huntEach hunt launched from the workflows page
Knowledge entryWhen an entry is created, when its content is edited, and on a manual re-embed

What costs nothing​

An alert Mobius never analyses is never billed. Nothing is charged for:

  • An alert dropped before triage: a repeat of one already classified, noise below the severity floor, an alert filtered out by the environment's ingestion policy, or an alert deferred by the ingest rate cap.
  • An alert closed by a hard known behavior rule, which skips the model entirely.
  • Everything the console itself does: reading, filtering, archiving, building cases, and every page of history.

The organization's own Wazuh costs, for the manager, the indexer and the dashboard, are billed by its Wazuh Cloud subscription or self-hosted stack and are out of scope for Mobius.

Start with $40 of free credit​

Every new organization gets $40 of free credit and needs no card to spend it. The billing page shows how much is left. The free credit is always spent first, before anything is billed.

Keep going past the free credit​

When the free credit runs out, alert ingestion, new workflow runs and response actions pause. Two separate things are needed to resume:

  1. A card on the organization, added in the Wazuh Hub. It is entered on the Hub's own hosted payment page, so card data never reaches Mobius, and it covers every Wazuh service the organization uses.
  2. Pay as you go, switched on from the billing page. The card is shared with the organization's other Wazuh services, so having one is never on its own an agreement to pay for Mobius.

The order matters only in that the card has to exist before the switch can be turned on.

Turning Pay as you go off is a withdrawal of consent to be charged, so it takes effect at once: if the free credit is already used up, alert ingestion, new workflow runs and response actions stop immediately rather than at the end of the period. Billing itself is unaffected: the subscription stays open until the period ends so that everything already analysed is invoiced, including the usage from the final hours before the switch was turned off. Nothing new is charged after it. An organization still inside its free credit is not cut off by turning the switch off; it simply will not be charged when the credit runs out.

Turning it back on cancels the pending cancellation and resumes service on the same subscription, with no new trial and no gap in the billing period.

The $40 free credit is granted once per organization. Cancelling and subscribing again later does not grant it a second time.

Gifts and sponsored credit​

Wazuh may grant an organization sponsored credit (a gift) or a usage credit through the Hub. Both appear on the billing page with the amount left and the date they expire, and both are spent before the card is charged.

  • A gift covers usage up to its amount. When it expires with a balance left, the usage it already covered is never billed retroactively; only usage after the expiry is charged.
  • An expired gift stays visible on the billing page for seven days, marked with the date it expired, so the change in the projected invoice is not a surprise.
  • Turning Pay as you go on while a gift is running does not end the gift; the card is only charged once the gift is spent.
  • A usage credit is shown for information and netted into the projected invoice estimate on the page. The credit itself is applied by the Hub at invoice time, never twice.

The monthly budget cap below is computed against what will actually be charged, after gifts and credits, so a covered organization does not hit its cap early.

Cap the monthly spend​

From Settings > Budget limits an admin sets a monthly budget. New organizations start at $100 per month, and the limit can be set anywhere between $1 and $1,000. For more than $1,000, contact us through the console.

A notification goes out at 85%, 90% and 100% of the budget. At 100% Mobius pauses new workflow runs, alert ingestion and response actions until the next billing month. Nothing is deleted, and everything resumes when the new month starts or when the limit is raised.

Invoices​

An invoice appears in the Invoices table at the bottom of the billing page once the billing period closes and the invoice is issued. Any row opens its PDF, and the Wazuh Hub holds the full history.

note

Only users in the admins group can view the billing page. Ask an admin for access. Billing notifications are routed in notification settings.