# TechBag — decision guides, full text > Every /browse/ decision guide in full. Generated 2026-09-07 from the same content model that renders the pages. > Vendor-neutral. Nothing gated. India pricing, GST treatment and procurement reality. --- # UEM & MDM — a TechBag decision guide *Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/endpoint-management/uem-mdm - Products compared: 12 The full narrative — hero claim, boundary section, decision variables, cost analysis and failure modes — is on the page itself at https://www.thetechbag.com/browse/endpoint-management/uem-mdm. This file carries the product data and the complete narrowing logic. ## The 12 products ### Jamf Pro — Jamf - **Who it's for:** Apple-heavy fleets that want the deepest macOS/iOS management there is. - **The honest limitation:** Apple-only. No Windows MDM at all; Android is a separate Jamf-for-Mobile bundle, not Jamf Pro. - **Price:** Quote — per device (Jamf publishes no list price) - **Details:** https://www.thetechbag.com/jamf/jamf-pro ### Jamf Now — Jamf - **Who it's for:** Very small Apple shops (under ~25 employees) that need basics, not automation. - **The honest limitation:** Deliberately shallow: no DDM update enforcement, no scripting, no patch policies (those are Jamf Pro). - **Price:** ~$4 — per device/mo (third-party; Jamf lists no price) - **Details:** https://www.thetechbag.com/jamf/jamf-now ### Jamf School — Jamf - **Who it's for:** Apple-only K-12 / education estates (Apple School Manager, Classroom). - **The honest limitation:** Education-tuned and Apple-only; no Jamf-Pro-grade DDM / patch / scripting. - **Price:** Quote — per device (education bundles) - **Details:** https://www.thetechbag.com/jamf/jamf-school ### Microsoft Intune — Microsoft - **Who it's for:** Microsoft-committed shops with a mixed Windows-heavy fleet. - **The honest limitation:** macOS depth historically trails Jamf. And it is NOT in any Office 365 plan (Office 365 ≠ Microsoft 365). - **Price:** $8 — per user/mo (Plan 1; often $0 if bundled) - **Details:** https://www.thetechbag.com/microsoft/microsoft-intune ### Scalefusion UEM — Scalefusion - **Who it's for:** Mixed fleets and rugged/field Android, especially where India data-residency matters. - **The honest limitation:** Vendor pricing page blocks automated reads; confirm current per-tier prices at quote time. - **Price:** ~$2 — per device/mo (10-device min; page fetch blocked — verify) - **Details:** https://www.thetechbag.com/scalefusion/scalefusion-uem ### Hexnode UEM — Hexnode - **Who it's for:** Mixed fleets wanting broad multi-OS coverage at a low entry price. - **The honest limitation:** No India data centre (US/EU/UAE). macOS DDM version floor + Apple-silicon specifics unconfirmed in docs. - **Price:** $2.20 — per device/mo (Pro tier; 15-device min) - **Details:** https://www.thetechbag.com/hexnode/hexnode-uem ### 42Gears SureMDM — 42Gears - **Who it's for:** Rugged/frontline Android + kiosk, with India/US/EU data-region choice or on-prem. - **The honest limitation:** macOS DDM update floor is macOS 15+ (higher than peers). FileVault key-escrow wording unconfirmed. - **Price:** $3.99 — per device/mo (Standard; bundles SureLock/SureFox) - **Details:** https://www.thetechbag.com/42gears/42gears-suremdm ### ManageEngine Endpoint Central — ManageEngine - **Who it's for:** IT teams wanting UEM + patch + software deployment in one, with India DCs or on-prem. - **The honest limitation:** Windows-enrollment specifics (Autopilot/Entra) and macOS DDM depth are datasheet-level, not doc-confirmed. - **Price:** Edition-based — per-endpoint editions (Free / Pro / Enterprise / UEM) - **Details:** https://www.thetechbag.com/manageengine/manageengine-endpoint-central ### miniOrange UEM — miniOrange - **Who it's for:** Identity-first shops (miniOrange IAM/SSO heritage) adding device management. - **The honest limitation:** A newer UEM: advanced macOS (FileVault escrow, DDM, Apple silicon) is not substantiated in public docs. - **Price:** Quote — per device/mo (quote-only; 14-day trial) - **Details:** https://www.thetechbag.com/miniorange/miniorange-uem ### Seqrite mSuite — Seqrite - **Who it's for:** India shops managing Android + iOS mobile only (Quick Heal / Seqrite estate). - **The honest limitation:** Mobile-only — NO macOS and NO Windows. Apple ABM/ADE not evidenced (email/SMS enrollment only). - **Price:** Quote — per device (quote-only) - **Details:** https://www.thetechbag.com/seqrite/seqrite-msuite ### NinjaOne MDM — NinjaOne - **Who it's for:** Teams already on NinjaOne RMM adding Apple/Android MDM in one console. - **The honest limitation:** MDM is an add-on, not standalone; Windows/Linux are RMM-only (not in the MDM module); macOS apps are Apps-&-Books only (no .pkg). - **Price:** Quote — per device (add-on to the NinjaOne platform) - **Details:** https://www.thetechbag.com/ninjaone/ninjaone-mdm ### LogMeIn Miradore (GoTo) — GoTo - **Who it's for:** Mixed fleets wanting a genuinely free-to-start, four-OS MDM (incl. macOS .pkg deploy). - **The honest limitation:** No documented DDM (classic MDM protocol); Finland-built / US-owned, no India data-residency confirmed. - **Price:** $3.30 — per device/mo (Premium; $4.75 Premium+) - **Details:** https://www.thetechbag.com/goto/goto-mdm ## Why each constraint rules out what it does **India data residency.** Rules out Jamf Pro, Jamf Now, Jamf School, Microsoft Intune, Hexnode UEM, NinjaOne MDM and LogMeIn Miradore (GoTo) — no India data residency; miniOrange UEM — India HQ, but data residency unconfirmed. That leaves Scalefusion UEM, 42Gears SureMDM, ManageEngine Endpoint Central and Seqrite mSuite. **Mostly Apple.** Rules out Jamf Now, miniOrange UEM and Seqrite mSuite — Apple management too shallow for an Apple-heavy fleet. That leaves Jamf Pro, Jamf School, Microsoft Intune, Scalefusion UEM, Hexnode UEM, 42Gears SureMDM, ManageEngine Endpoint Central, NinjaOne MDM and LogMeIn Miradore (GoTo). **Mostly Android.** Rules out Jamf Pro, Jamf Now and Jamf School — no Android management. That leaves Microsoft Intune, Scalefusion UEM, Hexnode UEM, 42Gears SureMDM, ManageEngine Endpoint Central, miniOrange UEM, Seqrite mSuite, NinjaOne MDM and LogMeIn Miradore (GoTo). **Windows in the fleet.** Rules out Jamf Pro, Jamf Now and Jamf School — Apple-only; Seqrite mSuite and NinjaOne MDM — mobile-only, no desktop. That leaves Microsoft Intune, Scalefusion UEM, Hexnode UEM, 42Gears SureMDM, ManageEngine Endpoint Central, miniOrange UEM and LogMeIn Miradore (GoTo). **A genuinely mixed fleet.** Rules out Jamf Pro, Jamf Now and Jamf School — Apple only; Seqrite mSuite and NinjaOne MDM — mobile only, no desktop. That leaves Microsoft Intune, Scalefusion UEM, Hexnode UEM, 42Gears SureMDM, ManageEngine Endpoint Central, miniOrange UEM and LogMeIn Miradore (GoTo). **Kiosk and dedicated devices.** Rules out Jamf Pro, Jamf Now and Jamf School — Apple-only, no Android dedicated (COSU) devices. That leaves Microsoft Intune, Scalefusion UEM, Hexnode UEM, 42Gears SureMDM, ManageEngine Endpoint Central, miniOrange UEM, Seqrite mSuite, NinjaOne MDM and LogMeIn Miradore (GoTo). **Fleets of 10–200 devices.** Rules nothing out on published terms. **Fleets of 200–2,000 devices.** Rules out Jamf Now — built for small shops (Jamf positions it for teams up to ~50 devices). That leaves Jamf Pro, Jamf School, Microsoft Intune, Scalefusion UEM, Hexnode UEM, 42Gears SureMDM, ManageEngine Endpoint Central, miniOrange UEM, Seqrite mSuite, NinjaOne MDM and LogMeIn Miradore (GoTo). **Fleets above 2,000 devices.** Rules out Jamf Now — built for small shops (Jamf positions it for teams up to ~50 devices). That leaves Jamf Pro, Jamf School, Microsoft Intune, Scalefusion UEM, Hexnode UEM, 42Gears SureMDM, ManageEngine Endpoint Central, miniOrange UEM, Seqrite mSuite, NinjaOne MDM and LogMeIn Miradore (GoTo). **Corporate-owned, fully managed.** Rules nothing out. Every product here enrols corporate-owned devices in a fully managed state — Android device owner and/or Apple supervised via Automated Device Enrolment — so there is no eliminating power and no chip. **BYOD, personal devices.** Rules nothing out on verified documentation. Every Android-capable product supports the work profile, and Jamf Pro and Jamf School document Apple User Enrolment. Jamf Now's User Enrolment support is not documented either way, so it is not ruled out. **Mixed corporate and BYOD.** Rules nothing out: the same consoles run fully managed and work-profile or User Enrolment devices side by side. **Small-estate fit, beyond the published minimums.** The published floors are low — Hexnode 15 devices, Scalefusion 10, 42Gears none, ManageEngine free to 25 — so at 10–200 only NinjaOne's ~50-device platform minimum and Jamf Pro's 25-device minimum bite, and only at the bottom of the band. Where enterprise-tier pricing makes a product a poor fit for a small estate is delivery-team judgement: [TechBag to confirm]. **Above 2,000 devices — what is and isn't proven.** Seqrite mSuite is proven at volume (Fino Payments Bank: 410 branches, 25,000+ banking points) and NinjaOne's platform runs estates of 100,000+ endpoints. miniOrange UEM and LogMeIn Miradore are marked unverified rather than ruled out: vendor claims of scale, no documented deployment at that volume. The tool stamps them, it does not eliminate them. ## Your situation ### All-Apple, 200–2,000 devices, dedicated IT **Shortlist:** Jamf Pro, Microsoft Intune, Scalefusion UEM **Why:** Apple depth (DDM, FileVault escrow, patch, scripting) is the deciding variable; Jamf Pro is the benchmark. **Trade-off:** Jamf is Apple-only and priced for it; if you also run Windows, Intune consolidates at the cost of some Mac depth. ### Android field devices — retail, delivery, manufacturing, rugged **Shortlist:** Scalefusion UEM, 42Gears SureMDM, Hexnode UEM **Why:** Dedicated/COSU kiosk mode + rugged-OEM support + zero-touch are what matter; the India-built vendors lead here. **Trade-off:** 42Gears/Scalefusion go deep on rugged/kiosk; if the fleet is also Apple-heavy, weigh macOS depth separately. ### Mixed Windows + Apple + Android, existing Microsoft commitment **Shortlist:** Microsoft Intune, Scalefusion UEM, Hexnode UEM **Why:** If you hold M365 E3/E5/Business Premium, Intune is likely already paid for — marginal cost near zero. **Trade-off:** Intune's macOS is good-not-Jamf; if Macs are your crown jewels, pair Intune (Win) with Jamf (Mac) or go Scalefusion. ### BYOD-heavy, employees resist agents on personal phones **Shortlist:** Microsoft Intune, Scalefusion UEM, Hexnode UEM **Why:** Android work profile + Apple User Enrollment keep the personal side cryptographically untouched — no full device control. **Trade-off:** MAM-without-enrollment protects apps only; if you need device compliance too, you need enrollment consent. ### Kiosk / dedicated — signage, POS, self-service **Shortlist:** 42Gears SureMDM, Scalefusion UEM, Hexnode UEM **Why:** COSU/dedicated lock-down and single-app mode are the whole job; the rugged/kiosk specialists win. **Trade-off:** Exiting Android dedicated/fully-managed requires a factory reset — plan provisioning accordingly (see enrollment). ### Regulated sector, data residency or on-prem required **Shortlist:** 42Gears SureMDM, ManageEngine Endpoint Central, Scalefusion UEM **Why:** Verified India data region and/or on-prem is the gating requirement before any feature comparison. **Trade-off:** India-built vendors satisfy residency; confirm each vendor's exact hosting region and on-prem terms at quote. ### Small team, no dedicated IT **Shortlist:** LogMeIn Miradore (GoTo), ManageEngine Endpoint Central, Jamf Now **Why:** A genuine free/low tier and simplicity matter more than depth: Miradore (≤50 free), ManageEngine (≤25 free), Jamf Now (≤3 free, Apple). **Trade-off:** Free tiers are capped and shallow; you'll outgrow them — but they prove the fit before you spend. ### Devices already bought retail — the recovery path **Shortlist:** Microsoft Intune, Scalefusion UEM, Hexnode UEM **Why:** Zero-touch/ADE only works for devices bought through an approved channel. Retail units can't be zero-touch enrolled without a wipe. **Trade-off:** Any UEM can still MANAGE them — you just lose zero-touch. Manual enrollment (or a wipe-and-reprovision) is the recovery path. --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/endpoint-management/uem-mdm* --- # RMM & Patch — a TechBag decision guide *Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/endpoint-management/rmm-patch - Products compared: 17 The full narrative — hero claim, boundary section, decision variables, cost analysis and failure modes — is on the page itself at https://www.thetechbag.com/browse/endpoint-management/rmm-patch. This file carries the product data and the complete narrowing logic. ## The 17 products ### Qualys Patch Management — Qualys - **Who it's for:** Estates where patching is driven by VULNERABILITY RISK rather than by a monthly update cycle. Qualys finds the vulnerability and fixes it from the same agent and the same console, so the prioritisation and the remediation share one risk model instead of being reconciled across two tools — which is the handover where most remediation programmes actually leak. The India platform is Pune-engineered, which matters for a residency conversation. - **The honest limitation:** This is not an RMM: no PSA, no ticketing, no remote-control-led workflow, no mobile management. If you want one console for helpdesk and endpoint operations, look at NinjaOne or Atera instead. It is also quote-only and sold as part of a platform, so the sizing conversation is about the whole TruRisk entitlement rather than a per-device patch price. - **Price:** Quote — per asset / year, quoted — sold on the Qualys Enterprise TruRisk Platform alongside VMDR rather than as a standalone RMM; TruRisk Eliminate adds mitigation where no patch exists - **Details:** https://www.thetechbag.com/qualys/qualys-patch-management ### NinjaOne Patch Management — NinjaOne - **Who it's for:** Teams that want patching with real deployment discipline — approval rings so updates reach a pilot group before the fleet, scheduling that respects maintenance windows, and reporting an auditor will accept. Cross-platform including Linux, with a third-party application catalogue, which is the part most native tooling handles badly. - **The honest limitation:** It is a capability of the NinjaOne platform, not a standalone product, so you are really evaluating NinjaOne — see the NinjaOne RMM entry for the commercial shape, including the ~50-device floor and quote-only pricing. If you want patching WITHOUT an RMM platform underneath it, Action1 or Qualys are the cleaner comparisons. - **Price:** Quote — per device / month, quoted — the patching capability within the NinjaOne platform rather than a separate purchase; approval rings and scheduled deployment across Windows, macOS and Linux plus a third-party application catalogue - **Details:** https://www.thetechbag.com/ninjaone/ninjaone-patch-management ### SuperOps Patch Management — SuperOps - **Who it's for:** Mixed Windows, macOS and Linux estates that want one patch policy across all three rather than a side process for whichever platform the tool half-covers — with maintenance windows per client, failed-patch visibility, and failures that raise tickets because the service desk is in the same product. - **The honest limitation:** The third-party application catalogue is thinner than NinjaOne's, which has the broadest in the category. Build your top-20 application list and check it during the trial — that single test decides this purchase, and a miss means manual patching forever. The 100-endpoint minimum is hard, and there is no confirmed India data region. - **Price:** $1.50 (≈ ₹125) — per endpoint / month at the 100-endpoint minimum, PUBLISHED — patching is included in both plans rather than gated behind a tier, and the same rate carries the RMM and the service desk - **Details:** https://www.thetechbag.com/superops/superops-patch-management ### Action1 Software Deployment — Action1 - **Who it's for:** Teams whose real problem is not patching what is installed but controlling WHAT is installed — pushing a new application to a fleet, updating one that is not in any catalogue, or removing software that should not be there. The uninstall half matters more than vendors usually admit: unremoved software is unpatched attack surface that nobody is tracking. - **The honest limitation:** Windows-first — Linux is not a documented patching target here, so mixed estates need something else alongside. And it is one capability of the Action1 platform rather than a standalone purchase; the free-to-200-endpoints tier and per-endpoint pricing above it are Action1’s, not this feature’s. - **Price:** Quote — per endpoint / month above the free tier — the same entitlement as the rest of Action1, so deployment is not a separate line item. Deploy, install, update AND uninstall applications, including custom packages - **Details:** https://www.thetechbag.com/action1/action1-software-deployment ### Action1 Vulnerability Remediation — Action1 - **Who it's for:** Organisations under CERT-In or sectoral pressure to demonstrate that vulnerabilities are not merely FOUND but FIXED, within a defined window. Most estates run a scanner and a separate deployment tool, and the gap between them is where remediation programmes fail — findings get exported, assigned, and quietly age. One tool that does both removes the handover entirely, and the free tier means you can prove it works before spending anything. - **The honest limitation:** Windows-first, so Linux and macOS-heavy estates need something alongside it. Its vulnerability detection is not as deep as a dedicated scanner — if you need the breadth of Qualys or Tenable for the FINDING half, use Action1 for the fixing and accept two tools. And the free tier, while genuinely generous, is a starting point rather than a permanent answer at scale. - **Price:** Quote — per endpoint / month above the free tier. Continuously discovers vulnerabilities and remediates them from the same agent — find and fix in one tool rather than two - **Details:** https://www.thetechbag.com/action1/action1-vulnerability-remediation ### LogMeIn Central — GoTo / LogMeIn - **Who it's for:** Teams already standardised on LogMeIn for remote access who want monitoring and patching in the same console rather than adding a second platform. The remote-access heritage is genuine depth rather than a bolted-on afterthought, and for a helpdesk-led operation that is the workflow people actually live in. - **The honest limitation:** Remote-access-first rather than patch-first: the patching is competent for Windows and third-party applications and it is not the reason anyone buys this. No documented Linux patching, no mobile management, no PSA. If patching is your primary requirement rather than remote access, Action1, NinjaOne or ManageEngine are stronger answers and cheaper ones. - **Price:** Quote — per device, quoted by edition — the veteran cloud endpoint-management platform: remote access at fleet scale plus monitoring, Windows and third-party patch management, and LogMeIn Antivirus as a paid module - **Details:** https://www.thetechbag.com/goto/goto-central ### NinjaOne RMM — NinjaOne - **Who it's for:** Internal IT and MSPs wanting the broadest Windows / macOS / Linux RMM — patching, scripting, remote access — with MDM, backup and endpoint security as add-ons in the same console. - **The honest limitation:** Quote-only with a ~50-device floor; per-device billing climbs linearly with the fleet, and MDM, backup and endpoint security are each a separate paid add-on. - **Price:** Quote — per device/mo — reported $1.50–3.75; ~50-device minimum - **Details:** https://www.thetechbag.com/ninjaone/ninjaone-rmm ### Atera RMM — Atera - **Who it's for:** Small IT teams running many devices: headcount, not fleet size, sets the bill — RMM, patching, remote access and a PSA in one. - **The honest limitation:** Every login is a paid seat (no read-only tier); AI Copilot and Network Discovery add $29 each per technician; third-party patching rides on WinGet / Chocolatey / Homebrew / APT rather than a curated catalog. - **Price:** $149 (≈ ₹12,367) — per technician/mo, unlimited devices (Professional, annual; Expert $189, Master $219) - **Details:** https://www.thetechbag.com/atera/atera-rmm ### SuperOps RMM — SuperOps - **Who it's for:** Small-to-mid MSPs (roughly 1–25 technicians) and internal IT of similar scale who want a price they can read off a public page and the service desk in the box rather than as a second contract — India-built in Chennai, so support hours match the Indian working day. - **The honest limitation:** The third-party application catalog is thinner than NinjaOne's — build your top-20 application list and check it in the trial, because that single test decides this purchase. The 100-endpoint minimum is hard, there is no confirmed India data region and no self-hosted option, and no analyst quadrant placement is possible for MSP-centric RMM vendors. - **Price:** $1.50 (≈ ₹125) — per endpoint/mo at the 100-endpoint minimum — PUBLISHED; $1.40 (101–500), $1.30 (501–1,000), $1.20 (1,000+). Prime Plus $2.50 early-bird (list $3.00) → $2.00 - **Details:** https://www.thetechbag.com/superops/superops-rmm ### N-able N-central — N-able - **Who it's for:** MSPs running many client estates that must be genuinely separated — architectural multi-tenancy with per-client policy and role-based access, plus SNMP network-device monitoring that can retire a second monitoring system, across Windows, macOS, Linux and cloud. - **The honest limitation:** The heavyweight of N-able's TWO platforms, and choosing wrongly is the expensive mistake here: it takes weeks rather than days to stand up because the policy is designed, not switched on. If you manage one estate, N-sight is the right answer. Quote-only with no published rate card, and the Bengaluru GCC does not answer data residency. - **Price:** Quote — per device / month, quote-only — third parties report ~$1.50–3.50 by volume, term and bundle, with an Essentials edition from ~$1.05; those are REPORTED figures, not N-able's own - **Details:** https://www.thetechbag.com/n-able/n-able-n-central ### N-able N-sight — N-able - **Who it's for:** Support-led shops and lean IT teams with one estate (or a handful they need not wall off) who want monitoring, cross-OS patching, ticketing and a genuinely strong attended and unattended remote-support workflow — working in days rather than weeks. - **The honest limitation:** Lighter multi-tenancy than N-central, and SNMP network-device monitoring is not a strength — if either is load-bearing, buy N-central and accept the longer implementation. Automation is shallower than N-central's policy engine. Quote-only, like the rest of the portfolio. - **Price:** Quote — per device / month, quote-only — reported below N-central; both platforms share the same patch engine, so Windows, macOS and Linux coverage is identical - **Details:** https://www.thetechbag.com/n-able/n-able-n-sight ### Action1 — Action1 - **Who it's for:** Patch-first teams: Windows / macOS / Linux patching, software deployment and vulnerability remediation, free until the 201st endpoint. - **The honest limitation:** Patch-and-deploy first, RMM second — monitoring and alerting are lighter than NinjaOne or Atera, there is no PSA, and the macOS third-party catalog (~30 apps) is far narrower than Windows. - **Price:** Quote — per endpoint/mo beyond 200 (Growth, annual) + a support subscription - **Details:** https://www.thetechbag.com/action1/action1-patch-management ### Action1 RMM & Remote Access — Action1 - **Who it's for:** Lean IT teams and MSPs that want remote control and endpoint visibility on the SAME agent that already patches the fleet — one tool, one agent, no second console to stand up. The case is efficiency for endpoint-centric teams rather than breadth. - **The honest limitation:** These are the remote ESSENTIALS on a patch-first platform, NOT a full RMM+PSA — Action1’s own positioning. No ticketing, no PSA or billing, no SNMP or network-device monitoring and no mobile admin app. NinjaOne, Atera and ManageEngine Endpoint Central do materially more here, and TechBag sells all three. - **Price:** Quote — per endpoint / month above the free tier — the same entitlement as the rest of Action1, so the remote-management features are not a separate line item. Real-time monitoring and alerts, browser-based remote desktop, remote PowerShell/Bash scripting and multi-tenant views - **Details:** https://www.thetechbag.com/action1/action1-rmm-remote-access ### ManageEngine Endpoint Central — ManageEngine - **Who it's for:** Teams wanting RMM-grade patching and software deployment inside a full UEM — on-prem, or India-hosted. - **The honest limitation:** Windows-first console heritage shows; each edition includes one technician (more are paid), and multi-tenancy is the separate Endpoint Central MSP edition, not a switch. - **Price:** $1.33–2.83 (≈ ₹110) — per endpoint/mo equivalent — Professional → Security, per 50 endpoints a year, on-prem - **Details:** https://www.thetechbag.com/manageengine/manageengine-endpoint-central ### Splashtop AEM — Splashtop - **Who it's for:** Teams already on Splashtop remote access adding real-time OS and third-party patching, CVE visibility and scripting — same agent, no second tool. - **The honest limitation:** Patches Windows and macOS only (Linux is remote-control only), 100-endpoint minimum, and monitoring / alerting depth sits below a full RMM. - **Price:** Under $1 (≈ ₹83) — per endpoint/mo (vendor-stated ceiling); 100-endpoint minimum; one technician licence per 10 endpoints - **Details:** https://www.thetechbag.com/splashtop/splashtop-aem ### LogMeIn Resolve — GoTo / LogMeIn - **Who it's for:** Helpdesk-first teams wanting remote support, ticketing, patching and a built-in MDM in one light console. - **The honest limitation:** Windows and macOS patching only; monitoring and scripting are lighter than NinjaOne or Atera, and the plan lines moved with the LogMeIn rebrand — confirm the current tier before quoting. - **Price:** $2.75 (≈ ₹228) — per Pro device/mo (Starter, annual); Standard $190/mo for 3 agents + 100 Pro devices - **Details:** https://www.thetechbag.com/goto/goto-resolve ### TeamViewer Remote Management — TeamViewer - **Who it's for:** TeamViewer estates adding monitoring, asset and patch management to the remote-access agent already on every machine. - **The honest limitation:** Quote-only with a 100-endpoint minimum; patching is Windows / macOS only and starts at the Advanced tier; remote-access-first, so monitoring and scripting are add-on-grade beside a dedicated RMM. - **Price:** Quote — per endpoint, annual (TeamViewer ONE Standard / Advanced / Enterprise; patching from Advanced) - **Details:** https://www.thetechbag.com/teamviewer/teamviewer-remote-management ## Why each constraint rules out what it does **On-prem or India data residency.** Rules out Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, Atera RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, Splashtop AEM, LogMeIn Resolve and TeamViewer Remote Management — cloud-only, no on-prem and no India data region. That leaves ManageEngine Endpoint Central. **Per technician, unlimited devices.** Rules out Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM, LogMeIn Resolve and TeamViewer Remote Management — priced per device / endpoint, not per technician. That leaves Atera RMM. **Per device or endpoint.** Rules out Atera RMM — priced per technician, not per device. That leaves Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM, LogMeIn Resolve and TeamViewer Remote Management. **Free to start.** Rules out Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, LogMeIn Central, NinjaOne RMM, Atera RMM, SuperOps RMM, N-able N-central, N-able N-sight, Splashtop AEM and TeamViewer Remote Management — no free tier (trial only). That leaves Action1 Software Deployment, Action1 Vulnerability Remediation, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central and LogMeIn Resolve. **Ticketing or PSA in the console.** Rules out Qualys Patch Management, NinjaOne Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM and TeamViewer Remote Management — no ticketing in the console (a separate service-desk product). That leaves SuperOps Patch Management, NinjaOne RMM, Atera RMM, SuperOps RMM and LogMeIn Resolve. **Backup from the same vendor.** Rules out Qualys Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, SuperOps RMM, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM and LogMeIn Resolve — no backup product; Atera RMM — backup via third-party integration, not a vendor SKU. That leaves NinjaOne Patch Management, NinjaOne RMM, N-able N-central, N-able N-sight and TeamViewer Remote Management. **Linux in the fleet.** Rules out Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, Splashtop AEM, LogMeIn Resolve and TeamViewer Remote Management — patches Windows and macOS only (Linux is remote-control at best). That leaves Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, NinjaOne RMM, Atera RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access and ManageEngine Endpoint Central. **Phones and tablets in scope.** Rules out Qualys Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, Splashtop AEM and TeamViewer Remote Management — no mobile device management; Atera RMM — mobile only through a separate Miradore subscription and console. That leaves NinjaOne Patch Management, SuperOps Patch Management, NinjaOne RMM, SuperOps RMM, ManageEngine Endpoint Central and LogMeIn Resolve. **Under 100 endpoints.** Rules out SuperOps Patch Management, SuperOps RMM, Splashtop AEM and TeamViewer Remote Management — published 100-endpoint minimum. That leaves Qualys Patch Management, NinjaOne Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, Atera RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central and LogMeIn Resolve. **2,000+ endpoints.** Rules nothing out on published terms. **Separate business units or tenants.** Rules out LogMeIn Central and ManageEngine Endpoint Central — multi-tenant is the separate Endpoint Central MSP edition; Atera RMM — IT-department plans are single-organisation; multi-tenant is the MSP plan. That leaves Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, NinjaOne RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, Splashtop AEM, LogMeIn Resolve and TeamViewer Remote Management. **Windows and macOS in the fleet.** Rules nothing out. All seven patch Windows and macOS. What differs is depth: the macOS third-party catalog ranges from hundreds of apps (LogMeIn Resolve lists ~100 on macOS, TeamViewer and ManageEngine hundreds across both) down to roughly 30 on Action1, and Atera's depends on what Homebrew carries. **Remote access included.** Rules nothing out — every product here ships remote control (NinjaOne via Splashtop / ScreenConnect in its bundle, Atera via Splashtop and AnyDesk, Action1 built in, ManageEngine built in, and the three remote-first vendors natively). The double-buy question is the other way round: if you already hold one of the three remote tools, their RMM tier may be enough. **Scripting depth.** Rules nothing out on documentation — all seven run scripts across endpoints. Depth differs: NinjaOne, Atera (library + AI-generated) and Action1 document automation at policy level; Splashtop AEM and Resolve document scripting; TeamViewer's is thinnest. Where the line falls for your runbooks is a PoC question, not a datasheet one. **100–2,000 endpoints.** Rules nothing out: the published minimums (Splashtop AEM and TeamViewer ONE at 100, NinjaOne ~50 reported) are cleared, and no product publishes a ceiling in this band. Which console starts to strain first is delivery-team experience: [TechBag to confirm]. **Endpoint security from the same vendor.** Not offered as a chip because the line between 'sells an EDR SKU' and 'integrates one' is blurred in every datasheet. NinjaOne resells endpoint security and integrates CrowdStrike / SentinelOne / Bitdefender; ManageEngine's Security edition adds vulnerability and ransomware controls; TeamViewer and Splashtop sell antivirus add-ons; Atera resells third-party AV. Read the agent-coexistence block before treating any of it as a second EDR. ## Your situation ### Internal IT, 200–2,000 mostly-Windows endpoints, no MSP **Shortlist:** NinjaOne RMM, Action1, ManageEngine Endpoint Central **Why:** Catalog-based patching with approval rings and a console built for one organisation; NinjaOne for breadth, Action1 for patch-first simplicity, ManageEngine if UEM depth or on-prem matters. **Trade-off:** NinjaOne is quote-only with a ~50-device floor; Action1's monitoring is lighter than a full RMM; ManageEngine's console carries its Windows-first heritage. ### Two technicians, 800 devices — headcount is tiny, the fleet is not **Shortlist:** Atera RMM, Action1, ManageEngine Endpoint Central **Why:** Per-technician pricing (Atera) or a free-to-200 / per-50-endpoint model makes the bill track the team, not the estate. **Trade-off:** Atera charges for every login and its add-ons stack; Action1 jumps to $4 per endpoint beyond 200 plus support; ManageEngine charges for technicians beyond the first. ### Patch compliance is the whole job — audits ask for proof **Shortlist:** Action1, ManageEngine Endpoint Central, NinjaOne RMM **Why:** Vulnerability-to-patch views, per-CVE evidence and exportable reports; Action1 and ManageEngine are built around the patch record, NinjaOne reports across the estate. **Trade-off:** An RMM's 'patched' is not a UEM's 'compliant' — if the audit asks for device state (encryption, configuration, enrolment), you still need a UEM beside it. ### Windows + macOS + Linux servers, one console **Shortlist:** NinjaOne RMM, Atera RMM, Action1 **Why:** Documented Linux patching — NinjaOne and Action1 by catalog, Atera by APT on Ubuntu / Debian — alongside Windows and macOS. **Trade-off:** macOS third-party coverage varies widely (Action1 ~30 apps; Atera depends on Homebrew); test your top 20 apps on every OS in the PoC. ### You already pay for Splashtop, TeamViewer or LogMeIn **Shortlist:** Splashtop AEM, TeamViewer Remote Management, LogMeIn Resolve **Why:** Their RMM tiers ride the agent you already run — no second agent, no second contract, and the double-buy disappears. **Trade-off:** All three patch Windows and macOS only, two carry 100-endpoint minimums, and monitoring / scripting depth is below NinjaOne, Atera or Action1. ### Separate business units that must not see each other **Shortlist:** NinjaOne RMM, Action1, Atera RMM **Why:** NinjaOne and Action1 document scoped organisations in one console; Atera does it on the MSP plan. **Trade-off:** On Atera's IT-department plans and on Endpoint Central (non-MSP) the separation is a different plan or edition — price that SKU, not the one on the website. ### UEM and RMM in one console — phones too **Shortlist:** ManageEngine Endpoint Central, NinjaOne RMM, LogMeIn Resolve **Why:** ManageEngine's UEM edition, NinjaOne's MDM add-on and Resolve's built-in MDM put mobile beside the RMM agent. **Trade-off:** Depth differs sharply: ManageEngine is a full UEM, NinjaOne MDM is Apple / Android without Windows MDM, Resolve MDM is light — see the UEM & MDM guide for the mobile side. ### Regulated — on-prem or India data residency is mandatory **Shortlist:** ManageEngine Endpoint Central **Why:** The only product here with an on-premises edition and an India data centre; the other six are cloud-only in US / EU / other regions. **Trade-off:** One survivor means no competitive tension on price — TechBag negotiates edition and technician count instead, and checks whether a cloud region you can accept reopens the field. --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/endpoint-management/rmm-patch* --- # Remote Access & Support — a TechBag decision guide *Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/endpoint-management/remote-access - Products compared: 8 The full narrative — hero claim, boundary section, decision variables, cost analysis and failure modes — is on the page itself at https://www.thetechbag.com/browse/endpoint-management/remote-access. This file carries the product data and the complete narrowing logic. ## The 8 products ### TeamViewer Remote — TeamViewer - **Who it's for:** The broadest cross-platform remote access there is — one tool for staff remote work, attended support and unattended machines, Windows to Linux to mobile. - **The honest limitation:** Licensed by named users with a fixed number of concurrent channels (Premium: one channel), session recordings are kept locally, and the consumer-grade free tier blocks you the moment it suspects commercial use. - **Price:** $24.90–229.90 (≈ ₹2,067) — per month, annual — Remote Access · Business · Premium · Corporate (licensed users + concurrent channels) - **Details:** https://www.thetechbag.com/teamviewer/teamviewer-remote ### TeamViewer Tensor — TeamViewer - **Who it's for:** Enterprises standardising TeamViewer with SSO, conditional access by device and user group, and a central audit log a regulator can read. - **The honest limitation:** Quote-only; conditional access is in Tensor Pro / Unlimited only; no credential vault or per-session approval workflow — policy, not privileged access. - **Price:** Quote — enterprise licence — SSO, conditional access, central auditability / event log, session recording - **Details:** https://www.thetechbag.com/teamviewer/teamviewer-tensor ### Splashtop Business Access — Splashtop - **Who it's for:** Staff reaching their own office PCs from anywhere — the remote-work purchase, per user, at the lowest published price here. - **The honest limitation:** Unattended access to your own machines only — no attended support sessions; session recording is local and only on Pro / Performance; on-prem is the separate Splashtop On-Prem product. - **Price:** $6–13 (≈ ₹498) — per user / month, annual — Solo $6 · Pro $8.25 · Performance $13 (Pro / Performance add session recording) - **Details:** https://www.thetechbag.com/splashtop/splashtop-business-access ### Splashtop Remote Support / SOS — Splashtop - **Who it's for:** Helpdesks and MSP-style teams: attended sessions on demand (SOS) and unattended access to managed endpoints (Remote Support), billed per concurrent technician. - **The honest limitation:** A technician tool, not a remote-work licence; cloud session recording and mobile support vary by plan line and are not documented for every SKU — confirm before quoting; on-prem is the separate Splashtop On-Prem product. - **Price:** $264–396 (≈ ₹21,912) — per concurrent technician / year — SOS is attended on demand; Remote Support adds unattended endpoints - **Details:** https://www.thetechbag.com/splashtop/splashtop-remote-support ### AnyDesk — AnyDesk - **Who it's for:** Fast sessions on poor links (the DeskRT codec), a self-hosted On-Premises edition, and published tiers that scale named users, devices and concurrent sessions together. - **The honest limitation:** Session recordings are always stored locally on the recording side, there is no central audit trail on the standard tiers, annual billing only, and the free tier is personal use only. - **Price:** $14.90–59.90 (≈ ₹1,237) — per month, annual only — Solo · Standard (20 users / 500 devices / 20 concurrent) · Advanced (100 / 1,000 / 50); Ultimate on quote - **Details:** https://www.thetechbag.com/anydesk/anydesk-remote-access ### LogMeIn Rescue — GoTo / LogMeIn - **Who it's for:** Enterprise helpdesks: attended support at scale with audit-ready session logging, disruption-free unattended access for kiosks and signage, and granular permissions. - **The honest limitation:** Per-technician seats at a premium price, mobile iOS / Android control is a paid add-on, and it is a support tool — not licensed for staff remote work. - **Price:** ~$130 (≈ ₹10,790) — per technician / month, annual (~$1,299–1,560 a year); Mobile Support add-on ~$37.50 per seat / month - **Details:** https://www.thetechbag.com/goto/goto-rescue ### LogMeIn Resolve — GoTo / LogMeIn - **Who it's for:** Small IT teams wanting remote support, ticketing, patching and MDM in one light console, with automatic session recording on by default. - **The honest limitation:** Licensed by agents plus Pro devices (not concurrent technicians); mobile support is a $20 / month add-on; remote-work use for staff is not documented; plan lines moved with the LogMeIn rebrand. - **Price:** Free–$2.75 (≈ ₹228) — free plan (3 agents, 5 Pro devices); Starter $2.75 per Pro device / month annual; Standard $190 / month (3 agents + 100 devices) - **Details:** https://www.thetechbag.com/goto/goto-resolve ### BeyondTrust Remote Support — BeyondTrust - **Who it's for:** Regulated support desks: forensic session recording, approval workflows, credential injection from a vault, Jump agents for unattended, and an on-prem appliance option. - **The honest limitation:** Quote-only and priced like the privileged-access product it is; overkill for a five-person helpdesk; third-party vendor access is properly its sibling, Privileged Remote Access, not this SKU. - **Price:** Quote — per concurrent technician, annual (one licence ≈ 150 managed assets); cloud or B Series appliance on-prem - **Details:** https://www.thetechbag.com/beyondtrust/beyondtrust-remote-support ## Why each constraint rules out what it does **Approval workflow and credential vault.** Rules out TeamViewer Remote, TeamViewer Tensor, Splashtop Business Access, Splashtop Remote Support / SOS, AnyDesk, LogMeIn Rescue and LogMeIn Resolve — no per-session approval workflow or credential injection (policy controls at most). That leaves BeyondTrust Remote Support. **Central, tamper-evident session recording.** Rules out TeamViewer Remote, Splashtop Business Access and AnyDesk — recordings are stored locally on the technician or host side. That leaves TeamViewer Tensor, Splashtop Remote Support / SOS, LogMeIn Rescue, LogMeIn Resolve and BeyondTrust Remote Support. **Concurrent-technician licensing.** Rules out TeamViewer Remote, Splashtop Business Access, AnyDesk and LogMeIn Rescue — named users (with or without concurrent channels), not concurrent seats; LogMeIn Resolve — priced per agent and per device, not per concurrent technician. That leaves TeamViewer Tensor, Splashtop Remote Support / SOS and BeyondTrust Remote Support. **Attended support.** Rules out Splashtop Business Access — unattended access to your own machines only. That leaves TeamViewer Remote, TeamViewer Tensor, Splashtop Remote Support / SOS, AnyDesk, LogMeIn Rescue, LogMeIn Resolve and BeyondTrust Remote Support. **Staff remote work.** Rules out Splashtop Remote Support / SOS, LogMeIn Rescue and BeyondTrust Remote Support — a technician support tool, licensed per technician, not per employee. That leaves TeamViewer Remote, TeamViewer Tensor, Splashtop Business Access, AnyDesk and LogMeIn Resolve. **Self-hosted or on-prem.** Rules out TeamViewer Remote, LogMeIn Rescue and LogMeIn Resolve — cloud-only. That leaves TeamViewer Tensor, Splashtop Business Access, Splashtop Remote Support / SOS, AnyDesk and BeyondTrust Remote Support. **Vendor-published list price.** Rules out TeamViewer Tensor and BeyondTrust Remote Support — quote-only. That leaves TeamViewer Remote, Splashtop Business Access, Splashtop Remote Support / SOS, AnyDesk, LogMeIn Rescue and LogMeIn Resolve. **Supporting iOS and Android screens.** Rules out Splashtop Business Access — desktop access only, no mobile device support. That leaves TeamViewer Remote, TeamViewer Tensor, Splashtop Remote Support / SOS, AnyDesk, LogMeIn Rescue, LogMeIn Resolve and BeyondTrust Remote Support. **Unattended access to managed machines.** Rules nothing out: all eight reach an unattended machine through an installed agent (TeamViewer host, Splashtop streamer, AnyDesk, Rescue unattended access, Resolve, BeyondTrust Jump agent). What differs is who may reach it and what is recorded — the audit chips above. **Performance on poor connections.** Rules nothing out on documentation — every vendor claims it. AnyDesk documents its DeskRT codec, Splashtop its high-frame-rate engine, TeamViewer adaptive quality. The honest test is your worst branch link at 4 pm; which tool wins it for your sites is [TechBag to confirm]. **Already bundled in your RMM.** Not a chip because it removes nothing here — it removes the purchase. NinjaOne and Atera bundle Splashtop; Action1 and ManageEngine Endpoint Central include remote control; LogMeIn Resolve is an RMM with support built in. If an RMM is on the bill, its remote tool may already cover attended and unattended support — only the audit and privileged cases justify a second tool. ## Your situation ### A five-person helpdesk doing attended support all day **Shortlist:** Splashtop Remote Support / SOS, LogMeIn Resolve, AnyDesk **Why:** Attended sessions on demand at published prices; Splashtop bills per concurrent technician, Resolve per agent with a free plan, AnyDesk per named user with concurrent sessions included. **Trade-off:** Recordings are local on AnyDesk and plan-dependent on Splashtop — fine until an audit asks; then the next shortlist applies. ### Staff need their own office PCs from home **Shortlist:** Splashtop Business Access, TeamViewer Remote, AnyDesk **Why:** Licensed per user for unattended access to their own machines — Splashtop Business Access is built for exactly this at the lowest published price. **Trade-off:** Support tools (Rescue, BeyondTrust, Splashtop SOS) are the wrong licence for this — per technician, not per employee. And every tool here needs MFA enforced on day one. ### BFSI or regulated — a regulator will ask for the recording **Shortlist:** BeyondTrust Remote Support, TeamViewer Tensor, LogMeIn Rescue **Why:** Central, tamper-evident recordings and audit logs; BeyondTrust adds per-session approval and credential injection from a vault, Tensor adds conditional access and a central event log, Rescue audit-ready logging. **Trade-off:** BeyondTrust is priced as privileged access; Tensor is a quote; Rescue is per technician at a premium. The cheapest tool on the page does the same session — and cannot answer the regulator. ### You already run an RMM **Shortlist:** Splashtop Remote Support / SOS, LogMeIn Resolve **Why:** NinjaOne and Atera bundle Splashtop; Resolve is itself an RMM with support inside. The remote tool may already be on the bill. **Trade-off:** The bundled tool covers attended and unattended support; it does not cover privileged approval or vendor access — if you need those, one additional tool, not a replacement. ### Kiosks, signage and OT screens — unattended without disturbing the display **Shortlist:** LogMeIn Rescue, BeyondTrust Remote Support, Splashtop Remote Support / SOS **Why:** Rescue's disruption-free unattended mode, BeyondTrust Jump agents, Splashtop Remote Support on managed endpoints — reach a machine nobody is sitting at, without interrupting what it is showing. **Trade-off:** Unattended agents on shared machines need an offboarding process — the access outlives the technician unless somebody revokes it. ### Third-party vendors need into your systems **Shortlist:** BeyondTrust Remote Support, TeamViewer Tensor **Why:** Approval per session, credential injection so the vendor never sees the password, full recording — BeyondTrust (properly its Privileged Remote Access sibling); Tensor's conditional access scopes who may reach what. **Trade-off:** This is a privileged-access purchase wearing a remote-support label; price it as one. Generic tools can do the session and cannot prove what the vendor did. ### Branches on bad links, across regions **Shortlist:** AnyDesk, Splashtop Remote Support / SOS, TeamViewer Remote **Why:** Codec and relay design decide it — AnyDesk's DeskRT, Splashtop's engine, TeamViewer's adaptive quality; all three publish prices and self-serve trials for a real test. **Trade-off:** Test on the worst link, not the demo. On-prem relays (AnyDesk On-Premises, Splashtop On-Prem, BeyondTrust appliance) change the answer if traffic must stay inside. ### Macs, Linux boxes and phones, one support tool **Shortlist:** TeamViewer Remote, AnyDesk, BeyondTrust Remote Support **Why:** Cross-platform attended and unattended with mobile screens: TeamViewer and AnyDesk natively, BeyondTrust with full audit; Rescue and Resolve add mobile as paid add-ons. **Trade-off:** Mobile remote control depends on the phone's OS permissions (Android vendor-specific; iOS screen-view only) — no tool changes that. --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/endpoint-management/remote-access* --- # An RMM closes the ticket by fixing the device. An ITSM tool closes it by recording what you agreed with the person. *ITSM & Service Desk — a TechBag decision guide. Last reviewed 2026-09-07.* > Both produce a queue of tickets, which is why they get bought for each other’s job. The difference is what the ticket is *about*: an RMM ticket is raised by a machine and closed by an action on that machine. A service-desk ticket is raised by a human and closed by an agreement being met — within an SLA, against a service catalogue, with an approval trail if anything changed. **The checkable fact:** The test that separates them: ask what happens when nothing is broken. An RMM has nothing to do. A service desk still has a laptop request to fulfil, a change to approve and a knowledge article to publish. - Canonical: https://www.thetechbag.com/browse/endpoint-management/itsm-service-desk - Category: [Endpoint Management](https://www.thetechbag.com/browse/endpoint-management) - Products compared: 14 ## What itsm & service desk actually is ITSM — IT service management — is the practice of running IT as a set of services with agreed levels, rather than as a queue of favours. In product terms it means a portal where people raise requests, a catalogue of what they may ask for, an SLA clock, a knowledge base, an approval trail for changes, and a configuration map (a CMDB) that says what depends on what. The eleven products below split into four honest groups. Four run the full ITIL process set. Two are helpdesks that support customers or shared mailboxes very well and do not run change management. Two are MSP service desks bundled with an RMM, where you are billing clients for the support rather than serving colleagues. And three are ServiceNow modules where the platform decision has already been made and the question is which licences the CMDB actually needs. **The most common mis-purchase.** Every product here is priced **per agent** — the people resolving tickets — and requesters are unlimited and free. A 2,000-employee organisation with 12 IT staff pays for 12 seats, not 2,000. Pricing this per headcount is the single most common way a shortlist loses the product that fitted. ## Why people buy the wrong one Three confusions account for almost every mis-purchase in this category. Each has a question that resolves it in one sentence. ### ITSM vs RMM Is the ticket about a machine, or about a person? ### ITSM vs a helpdesk Did the requirement come from an audit, or from a lost email? ### ITSM vs PSA Do you invoice someone for this work? None of these three is a better or worse product than the others. They answer different questions, and the cost of the wrong answer is a tool that works exactly as designed while failing the thing you bought it for. ## The decision variables Four variables move the shortlist. Everything else is preference. **ITIL depth.** Incident and request are universal. Change, problem and release are what an auditor means by ITSM, and they are frequently gated behind a higher tier. **The CMDB.** A map of what depends on what. Included in-tier by Freshservice, ServiceDesk Plus and Jira Service Management; a separate ITOM licence at ServiceNow; absent from the helpdesks. **Where it runs.** ServiceDesk Plus is the only product here that runs on your own infrastructure — the deciding factor for regulated, government and localisation-sensitive estates. **Who resolves.** Per agent, not per employee. And if you bill customers for the work, you need the PSA model rather than the ITSM one. ## The 14 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Ivanti Neurons for ITSM — Ivanti - **Who it's for:** Estates that need on-premises or hybrid rather than SaaS-only — the most deployment-flexible platform on this list, with a 2026 on-premises documentation set carrying fresh-install instructions, and one of only two here listed in the PinkVERIFY registry for BOTH configuration and asset management. - **The honest limitation:** NO India data region for ITSM — and this is easy to misread, because India DOES appear in Ivanti’s subprocessor list, on the AWS row for its security products and on an engineering contractor’s row. Every Neurons for ITSM row lists the US, Australia and Germany; the four India offices are a support fact, not a residency one. Separately, Ivanti products have been repeatedly exploited by state-linked actors (CISA AA25-022A) — those CVEs hit Connect Secure and VPN appliances, NOT this product, but security reviews assess vendors rather than SKUs. - **Price:** Quote only — quote-only across all three packages (ITSM, ESM, AEM) — Ivanti publishes no rate card, and the third-party estimates in circulation contradict each other badly enough to be unusable ($25–59/user/year against $95/agent/month) - **Details:** https://www.thetechbag.com/ivanti/ivanti-neurons-for-itsm ### BMC Helix ITSM — BMC Helix - **Who it's for:** Large, regulated Indian estates — the 2026 Gartner MQ Leader, and the only ITSM platform here with a DOCUMENTED India data storage region (OCI Mumbai, backups Hyderabad) plus a genuinely current on-premises build in a category that has gone almost entirely SaaS. - **The honest limitation:** The heaviest and most expensive platform on this list — below roughly 500 seats it is usually overkill, and implementation is a programme rather than a configuration exercise. Two specifics buyers miss: the CMDB IS bundled but BMC Helix Discovery, which keeps it accurate, is a SEPARATE SKU from $50,000; and the ownership is mid-transition, with Montagu having agreed a majority stake on 17 June 2026 in a carve-out that BMC says remains subject to regulatory approvals, with no disclosed closing date. - **Price:** Quote only — quote-only — BMC publishes no rate card, and the per-agent figures on third-party blogs are not vendor-sourced (one such source is a direct CMDB competitor). The one published price in the family is BMC Helix Discovery, from $50,000 - **Details:** https://www.thetechbag.com/bmc/bmc-helix-itsm ### ServiceNow ITSM — ServiceNow - **Who it's for:** Large enterprises running service management across IT, HR, security and customer service on one platform, where the CMDB and change process are audited and the implementation has a budget and a partner. - **The honest limitation:** The most expensive option here and the longest project — months, usually with a partner. ServiceNow does not publish list pricing, so it cannot be compared like-for-like on a spreadsheet. An India data region is not documented on the product pages — confirm before assuming residency. - **Price:** Quote only — per fulfiller / month, quote-only and enterprise-sold; the full ITIL process set — incident, request, problem, change, knowledge, service catalogue — on the Now Platform with a CMDB and Now Assist AI - **Details:** https://www.thetechbag.com/servicenow/servicenow-itsm ### Freshservice — Freshworks - **Who it's for:** Mid-market IT teams that want the full ITIL process set without a ServiceNow-sized project — and Indian buyers who want the vendor's engineering in the same country. - **The honest limitation:** Published tiers gate the processes: problem, change and release sit at the $99 tier, so the honest comparison against a cheaper tool is not the $19 line. India-built (Chennai) but confirm the data region your tenant lands in. - **Price:** $19–99 (≈ ₹1,577) — per agent / month on annual billing across Starter, Growth, Pro and Enterprise: $19 core ITSM, $49 adds asset management and the service catalogue, $99 adds problem, change and release management; requesters are unlimited and free - **Details:** https://www.thetechbag.com/freshworks/freshservice ### ManageEngine ServiceDesk Plus — ManageEngine - **Who it's for:** Regulated, government and data-localisation-sensitive Indian estates that need the service desk inside their own environment, and mid-market IT that wants mature ITSM without an enterprise price. - **The honest limitation:** The interface is denser than the modern SaaS tools and shows its on-premises lineage; the cloud edition is younger than the on-prem one. The free edition stops at 5 technicians, which is a pilot, not a plan. - **Price:** Published, per technician — per technician / year, published list, on-premises or cloud; ITIL practices out of the box — incident, request catalogue, problem, change, CMDB, ITAM, knowledge base — with a free edition for up to 5 technicians - **Details:** https://www.thetechbag.com/manageengine/manageengine-servicedesk-plus ### Jira Service Management — Atlassian - **Who it's for:** Estates where development and IT operations must share one system — an incident links straight to the Jira issue, and the change ties to the pipeline that shipped it. - **The honest limitation:** The case weakens sharply if you do not already run Jira: the value is the shared platform, and without it you are buying a competent service desk with an unfamiliar model. Agents are billed; requesters are not. - **Price:** Published, per agent — per agent / month across Free, Standard, Premium and Enterprise, published list; request, incident, change, problem and a built-in CMDB, with on-call and alerting derived from Opsgenie - **Details:** https://www.thetechbag.com/atlassian/atlassian-jira-service-management ### Zoho Desk — Zoho - **Who it's for:** Indian businesses that want a capable helpdesk priced in rupees, particularly where Zoho CRM is already the system of record and support needs customer context. - **The honest limitation:** A customer-support helpdesk, not an ITSM platform: no CMDB, no IT asset management, and change and problem management are not the ITIL processes an auditor means. Buy it for supporting customers, not for running IT. - **Price:** ₹420–2,400 — per agent / month quoted in INR across Express, Standard, Professional and Enterprise (₹420 · ₹800 · ₹1,400 · ₹2,400), with light-agent seats at ₹345 and a free tier; omnichannel ticketing, knowledge base, SLAs and Zia AI - **Details:** https://www.thetechbag.com/zoho/zoho-desk ### Atera PSA & Helpdesk — Atera - **Who it's for:** MSPs and small internal IT teams that want the ticket, the remote session, the fix and the invoice in one platform, with the monitoring alert opening the ticket automatically. - **The honest limitation:** Lighter than the dedicated MSP PSA suites (ConnectWise Manage, Autotask) on billing depth and workflow customisation, and lighter than the ITSM platforms on change, problem and CMDB. An India data region is not documented. - **Price:** Per technician — per technician / month with unlimited devices and customers, inside the same platform as the RMM; ticketing, end-user portal, SLAs, time tracking, contracts and — for MSPs — billing and invoicing - **Details:** https://www.thetechbag.com/atera/atera-psa ### SuperOps PSA — SuperOps - **Who it's for:** MSPs of roughly 1–25 technicians running a conventional service book — tickets, SLAs, block hours, recurring billing — who want the service desk in the same product as the monitoring rather than joined to it by an integration somebody maintains. - **The honest limitation:** Genuinely lighter than ConnectWise Manage, Autotask and HaloPSA: project management is minimal, procurement is largely absent, contract handling is standard rather than intricate, and reporting stops short of per-contract profitability. Priced per ENDPOINT, so a high device-to-technician ratio favours per-technician rivals. India-built in Chennai, but no India data region is documented — and a service desk holds client personal data. - **Price:** Included — included in both plans at the published per-endpoint rate ($1.50 at the 100-endpoint minimum down to $1.20 above 1,000) — there is no separate PSA SKU and no per-technician or per-seat charge, so adding a technician costs nothing - **Details:** https://www.thetechbag.com/superops/superops-psa ### Freshdesk — Freshworks - **Who it's for:** Support teams answering CUSTOMERS rather than colleagues — the Zendesk alternative most Indian buyers actually shortlist, India-built in Chennai, quick to stand up and priced for a team that cannot absorb an implementation project. - **The honest limitation:** A customer-support helpdesk, NOT an ITSM platform — the same caveat as Zoho Desk and it matters just as much: no CMDB, no IT asset management, and no change or problem management in the sense an auditor means. If you are running internal IT, Freshservice is the Freshworks product you want and it is on this list. Buy Freshdesk for supporting customers. - **Price:** $0–95 — per agent / month across Free, Growth, Pro and Enterprise, published list; omnichannel ticketing (email, chat, phone, social), knowledge base, automation, SLAs and Freddy AI — with a genuinely free tier - **Details:** https://www.thetechbag.com/freshworks/freshdesk ### Hiver — Hiver - **Who it's for:** Teams that already live in a shared mailbox — IT, operations, finance, HR — and want ownership, SLAs and reporting without asking anyone to learn a ticketing tool. - **The honest limitation:** It is a shared inbox with service management on top, not an ITSM platform: no CMDB, no asset management, no change or problem process. It is the right answer only when the honest requirement is 'stop losing emails', not 'run IT to ITIL'. - **Price:** $25–85 (≈ ₹2,075) — per user / month on annual billing across Free, Growth ($25 ≈ ₹2,075), Pro ($55) and Elite ($85), two-seat minimum; shared inboxes, assignment, collision detection, SLAs and AI inside Gmail or Outlook - **Details:** https://www.thetechbag.com/hiver/hiver-helpdesk ### monday service — monday.com - **Who it's for:** Teams that already run work on monday.com and want IT, HR and ops service desks on the same Work OS rather than in a silo — AI-assisted intake, routing, a self-service portal and SLAs, standing up in days with no-code setup. - **The honest limitation:** Ease and Work-OS unity, NOT enterprise ITSM depth — no CMDB and only basic asset tracking, so change, problem and configuration management in the sense an auditor means are not here. It is also monday’s NEWEST product (2024), billed in USD with NO India data residency (AWS US/EU). If you need a CMDB or India residency, ServiceNow, Freshservice or ManageEngine are on this list. - **Price:** Quote only — per seat across tiers with a 3-SEAT MINIMUM, licensed separately from monday work management — monday.com renders its service tiers client-side, so no list figure is quoted here; TechBag confirms current tiers at quote - **Details:** https://www.thetechbag.com/monday/monday-service ### ServiceNow ITOM — ServiceNow - **Who it's for:** ServiceNow estates whose CMDB is the point — where the configuration map has to be discovered and maintained automatically rather than kept by hand. - **The honest limitation:** A separate purchase from ITSM and frequently the reason a ServiceNow quote doubles. Buying ITSM and expecting an accurate CMDB without ITOM is the most common budget surprise in this category. - **Price:** Quote only — quote-only, licensed separately from ITSM; discovery and service mapping that populate the CMDB automatically, plus event management and AIOps - **Details:** https://www.thetechbag.com/servicenow/servicenow-itom ### ServiceNow ITAM — ServiceNow - **Who it's for:** Enterprises whose driver is the software audit or the renewal cycle — knowing what is owned, what is deployed and what is about to expire. - **The honest limitation:** Another separate licence on top of ITSM. Where the real problem is device inventory rather than licence position, a UEM or RMM already holds most of the data at a fraction of the cost. - **Price:** Quote only — quote-only, licensed separately; hardware, software and cloud asset management with licence position and end-of-life tracking on the same CMDB - **Details:** https://www.thetechbag.com/servicenow/servicenow-itam ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **the full ITIL set.** Rules out Zoho Desk, Freshdesk, Hiver and monday service — a helpdesk: no ITIL change or problem process; Atera PSA & Helpdesk, SuperOps PSA, ServiceNow ITOM and ServiceNow ITAM — incident and request are solid; change and problem are thin or absent. That leaves Ivanti Neurons for ITSM, BMC Helix ITSM, ServiceNow ITSM, Freshservice, ManageEngine ServiceDesk Plus and Jira Service Management. **a real CMDB.** Rules out Zoho Desk, Freshdesk, Hiver and monday service — no CMDB; Atera PSA & Helpdesk and SuperOps PSA — basic asset list, not a configuration map with relationships. That leaves Ivanti Neurons for ITSM, BMC Helix ITSM, ServiceNow ITSM, Freshservice, ManageEngine ServiceDesk Plus, Jira Service Management, ServiceNow ITOM and ServiceNow ITAM. **asset management included.** Rules out Zoho Desk, Freshdesk and Hiver — no asset management; Atera PSA & Helpdesk, SuperOps PSA and monday service — basic inventory only. That leaves Ivanti Neurons for ITSM, BMC Helix ITSM, ServiceNow ITSM, Freshservice, ManageEngine ServiceDesk Plus, Jira Service Management, ServiceNow ITOM and ServiceNow ITAM. **on-premises.** Rules out ServiceNow ITSM, Freshservice, Jira Service Management, Zoho Desk, Atera PSA & Helpdesk, SuperOps PSA, Freshdesk, Hiver, monday service, ServiceNow ITOM and ServiceNow ITAM — SaaS only. That leaves Ivanti Neurons for ITSM, BMC Helix ITSM and ManageEngine ServiceDesk Plus. **live in days.** Rules out Ivanti Neurons for ITSM, BMC Helix ITSM, ServiceNow ITSM, ServiceNow ITOM and ServiceNow ITAM — a months-long project, usually with a partner; Freshservice, ManageEngine ServiceDesk Plus and Jira Service Management — weeks, realistically. That leaves Zoho Desk, Atera PSA & Helpdesk, SuperOps PSA, Freshdesk, Hiver and monday service. **a free edition.** Rules out Ivanti Neurons for ITSM, BMC Helix ITSM, ServiceNow ITSM, Freshservice, Atera PSA & Helpdesk, SuperOps PSA, monday service, ServiceNow ITOM and ServiceNow ITAM — no free edition. That leaves ManageEngine ServiceDesk Plus, Jira Service Management, Zoho Desk, Freshdesk and Hiver. **India.** Rules nothing out on published terms. It flags Ivanti Neurons for ITSM — An India data region is not documented on the vendor's pages, BMC Helix ITSM — Data region available, ServiceNow ITSM — An India data region is not documented on the vendor's pages, Jira Service Management — Data region available, Atera PSA & Helpdesk — An India data region is not documented on the vendor's pages, SuperOps PSA — An India data region is not documented on the vendor's pages, monday service — An India data region is not documented on the vendor's pages, ServiceNow ITOM — An India data region is not documented on the vendor's pages and ServiceNow ITAM — An India data region is not documented on the vendor's pages — marked, not removed. **billing customers.** Rules out Ivanti Neurons for ITSM, BMC Helix ITSM, ServiceNow ITSM, Freshservice, ManageEngine ServiceDesk Plus, Jira Service Management, Zoho Desk, Freshdesk, Hiver, monday service, ServiceNow ITOM and ServiceNow ITAM — no contract, rate or invoicing model for billing clients. That leaves Atera PSA & Helpdesk and SuperOps PSA. **service management beyond IT.** Rules out Zoho Desk, Atera PSA & Helpdesk, SuperOps PSA, Freshdesk, Hiver and monday service — scoped to IT support, or to one mailbox. That leaves Ivanti Neurons for ITSM, BMC Helix ITSM, ServiceNow ITSM, Freshservice, ManageEngine ServiceDesk Plus, Jira Service Management, ServiceNow ITOM and ServiceNow ITAM. **Per agent, never per employee.** Every product here bills the people resolving tickets — agents, technicians, fulfillers. Requesters are unlimited and free. Estates that price this per headcount arrive at a number roughly twenty times too high and disqualify the product that fitted. **ServiceNow does not publish list pricing.** It is quote-only and enterprise-sold. Every figure you see quoted publicly is someone else's negotiated deal, and it is not yours. Budget the discovery and the partner alongside the licence. **The CMDB is usually a second purchase.** ServiceNow ITOM populates the CMDB by discovery, and it is licensed separately from ITSM. Freshservice, ServiceDesk Plus and Jira Service Management include a CMDB in-tier. This is the single biggest difference between a quoted number and a delivered one. **A helpdesk is not an ITSM platform.** Zoho Desk and Hiver are excellent at what they do and neither runs change management. If the requirement came from an audit, they are out; if it came from 'we keep losing emails', they may be the whole answer. ## Four situations, and what each one buys If one of these is your sentence, the shortlist is short. ### An auditor asked for the change-approval trail **Shortlist:** ServiceNow ITSM, Freshservice, ManageEngine ServiceDesk Plus, Jira Service Management **Why:** Change management with approvals and an evidence trail is a full-ITIL feature. All four have it; the helpdesks do not. **Trade-off:** At Freshservice the change process sits at the $99 Pro tier — compare tier to tier, not headline to headline. ### The service desk cannot leave our data centre **Shortlist:** ManageEngine ServiceDesk Plus **Why:** It is the only product here that runs on-premises as a first-class deployment, from an India-headquartered vendor with Indian data centres. **Trade-off:** A denser interface than the modern SaaS tools, and you own the upgrade cycle. ### Support@ is a shared mailbox and things get missed **Shortlist:** Hiver, Zoho Desk **Why:** Ownership, collision detection and SLAs inside the mail client your team already uses — no migration, no new tool to learn. **Trade-off:** Neither runs change or problem management. If an audit arrives later, this is not the tool that answers it. ### We bill clients for IT support **Shortlist:** Atera PSA & Helpdesk **Why:** PSA plus RMM in one platform, priced per technician with unlimited devices — the alert opens the ticket, the technician fixes and logs time, the contract bills it. **Trade-off:** Lighter than ConnectWise Manage or Autotask on billing depth and workflow customisation. ## At scale The meter is agents, so scale here means the size of the IT team, not the size of the organisation. ### 1 agents — Up to 5 agents - ServiceDesk Plus free edition covers it outright - Hiver's two-seat minimum makes it viable - Zoho Desk's free tier and ₹420 Express tier fit **The test:** Ask whether you need ITIL at all, or a shared inbox with ownership. ### 2 agents — 5–25 agents - Freshservice and Jira Service Management sit naturally here - ServiceDesk Plus if on-premises matters - Change management starts being asked for **The test:** Price the tier that contains change management, not the entry tier. ### 3 agents — 25–100 agents - Full ITIL becomes the requirement, not a preference - CMDB population needs an owner - Service management spreads beyond IT — HR, facilities **The test:** Ask who maintains the CMDB, by name. ### 4 agents — 100+ agents - ServiceNow's case strengthens — one platform across departments - ITOM and ITAM become separate line items - Implementation needs a partner and a budget **The test:** Get the ITOM and ITAM licences quoted at the same time as ITSM. Documented deployment scale is verified per product where the vendor publishes it; where it is not established, the product says so rather than implying it. ## Getting out Service desks accumulate history, and the history is the asset. Three things decide how painful leaving is. **Ticket history** — Every product here exports tickets to CSV or through an API *(Portable, with effort)* **The knowledge base** — Articles export as text or HTML; formatting and attachments frequently do not survive *(Partly portable)* **The CMDB and its relationships** — Relationships are the part that rarely exports cleanly — the map usually gets rebuilt *(Expect to rebuild)* **Workflows and automations** — No standard format exists; these are rebuilt in the new tool every time *(Not portable)* The practical consequence: the CMDB and the automations are what lock you in, not the tickets. Ask about them before signing, not at renewal. ## What it costs Per agent per month, tier-matched. Requesters are free everywhere on this page. ### Check what you already own Three of these are frequently already paid for. - **Jira — If engineering runs Jira, Jira Service Management is on the same platform.** The incident links to the issue that caused it, and the licence conversation is with a vendor you already have. - **Zoho One — Zoho Desk is included in the Zoho One suite.** If the organisation already runs Zoho One, the helpdesk is a switch to turn on rather than a purchase. - **Your RMM — Atera bundles PSA with the RMM at no separate cost.** MSPs already running Atera have the service desk in the platform — check before buying a second one. None of these is automatically the right answer. But each is a genuine option that a shortlist built from a vendor comparison will miss. ### The rest of the bill The licence is rarely the whole number. ### What isn't in the licence price - **Implementation.** Weeks for the mid-market tools; a months-long partner engagement for ServiceNow. - **CMDB discovery.** ServiceNow ITOM is a separate licence. Included in-tier by Freshservice, ServiceDesk Plus and Jira Service Management. - **Asset management.** ServiceNow ITAM is separately licensed; Freshservice gates ITAM at the $49 Growth tier. - **Infrastructure.** On-premises ServiceDesk Plus means your server, your database, your upgrades. ## What goes wrong Four ways this purchase goes wrong, each recoverable if you catch it before signing. - **Pricing it per employee.** Every product here bills agents, not employees. A 2,000-person organisation with 12 IT staff buys 12 seats. Getting this wrong inflates the number roughly twentyfold and eliminates the right product. - **Comparing entry tiers.** Change and problem management sit at higher tiers. A $19 line and a $99 line are not the same product; compare the tier that contains what the audit asked for. - **Assuming the CMDB fills itself.** It does not. Either discovery is licensed and owned, or the map is hand-maintained and decays within months. - **Buying ITSM to replace an RMM.** They both produce tickets and they do different jobs. If the requirement is patching and monitoring at scale, the answer is on the RMM & Patch guide, not this one. ## Questions this guide answers ### What is the difference between ITSM and an RMM? An RMM monitors, patches and fixes devices at a distance — its tickets are raised by machines and closed by acting on the machine. An ITSM tool runs the service desk: requests from humans, SLAs, a service catalogue, change approvals and a configuration map. They overlap only in that both show you a queue of tickets. Buying one for the other's job leaves either no change process or nothing watching the estate. ### Is ServiceNow worth it for a mid-sized Indian company? Usually not as a first ITSM purchase. ServiceNow is quote-only, enterprise-sold, and implementation is measured in months with a partner. Freshservice (India-built, published per-agent pricing from $19) and ManageEngine ServiceDesk Plus (India-built, published per-technician pricing, on-premises or cloud) cover the same ITIL processes at mid-market cost and effort. ServiceNow's case strengthens when service management extends beyond IT into HR, security and customer service on one platform. ### How is ITSM software priced? Per agent — the people resolving tickets — not per employee. Requesters are unlimited and free on every product on this page. Freshservice publishes $19, $49 and $99 per agent per month; Zoho Desk publishes ₹420 to ₹2,400 per agent per month; ManageEngine and Atlassian publish per-technician and per-agent lists; ServiceNow is quote-only. TechBag quotes all of them in INR with GST. ### Do I need a CMDB? If an auditor asked about your change process, yes — a change process without a dependency map cannot answer 'what will this break?'. Freshservice, ServiceDesk Plus and Jira Service Management include a CMDB in-tier. ServiceNow populates it through ITOM, which is a separate licence and the most common reason a quote doubles. ### Can a shared inbox replace a service desk? Sometimes, honestly. If the problem is that support@ loses emails and nobody knows who owns what, Hiver or Zoho Desk add ownership, SLAs and reporting without a migration. If the requirement came from an audit asking for change and problem management, a shared inbox cannot answer it and buying one delays the real purchase. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/endpoint-management/itsm-service-desk* --- # Endpoint Management — which device-management route fits — and why the hardware purchase channel decides your options *A TechBag category guide. Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/endpoint-management - Routes: 4 ## The routes ### UEM & MDM - 12 products compared - Guide: https://www.thetechbag.com/browse/endpoint-management/uem-mdm ### RMM & Patch - 17 products compared - Guide: https://www.thetechbag.com/browse/endpoint-management/rmm-patch ### Remote Access & Support - 8 products compared - Guide: https://www.thetechbag.com/browse/endpoint-management/remote-access ### ITSM & Service Desk An RMM closes the ticket by fixing the device. An ITSM tool closes it by recording what you agreed with the person. - 14 products compared - Guide: https://www.thetechbag.com/browse/endpoint-management/itsm-service-desk - Boundary terms resolved: ITSM vs RMM · ITSM vs a helpdesk · ITSM vs PSA --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/endpoint-management* --- # EPP and EDR answer different questions. Most buyers purchase one believing they bought both. *Endpoint Protection — a TechBag decision guide. Last reviewed 2026-09-07.* > Prevention stops what it recognises. Detection and response records what got through so a person can find it and act — and without that person, the EDR console is the most expensive dashboard nobody opens. **The checkable fact:** Microsoft 365 E3 includes Defender for Endpoint Plan 1 — prevention only. The EDR is Plan 2, and that is in E5. Check the SKU before assuming you own detection. - Canonical: https://www.thetechbag.com/browse/security/endpoint-protection - Category: [Security](https://www.thetechbag.com/browse/security) - Products compared: 36 ## What endpoint protection actually is An agent on every laptop, desktop, server and (usually) phone that does two jobs. The first is **prevention**: block known malware, exploit techniques and ransomware behaviour before they run — the antivirus lineage, now machine-learning and behaviour-based. The second is **detection and response**: record process, file, network and identity events continuously, raise what looks wrong, and give a person the tools to investigate and act — isolate the machine, kill the process, roll files back, hunt across the estate. The first job runs itself. The second does not — it produces alerts, and alerts need someone with time and skill to read them. That is why every vendor on this page also sells **people**: a managed detection and response service that runs the console for you (its own guide is [here](https://www.thetechbag.com/browse/security/managed-detection-response)). Whether you need the second job, and who will do it, decides this purchase more than any detection-rate chart. **The most common mis-purchase.** EDR without someone to triage it is **shelfware with a licence fee**. If nobody on your side will open the console daily, buy the managed tier or stay with prevention — and say so in the evaluation, because the vendor’s demo will not. ## EPP · EDR · XDR — and why they aren’t a quality ladder Three letters that every vendor sells as tiers. They are not better-worse; they are narrower-wider. Each one widens the scope of what is recorded — and each widening costs more and needs more people to read what it records. ### EPP — Endpoint Protection Platform Prevention at the endpoint: block known malware, exploit techniques and ransomware behaviour before they run. The console is for policy and reporting; it runs itself. Every vendor's entry tier. Broad enough for many estates under ~300 seats that accept nothing is hunting. ### EDR — Endpoint Detection & Response Continuous recording of process, file, network and identity events on the endpoint, alerts on what looks wrong, and a console to investigate, isolate, kill, hunt — and at some vendors roll files back. It produces work for a person every day. Not 'better EPP'; a different job that assumes EPP missed something. ### XDR — Extended Detection & Response EDR's recording joined with email, identity, cloud and network signals so one incident is one story. Wider scope again — more to see, more to staff, and worth it only when those other sources exist and someone correlates them. Platform vendors sell it as the reason to buy everything from them. **These are widening scopes, not tiers of quality.** A good EPP is not a worse EDR; an XDR is not the best EPP. Broader records more, costs more, and needs more people to run it. Buy the scope someone on your side will operate — and if that is nobody, the next guide (MDR) is the one you need. ## The decision variables Seven variables decide this purchase — the instrument tests the ones documentation can verify; the rest are prose because the honest answer depends on your team. **Prevention depth vs detection-and-response depth.** Which job you are buying — the entry tier blocks, the higher tier records and lets a person respond. Every vendor sells both; the price gap is the second job. **Who operates it.** The honest cut. An EDR with no one to triage it is shelfware — so the chip asks whether the vendor sells the people too, and whether that managed tier is priced for you or enterprise-gated. **Agent coexistence.** What is already on the machine: UEM, RMM, backup, an old AV. One real-time engine per machine; Windows steps Defender aside automatically; two third-party engines do not coexist. **Rollback and remediation.** Four mechanisms and one absence — protected-copy restore, agent-level rollback, containment, restore-from-backup, or isolate-and-kill only. Know which you bought before the first incident. **Managed option availability.** Whether the vendor's own 24/7 service exists for this SKU, what it covers, and what it costs — the MDR guide takes it from here. **Platform bundling vs best-of-breed.** One suite (Microsoft, Sophos, Trend, Kaspersky, Bitdefender, ESET) or the best agent most consoles integrate (CrowdStrike, SentinelOne) — and the UEM / RMM / backup vendors selling security inside their console. Convenience versus depth; the card's limitation tells you the price. **India data residency.** Documented for SentinelOne and Sophos (Mumbai), Seqrite, Acronis, Scalefusion; announced for CrowdStrike; unknown for most. The instrument never eliminates on 'unknown' — it flags and you ask in writing. ## The 36 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Elastic Defend — Elastic - **Who it's for:** Estates already running Elastic Security: the SAME Elastic Agent that ships your logs enforces endpoint protection, so there is no second agent to deploy or upgrade — and it runs on-premises or air-gapped, which most EPP consoles cannot. - **The honest limitation:** It is the endpoint half of a platform, not a standalone EPP you would buy against CrowdStrike or SentinelOne on their own terms: no dedicated mobile console, no automated ransomware rollback, and no managed-detection service of its own. - **Price:** Free → tier — included with the Elastic platform rather than sold as a standalone endpoint SKU; the engine is free under AGPL and the features come with the subscription tier you already buy — self-managed, Elastic Cloud Hosted or Serverless - **Details:** https://www.thetechbag.com/elastic/elastic-defend ### CrowdStrike Falcon Prevent (Go / Pro) — CrowdStrike - **Who it's for:** Teams that want CrowdStrike's prevention agent today and a path to Insight EDR tomorrow without a second install. - **The honest limitation:** Prevention only — no timeline, hunting or response until you add Insight; no file rollback; India in-country cloud is announced, not yet documented live. - **Price:** $59.99–99.99 (≈ ₹4,979) — per device / year — Falcon Go (prevention) · Pro; the reference cloud-native agent - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-falcon-prevent ### CrowdStrike Falcon Insight XDR — CrowdStrike - **Who it's for:** Security teams that will hunt — the reference EDR telemetry, forensic timeline and Real Time Response. - **The honest limitation:** An EDR that needs operators: no automatic file rollback, Falcon Complete (managed) is enterprise-priced on quote, and the bundle is the cloud-only Falcon platform. - **Price:** $184.99 (≈ ₹15,354) — per device / year (Falcon Enterprise bundle with Prevent); Falcon Complete MDR on quote - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-falcon-insight-xdr ### SentinelOne Singularity Endpoint — SentinelOne - **Who it's for:** Autonomous prevention-to-response on one agent with documented one-click rollback and an India data region. - **The honest limitation:** No vendor-published list (street price varies widely), no on-prem console; mobile is a paid Singularity Mobile add-on. - **Price:** ~$70–180 (≈ ₹5,809) — per endpoint / year reseller list (Core · Control · Complete); Vigilance MDR add-on; Mumbai region - **Details:** https://www.thetechbag.com/sentinelone/sentinelone-singularity-endpoint ### Microsoft Defender for Endpoint P1 / P2 — Microsoft - **Who it's for:** Microsoft 365 estates — the EPP/EDR you may already hold, with the tightest Intune and Entra integration there is. - **The honest limitation:** E3 carries only P1 (no EDR); file rollback is OneDrive Files Restore, not the agent; Defender Experts (managed) needs E5 and a quote; the console assumes a Microsoft estate. - **Price:** $3 / $5.20 (≈ ₹249) — per user / month standalone (P1 prevention / P2 EDR); $0 marginal when bundled - **Details:** https://www.thetechbag.com/microsoft/microsoft-defender-for-endpoint ### Sophos Intercept X Advanced — Sophos - **Who it's for:** Prevention with CryptoGuard file rollback for teams that want Sophos MDR to be the default operating model later. - **The honest limitation:** The Advanced SKU is prevention — detection and response is the separate 'with XDR' tier; no published list; CryptoGuard rollback needs ~3 GB free disk. - **Price:** Quote — per user / year (reported ~$30–50); Sophos Central; Mumbai region - **Details:** https://www.thetechbag.com/sophos/sophos-intercept-x ### Sophos Intercept X Advanced with XDR — Sophos - **Who it's for:** Teams that want EDR/XDR on the Sophos agent with the MDR tier one step away. - **The honest limitation:** Estimates only — no published list; XDR breadth across email / firewall / cloud is a Sophos-estate story; no on-prem console. - **Price:** Quote — per user / year (reported ~$48); adds XDR data lake, cross-product detections; Mumbai region - **Details:** https://www.thetechbag.com/sophos/sophos-xdr ### Bitdefender GravityZone Business Security — Bitdefender - **Who it's for:** Price-sensitive mixed fleets wanting published per-device prevention with Ransomware Mitigation and an on-prem console option. - **The honest limitation:** Prevention tier — EDR is the Premium SKU; first-year promotional pricing renews at standard rates (users report 2–3×); India cloud region not documented. - **Price:** $57–74 (≈ ₹4,731) — per device / year — Small Business · Business Security (EPP); Premium adds EDR - **Details:** https://www.thetechbag.com/bitdefender/bitdefender-business-security ### Bitdefender GravityZone EDR / XDR (Premium · Enterprise) — Bitdefender - **Who it's for:** Bitdefender prevention plus a real EDR tier, with MDR available from the same vendor. - **The honest limitation:** XDR and Enterprise are quote-only; the published Premium price is first-year promotional; India region not documented. - **Price:** $95.89 (≈ ₹7,959) — per device / year (Business Security Premium with EDR); XDR / Enterprise on quote - **Details:** https://www.thetechbag.com/bitdefender/bitdefender-edr-xdr ### Bitdefender GravityZone PHASR — Bitdefender - **Who it's for:** GravityZone estates that want the attack surface tailored per user before prevention ever has to fire. - **The honest limitation:** An add-on, not standalone protection — it hardens, it does not detect or roll back; quote-only. - **Price:** Quote — add-on to GravityZone — proactive hardening and attack-surface reduction per user behaviour - **Details:** https://www.thetechbag.com/bitdefender/bitdefender-phasr ### ESET PROTECT Entry — ESET - **Who it's for:** Lean teams wanting a light agent, published pricing, on-prem or cloud console and Ransomware Remediation. - **The honest limitation:** Prevention only — no EDR (Elite), no mobile (Advanced+), no sandbox; ESET MDR is a separate quote. - **Price:** $42.20 (≈ ₹3,503) — per device / year (5-device packs); endpoint + file-server protection - **Details:** https://www.thetechbag.com/eset/eset-protect-entry ### ESET PROTECT Advanced — ESET - **Who it's for:** ESET Entry plus sandboxing, encryption and phones in the same console. - **The honest limitation:** Still prevention — EDR arrives only at Elite (quote, 25-device minimum); India cloud region not documented. - **Price:** $55 (≈ ₹4,565) — per device / year; adds cloud sandbox, full-disk encryption, Mobile Threat Defense - **Details:** https://www.thetechbag.com/eset/eset-protect-advanced ### ESET PROTECT Complete — ESET - **Who it's for:** One ESET console for endpoint, mail and patching in a small estate. - **The honest limitation:** Breadth without EDR — detection and response is the Elite tier; the M365 / Workspace protection is email filtering, not an EDR for mail. - **Price:** $57.54 (≈ ₹4,776) — per device / year; adds Microsoft 365 / Google Workspace protection, mail server, vulnerability & patch - **Details:** https://www.thetechbag.com/eset/eset-protect-complete ### ESET PROTECT Elite (ESET Inspect XDR) — ESET - **Who it's for:** ESET estates that outgrew prevention and want the XDR tier and ESET MDR on the same agent. - **The honest limitation:** Quote-only with a 25-device minimum; ESET Inspect is an operator's console — budget the analyst or the MDR. - **Price:** Quote — per device / year, 25-device minimum; adds ESET Inspect (XDR) and MFA - **Details:** https://www.thetechbag.com/eset/eset-protect-elite ### Trend Vision One Endpoint Security — Trend Micro - **Who it's for:** Estates that want Trend's endpoint sensor feeding Vision One XDR, with Service One MDR from the same vendor. - **The honest limitation:** Advanced is the EDR-grade tier at ~6× Essentials; credit-based Vision One billing is hard to forecast; automatic file rollback is not documented. - **Price:** $2.25–14.92 (≈ ₹187) — per endpoint / month — Essentials · Standard · Advanced; Apex One on-prem still sold - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-endpoint-security ### Trend Vision One XDR — Trend Micro - **Who it's for:** Trend estates correlating endpoint with email, network and cloud telemetry in one platform. - **The honest limitation:** Needs Trend sensors to be worth it; credit consumption is opaque until you run it; no published list. - **Price:** Credits — Vision One credits, annual; correlates endpoint, email, network, cloud, identity - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-xdr ### Kaspersky Next (EDR Foundations · Optimum · Expert) — Kaspersky - **Who it's for:** Estates wanting a full prevention-to-EDR ladder with the Remediation Engine rollback and an MXDR option on the same agent. - **The honest limitation:** Procurement-sensitive in some sectors and countries (US ban; check your regulator); EDR Expert is enterprise-priced; India data region not documented. - **Price:** from €287.50 — per 5 users / year (Foundations); Optimum / Expert and MXDR on quote; on-prem or cloud console - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-next ### Kaspersky Endpoint Security Cloud — Kaspersky - **Who it's for:** Small estates wanting Kaspersky prevention with phones included and nothing to host. - **The honest limitation:** Prevention-first — full EDR is the Next line; cloud-only; the same procurement caveats as Kaspersky Next. - **Price:** Quote — per user / year, cloud console; Pro / Plus tiers add EDR Optimum-grade features - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-endpoint-security-cloud ### Seqrite Endpoint Protection (on-prem) — Seqrite - **Who it's for:** India-regulated estates that need CERT-In-empanelled, INR-billed, on-prem endpoint protection with local support. - **The honest limitation:** Prevention tier — EDR/XDR are separate SKUs; mobile is mSuite (separate console); ransomware recovery restores from its own backup rather than rolling back; scale above 2,000 claimed, not documented. - **Price:** ₹799+ — per endpoint / year, INR-native (EPS Core → Total); EDR / XDR on quote - **Details:** https://www.thetechbag.com/seqrite/seqrite-endpoint-protection ### Seqrite Endpoint Protection Cloud — Seqrite - **Who it's for:** The same Seqrite protection with nothing to host and data in India. - **The honest limitation:** Cloud-only variant of a prevention tier; EDR/XDR are add-ons; scale above 2,000 endpoints not documented. - **Price:** Quote — per endpoint / year, INR-native, India-hosted cloud console - **Details:** https://www.thetechbag.com/seqrite/seqrite-endpoint-protection-cloud ### Seqrite EDR — Seqrite - **Who it's for:** Seqrite estates adding detection and response without leaving the India-hosted stack. - **The honest limitation:** An add-on to EPS, not standalone; quote-only; depth of hunting and telemetry retention is not documented at the level CrowdStrike or SentinelOne publish. - **Price:** Quote — add-on per endpoint / year (≈ ₹350 over EPS Core reported); INR-native - **Details:** https://www.thetechbag.com/seqrite/seqrite-edr ### Seqrite XDR (HawkkHunt) — Seqrite - **Who it's for:** India estates wanting XDR and MDR from one CERT-In-empanelled vendor. - **The honest limitation:** XDR breadth is Seqrite-stack-first; quote-only; unverified above 2,000 endpoints. - **Price:** Quote — per endpoint / year, INR-native; correlates Seqrite endpoint, network and cloud telemetry - **Details:** https://www.thetechbag.com/seqrite/seqrite-xdr ### Xcitium ZeroDwell (containment) — Xcitium - **Who it's for:** Teams that want unknown files contained at the kernel before they run — a different bet from detect-then-respond. - **The honest limitation:** Containment is the mechanism, not rollback — nothing to restore because nothing ran, and no file-restore if something is allowed; on-prem and India region not documented. - **Price:** $2.39 (≈ ₹198) — per endpoint / month, modular and postpaid; OpenEDR free to 50 endpoints - **Details:** https://www.thetechbag.com/xcitium/xcitium-zerodwell ### Xcitium EDR — Xcitium - **Who it's for:** An EDR module that can sit on top of Defender AV or the Xcitium stack. - **The honest limitation:** Module pricing adds up; unverified above 2,000 endpoints; India region not documented. - **Price:** Modular — per endpoint / month module; runs beside Microsoft Defender (documented) - **Details:** https://www.thetechbag.com/xcitium/xcitium-edr ### Xcitium XDR — Xcitium - **Who it's for:** Xcitium estates widening the recording beyond the endpoint. - **The honest limitation:** XDR depth is Xcitium-stack-first; scale and region unverified. - **Price:** Modular — per endpoint / month module; network, cloud and endpoint telemetry - **Details:** https://www.thetechbag.com/xcitium/xcitium-xdr ### Xcitium OpenEDR — Xcitium - **Who it's for:** Teams that want real EDR telemetry for nothing, and will run it themselves. - **The honest limitation:** Windows-only, EDR-only (no prevention engine), nobody watches it but you — shelfware unless someone reads the console daily. - **Price:** Free — open-source EDR, free to 50 endpoints; paid platform beyond - **Details:** https://www.thetechbag.com/xcitium/xcitium-openedr ### Check Point Harmony Endpoint — Check Point - **Who it's for:** Check Point estates wanting prevention-first endpoint with anti-ransomware restore and Infinity-portal management. - **The honest limitation:** No published list (reported ranges only); managed service is enterprise-gated; India data region not documented. - **Price:** ~$25–45 (≈ ₹2,075) — per user / year reported (Basic · Advanced · Complete); on-prem or Infinity cloud management - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-harmony-endpoint ### Cisco Secure Endpoint — Cisco - **Who it's for:** Cisco-network estates wanting endpoint telemetry that joins Umbrella, Secure Firewall and Cisco XDR. - **The honest limitation:** Only Essentials is published; the XDR and hunting tiers are quote-only; file rollback not documented; mobile not covered. - **Price:** $6.75 (≈ ₹560) — per user / month (Essentials); Advantage / Premier (XDR, hunting) on quote; private-cloud appliance option - **Details:** https://www.thetechbag.com/cisco/cisco-secure-endpoint ### Cisco XDR — Cisco - **Who it's for:** Cisco estates correlating endpoint, network, email and identity in one console. - **The honest limitation:** Needs sources to correlate — alone it is a console; quote-only; no rollback; cloud-only. - **Price:** ~$69 (≈ ₹5,727) — per user / year reported (Essentials · Advantage · Premier); correlates Cisco and third-party telemetry - **Details:** https://www.thetechbag.com/cisco/cisco-xdr ### Fortinet FortiEDR — Fortinet - **Who it's for:** Fortinet Security Fabric estates wanting pre- and post-infection protection with an MDR option on the same agent. - **The honest limitation:** No published list; automatic file rollback not documented; no mobile coverage; strongest inside a Fortinet stack. - **Price:** ~$20–35 (≈ ₹1,660) — per endpoint / year reported; on-prem or cloud; FortiGuard MDR option - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortiedr ### Acronis Cyber Protect (EDR) — Acronis - **Who it's for:** Estates that want backup and EDR in one agent — recovery is a restore, not a rollback. - **The honest limitation:** Recovery means restoring from Acronis backup (strong, but not automatic rollback); EDR depth is below the pure-play leaders; per-workload pricing climbs with servers. - **Price:** ~₹3,500 — per workload / month (Advanced with EDR, India reseller list); cloud or on-prem; Mumbai data centre - **Details:** https://www.thetechbag.com/acronis/acronis-cyber-protect ### Coro Endpoint & EDR — Coro - **Who it's for:** SMBs that want endpoint, email, cloud-app and posture in one modular agent with a managed option. - **The honest limitation:** Linux agent is remote scan-only; no documented file rollback; public list withdrawn in 2026; unverified above 2,000 endpoints. - **Price:** Quote — per user / month, modular (historically ~$7.50–10.50); managed SOC option - **Details:** https://www.thetechbag.com/coro/coro-endpoint-edr ### Norton Small Business — Norton - **Who it's for:** Very small businesses that want consumer-grade antivirus with a business licence and nothing to manage. - **The honest limitation:** Licensed for up to 20 devices — not an enterprise product; no EDR, no Linux, no console for compliance evidence, no managed option. - **Price:** $179.99 (≈ ₹14,939) — per year for 10 devices (first year; Premium $299.99); up to 20 devices - **Details:** https://www.thetechbag.com/norton/norton-small-business ### Hexnode XDR — Hexnode - **Who it's for:** Hexnode UEM estates that want threat protection in the console they already run. - **The honest limitation:** A young product from a UEM vendor — EDR depth, Linux coverage and rollback are not documented; no managed service; unverified at scale. - **Price:** $5.50 (≈ ₹457) — per device / month; UEM-native endpoint security inside the Hexnode console - **Details:** https://www.thetechbag.com/hexnode/hexnode-xdr ### Scalefusion Veltar — Scalefusion - **Who it's for:** Scalefusion UEM estates adding web filtering, DLP and zero-trust access from the same India-hosted console. - **The honest limitation:** Not an anti-malware engine — no detection and response, no rollback; a hardening and access layer beside your EPP, not instead of it. - **Price:** ~$3–4 (≈ ₹249) — per device / month reported; UEM-native: web filtering, DLP, VPN/ZTNA, compliance - **Details:** https://www.thetechbag.com/scalefusion/scalefusion-veltar ### NinjaOne Endpoint Security (Bitdefender / SentinelOne) — NinjaOne - **Who it's for:** NinjaOne RMM estates that want the EDR engine deployed and watched from the RMM console. - **The honest limitation:** You buy the RMM first; the engine is Bitdefender or SentinelOne with their capabilities — rollback and managed options depend on which; NinjaOne regions are US/EU/CA/OC, no India. - **Price:** ~$3–5 (≈ ₹249) — per endpoint / month reported, on top of the NinjaOne RMM seat; resold Bitdefender or SentinelOne engine - **Details:** https://www.thetechbag.com/ninjaone/ninjaone-endpoint-security ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Full EDR.** Rules out CrowdStrike Falcon Prevent (Go / Pro), Sophos Intercept X Advanced, Bitdefender GravityZone Business Security, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Norton Small Business and Hexnode XDR — a prevention-tier SKU; EDR is a higher tier or a separate product; Bitdefender GravityZone PHASR and Scalefusion Veltar — a hardening / access add-on, not detection and response. That leaves Elastic Defend, CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). **Prevention only is enough.** Rules out CrowdStrike Falcon Insight XDR, Trend Vision One XDR, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR and Cisco XDR — an EDR / XDR SKU that needs operators and a prevention engine beside it; Bitdefender GravityZone PHASR and Scalefusion Veltar — an add-on that needs a protection engine beside it. That leaves Elastic Defend, CrowdStrike Falcon Prevent (Go / Pro), SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR, Norton Small Business, Hexnode XDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). **Nobody to triage alerts.** Rules out Elastic Defend, Xcitium OpenEDR, Norton Small Business, Hexnode XDR and Scalefusion Veltar — no managed detection service from the vendor. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags CrowdStrike Falcon Prevent (Go / Pro) — Managed tier is enterprise-gated (quote / E5), CrowdStrike Falcon Insight XDR — Managed tier is enterprise-gated (quote / E5), Microsoft Defender for Endpoint P1 / P2 — Managed tier is enterprise-gated (quote / E5), Check Point Harmony Endpoint — Managed tier is enterprise-gated (quote / E5), Cisco Secure Endpoint — Managed tier is enterprise-gated (quote / E5) and Cisco XDR — Managed tier is enterprise-gated (quote / E5) — marked, not removed. **Automatic file rollback.** Rules out Elastic Defend, CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, Microsoft Defender for Endpoint P1 / P2, Cisco XDR, Coro Endpoint & EDR, Norton Small Business and Scalefusion Veltar — no documented automatic file rollback (response is isolate, kill, restore from your own backups). That leaves SentinelOne Singularity Endpoint, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Hexnode XDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Bitdefender GravityZone PHASR — Rollback not documented either way, Trend Vision One Endpoint Security — Rollback not documented either way, Trend Vision One XDR — Rollback not documented either way, Seqrite Endpoint Protection (on-prem) — Restores from its own backup rather than automatic rollback, Seqrite Endpoint Protection Cloud — Restores from its own backup rather than automatic rollback, Seqrite EDR — Restores from its own backup rather than automatic rollback, Seqrite XDR (HawkkHunt) — Restores from its own backup rather than automatic rollback, Xcitium ZeroDwell (containment) — Prevents by containing unknown files before they run, Xcitium EDR — Prevents by containing unknown files before they run, Xcitium XDR — Prevents by containing unknown files before they run, Xcitium OpenEDR — Rollback not documented either way, Cisco Secure Endpoint — Rollback not documented either way, Fortinet FortiEDR — Rollback not documented either way, Acronis Cyber Protect (EDR) — Restores from its own backup rather than automatic rollback, Hexnode XDR — Rollback not documented either way and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — Rollback not documented either way — marked, not removed. **Linux servers with real-time protection.** Rules out Xcitium OpenEDR and Norton Small Business — no Linux coverage; Coro Endpoint & EDR — Linux agent is scan-only, no real-time protection. That leaves Elastic Defend, CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Bitdefender GravityZone PHASR — Linux coverage not documented, Hexnode XDR — Linux coverage not documented and Scalefusion Veltar — Linux coverage not documented — marked, not removed. **Phones and tablets in the same console.** Rules out Elastic Defend, Bitdefender GravityZone PHASR, ESET PROTECT Entry, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium OpenEDR, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR) and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — no mobile coverage in this SKU. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Coro Endpoint & EDR, Norton Small Business, Hexnode XDR and Scalefusion Veltar. It flags CrowdStrike Falcon Prevent (Go / Pro) — Mobile is a paid add-on to the same console, CrowdStrike Falcon Insight XDR — Mobile is a paid add-on to the same console, SentinelOne Singularity Endpoint — Mobile is a paid add-on to the same console, Sophos Intercept X Advanced — Mobile is a paid add-on to the same console, Sophos Intercept X Advanced with XDR — Mobile is a paid add-on to the same console, Bitdefender GravityZone Business Security — Mobile is a paid add-on to the same console, Bitdefender GravityZone EDR / XDR (Premium · Enterprise) — Mobile is a paid add-on to the same console, Trend Vision One Endpoint Security — Mobile is a paid add-on to the same console, Trend Vision One XDR — Mobile is a paid add-on to the same console and Check Point Harmony Endpoint — Mobile is a paid add-on to the same console — marked, not removed. **On-prem management console.** Rules out CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Trend Vision One XDR, Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection Cloud, Cisco XDR, Coro Endpoint & EDR, Norton Small Business, Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — cloud-only console. That leaves Elastic Defend, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Seqrite Endpoint Protection (on-prem), Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR and Acronis Cyber Protect (EDR). It flags Xcitium ZeroDwell (containment) — On-prem option not documented either way, Xcitium EDR — On-prem option not documented either way and Xcitium XDR — On-prem option not documented either way — marked, not removed. **Vendor-published list price.** Rules out SentinelOne Singularity Endpoint, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone PHASR, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One XDR, Seqrite EDR, Seqrite XDR (HawkkHunt), Check Point Harmony Endpoint, Cisco XDR, Fortinet FortiEDR, Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — quote-only (reported ranges at most). That leaves Elastic Defend, CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, Microsoft Defender for Endpoint P1 / P2, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Cisco Secure Endpoint, Acronis Cyber Protect (EDR), Norton Small Business, Hexnode XDR and Scalefusion Veltar. **Above 2,000 endpoints.** Rules out Norton Small Business — licensed for up to 20 devices. That leaves Elastic Defend, CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR, Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Seqrite Endpoint Protection (on-prem) — Unverified above 2,000 endpoints, Seqrite Endpoint Protection Cloud — Unverified above 2,000 endpoints, Seqrite EDR — Unverified above 2,000 endpoints, Seqrite XDR (HawkkHunt) — Unverified above 2,000 endpoints, Xcitium ZeroDwell (containment) — Unverified above 2,000 endpoints, Xcitium EDR — Unverified above 2,000 endpoints, Xcitium XDR — Unverified above 2,000 endpoints, Xcitium OpenEDR — Unverified above 2,000 endpoints, Coro Endpoint & EDR — Unverified above 2,000 endpoints, Hexnode XDR — Unverified above 2,000 endpoints and Scalefusion Veltar — Unverified above 2,000 endpoints — marked, not removed. **India data residency.** Documented: SentinelOne (Mumbai), Sophos Central (Mumbai), Seqrite (India data centres and on-prem), Acronis (Mumbai), Scalefusion Veltar (India-hosted). CrowdStrike announced an India in-country cloud in January 2026 — announced, not yet documented live. NinjaOne's regions are US / EU / CA / OC (no India). Not documented either way for the rest — so no chip, and nothing is ruled out on it. Ask for the region in writing. **Platform bundling vs best-of-breed.** Not a chip because it is a strategy, not a capability: Defender inside Microsoft 365, NinjaOne / Hexnode / Scalefusion beside a UEM or RMM, Acronis beside backup, Sophos / Trend / Kaspersky / Bitdefender / ESET as platform suites, CrowdStrike / SentinelOne as the best-of-breed agents most other consoles integrate. The instrument tells you what each SKU does; whether one console or two is the right trade is the operating-capacity question. **Agent coexistence.** Rules nothing out but decides the rollout: Windows drops Defender Antivirus to passive mode when another engine registers, so any EPP here coexists with Defender for Endpoint telemetry; Xcitium EDR documents running beside Defender; two third-party real-time engines do not coexist — and the RMM's or UEM's bundled security is the usual way a second one arrives. **Under 50 endpoints.** Rules nothing out on published minimums — Xcitium OpenEDR is free to 50, ESET sells 5-device packs, Defender for Business is sized to 300 users, Bitdefender and CrowdStrike Falcon Go sell small packs, Norton covers up to 20. Which enterprise tiers are a poor fit at this size is delivery-team judgement: [TechBag to confirm]. ## Eight situations, eight shortlists — with the operating question answered Each shortlist states who will run it. If the answer is nobody, the shortlist changes — that is the point. ### 50–500 seats, no security team — someone else must watch it **Shortlist:** Sophos Intercept X Advanced with XDR, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Elite (ESET Inspect XDR) **Why:** Managed detection priced for mid-market, sold with the agent by the same vendor: Sophos leads with MDR as the default product, Bitdefender and ESET sell it on top of published tiers. **Trade-off:** MDR scope is endpoint-first and the contract is what you are buying — read the scope on the Managed Detection & Response guide before the licence. ### Microsoft 365 E5 (or E5 Security) already in place **Shortlist:** Microsoft Defender for Endpoint P1 / P2 **Why:** Defender for Endpoint P2 is already paid for; a second EDR duplicates it. On E3 you hold only P1 — prevention — so the choice becomes E5 Security against a third-party EDR. **Trade-off:** No file rollback in the agent, Defender Experts is a quote, and the console assumes Intune and Entra. One survivor here is the answer, not a gap. ### Ransomware-scarred — file rollback is the requirement **Shortlist:** SentinelOne Singularity Endpoint, Sophos Intercept X Advanced, Kaspersky Next (EDR Foundations · Optimum · Expert) **Why:** Documented automatic rollback: SentinelOne one-click on Windows, Sophos CryptoGuard from protected copies / VSS, Kaspersky's Remediation Engine; ESET and Bitdefender and Check Point qualify too. **Trade-off:** Rollback has conditions (disk space, Windows-first) and restores files, not the breach. Xcitium's containment is the other bet; Acronis and Seqrite restore from their own backups. ### A security team exists and wants to hunt **Shortlist:** CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2 **Why:** Full EDR telemetry, advanced hunting, forensic timeline and scripted response — the reference agents, and the Microsoft-estate equivalent in P2. **Trade-off:** Self-run EDR is a staffing decision: budget analysts or an MDR contract beside the licence. CrowdStrike has no rollback; SentinelOne has no published list. ### India-regulated — on-prem console or India data centre **Shortlist:** Seqrite Endpoint Protection (on-prem), ESET PROTECT Elite (ESET Inspect XDR), Acronis Cyber Protect (EDR) **Why:** On-prem consoles (Seqrite, ESET PROTECT On-Prem, GravityZone, Kaspersky Security Center, Check Point, FortiEDR) and India data centres (Seqrite, Acronis Mumbai, SentinelOne and Sophos Mumbai for cloud). **Trade-off:** On-prem means you run the console server. If cloud with an India region is acceptable, SentinelOne and Sophos reopen the field; CrowdStrike's India cloud is announced, not yet live. ### Budget decides — published prices, no sales cycle **Shortlist:** ESET PROTECT Entry, Bitdefender GravityZone Business Security, Trend Vision One Endpoint Security **Why:** ESET from $42.20 and Bitdefender from $57 per device per year, Trend Vision One Endpoint Essentials from $2.25 per endpoint per month, Xcitium modular from $2.39 — on the vendors' own pages. **Trade-off:** Published entry tiers are prevention-only; EDR costs more at every vendor. Bitdefender's first-year price renews higher — price year two. ### You already run a UEM, an RMM or a backup agent — and want one console **Shortlist:** NinjaOne Endpoint Security (Bitdefender / SentinelOne), Acronis Cyber Protect (EDR), Hexnode XDR **Why:** NinjaOne deploys and watches a resold Bitdefender / SentinelOne engine from the RMM; Acronis puts backup and EDR in one agent; Hexnode XDR and Scalefusion Veltar add security inside the UEM. **Trade-off:** Depth follows the engine: NinjaOne's is real EDR, Acronis recovers by restore, Hexnode XDR is young and Veltar is hardening and access, not an EDR. One console is a convenience; the catch on the card is what you give up. ### Prevention first, with containment instead of detection **Shortlist:** Xcitium ZeroDwell (containment), Sophos Intercept X Advanced, Bitdefender GravityZone PHASR **Why:** Xcitium contains unknown files at the kernel so nothing unrecognised runs; Sophos Intercept X Advanced is prevention with rollback; PHASR hardens the attack surface per user before prevention has to fire. **Trade-off:** Containment can hold a benign-but-new binary until verdicted; PHASR is an add-on, not a protection engine; none of these is a substitute for someone watching when prevention misses. ## At scale Detection quality barely moves with size. Alert volume per analyst, exclusion sprawl and the managed contract’s scope are what move — and they decide whether the EDR tier is real or nominal. ### 200 endpoints — The operating model is the constraint - Prevention-only is often the honest tier here; an EDR console with no owner becomes noise by week three. - Defender for Business, Falcon Go, ESET Entry, GravityZone Business, Trend Essentials, Xcitium's free tier and Norton are all sized for this band. - If you buy EDR, buy the managed tier with it — the licence is the smaller half. **The test:** Run a detection-only week: count alerts, count the ones a human read, count the ones acted on. ### 2,000 endpoints — Alert volume and exclusions are the constraint - Untuned EDR produces more alerts than a small team can triage; tuning and exclusions become an engineering task with an owner. - Agent coexistence with the UEM and RMM fleets must be documented per OS — one bad exclusion at this size is an outage. - MDR scope matters now: which alerts they take, which they hand back, what ‘response’ means in the SLA. **The test:** Deploy to a 200-device ring with the RMM and UEM agents present; measure false positives and CPU for a week; read the MDR SLA aloud. ### 10,000 endpoints — Telemetry, retention and the API are the constraint - Retention windows (days of searchable telemetry) and hunting query performance become line items. - Delegated, scoped administration by region or business unit is mandatory; console and API rate limits decide what you can automate. - Agent updates need rings of their own — a bad sensor release across 10,000 machines is the category's worst day, and it has happened. **The test:** Pull 30 days of telemetry through the API; run your three hardest hunts; confirm staged sensor-update control in writing. CrowdStrike, SentinelOne, Defender, Sophos, Bitdefender, ESET, Trend, Kaspersky, Check Point, Cisco, Fortinet, Acronis and NinjaOne's engines document estates far above 2,000 endpoints; Xcitium, Seqrite, Coro, Hexnode, Scalefusion Veltar and OpenEDR are flagged unverified at that size, not ruled out; Norton is licensed to 20. Where a specific console strains for your estate: [TechBag to confirm]. ## Swapping an EPP is a security event, not an install The agent swap is scriptable through your UEM or RMM. What makes it expensive is the gap: the minutes between old engine off and new engine on, on every machine, and the tamper-protection password nobody remembers. **The agent** — Push the new agent first (passive where the vendor supports it), then remove the old with its tamper-protection credential, then activate. Never the other order. *(Scriptable, in rings)* **Policies and exclusions** — Exclusions for your line-of-business apps, the RMM, the UEM and backup agents are rebuilt by hand. Miss one and the first week is an outage. *(Rebuild)* **Detection history** — Alerts, timelines and hunting data stay in the old console. Export what an audit might ask for before the licence ends. *(Export or lose)* **The managed contract** — MDR terms run on their own calendar. Overlap two services or end one early — either is a cost line nobody put in the licence comparison. *(Overlap or gap)* **Cut-over plan and hours for your estate:** [TechBag to confirm] — TechBag scopes it from your OS mix, the agents already present and the managed contract dates. ## The licence is the smaller half What you may already hold, what the tiers cost in USD and INR, and the part that never appears on the licence line — the people who run it. ### Do you already own one? Four licences you may hold carry endpoint protection. One of them is usually the answer for a Microsoft estate. - **Microsoft 365 — Yes, if.** E5 or E5 Security (Defender for Endpoint P2 — full EDR) or Business Premium (Defender for Business). E3 carries P1 only: prevention, no EDR. - **Your RMM / UEM — Sometimes.** NinjaOne resells Bitdefender / SentinelOne; Hexnode XDR and Scalefusion Veltar live inside the UEM; Acronis pairs EDR with backup. Check which engine — and that it is not a second one. - **Your suite vendor — Often.** Sophos, Trend, Kaspersky, Bitdefender, ESET, Check Point, Cisco and Fortinet all bundle endpoint into their platform contracts. Read the SKU: prevention tier or EDR tier. - **Google Workspace — No.** Gmail filters mail; Chrome Enterprise manages the browser. Neither is an endpoint protection agent for Windows, macOS or Linux. If Defender P2 is already on your invoice, we say so first — and then talk about who will run it. ### What the tiers cost Published USD with INR for scale; per device per year unless the vendor prices per user per month; the EDR tier named separately from the prevention tier wherever the vendor publishes both. Seqrite’s and Acronis’s INR are the India list. ### What isn't in the licence price - **The analyst, or the MDR contract.** An EDR tier without a person is a licence for a dashboard. Price the analyst headcount or the managed service beside the tier — Sophos MDR is reported at $80 ≈ ₹6,640–$200 ≈ ₹16,600 per user per year on top of the agent; CrowdStrike Falcon Complete $25 ≈ ₹2,075–$45 ≈ ₹3,735 per endpoint per *month* reported. That line is usually larger than the licence. - **The renewal, not the promotion.** First-year prices (Bitdefender’s in particular) renew at standard rates; reseller street prices (SentinelOne) move with volume; Microsoft’s E5 moved to $60 in July 2026. Ask for the year-two number in writing before comparing year one. - **Removing the engine you replace.** Tamper-protection credentials, a staged cut-over, exclusion rebuilds and a week of tuning — people-hours, not licence dollars. It sits in [the switching-cost section](#migration), and the hours for your estate are [TechBag to confirm]. ## What goes wrong Each of these is documented vendor behaviour; the matching to real TechBag engagements happens before any becomes a named case. They are cheaper to read now than to live through after the contract. - **EDR bought, nobody triages it.** The console fills; nobody owns it; by month three it is closed. The licence was the cheap half of a purchase that needed a person or a managed contract. - **Two real-time engines on one machine.** The RMM's security add-on, the UEM's XDR or the backup vendor's AV lands beside the EPP you chose. Both degrade; one blocks the other's updates. Only Defender is designed to step aside. - **Assuming EPP covers response.** Prevention tiers stop what they recognise and report the rest. When something gets through there is no timeline, no isolation, no hunt — because that was the next tier. - **Rollback that doesn't cover what you assumed.** Windows-first; needs free disk (Sophos ~3 GB); no rollback if the process was stopped after encryption finished; restores files, not the breach — and absent at CrowdStrike, Defender, Cisco and Coro. - **Alert volume makes the console unusable.** Untuned EDR at 2,000 endpoints outruns a small team within weeks; tuning and exclusions need an owner. The most common reason an EDR quietly fails. - **E3 'includes Defender' — Plan 1, not Plan 2.** Prevention only. The EDR is P2, in E5 or E5 Security. A buyer who stops at 'included' has no detection and believes they do. - **Tamper protection blocks the migration.** The old agent will not uninstall without its credential; the project stalls at machine one. Recover the password before you sign the new contract. - **Year-two price shock.** Promotional first-year pricing (Bitdefender), reseller street pricing (SentinelOne), credit consumption (Trend) and the July 2026 E5 rise all move at renewal. Compare year-two numbers, tier-matched, or the comparison is fiction. ## Questions this guide answers ### What is the difference between EPP, EDR and XDR? EPP prevents known and predicted threats at the endpoint. EDR records what happens on the endpoint so a person can detect, investigate and respond to what got through — it needs someone to read it. XDR extends that telemetry across email, identity, cloud and network. They are widening scopes, not tiers of quality: broader records more, costs more and needs more people to run. Most buyers purchase an EPP believing they bought detection and response. ### Is Microsoft Defender for Endpoint already included in Microsoft 365? Partly. Microsoft 365 E3 includes Defender for Endpoint Plan 1 — prevention, attack-surface reduction, no EDR. E5 and the E5 Security add-on include Plan 2 — full EDR. Business Premium includes Defender for Business. Standalone, P1 is about $3 and P2 $5.20 per user per month. On E3, the real choice is E5 Security against a third-party EDR. ### Which endpoint-protection products can roll back ransomware-encrypted files? Documented automatic rollback: SentinelOne (one-click on Windows), Sophos Intercept X (CryptoGuard), ESET PROTECT (Ransomware Remediation), Bitdefender GravityZone (Ransomware Mitigation), Kaspersky (Remediation Engine) and Check Point Harmony Endpoint (Anti-Ransomware restore). Acronis and Seqrite restore from their own backups. CrowdStrike, Microsoft Defender for Endpoint, Cisco and Coro respond by isolating and killing, not by restoring files. Xcitium contains unknown files before they run, so there is nothing to roll back. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/security/endpoint-protection* --- # You’re not buying software. You’re buying whether someone picks up the phone at 2am — and what they’re permitted to do. *Managed Detection & Response — a TechBag decision guide. Last reviewed 2026-09-07.* > An MDR is a team, a scope and an authority: who watches, what they watch (endpoint-only, the vendor’s platform, or your whole estate), and whether they may contain, remediate or only advise. The software underneath is someone’s EDR — theirs, or yours. **The checkable fact:** Sophos MDR documents integrations for CrowdStrike, Microsoft and others — it can run on an EDR you already own. CrowdStrike Falcon Complete monitors the Falcon platform only. Same word, opposite contracts. - Canonical: https://www.thetechbag.com/browse/security/managed-detection-response - Category: [Security](https://www.thetechbag.com/browse/security) - Products compared: 13 ## What managed detection & response actually is Someone else’s analysts, 24 hours a day, reading the alerts your detection tools raise, deciding which are real, investigating them and — up to a line written in the contract — acting: isolating a host, killing a process, resetting a credential, telling you what to rebuild. The software is the EDR or XDR underneath; the product is the **people, the scope and the authority**. Three things vary more than the brochures admit. **Scope**: endpoint-only, the vendor’s own platform modules, or your whole estate including identity, email, cloud and network. **Whose telemetry**: most services require their own agent; a few run on the EDR you already have — which decides what happens at renewal. **Authority**: advise, contain with pre-approval, or full remediation and incident response. The [endpoint-protection guide](https://www.thetechbag.com/browse/security/endpoint-protection) chooses the agent; this page chooses who runs it. **The most common mis-purchase.** Endpoint-only scope discovered **during an incident**: the attack came through email or a cloud identity, the MDR saw the endpoint, and the contract said endpoints. Scope is the first line of the SLA to read, not the last. ## MDR vs EDR you operate · MDR vs MSSP · MDR vs MXDR Three pairs this buyer confuses, and nothing more. None of them is a quality ladder — each is a wider scope of people and telemetry, and wider costs more and needs more of your cooperation to run. ### MDR vs EDR you operate yourself Same EDR; different operator. Self-run EDR means your analysts read the console every day — budget the people. MDR means the vendor's or a partner's analysts do, within a contract. The tool is identical; the difference is the 2am phone call and who is permitted to act. ### MDR vs MSSP An MSSP manages security devices and monitors logs — firewalls, SIEM, tickets — and escalates to you. An MDR is built around detection and response on endpoints and telemetry, with analysts who investigate and act. MSSP breadth, MDR depth; many providers now sell both under one name — ask which you are being sold. ### MDR vs MXDR MXDR is MDR over XDR telemetry: endpoint plus email, identity, cloud and network, correlated. Wider scope, more sources to onboard, more for the analysts to read — and only worth it when those sources exist and the service actually ingests them. Platform vendors use the X to mean 'our stack'; ask which sources, named. **These are widening scopes, not tiers.** Self-run EDR → MDR → MXDR → MSSP-plus-MDR each adds people and telemetry, costs more, and needs more of your estate wired in. Buy the scope that matches where your incidents actually start — and read the authority line before the price. ## The decision variables Six variables decide this purchase. The instrument tests the ones documentation can verify (telemetry, scope, channel, compliance); response authority, India hours, onboarding and exit are prose because the honest answer is in the SLA, not the datasheet. **Scope of what's monitored.** Endpoint-only, the vendor's platform modules, or your whole estate including identity, email, cloud and network — the most common mis-purchase is discovering the first during an incident. **Response authority.** Advise-only, pre-approved containment, or full remediation and incident response. The ceiling is written in the SLA; read it aloud. **Whose telemetry.** Does the service require its own EDR agent, or run on the one you already have? It decides the price of switching and what you keep at renewal. **India-hours coverage and language.** 24/7 global is not the same as an analyst in Indian hours and language; only Mitigata documents an India SOC. **Onboarding time.** Days once a vendor agent is deployed; weeks per source for a BYO-telemetry estate. **What happens when you leave.** Vendor-agent MDRs take the tuning and detections with them; BYO services leave your tools standing. Price the re-tooling before you sign, not after. ## The 13 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### N-able Security (Adlumin) — N-able - **Who it's for:** MSPs that want to sell managed security under their own brand without building a security operations centre — the 24/7 analyst rota alone is unreachable for most. SentinelOne-powered EDR plus the Adlumin platform acquired November 2024 for up to $266M: cloud-native XDR, MDR, ITDR, SIEM support, SOAR and pen testing, sitting beside an N-able RMM you may already run. - **The honest limitation:** THE MODULE LIST IS NOT THE PRODUCT — the service commitment is, and when you resell under your own name your client holds YOU rather than Adlumin. Get response times, analyst coverage hours and escalation paths in writing and hold them against what you have promised your own clients; any gap is one you absorb on every incident. The EDR engine is licensed from SentinelOne, not owned. The Adlumin integration is only eighteen months old. Where the SOC analysts sit is a separate question from N-able's Bengaluru engineering centre — ask it explicitly. - **Price:** Quote — Quote-only, and a separate product from N-able's RMM platforms. EDR is typically per endpoint; the managed services price by their own logic. Establish what incident response is included versus chargeable — that is where MDR contracts most often surprise people - **Details:** https://www.thetechbag.com/n-able/n-able-security ### Rapid7 Managed Threat Complete — Rapid7 - **Who it's for:** Mid-market organisations that want a 24/7 SOC and vulnerability management from one vendor on one agent. The SLAs are contractual rather than marketing — 15 minutes to begin investigating a critical alert, a phone call within 30 minutes of identifying an incident — and they are identical across all three tiers. A Leader in the 2025 Frost Radar for MDR. - **The honest limitation:** ACTIVE RESPONSE CONTAINS EXACTLY TWO THINGS: it quarantines endpoints and disables users. That is the complete list, and most buyers assume more. Incident response is remote-only with no on-site attendance, and the Rapid7 Agent is MANDATORY even where a third-party EDR does the containment — assets without it are excluded from threat hunts and investigations entirely. No India data region, so your logs sit offshore. Reviewers also report the SOC sometimes closes incidents without sufficient explanation. - **Price:** Quote — Buyer-reported ~$15–22 per asset / month (midpoint near $17) with a 500-asset minimum commonly applied — quote-only, so treat those as directional. What is genuinely unusual is what the per-asset price INCLUDES: unlimited incident response with no retainer or hour cap, and unlimited InsightVM vulnerability scanning bundled in, which no pure-play MDR vendor offers - **Details:** https://www.thetechbag.com/rapid7/rapid7-managed-threat-complete ### Sophos MDR (Essentials · Complete) — Sophos - **Who it's for:** The largest pure-play MDR: 24/7 analysts on Sophos's agent or on the EDR, firewall and identity telemetry you already run, with full-scale incident response in the Complete tier. - **The honest limitation:** No published list (reported ranges only); the Essentials tier stops at containment — full incident response is Complete; an India-located SOC is not documented. - **Price:** ~$80–200+ (≈ ₹6,640) — per user / year reported (Essentials → Complete); AWS Marketplace lists $239.64 per endpoint / year; Mumbai data region - **Details:** https://www.thetechbag.com/sophos/sophos-mdr ### Bitdefender MDR (Foundations · Premium · Enterprise) — Bitdefender - **Who it's for:** GravityZone estates — and SMBs via Foundations — wanting 24×7 monitoring, pre-approved response and threat-intel hunting without building a SOC. - **The honest limitation:** Runs on Bitdefender's agent only; incident response beyond containment and the tailored threat model arrive at Premium / Enterprise; India SOC not documented. - **Price:** ~$6.99–10.49 (≈ ₹580) — per endpoint / month reported (MDR Core / Advanced SKUs); needs GravityZone - **Details:** https://www.thetechbag.com/bitdefender/bitdefender-mdr ### Kaspersky MDR (Optimum · Expert) — Kaspersky - **Who it's for:** Kaspersky Next estates wanting the vendor's analysts with response actions (isolate, kill, registry) run automatically or on your approval. - **The honest limitation:** Kaspersky telemetry only; procurement-sensitive in some sectors and countries (check your regulator); incident response is a separate Kaspersky service; no published list. - **Price:** Quote — per endpoint / year; Optimum (SMB, in Kaspersky Next MXDR Optimum) · Expert (enterprise, with KATA) - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-mdr ### CrowdStrike Falcon Complete — CrowdStrike - **Who it's for:** Enterprises on the Falcon platform that want CrowdStrike's own team running it 24/7 with surgical remediation and a breach warranty. - **The honest limitation:** Monitors the Falcon platform — third-party telemetry is Next-Gen SIEM, not Complete; enterprise-priced on quote; India in-country cloud announced, not yet documented live. - **Price:** ~$25–45 (≈ ₹2,075) — per endpoint / month reported (enterprise deployments); quote-only; covers the Falcon modules you license - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-falcon-complete ### SentinelOne Vigilance Respond / Respond Pro — SentinelOne - **Who it's for:** SentinelOne estates adding 24/7 triage, containment and — in Respond Pro — forensics and incident response on the agent they already run. - **The honest limitation:** An add-on to SentinelOne only; priced per endpoint on top of the endpoint licence; an India-located SOC is not documented (data region is). - **Price:** ~$15–50 (≈ ₹1,245) — per endpoint / year add-on reported, on top of a Singularity licence (Complete ~$179.99); Respond Pro adds DFIR; Mumbai region - **Details:** https://www.thetechbag.com/sentinelone/sentinelone-singularity-mdr ### Trend Service One (Managed XDR) — Trend Micro - **Who it's for:** Trend Vision One estates that want the vendor's analysts correlating endpoint, email, cloud and network from one console. - **The honest limitation:** Needs Trend sensors across those surfaces to be worth it; credit billing is opaque until you run it; no published list. - **Price:** Credits / quote — Vision One credits + service tier; covers endpoint, email, server, cloud workload and network sensors - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-service-one ### ESET MDR / MDR Ultimate — ESET - **Who it's for:** ESET PROTECT estates that want 24/7 monitoring with response actions ESET runs automatically or only the ones you allow. - **The honest limitation:** ESET endpoint telemetry only — no third-party EDR, no estate-wide ingestion; quote-only; the Elite tier is a prerequisite for XDR-grade detection. - **Price:** Quote — per device / year on top of ESET PROTECT (Elite for Inspect XDR); Ultimate adds premium support and a named team - **Details:** https://www.thetechbag.com/eset/eset-protect-mdr ### Xcitium MDR — Xcitium - **Who it's for:** Xcitium estates — and Defender shops — that want analysts plus ZeroDwell containment so unknowns never run while the SOC looks. - **The honest limitation:** Young at scale (unverified above 2,000 endpoints); response is containment-first rather than full incident response; India SOC not documented. - **Price:** Modular — per endpoint / month modules on the Xcitium platform; Managed EDR for Microsoft Defender is a documented variant - **Details:** https://www.thetechbag.com/xcitium/xcitium-mdr ### Barracuda Managed XDR — Barracuda - **Who it's for:** Organisations served by an MSP that wants a 24/7 SOC over endpoints, email, identity and cloud without building one. - **The honest limitation:** Sold and delivered through MSPs, not direct; response is containment and guidance through the MSP; which third-party EDRs it ingests is partner-documented, not listed publicly. - **Price:** Quote — per endpoint / user through an MSP; ingests endpoint, server, identity, cloud, email and firewall telemetry - **Details:** https://www.thetechbag.com/barracuda/barracuda-managed-xdr ### Coro Managed SOC — Coro - **Who it's for:** SMBs that want one agent, one console and one bill — with Coro's SOC handling what its auto-remediation does not. - **The honest limitation:** Coro modules only (endpoint, email, cloud apps) — nothing it does not itself monitor; SMB-positioned and unverified above 2,000 endpoints; price now quote-only. - **Price:** ~$20 (≈ ₹1,660) — per user / month managed (historical; public list withdrawn in 2026) over Coro's endpoint, email and cloud-app modules - **Details:** https://www.thetechbag.com/coro/coro-managed-soc ### Mitigata Managed SOC — Mitigata - **Who it's for:** India-regulated organisations that want the SOC, the compliance programme (DPDP, ISO 27001, SOC 2, SEBI CSCRF) and the cyber-insurance broker from one provider, in Indian hours and language. - **The honest limitation:** Founded 2023 — documented scale is young and the tooling is partner-delivered on your stack; quote-only; not a fit if you want a single global vendor's branded agent and SOC. - **Price:** Quote (INR) — INR, per estate; 24×7 SOC from India on your tools, with incident response, forensics, CERT-In-empanelled audits and IRDAI-regulated cyber insurance under one roof - **Details:** https://www.thetechbag.com/mitigata/mitigata-managed-soc ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Runs on the tools you already have.** Rules out Rapid7 Managed Threat Complete, Bitdefender MDR (Foundations · Premium · Enterprise), Kaspersky MDR (Optimum · Expert), CrowdStrike Falcon Complete, SentinelOne Vigilance Respond / Respond Pro, Trend Service One (Managed XDR), ESET MDR / MDR Ultimate and Coro Managed SOC — requires the vendor's own agent; it does not run on third-party telemetry. That leaves N-able Security (Adlumin), Sophos MDR (Essentials · Complete), Xcitium MDR, Barracuda Managed XDR and Mitigata Managed SOC. **You run CrowdStrike.** Rules out Bitdefender MDR (Foundations · Premium · Enterprise), Kaspersky MDR (Optimum · Expert), SentinelOne Vigilance Respond / Respond Pro, Trend Service One (Managed XDR), ESET MDR / MDR Ultimate and Coro Managed SOC — cannot run on CrowdStrike telemetry (its own agent only). That leaves N-able Security (Adlumin), Rapid7 Managed Threat Complete, Sophos MDR (Essentials · Complete), CrowdStrike Falcon Complete, Xcitium MDR, Barracuda Managed XDR and Mitigata Managed SOC. It flags N-able Security (Adlumin) — Ingests third-party telemetry; CrowdStrike specifically not documented, Xcitium MDR — Ingests third-party telemetry; CrowdStrike specifically not documented and Barracuda Managed XDR — Ingests third-party telemetry; CrowdStrike specifically not documented — marked, not removed. **You run Microsoft Defender.** Rules out Bitdefender MDR (Foundations · Premium · Enterprise), Kaspersky MDR (Optimum · Expert), CrowdStrike Falcon Complete, SentinelOne Vigilance Respond / Respond Pro, Trend Service One (Managed XDR), ESET MDR / MDR Ultimate and Coro Managed SOC — cannot run on Defender telemetry (its own agent only). That leaves N-able Security (Adlumin), Rapid7 Managed Threat Complete, Sophos MDR (Essentials · Complete), Xcitium MDR, Barracuda Managed XDR and Mitigata Managed SOC. **You run SentinelOne.** Rules out Bitdefender MDR (Foundations · Premium · Enterprise), Kaspersky MDR (Optimum · Expert), CrowdStrike Falcon Complete, Trend Service One (Managed XDR), ESET MDR / MDR Ultimate and Coro Managed SOC — cannot run on SentinelOne telemetry (its own agent only). That leaves N-able Security (Adlumin), Rapid7 Managed Threat Complete, Sophos MDR (Essentials · Complete), SentinelOne Vigilance Respond / Respond Pro, Xcitium MDR, Barracuda Managed XDR and Mitigata Managed SOC. It flags Sophos MDR (Essentials · Complete) — Ingests third-party telemetry; SentinelOne specifically not documented, Xcitium MDR — Ingests third-party telemetry; SentinelOne specifically not documented and Barracuda Managed XDR — Ingests third-party telemetry; SentinelOne specifically not documented — marked, not removed. **Whole-estate scope.** Rules out ESET MDR / MDR Ultimate — endpoint telemetry only. That leaves N-able Security (Adlumin), Rapid7 Managed Threat Complete, Sophos MDR (Essentials · Complete), Bitdefender MDR (Foundations · Premium · Enterprise), Kaspersky MDR (Optimum · Expert), CrowdStrike Falcon Complete, SentinelOne Vigilance Respond / Respond Pro, Trend Service One (Managed XDR), Xcitium MDR, Barracuda Managed XDR, Coro Managed SOC and Mitigata Managed SOC. It flags Bitdefender MDR (Foundations · Premium · Enterprise) — Covers the vendor's own platform modules, Kaspersky MDR (Optimum · Expert) — Covers the vendor's own platform modules, CrowdStrike Falcon Complete — Covers the vendor's own platform modules, SentinelOne Vigilance Respond / Respond Pro — Covers the vendor's own platform modules, Xcitium MDR — Covers the vendor's own platform modules and Coro Managed SOC — Covers the vendor's own platform modules — marked, not removed. **Buying direct.** Rules out N-able Security (Adlumin) and Barracuda Managed XDR — sold and delivered through MSPs. That leaves Rapid7 Managed Threat Complete, Sophos MDR (Essentials · Complete), Bitdefender MDR (Foundations · Premium · Enterprise), Kaspersky MDR (Optimum · Expert), CrowdStrike Falcon Complete, SentinelOne Vigilance Respond / Respond Pro, Trend Service One (Managed XDR), ESET MDR / MDR Ultimate, Xcitium MDR, Coro Managed SOC and Mitigata Managed SOC. **CERT-In audit and cyber insurance together.** Rules out N-able Security (Adlumin), Rapid7 Managed Threat Complete, Sophos MDR (Essentials · Complete), Bitdefender MDR (Foundations · Premium · Enterprise), Kaspersky MDR (Optimum · Expert), CrowdStrike Falcon Complete, SentinelOne Vigilance Respond / Respond Pro, Trend Service One (Managed XDR), ESET MDR / MDR Ultimate, Xcitium MDR, Barracuda Managed XDR and Coro Managed SOC — a detection-and-response service only; audits and insurance are other vendors. That leaves Mitigata Managed SOC. **Above 5,000 endpoints.** Rules nothing out on published terms. It flags N-able Security (Adlumin) — Unverified above 5,000 endpoints, Xcitium MDR — Unverified above 5,000 endpoints, Coro Managed SOC — Unverified above 5,000 endpoints and Mitigata Managed SOC — Unverified above 5,000 endpoints — marked, not removed. **Response authority.** Not a chip because every service here documents containment; what differs is the ceiling. Sophos MDR Complete, CrowdStrike Falcon Complete, SentinelOne Respond Pro and Mitigata document full incident response (forensics, eradication, rebuild guidance); Bitdefender, Trend, Xcitium, Barracuda and Coro document pre-approved containment with guidance; Kaspersky and ESET let you set whether the analysts act automatically or on approval, and Kaspersky's incident response is a separate service. Read the authority line of the SLA — it is the product. **India-hours coverage and language.** Documented India SOC: Mitigata. Every other service is 24/7 from global SOCs — which may well cover Indian business hours — but an India-located analyst team, Indian-language support and in-country data handling are not documented for them, so nothing is ruled out on it. Ask where the analyst who calls at 2am sits, and in what language. **Onboarding time.** Vendor-agent services onboard in days once the agent is deployed (the agent rollout is the project); BYO-telemetry services (Sophos integrations, Barracuda, Mitigata) onboard per source — weeks for a multi-vendor estate. Your number is [TechBag to confirm]. **What happens when you leave.** Vendor-agent MDRs leave you with the agent licence and no analysts — the detections and the tuning were theirs; BYO services leave your tools and your telemetry in place. Exit is the hidden variable: price the re-tooling before you sign. **Under 100 endpoints.** Rules nothing out on documentation: Bitdefender MDR Foundations, Coro, Xcitium and Sophos MDR are sold to small estates; CrowdStrike Falcon Complete is enterprise-positioned but publishes no floor. Which SLAs are a poor fit at that size is delivery-team judgement: [TechBag to confirm]. ## Eight situations, eight shortlists — with the authority line answered Each shortlist names who will be on the bridge at 2am and what they may do. If you already run an EDR, start from that row. ### 200–2,000 endpoints, no SOC, no EDR yet — buy the agent and the people together **Shortlist:** Sophos MDR (Essentials · Complete), Bitdefender MDR (Foundations · Premium · Enterprise), ESET MDR / MDR Ultimate **Why:** One contract: the vendor's agent plus 24/7 analysts, priced for mid-market. Sophos leads with MDR as the default product; Bitdefender Foundations and ESET MDR ride on published endpoint tiers. **Trade-off:** You are choosing the EDR at the same time — and the exit path: when the MDR goes, the agent's tuning and detections go with it. ### You already run CrowdStrike **Shortlist:** CrowdStrike Falcon Complete, Sophos MDR (Essentials · Complete), Mitigata Managed SOC **Why:** Falcon Complete runs the platform you licensed with surgical remediation and a breach warranty; Sophos MDR and Mitigata are documented to ingest CrowdStrike telemetry if you want an independent SOC. **Trade-off:** Falcon Complete is enterprise-priced and Falcon-only; an independent SOC adds integration work and a second party to the incident bridge. ### Microsoft 365 E5 — Defender for Endpoint P2 is already on the invoice **Shortlist:** Sophos MDR (Essentials · Complete), Xcitium MDR, Barracuda Managed XDR **Why:** Defender Experts for XDR is Microsoft's own managed tier (E5 prerequisite, quote); the documented third-party options that run on Defender telemetry are Sophos MDR, Xcitium's Managed EDR for Microsoft Defender and Barracuda's MXDR. **Trade-off:** Running someone else's SOC on Defender telemetry keeps your agent; running Microsoft's keeps one vendor — price both, and read what 'response' means in each. ### You already run SentinelOne **Shortlist:** SentinelOne Vigilance Respond / Respond Pro, Mitigata Managed SOC **Why:** Vigilance Respond (and Respond Pro with DFIR) is the add-on built for the agent; Mitigata runs on your tools with an India SOC. **Trade-off:** Vigilance is priced per endpoint on top of the endpoint licence; Sophos and Barracuda may ingest SentinelOne but do not document it — confirm before assuming. ### India-regulated — audits, insurance and a 24×7 SOC in Indian hours **Shortlist:** Mitigata Managed SOC **Why:** The only service here with a documented India SOC plus CERT-In-empanelled audits, DPDP / ISO 27001 / SOC 2 / SEBI CSCRF programmes and IRDAI-regulated cyber insurance under one roof — uncopyable by a global vendor. **Trade-off:** Founded 2023: young scale, partner-delivered tooling on your stack, quote-only. One survivor is the honest answer here; pair it with a global agent if the board wants a brand. ### Whole estate — email, identity, cloud and network, not only endpoints **Shortlist:** Trend Service One (Managed XDR), Sophos MDR (Essentials · Complete), Barracuda Managed XDR **Why:** Trend correlates its sensors across email, endpoint, cloud and network; Sophos and Barracuda ingest third-party telemetry across the same surfaces. **Trade-off:** Trend's breadth needs Trend sensors everywhere; Sophos and Barracuda need integration work per source — and scope creep is where 'endpoint-only discovered during an incident' is avoided or not. ### Your MSP runs IT and should run security too **Shortlist:** Barracuda Managed XDR, Xcitium MDR, Coro Managed SOC **Why:** Barracuda Managed XDR is built to be delivered through MSPs; Xcitium and Coro sell MSP programmes with the SOC attached. **Trade-off:** You are one step removed from the analyst — make the MSP's escalation path and your direct access to the SOC part of the contract. ### SMB wanting one agent, one console, one bill **Shortlist:** Coro Managed SOC, Xcitium MDR, Bitdefender MDR (Foundations · Premium · Enterprise) **Why:** Coro's modules with its SOC, Xcitium's modular platform with MDR, Bitdefender MDR Foundations — all priced and positioned for small estates. **Trade-off:** Scope is the stack: Coro watches Coro, Xcitium watches Xcitium; if the incident starts in a tool they do not see, you are on your own. ## At scale An MDR scales by alert volume and by the number of sources it must ingest, not by endpoint count alone. The bill scales per endpoint; the value scales with scope. ### 250 endpoints — Scope is the constraint - A vendor-agent MDR onboards in days and covers the endpoints; the incident that starts in email or identity is outside the contract unless you wired it in. - Bitdefender Foundations, Coro, Xcitium and Sophos MDR Essentials are priced for this band; Falcon Complete is enterprise-positioned. - The agent and the SOC are one decision here — and so is the exit. **The test:** Run a tabletop: an email-borne credential theft. Ask the vendor which step they would have seen and which they would have acted on. ### 2,000 endpoints — Sources and authority are the constraint - Identity, email and cloud telemetry must be ingested or the SOC is blind where attacks start; BYO-telemetry services earn their keep here. - Authority must be pre-agreed per action — a containment that waits for approval at 2am is a notification. - Tuning becomes a joint project: their detections, your exclusions, one owner on each side. **The test:** Ask for the named list of ingested sources for your estate and a signed authority matrix before the PoC, not after. ### 10,000 endpoints — Exit and sovereignty are the constraint - Multi-region, multi-business-unit scoping; data residency per source; the India SOC question becomes a board question. - A mandated agent at this size is a multi-year lock — price the switch before the first renewal. - Your own SOC-lite (SIEM + a few analysts) plus an MDR for night cover is the common honest shape. **The test:** Price a full exit: agent replacement, detection rebuild, telemetry export. If the number is unbearable, you have learned the real contract. Sophos, Bitdefender, Kaspersky, CrowdStrike, SentinelOne, Trend, ESET and Barracuda document estates well above 5,000 endpoints; Xcitium, Coro and Mitigata are flagged unverified at that size, not ruled out. Where a specific service strains for your estate: [TechBag to confirm]. ## Leaving an MDR is the variable nobody priced The analysts stop; the agent stays licensed or not; the detections and tuning were theirs. What you keep depends entirely on whose telemetry the service ran on. **Vendor-agent MDR** — The agent licence continues (you can self-run or buy another MDR on it); the vendor's detection content, tuning and runbooks leave with the service. *(Re-tool the operations)* **BYO-telemetry MDR** — Your EDR, SIEM and integrations stay; you lose the analysts and whatever detections lived in their platform. Onboarding the next service is per source again. *(Re-onboard sources)* **Evidence and history** — Incident records, timelines and reports sit in the provider's portal. Export what audits and insurers may ask for before the contract ends. *(Export or lose)* **The overlap** — MDR contracts run on their own calendar; the new service needs weeks to onboard. Overlap two or accept a gap — either is a cost line. *(Overlap or gap)* **Exit plan and re-onboarding weeks for your estate:** [TechBag to confirm] — TechBag scopes it from your sources, agents and contract dates. ## Per endpoint per month, times who is on the bridge What you may already hold, the services priced the same way at three estate sizes in USD and INR, and what the licence line leaves out — which, for an MDR, is most of the story. ### Do you already own one? Four places a managed service may already be within reach. - **Microsoft 365 E5 — Partly.** Defender Experts for XDR is Microsoft’s own managed tier over Defender P2 — E5 prerequisite, quoted separately. E5 gives you the telemetry, not the analysts. - **Your EDR vendor — Often.** Sophos, SentinelOne, Bitdefender, ESET, Kaspersky, Trend, Xcitium and CrowdStrike all sell the people on top of the agent you run. Read scope and authority before assuming it is the obvious answer. - **Your MSP — Sometimes.** Barracuda Managed XDR, Xcitium and Coro are built to be delivered by MSPs. Ask the MSP which SOC is behind it and what authority they hold. - **Your cyber-insurer — No.** Insurers price your controls; they do not run them — except Mitigata, which is an IRDAI-regulated broker and a SOC at once. If the people you need already sit behind a licence you hold, we say so — and then read the authority line with you. ### What the rest actually cost Reported and reseller-listed prices (no MDR vendor here publishes a list), normalised to per endpoint per month, INR for scale, then worked at 250 / 1,000 / 5,000 endpoints. Where a service is quote-only the line says so rather than guessing. ### What isn't in the licence price - **The authority you didn't buy.** A service that notifies at 2am while you approve is a notification, not a response. The price gap between Essentials and Complete tiers — reported $80 ≈ ₹6,640 to $200 ≈ ₹16,600 per user per year at Sophos — is the gap between those two nights. - **Your own hours.** Every MDR needs a person on your side to answer the call, approve the action and own the tuning. Budget one named owner and an escalation rota; the vendor will ask for it in week one. - **The exit.** Agent replacement, detection rebuild, telemetry re-onboarding — the switching-cost section above. With a mandated-agent service this is the largest number in the contract; with a BYO service it is the smallest. Your number is [TechBag to confirm]. ## What goes wrong Documented scope and authority lines, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover on the bridge. - **Endpoint-only scope discovered during an incident.** The attack came through email or a cloud identity; the MDR saw the endpoint; the contract said endpoints. Scope is the first SLA line to read. - **Vendor lock via the mandated agent.** The MDR required its EDR; three years later the EDR, the detections and the tuning are all theirs. Switching means re-tooling the estate — the real contract length. - **'24/7' that means a ticket queue.** Round-the-clock monitoring is not round-the-clock response. Ask whether a human investigates at 2am or a ticket is created for 9am — in which time zone. - **Response authority narrower than assumed.** Pre-approved containment stopped at isolating the host; credential resets and cloud actions were 'advise'. The authority matrix, signed, is the product. - **No exit path without re-tooling.** Nobody priced leaving. With a mandated agent, the exit is an endpoint migration plus a detection rebuild; plan it before signing, not at renewal. - **Two SOCs, one incident.** An MDR for endpoints and an MSSP for the firewall, neither owning the bridge. Name the incident commander in the contract. - **Platform 'XDR' that means 'our stack'.** The X covered the vendor's email and cloud modules you do not run. Name the ingested sources for your estate, in writing. - **India hours assumed, not documented.** Global SOC coverage is real; an analyst in Indian hours and language is documented once on this page. Ask where the caller sits. ## Questions this guide answers ### What is the difference between MDR, MSSP and MXDR? MDR is a team of analysts running detection and response on endpoint (and often wider) telemetry, with authority to investigate and act within a contract. An MSSP manages security devices and monitors logs and escalates to you — breadth rather than response depth. MXDR is MDR over XDR telemetry: endpoint plus email, identity, cloud and network, correlated. They are widening scopes, not tiers of quality; wider costs more and needs more of your estate wired in. ### Can an MDR run on the EDR I already have? Some can. Sophos MDR documents integrations for CrowdStrike, Microsoft and other telemetry; Xcitium documents Managed EDR for Microsoft Defender; Barracuda Managed XDR and Mitigata run on your tools. CrowdStrike Falcon Complete, SentinelOne Vigilance, Bitdefender MDR, Kaspersky MDR, ESET MDR, Trend Service One and Coro require their own agent or platform — which also decides what you keep when you leave. ### Which MDR is India-specific? Mitigata: a 24×7 SOC from India on your tools, with CERT-In-empanelled audits, DPDP / ISO 27001 / SOC 2 / SEBI CSCRF programmes and IRDAI-regulated cyber-insurance broking under one roof. SentinelOne and Sophos document Mumbai data regions for their platforms; an India-located analyst team is not documented for the global services. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/security/managed-detection-response* --- # Your mail platform already filters spam. What it doesn’t stop is a message with no attachment, no link and no malware. *Email Security — a TechBag decision guide. Last reviewed 2026-09-07.* > Exchange Online Protection and Gmail catch the commodity threats; the remaining purchase is behavioural — who normally writes to whom about what — and architectural: a gateway in front of the tenant, or an API behind it. **The checkable fact:** Defender for Office 365 Plan 1 is in Business Premium and, from 1 July 2026, in Microsoft 365 E3; Plan 2 is in E5. Check which you hold before pricing a third filter. - Canonical: https://www.thetechbag.com/browse/security/email-security - Category: [Security](https://www.thetechbag.com/browse/security) - Products compared: 22 ## What email security actually is A filter between the internet and your people’s inboxes — and increasingly their chat windows. It removes malware and phishing links (the commodity job your platform already does well), and it tries to catch the message that carries neither: the supplier “changing bank details”, the CEO asking for gift cards, the lookalike domain. That second job is **behavioural**: it needs to know who normally writes to whom, about what, from where. Two architectures do it. A **gateway** takes your MX record and filters before mail reaches the tenant — strong for commodity threats, outbound DLP and continuity, slow to cut over. An **API** deployment reads the mailbox through Microsoft’s or Google’s interfaces — live in an hour, no MX change, and (depending on the product) removing a message seconds after delivery or blocking it inline. Enterprises increasingly run one of each; SMBs increasingly run the API layer on top of what the platform includes. **The most common mis-purchase.** **Gateway or API** is not a feature; it is the deployment model, and it sets cut-over risk, what the tool can see, whether it can block before delivery, and who owns the quarantine. Decide it before the vendor shortlist, not after. ## Gateway vs API deployment · what the mail platform already filters Two things this buyer confuses, and nothing more. Neither pair is a ladder: gateway and API are different places to stand, and the platform’s own filtering is the floor you are adding to, not replacing. ### Gateway (MX) deployment Your MX record points at the vendor; mail is filtered before it reaches Microsoft 365 or Google. Sees everything inbound and outbound, blocks before delivery, carries DLP and continuity — and the cut-over is a project with a rollback plan. Proofpoint, Mimecast, Barracuda, FortiMail, Forcepoint, Trend, Cloudflare inline. ### API deployment The vendor reads and acts on mailboxes through Microsoft Graph or Google APIs. No MX change, live in an hour, sees internal and collaboration traffic — and some products scan post-delivery (remove within seconds) while others (Check Point inline mode) block before the user sees it. Abnormal, Check Point, Coro; Proofpoint, Mimecast, Sophos, Barracuda, Trend, Cloudflare and Kaspersky also offer it. ### What the platform already filters Exchange Online Protection in every Microsoft 365 plan; Defender for Office 365 P1 in Business Premium and (from July 2026) E3; P2 in E5. Gmail's 99.9% spam/phishing/malware block and advanced phishing controls in every edition. The floor is high; what it lacks at depth is behavioural BEC detection, collaboration scanning and third-party DLP. **These are widening scopes, not tiers.** Platform filtering → an API behavioural layer → a full gateway each adds visibility and control, costs more, and adds a console someone must run. Buy the deployment your change-control and your threat actually require — and read what your tenant already includes before adding a third filter. ## The decision variables Six variables decide this purchase. The instrument tests deployment, threat focus, collaboration scope, awareness, hosting and published pricing; India residency and the platform floor are prose because the honest answers are “documented twice” and “it depends on your licence”. **Gateway vs API deployment.** The architectural split that decides cut-over risk, pre- vs post-delivery blocking, and who owns the quarantine. Many vendors now do both — the chip shows which. **BEC and impersonation vs malware filtering.** The commodity job is done by the platform; the purchase is the message with no payload. Behavioural detection is documented at most vendors here — Kaspersky's is anti-phishing first. **What Microsoft 365 / Google already include.** EOP and Defender P1/P2, Gmail's controls — the floor. Know which plan you hold before you price a third filter. **Collaboration coverage beyond mail.** Teams, Slack, SharePoint, OneDrive, Google Drive — where the links now arrive. An add-on almost everywhere; in-policy at Check Point and Abnormal. **Awareness training — bundled or separate.** Barracuda, Trend (Phish Insight) and Coro bundle it; Proofpoint, Mimecast, Sophos and Kaspersky sell it as a separate SKU; Abnormal, Check Point, FortiMail, Cloudflare, Forcepoint and Bitdefender do not sell it. Bought and never run is the failure mode. **India data residency for mail content.** Documented at Proofpoint (Mumbai) and Sophos (Mumbai); unknown elsewhere. Flagged, never eliminated — ask in writing. ## The 22 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### N-able Mail Assure — N-able - **Who it's for:** MSPs administering email security across many client tenants who want ONE console instead of thirty Microsoft admin centres — which is frequently the real business case. Filtering runs both directions (outbound limits how far a compromised account travels), with continuity when the mail platform is down and archiving whose retention survives mailbox deletion and platform migration. - **The honest limitation:** Its mechanism is collective intelligence — threat data pooled across the customer base — which is fast and effective against VOLUME attacks and has no prior sighting to learn from on a message written for one organisation. Not the deepest product here: Proofpoint and Mimecast go further on targeted attack and Abnormal AI's behavioural approach is strong precisely where pooling is weakest. And check first whether the client's existing M365 tier already includes Defender for Office 365 — many own it and have never configured it. - **Price:** Quote — Quote-only, and a separate product from N-able's RMM platforms. Establish whether archiving is included or an add-on, how retention beyond the standard window is charged, and whether counting is per seat or per domain across your client base - **Details:** https://www.thetechbag.com/n-able/n-able-mail-assure ### Abnormal Inbound Email Security — Abnormal AI - **Who it's for:** Estates on Microsoft 365 or Google Workspace that keep the native gateway and add behavioural AI for the message with no attachment, no link and no malware. - **The honest limitation:** API-only — it does not replace the gateway; reported minimum contract values rule out very small estates; no awareness training; India residency not documented. - **Price:** ~$15–35 (≈ ₹1,245) — per employee / year reported; API-only (no MX change); minimum contracts reported $25–50k - **Details:** https://www.thetechbag.com/abnormal/abnormal-inbound-email ### Abnormal Account Takeover Protection — Abnormal AI - **Who it's for:** Abnormal estates adding account-compromise detection to inbound protection. - **The honest limitation:** An add-on to Abnormal, not a mail filter on its own; quote-only. - **Price:** Quote — add-on module; detects compromised mailboxes and identities via behavioural baselines - **Details:** https://www.thetechbag.com/abnormal/abnormal-account-takeover ### Proofpoint Email Protection (Essentials · Core) — Proofpoint - **Who it's for:** The reference gateway — now also API-deployable — for estates that want Proofpoint's threat intelligence, DLP and archiving lineage with an India data centre. - **The honest limitation:** Essentials is the published SMB line; enterprise Core is quote-only and the suite (awareness, DMARC, DLP) is separate SKUs that add up; on-prem is the legacy appliance path. - **Price:** $2–5.86 (≈ ₹166) — per user / month (Essentials Business → Professional); Core / enterprise on quote; Mumbai data centre (2025) - **Details:** https://www.thetechbag.com/proofpoint/proofpoint-email-security ### Proofpoint Email Fraud Defense (DMARC) — Proofpoint - **Who it's for:** Teams that must stop their own domain being spoofed — DMARC to enforcement with supplier visibility. - **The honest limitation:** Stops spoofing of your domain; does not filter inbound mail — a companion, not a filter. - **Price:** Quote — DMARC authentication and supplier-risk visibility; gateway-agnostic - **Details:** https://www.thetechbag.com/proofpoint/proofpoint-email-fraud ### Proofpoint Security Awareness — Proofpoint - **Who it's for:** Estates that want the training fed by the same threat intelligence that filters their mail. - **The honest limitation:** Training, not detection; bought and never run is the category's quietest failure. - **Price:** Quote — per user / year; simulations + training tied to Proofpoint threat data - **Details:** https://www.thetechbag.com/proofpoint/proofpoint-awareness-training ### Mimecast Email Security (Cloud Gateway · Cloud Integrated) — Mimecast - **Who it's for:** Mid-market and enterprise estates wanting a mature gateway with an API option, archiving and continuity from one vendor. - **The honest limitation:** No published list; the collaboration, awareness and DMARC pieces are separate SKUs; India data centre not documented (APAC is Singapore). - **Price:** ~$5–15 (≈ ₹415) — per user / month reported (UK G-Cloud shows ~$58–88 / user / year for mid tiers); gateway or API-integrated for Microsoft 365 - **Details:** https://www.thetechbag.com/mimecast/mimecast-advanced-email-security ### Mimecast Collaboration Security — Mimecast - **Who it's for:** Mimecast estates extending protection to the messages that are not email. - **The honest limitation:** An add-on — the gateway is a separate SKU; quote-only. - **Price:** Quote — Teams, Slack, Zoom and file-share protection; API-based add-on - **Details:** https://www.thetechbag.com/mimecast/mimecast-collaboration-security ### Mimecast Aware (awareness training) — Mimecast - **Who it's for:** Mimecast estates adding training from the same console. - **The honest limitation:** Training, not detection; separate SKU. - **Price:** Quote — per user / year; video-led training and simulations - **Details:** https://www.thetechbag.com/mimecast/mimecast-aware ### Mimecast DMARC Analyzer — Mimecast - **Who it's for:** Teams getting their own domains to DMARC enforcement, whatever gateway they run. - **The honest limitation:** Protects your domain's reputation; filters nothing inbound. - **Price:** Quote — DMARC, SPF, DKIM reporting to enforcement; gateway-agnostic - **Details:** https://www.thetechbag.com/mimecast/mimecast-dmarc-analyzer ### Sophos Email — Sophos - **Who it's for:** Sophos Central estates that want mail filtering in the same console as endpoint, firewall and MDR — with a Mumbai data region. - **The honest limitation:** No published list; no Teams / Slack coverage; awareness (Phish Threat) is a separate SKU; strongest inside a Sophos estate. - **Price:** ~$28–48 (≈ ₹2,324) — per user / year reported (Advanced; Email Plus tier from April 2026 on quote); gateway or Microsoft 365 API; Mumbai region - **Details:** https://www.thetechbag.com/sophos/sophos-email ### Sophos Phish Threat — Sophos - **Who it's for:** Sophos estates running simulations from the console they already use. - **The honest limitation:** Training only; separate SKU. - **Price:** Quote — per user / year; simulations and training in Sophos Central - **Details:** https://www.thetechbag.com/sophos/sophos-phish-threat ### Check Point Harmony Email & Collaboration — Check Point - **Who it's for:** Microsoft 365 / Google Workspace estates that want API deployment that can still block before delivery, plus collaboration apps in scope. - **The honest limitation:** API-only (no MX gateway); no awareness SKU; no published list; India data region not documented. - **Price:** ~$15–40 (≈ ₹1,245) — per user / year reported; API-based for Microsoft 365 and Google Workspace with inline prevent mode; Teams, SharePoint, OneDrive, Google Drive - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-harmony-email ### Barracuda Email Protection — Barracuda - **Who it's for:** Mid-market estates that want gateway filtering, API-based impersonation protection, awareness training and backup in one published-price bundle. - **The honest limitation:** Collaboration apps are not covered; the useful pieces (forensics, awareness) sit in the higher tiers; India data centre not documented. - **Price:** $3–12 (≈ ₹249) — per user / month (Advanced → Premium Plus); gateway plus API impersonation protection; awareness training bundled at higher tiers; appliance option - **Details:** https://www.thetechbag.com/barracuda/barracuda-email-protection ### Fortinet FortiMail — Fortinet - **Who it's for:** Fortinet Security Fabric estates — and anyone who needs an on-prem mail gateway they own. - **The honest limitation:** Gateway-first; no collaboration coverage; no awareness SKU on TechBag; quote-only. - **Price:** Quote — appliance, VM or FortiMail Cloud; per mailbox / domain on quote; Microsoft 365 API integration is documented for the cloud service - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortimail ### Trend Micro Email Security / Vision One Email & Collaboration — Trend Micro - **Who it's for:** Trend Vision One estates wanting mail and collaboration telemetry in the same XDR as the endpoint, with Phish Insight simulations included. - **The honest limitation:** Listing prices vary widely with volume; Vision One credit billing for the XDR side is opaque; India data region not documented. - **Price:** ~$60 (≈ ₹4,980) — per user / year listing (Standard); Advanced higher; 4–5k seats reported $6–8; gateway or API (Cloud App Security for Microsoft 365 / Google) - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-email-security ### Cloudflare Email Security (Area 1) — Cloudflare - **Who it's for:** Cloudflare One estates adding pre-emptive phishing and BEC detection to the zero-trust bundle. - **The honest limitation:** Sold inside the Zero Trust bundle — no standalone list; no collaboration or awareness; strongest when Cloudflare already fronts your traffic. - **Price:** Quote — per user, inside Cloudflare Zero Trust; MX (inline) or API deployment - **Details:** https://www.thetechbag.com/cloudflare/cloudflare-email-security ### Bitdefender GravityZone Extended Email Security — Bitdefender - **Who it's for:** GravityZone estates adding mail filtering to the console they already run. - **The honest limitation:** New in 2026 — deployment mode, collaboration coverage and depth are thinly documented; listed as a small bundle rather than per mailbox. - **Price:** $479.47 (≈ ₹39,796) — per year listing for a small bundle (5 devices, 2 file servers, 8 mailboxes); launched April 2026 - **Details:** https://www.thetechbag.com/bitdefender/bitdefender-email-security ### Kaspersky Security for Mail Server / for Microsoft Office 365 — Kaspersky - **Who it's for:** Kaspersky estates wanting anti-phishing and malware filtering on-prem or inside Microsoft 365, with collaboration stores in scope. - **The honest limitation:** Behavioural BEC detection is not documented at the level of Abnormal or Check Point; procurement caveats apply in some sectors; quote-only. - **Price:** Quote — per mailbox / year; on-prem mail-server gateway or API for Microsoft 365 (Exchange Online, SharePoint, OneDrive, Teams) - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-email-security ### Kaspersky Security Awareness (ASAP) — Kaspersky - **Who it's for:** Teams wanting automated, adaptive training independent of the mail filter. - **The honest limitation:** Training only; procurement caveats apply. - **Price:** Quote — per user / year; automated training platform - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-security-awareness ### Forcepoint Email Security — Forcepoint - **Who it's for:** Regulated estates that want an on-prem or hybrid gateway with DLP from the same vendor. - **The honest limitation:** Gateway only (no API mode); no collaboration or awareness; strongest paired with Forcepoint DLP. - **Price:** $2.40 (≈ ₹199) — per user / month listing; cloud, on-prem or hybrid gateway with Forcepoint DLP integration - **Details:** https://www.thetechbag.com/forcepoint/forcepoint-email-security ### Coro Email Protection — Coro - **Who it's for:** SMBs that want mail protection in the same modular agent and bill as endpoint and cloud apps. - **The honest limitation:** API-only; collaboration apps are a separate module; price now quote-only; India residency not documented. - **Price:** ~$10.50 (≈ ₹872) — per user / month historical (public list withdrawn in 2026); API for Microsoft 365 and Google; awareness module bundled - **Details:** https://www.thetechbag.com/coro/coro-email-security ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **API deployment.** Rules out N-able Mail Assure, Fortinet FortiMail and Forcepoint Email Security — MX gateway only; Proofpoint Email Fraud Defense (DMARC) and Mimecast DMARC Analyzer — DMARC tooling, not a mail filter; Proofpoint Security Awareness, Mimecast Aware (awareness training), Sophos Phish Threat and Kaspersky Security Awareness (ASAP) — awareness training, not a mail filter. That leaves Abnormal Inbound Email Security, Abnormal Account Takeover Protection, Proofpoint Email Protection (Essentials · Core), Mimecast Email Security (Cloud Gateway · Cloud Integrated), Mimecast Collaboration Security, Sophos Email, Check Point Harmony Email & Collaboration, Barracuda Email Protection, Trend Micro Email Security / Vision One Email & Collaboration, Cloudflare Email Security (Area 1), Bitdefender GravityZone Extended Email Security, Kaspersky Security for Mail Server / for Microsoft Office 365 and Coro Email Protection. It flags Bitdefender GravityZone Extended Email Security — Deployment mode not documented — marked, not removed. **MX gateway deployment.** Rules out Abnormal Inbound Email Security, Check Point Harmony Email & Collaboration and Coro Email Protection — API-only; it does not sit in front of the tenant; Abnormal Account Takeover Protection — an account-takeover add-on, not the mail filter; Proofpoint Email Fraud Defense (DMARC) and Mimecast DMARC Analyzer — DMARC tooling, not a mail filter; Proofpoint Security Awareness, Mimecast Aware (awareness training), Sophos Phish Threat and Kaspersky Security Awareness (ASAP) — awareness training, not a mail filter; Mimecast Collaboration Security — a collaboration add-on, not the mail filter. That leaves N-able Mail Assure, Proofpoint Email Protection (Essentials · Core), Mimecast Email Security (Cloud Gateway · Cloud Integrated), Sophos Email, Barracuda Email Protection, Fortinet FortiMail, Trend Micro Email Security / Vision One Email & Collaboration, Cloudflare Email Security (Area 1), Bitdefender GravityZone Extended Email Security, Kaspersky Security for Mail Server / for Microsoft Office 365 and Forcepoint Email Security. It flags Bitdefender GravityZone Extended Email Security — Deployment mode not documented — marked, not removed. **BEC and impersonation without a payload.** Rules out N-able Mail Assure and Kaspersky Security for Mail Server / for Microsoft Office 365 — anti-phishing and malware filtering; behavioural BEC detection not documented; Abnormal Account Takeover Protection — an account-takeover add-on, not the mail filter; Proofpoint Email Fraud Defense (DMARC) and Mimecast DMARC Analyzer — DMARC tooling, not a mail filter; Proofpoint Security Awareness, Mimecast Aware (awareness training), Sophos Phish Threat and Kaspersky Security Awareness (ASAP) — awareness training, not a mail filter; Mimecast Collaboration Security — a collaboration add-on, not the mail filter. That leaves Abnormal Inbound Email Security, Proofpoint Email Protection (Essentials · Core), Mimecast Email Security (Cloud Gateway · Cloud Integrated), Sophos Email, Check Point Harmony Email & Collaboration, Barracuda Email Protection, Fortinet FortiMail, Trend Micro Email Security / Vision One Email & Collaboration, Cloudflare Email Security (Area 1), Bitdefender GravityZone Extended Email Security, Forcepoint Email Security and Coro Email Protection. **Collaboration apps too.** Rules out N-able Mail Assure, Mimecast Email Security (Cloud Gateway · Cloud Integrated), Sophos Email, Barracuda Email Protection, Fortinet FortiMail, Cloudflare Email Security (Area 1), Bitdefender GravityZone Extended Email Security, Forcepoint Email Security and Coro Email Protection — email only; no collaboration-app coverage; Abnormal Account Takeover Protection — an account-takeover add-on, not the mail filter; Proofpoint Email Fraud Defense (DMARC) and Mimecast DMARC Analyzer — DMARC tooling, not a mail filter; Proofpoint Security Awareness, Mimecast Aware (awareness training), Sophos Phish Threat and Kaspersky Security Awareness (ASAP) — awareness training, not a mail filter. That leaves Abnormal Inbound Email Security, Proofpoint Email Protection (Essentials · Core), Mimecast Collaboration Security, Check Point Harmony Email & Collaboration, Trend Micro Email Security / Vision One Email & Collaboration and Kaspersky Security for Mail Server / for Microsoft Office 365. **Awareness training in the same contract.** Rules out N-able Mail Assure, Abnormal Inbound Email Security, Abnormal Account Takeover Protection, Proofpoint Email Fraud Defense (DMARC), Mimecast DMARC Analyzer, Check Point Harmony Email & Collaboration, Fortinet FortiMail, Cloudflare Email Security (Area 1), Bitdefender GravityZone Extended Email Security and Forcepoint Email Security — no awareness training from this vendor. That leaves Proofpoint Email Protection (Essentials · Core), Proofpoint Security Awareness, Mimecast Email Security (Cloud Gateway · Cloud Integrated), Mimecast Collaboration Security, Mimecast Aware (awareness training), Sophos Email, Sophos Phish Threat, Barracuda Email Protection, Trend Micro Email Security / Vision One Email & Collaboration, Kaspersky Security for Mail Server / for Microsoft Office 365, Kaspersky Security Awareness (ASAP) and Coro Email Protection. It flags Proofpoint Email Protection (Essentials · Core) — Same vendor, separate SKU, Mimecast Email Security (Cloud Gateway · Cloud Integrated) — Same vendor, separate SKU, Mimecast Collaboration Security — Same vendor, separate SKU, Sophos Email — Same vendor, separate SKU and Kaspersky Security for Mail Server / for Microsoft Office 365 — Same vendor, separate SKU — marked, not removed. **On-prem or hybrid gateway.** Rules out N-able Mail Assure, Abnormal Inbound Email Security, Abnormal Account Takeover Protection, Mimecast Email Security (Cloud Gateway · Cloud Integrated), Mimecast Collaboration Security, Sophos Email, Check Point Harmony Email & Collaboration, Cloudflare Email Security (Area 1), Bitdefender GravityZone Extended Email Security and Coro Email Protection — cloud-only service; Proofpoint Email Fraud Defense (DMARC) and Mimecast DMARC Analyzer — DMARC tooling, not a mail filter; Proofpoint Security Awareness, Mimecast Aware (awareness training), Sophos Phish Threat and Kaspersky Security Awareness (ASAP) — awareness training, not a mail filter. That leaves Proofpoint Email Protection (Essentials · Core), Barracuda Email Protection, Fortinet FortiMail, Trend Micro Email Security / Vision One Email & Collaboration, Kaspersky Security for Mail Server / for Microsoft Office 365 and Forcepoint Email Security. It flags Trend Micro Email Security / Vision One Email & Collaboration — On-prem option not documented either way — marked, not removed. **Vendor-published list price.** Rules out N-able Mail Assure, Abnormal Inbound Email Security, Abnormal Account Takeover Protection, Proofpoint Email Fraud Defense (DMARC), Proofpoint Security Awareness, Mimecast Email Security (Cloud Gateway · Cloud Integrated), Mimecast Collaboration Security, Mimecast Aware (awareness training), Mimecast DMARC Analyzer, Sophos Email, Sophos Phish Threat, Check Point Harmony Email & Collaboration, Fortinet FortiMail, Cloudflare Email Security (Area 1), Kaspersky Security for Mail Server / for Microsoft Office 365, Kaspersky Security Awareness (ASAP) and Coro Email Protection — quote-only (reported ranges at most). That leaves Proofpoint Email Protection (Essentials · Core), Barracuda Email Protection, Trend Micro Email Security / Vision One Email & Collaboration, Bitdefender GravityZone Extended Email Security and Forcepoint Email Security. **India data residency for mail content.** Documented: Proofpoint (Mumbai data centre, 2025) and Sophos Central (Mumbai). Not documented either way for the rest — Mimecast's APAC centre is Singapore; Abnormal, Check Point, Barracuda, Trend, Cloudflare, Bitdefender, Kaspersky, Forcepoint and Coro publish no India region for mail content. Nothing is ruled out on it; ask where the message body is stored and scanned, in writing. **What Microsoft 365 and Google Workspace already filter.** Not a chip because it removes nothing from this list — it removes part of the purchase. Exchange Online Protection is in every Microsoft 365 plan; Defender for Office 365 Plan 1 (Safe Links / Attachments, anti-phishing) is in Business Premium and, from 1 July 2026, in E3; Plan 2 (Threat Explorer, automated investigation, attack simulation) is in E5. Gmail blocks 99.9% of spam, phishing and malware and exposes advanced phishing and malware controls in every edition. What neither does at depth is behavioural BEC detection, collaboration-app scanning and third-party DLP — that is the gap these products price. **Double-filtering.** Two filters in series (a gateway and the platform's own) is fine; two that both quarantine, with two admin consoles and two release paths, is the usual source of 'the mail never arrived'. Decide which one holds the quarantine before cut-over. ## Eight situations, eight shortlists — with the deployment decided first Every shortlist starts from your mail platform and whether MX may change. The filter is the second decision. ### Microsoft 365, a BEC scare, and no appetite to touch MX **Shortlist:** Abnormal Inbound Email Security, Check Point Harmony Email & Collaboration, Coro Email Protection **Why:** API-based behavioural detection sits behind Exchange Online Protection and Defender P1 without a gateway cut-over; Check Point can still block inline, Coro bundles it for SMBs. **Trade-off:** Abnormal's reported minimums rule out very small estates; API-only tools do not replace the gateway you may need for outbound DLP and continuity. ### Google Workspace estate **Shortlist:** Check Point Harmony Email & Collaboration, Abnormal Inbound Email Security, Trend Micro Email Security / Vision One Email & Collaboration **Why:** All three document Google Workspace API deployment (Check Point and Trend also cover Google Drive / collaboration); Gmail keeps the commodity filtering. **Trade-off:** Gateway-first vendors (Proofpoint, Mimecast, Barracuda, FortiMail) work on Google too — but via MX, with the cut-over that implies. ### Regulated — an on-prem or hybrid gateway, or an India data centre **Shortlist:** Forcepoint Email Security, Fortinet FortiMail, Proofpoint Email Protection (Essentials · Core) **Why:** Forcepoint and FortiMail ship appliances and VMs you own; Proofpoint documents a Mumbai data centre; Kaspersky and Barracuda also offer on-prem gateways. **Trade-off:** On-prem means you patch the gateway; a Mumbai region for cloud (Proofpoint, Sophos) may satisfy the regulator without the appliance — ask before you buy hardware. ### You already run Sophos, Trend, Kaspersky, Bitdefender or ESET on the endpoint **Shortlist:** Sophos Email, Trend Micro Email Security / Vision One Email & Collaboration, Kaspersky Security for Mail Server / for Microsoft Office 365 **Why:** Mail inside the console you already run (Sophos Central, Vision One, Kaspersky Security Center) — one agent estate, one vendor, and often one bundle price. **Trade-off:** Suite email is rarely the deepest BEC detection; if impersonation is the threat, layer an API tool on top rather than assume the suite covers it. ### Enterprise — gateway and API, layered **Shortlist:** Proofpoint Email Protection (Essentials · Core), Abnormal Inbound Email Security, Mimecast Email Security (Cloud Gateway · Cloud Integrated) **Why:** The common enterprise shape: a gateway (Proofpoint or Mimecast) for commodity threats, outbound DLP and continuity, plus an API behavioural layer (Abnormal, Check Point) for BEC. **Trade-off:** Two contracts, two consoles, one quarantine owner — decide which before cut-over or the double-filtering failure mode finds you. ### Teams, Slack and SharePoint are where the links now arrive **Shortlist:** Check Point Harmony Email & Collaboration, Mimecast Collaboration Security, Abnormal Inbound Email Security **Why:** Check Point covers Teams / SharePoint / OneDrive / Google Drive in the same policy; Mimecast sells Collaboration Security as an add-on; Abnormal extends to Slack, Teams and Zoom messaging; Trend and Kaspersky cover the Microsoft stores. **Trade-off:** Collaboration coverage is an add-on almost everywhere — price it as one; and the platform's own DLP for those apps may already be on your invoice. ### Awareness training and DMARC on the same contract **Shortlist:** Proofpoint Email Protection (Essentials · Core), Mimecast Email Security (Cloud Gateway · Cloud Integrated), Barracuda Email Protection **Why:** Proofpoint (Security Awareness + Email Fraud Defense), Mimecast (Aware + DMARC Analyzer) and Barracuda (awareness bundled at Premium Plus) put filter, training and domain protection under one vendor. **Trade-off:** Same vendor is not the same SKU — Proofpoint's and Mimecast's pieces are priced separately; Barracuda's bundle is tier-gated. Training bought and never run is the failure mode, whoever sells it. ### SMB — published price, no sales cycle **Shortlist:** Proofpoint Email Protection (Essentials · Core), Barracuda Email Protection, Forcepoint Email Security **Why:** Proofpoint Essentials from $2 per user per month, Barracuda from $3, Forcepoint at $2.40 — on the vendors' own pages or listings. **Trade-off:** Published entry tiers are gateway filtering; BEC behavioural AI and collaboration coverage cost more at every vendor — check which tier you are actually pricing. ## At scale Mail security scales by mailboxes and by the number of domains, tenants and collaboration apps in scope — and by how many people will answer user reports. ### 250 mailboxes — The floor plus one layer - What the platform includes is most of the answer; an API behavioural layer or a published-price gateway is the purchase. - Abnormal's reported minimums rule it out; Proofpoint Essentials, Barracuda, Forcepoint, Coro and the suite vendors are priced for this band. - One admin owns the quarantine and the user-report queue. **The test:** Send yourself a payload-free impersonation from a lookalike domain during the trial; count which layer caught it. ### 2,000 mailboxes — Domains, DLP and the report queue - Multiple domains and DMARC enforcement become a project; outbound DLP starts to matter — which pulls toward a gateway or the platform's own DLP. - User-reported phish at this size needs triage tooling or it becomes noise. - Collaboration apps are now in scope whether you bought coverage or not. **The test:** Run DMARC to p=reject on one domain; measure the user-report volume for a month and who triaged it. ### 20,000 mailboxes — Architecture, residency and two layers - Gateway plus API is the common shape; continuity and archiving are separate decisions with their own vendors. - Data residency for mail content becomes a board question — two vendors document an India centre. - Tenant consolidation and M&A mean the filter must handle many tenants and many MX records. **The test:** Test cut-over on a pilot domain with full rollback; confirm where the message body is scanned and stored, in writing. Proofpoint, Mimecast, Barracuda, Trend, Sophos, Check Point, Cloudflare, Kaspersky and Forcepoint document very large estates; Abnormal does too (enterprise-first); Coro is SMB-positioned; Bitdefender’s email product is new (April 2026). Where a specific filter strains for your estate: [TechBag to confirm]. ## Switching filters is a DNS change — or an API revoke — plus everything you tuned The technical swap is small; the policy, the allow-lists, the quarantine history and the users’ habits are what move slowly. **MX gateway** — Lower TTL, point MX at the new gateway, keep the old for a week, then remove it and lock the tenant connector to the new IPs. A DNS change with a project around it. *(DNS + connector)* **API product** — Authorise the new app, run both for a fortnight in report-only, revoke the old. The lightest switch in security. *(Authorise / revoke)* **Policies and allow-lists** — Impersonation lists, trusted senders, DLP rules and quarantine policies are rebuilt by hand — no import format. *(Rebuild)* **Quarantine and reports** — Quarantined mail, investigation history and user-report records stay in the old console. Export or release what you need before it closes. *(Export or lose)* **Cut-over plan and rebuild hours for your tenant:** [TechBag to confirm] — TechBag scopes it from your domains, policies and collaboration apps in scope. ## Per mailbox per month, layered on what you already pay for What your tenant already includes, what the filters cost in USD and INR at three estate sizes, and what the licence leaves out. ### Do you already own one? Four licences you may hold already filter mail. Usually they are the floor, not the answer — but know the floor. - **Microsoft 365 — Partly.** Exchange Online Protection everywhere; Defender for Office 365 P1 in Business Premium and (from 1 July 2026) E3; P2 in E5. Commodity filtering, Safe Links / Attachments, basic impersonation — not behavioural BEC AI, not third-party DLP. - **Google Workspace — Partly.** Gmail blocks 99.9% of spam, phishing and malware with advanced controls in every edition. Behavioural BEC, collaboration-app scanning and DLP depth are what the products here add. - **Your endpoint suite — Often.** Sophos Email, Trend, Kaspersky, Bitdefender and ESET PROTECT Complete bundle mail filtering with the endpoint contract. Read the tier — it is rarely the deepest BEC detection. - **Your SASE / CDN — Sometimes.** Cloudflare Zero Trust includes Email Security; Cisco and Fortinet bundle mail into their platforms. If you already pay, ask what is switched on. If the plan you hold already does the job, we say so before the quote — and then show you the message it would have missed. ### What the rest actually cost Published and reported prices normalised to per mailbox per month (INR for scale), then worked at 250 / 2,000 / 20,000 mailboxes. The platform’s own add-ons are in the grid because they are the honest comparator. ### What isn't in the licence price - **The cut-over.** An MX change with rollback, connector lock-down and a week of dual-running; or an API authorisation and a fortnight in report-only. People-hours, not licence dollars — in [the switching-cost section](#migration); your number is [TechBag to confirm]. - **The quarantine owner and the report queue.** Someone releases quarantined mail and triages user reports every working day. At 2,000 mailboxes that is a role, not a task — and two products with two quarantines doubles it. - **Training that nobody runs.** Awareness SKUs bundled or separate (Barracuda, Trend, Coro bundle; Proofpoint, Mimecast, Sophos, Kaspersky sell separately) need a person to schedule simulations and read the results. Budget the hour a month or skip the SKU. ## What goes wrong Documented deployment behaviour, cross-checked against TechBag engagements before any becomes a named case. Most of these are seams, not products. - **Double-filtering with the native platform.** A gateway and Defender / Gmail both quarantining, two consoles, two release paths. 'The mail never arrived' — decide which product owns the quarantine before cut-over. - **MX record changes during a gateway cutover.** TTL not lowered, no rollback record, tenant connector not locked to the gateway — mail bounces or bypasses for a day. A DNS change is a project. - **API deployments that only scan post-delivery.** The message was read in the seconds before removal. If that window matters, choose an inline-capable API (Check Point) or a gateway. - **Awareness training bought and never run.** The SKU was on the quote; nobody scheduled a simulation. The cheapest line in the contract and the most often wasted. - **BEC assumed covered by the suite.** The endpoint suite's mail tier filtered malware well and missed the supplier's changed bank details. Behavioural detection is the top tier or a separate vendor. - **Collaboration apps left out of scope.** The link arrived in Teams; the contract said mail. Coverage beyond mail is an add-on almost everywhere. - **Your own domain spoofed.** No inbound filter stops a spoof of you arriving at your customers. DMARC to enforcement is a separate project — Proofpoint EFD, Mimecast DMARC Analyzer, or your platform. - **Residency assumed.** Two vendors document an India data centre for mail content. For the rest, where the message body is scanned and stored is a question to ask in writing — not a box on the datasheet. ## Questions this guide answers ### What is the difference between gateway and API email security? A gateway takes your MX record and filters mail before it reaches Microsoft 365 or Google — pre-delivery blocking, outbound DLP and continuity, with a DNS cut-over. An API product reads mailboxes through Microsoft Graph or Google APIs — no MX change, live in an hour, visibility into internal and collaboration traffic; some remove messages seconds after delivery, others (Check Point's inline mode) block before the user sees them. Many vendors now offer both; enterprises often run one of each. ### Does Microsoft 365 already include email security? Yes, a floor: Exchange Online Protection in every plan; Defender for Office 365 Plan 1 (Safe Links, Safe Attachments, anti-phishing) in Business Premium and, from 1 July 2026, in E3; Plan 2 (Threat Explorer, automated investigation and response, attack simulation) in E5. Standalone P1 is about $2 and P2 $5 per user per month. What it lacks at depth is behavioural BEC detection, collaboration-app scanning and third-party DLP. ### Which email security vendors document an India data centre? Proofpoint (Mumbai data centre, launched 2025) and Sophos (Sophos Central Mumbai region). Mimecast's APAC centre is Singapore; Abnormal, Check Point, Barracuda, Trend Micro, Cloudflare, Bitdefender, Kaspersky, Forcepoint and Coro publish no India region for mail content — ask in writing before assuming. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/security/email-security* --- # Finding vulnerabilities is the easy part. The question is which twenty matter, and who fixes them. *Vulnerability Management — a TechBag decision guide. Last reviewed 2026-09-07.* > Every tool here will hand you thousands of findings on day one. The purchase is the model that ranks them by real risk, and the capacity — yours or the tool’s — to close the ones at the top. **The checkable fact:** Tenable Nessus Professional is $4,790 a year per scanner, unlimited IPs. Qualys VMDR is reported at ~$199–250 per asset a year — and bundles the patch. Same findings; opposite answers to “who fixes it”. - Canonical: https://www.thetechbag.com/browse/security/vulnerability-management - Category: [Security](https://www.thetechbag.com/browse/security) - Products compared: 15 ## What vulnerability management actually is A continuous inventory of what you run and what is wrong with it: missing patches, misconfigurations, exposed services, weak ciphers — on hosts, web applications, cloud accounts, containers and industrial controllers. A scanner (or an agent) finds them; a scoring model ranks them; a report or a ticket hands them to whoever fixes things. That last hand-off is where most programmes fail. The field has split three ways. **Scanners** (Nessus, Tenable VM, Qualys VMDR, WAS) find and rank. **Exposure platforms** (Tenable One, Qualys TruRisk, Trend CREM, Falcon Exposure) aggregate several sources into one risk view with attack-path context. **Remediation tools** (Action1, Qualys Patch Management) actually apply the fix — and a **service** (Mitigata VAPT, Sophos Managed Risk) does the work with people. Knowing which of the three your gap is saves the purchase. **The most common mis-purchase.** Raw CVSS is useless at volume — half of everything is “high”. The **prioritisation model** (exploit activity, threat intelligence, asset criticality, compensating controls) is what separates a list from a plan. Ask every vendor how many of your 20,000 findings their model calls urgent, and why. ## Scanning vs exposure management vs pentest vs BAS Four terms this buyer confuses, and nothing more. They are widening or adjacent scopes — not tiers. Each costs more and needs more people than the one before, and none replaces the others. ### Vulnerability scanning Automated, continuous, broad: find known weaknesses on everything you can reach or install an agent on, rank them, report. The foundation — and the source of the thousands of findings nobody actions. Nessus, Tenable VM, Qualys VMDR, WAS, Falcon Exposure. ### Exposure management Scanning's findings plus cloud posture, identity, OT and external attack surface, aggregated into one risk view with attack paths. Wider scope, enterprise price, and it still does not fix anything — it tells you what to fix first. Tenable One, Qualys TruRisk, Trend CREM. ### Penetration testing (VAPT) Humans, point-in-time, goal-directed: can an attacker actually get in through this application or network, chaining what a scanner only lists. Required by many Indian regulators as an empanelled report. Mitigata VAPT; not a replacement for continuous scanning. ### Breach & attack simulation (BAS) Automated adversary techniques run continuously against your controls to see what your EDR, mail filter and SIEM actually catch. Adjacent: it tests detection, not exposure. No BAS product is on this page — it belongs beside the SOC. **These are adjacent and widening scopes, not a ladder.** Scanning finds; exposure management ranks across surfaces; a pentest proves; BAS tests the defenders. Each costs more and needs more people to act on than the last — and the cheapest purchase of all is remediation capacity for the findings you already have. ## The decision variables Six variables decide this purchase. The instrument tests coverage, prioritisation model, agent vs agentless, remediation, the CERT-In line and published pricing; compliance reporting and scale are prose because the honest answer depends on your regulator and your estate. **Scanning coverage.** Network and hosts, web apps and APIs, cloud accounts and containers, OT — each vendor covers some natively and sells the rest as separate SKUs. The chips name which. **Prioritisation model.** The real differentiator: TruRisk, VPR, ExPRT.AI, Trend's risk index, an expert's judgement — or raw CVSS. Ask how many of your findings each model calls urgent, and why. **Agent-based vs agentless vs both.** Agents see roaming laptops and need no scan window; scanners see unmanaged devices and need credentials; both is the usual honest answer for a mixed estate. **Does it remediate or only report.** Where Action1 and Qualys differ fundamentally from Tenable, CrowdStrike and Trend: the fix on the same agent, or a ticket to your patch tool. **Compliance reporting for RBI, SEBI CSCRF, ISO.** Tool reports satisfy many audits; some Indian regulators name an empanelled VAPT — Mitigata's line. Read the circular before the datasheet. **Scale behaviour.** Per-asset pricing, scan windows, agent fleets and the size of the list nobody actions — the thresholds are in the scale section, the vendor-specific ones are delivery-team experience. ## The 15 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Rapid7 InsightVM — Rapid7 - **Who it's for:** Hybrid estates that want prioritisation grounded in real exploitation evidence rather than raw CVSS, and — the part most vulnerability tools do badly — a way to turn findings into assigned work with deadlines. Shares one agent with Rapid7’s SIEM, so a detection can be read alongside the vulnerability posture of the same host. - **The honest limitation:** HYBRID, NOT SaaS — you must host a Security Console with a PostgreSQL database, and the sizing is heavy (12 cores / 64 GB / 2 TB at 20,000 assets). Reviewers report console memory exhaustion during parallel scans and scheduled scans taking 20 hours where a manual run takes 3–4. The agent does LOCAL checks only — no remote or unauthenticated network checks — so an agent-only rollout silently misses exposed services and TLS misconfigurations. Real Risk scoring was retired 21 Jan 2026 and historical scores cannot be recalculated. - **Price:** ~$1.62 (≈ ₹1,577) — per asset / MONTH published from 500 assets (~$19/asset/year) — one of the few published prices in this category. Active Risk scores 0–1000 weighted by real exploitation evidence from CISA KEV, Metasploit and Rapid7’s own honeypot network; Remediation Projects and SLA goals assign findings as deadlined work - **Details:** https://www.thetechbag.com/rapid7/rapid7-insightvm ### Rapid7 InsightAppSec — Rapid7 - **Who it's for:** Teams needing dynamic testing of internet-facing web applications and APIs, and Indian buyers mapping to SEBI CSCRF’s per-release VAPT expectation — per-application pricing lines up neatly with a per-application testing obligation. - **The honest limitation:** DAST only — it tests running applications from the outside, so it finds nothing in source code and does not replace SAST or dependency scanning. Priced per application, so a large portfolio adds up quickly. And it inherits Rapid7’s platform constraint: no India data region. - **Price:** $175 (≈ ₹1,74,300) — per APPLICATION / month published (~$2,100/app/year) — rare transparency in DAST, and it makes it easy to start with just the handful of applications that genuinely face the internet. Crawls running web apps and APIs and attacks them as an external tester would, covering the OWASP Top 10 with attack replay so a developer can reproduce a finding - **Details:** https://www.thetechbag.com/rapid7/rapid7-insightappsec ### Qualys VMDR (with patching) — Qualys - **Who it's for:** Estates that want discovery, scanning, TruRisk prioritisation and remediation on one agent — the 'find it and fix it' tenant, with a Pune-engineered India platform. - **The honest limitation:** No published list (reported per-asset ranges); web-app scanning (WAS) and cloud (TotalCloud) are separate SKUs; the per-asset price looks high until volume discounts bite. - **Price:** ~$199–250 (≈ ₹16,517) — per asset / year reported (volume discounts from ~1,000 assets); Cloud Agents + scanners; TruRisk scoring; one-click patch via the same agent; India platform - **Details:** https://www.thetechbag.com/qualys/qualys-vmdr ### Qualys TruRisk Eliminate / Enterprise TruRisk Management — Qualys - **Who it's for:** Qualys estates that want one risk number per business unit and mitigation options when patching is impossible. - **The honest limitation:** A layer over Qualys telemetry — it aggregates what you already license; quote-only. - **Price:** Quote — platform layer over Qualys data — risk aggregation across VM, WAS, TotalCloud; mitigations (isolate, disable) where a patch is not available - **Details:** https://www.thetechbag.com/qualys/qualys-trurisk ### Qualys Web Application Scanning — Qualys - **Who it's for:** Teams scanning web apps and APIs at scale from the same Qualys tenant as the host VM. - **The honest limitation:** Web and API only; reports, does not fix; quote-only. - **Price:** Quote — per web application / API; DAST with PCI-ready reporting - **Details:** https://www.thetechbag.com/qualys/qualys-web-app-scanning ### Qualys Patch Management — Qualys - **Who it's for:** Qualys estates closing the loop from finding to patch on the same agent. - **The honest limitation:** Remediation, not discovery — it needs VMDR's findings; quote-only. - **Price:** Quote — per asset / year; OS and third-party patching through the Qualys Cloud Agent, driven by VMDR findings - **Details:** https://www.thetechbag.com/qualys/qualys-patch-management ### Tenable Vulnerability Management — Tenable - **Who it's for:** The published-price cloud VM platform — Nessus breadth, VPR prioritisation, and a clean path to Tenable One later. - **The honest limitation:** Reports and integrates; it does not patch. Web-app and cloud scanning are separate SKUs; India data region not documented. - **Price:** $28–45 (≈ ₹2,324) — per asset / year (from $3,700 / year for 100 assets); Nessus scanners + agents; VPR prioritisation - **Details:** https://www.thetechbag.com/tenable/tenable-vulnerability-management ### Tenable Nessus Professional — Tenable - **Who it's for:** Consultants, auditors and small teams that want the reference scanner with no per-asset meter. - **The honest limitation:** A single scanner with no central management, no agents and no remediation — the enterprise tier is Tenable VM / Security Center; basic web scanning only. - **Price:** $4,790 (≈ ₹3,97,570) — per scanner / year, unlimited IPs (2-year ≈ $4,665 / yr, 3-year ≈ $4,546 / yr); 24/7 support +$400; software you run - **Details:** https://www.thetechbag.com/tenable/tenable-nessus ### Tenable One (Exposure Management) — Tenable - **Who it's for:** Enterprises that want one exposure view across hosts, web apps, cloud, identity and OT with attack-path context. - **The honest limitation:** Enterprise-priced and quote-only; reports and prioritises, does not remediate; you are buying several Tenable products at once. - **Price:** Quote — platform licence (typically from ~$50k / year reported); VM + web + cloud + identity + OT + attack-path analysis - **Details:** https://www.thetechbag.com/tenable/tenable-one ### Tenable OT Security — Tenable - **Who it's for:** Plants and utilities that need vulnerability and asset visibility on PLCs and industrial networks without agents. - **The honest limitation:** OT only — pair it with IT VM; quote-only; on-prem appliances you run. - **Price:** Quote — per OT site / asset; passive monitoring plus active querying of industrial controllers; on-prem - **Details:** https://www.thetechbag.com/tenable/tenable-ot-security ### CrowdStrike Falcon Exposure Management — CrowdStrike - **Who it's for:** Falcon estates that want host vulnerabilities from the sensor they already run, prioritised by exploit intelligence, with no scan window. - **The honest limitation:** Host coverage is wherever the Falcon sensor is — no network scanner, no web DAST; cloud posture is Falcon Cloud Security; it does not patch; quote-only. - **Price:** Quote — module on the Falcon sensor (Spotlight + external attack surface); ExPRT.AI prioritisation; quote-only - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-falcon-exposure-management ### Trend Vision One Cyber Risk Exposure Management (ASRM) — Trend Micro - **Who it's for:** Trend Vision One estates that want a risk index across endpoint sensors, cloud accounts and external attack surface in the same console as XDR. - **The honest limitation:** Credit-priced — opaque until you run it; depth depends on Trend sensors being present; web-app and OT coverage not documented; does not patch. - **Price:** Credits — Vision One credits — 20 credits per assessed desktop / server (Core), 8,000 per connected cloud account; risk index across endpoints, cloud accounts and external surface - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-attack-surface-risk-management ### Action1 Vulnerability Remediation — Action1 - **Who it's for:** Teams whose gap is remediation capacity, not discovery — it finds and fixes on the endpoint, free until the 201st. - **The honest limitation:** Endpoints only — no network, web, cloud or OT scanning; prioritisation is severity-led rather than documented threat-intel risk scoring; unverified above 10,000 endpoints. - **Price:** $4 (≈ ₹332) — per endpoint / month beyond 200 (annual) + support; Windows / macOS / Linux endpoints; assess and patch from one agent - **Details:** https://www.thetechbag.com/action1/action1-vulnerability-remediation ### Mitigata VAPT — Mitigata - **Who it's for:** India-regulated organisations that need a CERT-In-empanelled VAPT report for RBI, SEBI CSCRF, IRDAI or ISO audits — web, API, network, cloud and mobile — from an Indian provider. - **The honest limitation:** A service, not a platform: findings and a re-test, you fix; priced per application rather than per asset; depends on Mitigata's team, not your console. - **Price:** ₹52,000+ — per application (≈ $626), tiered; automated scanning + manual review + configuration analysis; CERT-In-empanelled reports - **Details:** https://www.thetechbag.com/mitigata/mitigata-vapt ### Sophos Managed Risk (powered by Tenable) — Sophos - **Who it's for:** Sophos Central estates that want Tenable scanning run and prioritised by Sophos's team, beside their MDR. - **The honest limitation:** A managed service that advises — remediation is yours; quote-only; strongest inside a Sophos estate. - **Price:** Quote — subscription per user and server; external attack surface plus internal (IASM by Tenable, July 2025) with Sophos analysts; Sophos Central - **Details:** https://www.thetechbag.com/sophos/sophos-managed-risk ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Must remediate, not only report.** Rules out Rapid7 InsightAppSec, Qualys Web Application Scanning, Tenable Vulnerability Management, Tenable Nessus Professional, Tenable One (Exposure Management), Tenable OT Security, CrowdStrike Falcon Exposure Management and Trend Vision One Cyber Risk Exposure Management (ASRM) — reports and prioritises; remediation is your patch tool; Mitigata VAPT and Sophos Managed Risk (powered by Tenable) — advisory: findings and a re-test, you fix. That leaves Rapid7 InsightVM, Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Patch Management and Action1 Vulnerability Remediation. **Web applications and APIs.** Rules out Rapid7 InsightVM, Qualys VMDR (with patching) and Tenable Vulnerability Management — web-app scanning is a separate SKU from this vendor; Qualys Patch Management, Tenable OT Security, CrowdStrike Falcon Exposure Management and Action1 Vulnerability Remediation — no web-application scanning. That leaves Rapid7 InsightAppSec, Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Web Application Scanning, Tenable Nessus Professional, Tenable One (Exposure Management), Trend Vision One Cyber Risk Exposure Management (ASRM), Mitigata VAPT and Sophos Managed Risk (powered by Tenable). It flags Qualys TruRisk Eliminate / Enterprise TruRisk Management — Web-app coverage not documented, Tenable Nessus Professional — Basic web checks only, Trend Vision One Cyber Risk Exposure Management (ASRM) — Web-app coverage not documented and Sophos Managed Risk (powered by Tenable) — Web-app coverage not documented — marked, not removed. **Cloud accounts and containers.** Rules out Rapid7 InsightVM, Qualys VMDR (with patching), Tenable Vulnerability Management and CrowdStrike Falcon Exposure Management — cloud posture is a separate SKU from this vendor; Qualys Web Application Scanning, Qualys Patch Management, Tenable Nessus Professional, Tenable OT Security and Action1 Vulnerability Remediation — no cloud-account coverage. That leaves Rapid7 InsightAppSec, Qualys TruRisk Eliminate / Enterprise TruRisk Management, Tenable One (Exposure Management), Trend Vision One Cyber Risk Exposure Management (ASRM), Mitigata VAPT and Sophos Managed Risk (powered by Tenable). It flags Rapid7 InsightAppSec — Cloud coverage not documented, Qualys TruRisk Eliminate / Enterprise TruRisk Management — Cloud coverage not documented and Sophos Managed Risk (powered by Tenable) — Cloud coverage not documented — marked, not removed. **OT and industrial networks.** Rules out Rapid7 InsightAppSec, Qualys Web Application Scanning, Qualys Patch Management, Tenable Vulnerability Management, Tenable Nessus Professional, CrowdStrike Falcon Exposure Management, Action1 Vulnerability Remediation and Sophos Managed Risk (powered by Tenable) — no OT / ICS coverage. That leaves Rapid7 InsightVM, Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Tenable One (Exposure Management), Tenable OT Security, Trend Vision One Cyber Risk Exposure Management (ASRM) and Mitigata VAPT. It flags Rapid7 InsightVM — OT coverage not documented, Qualys VMDR (with patching) — OT coverage not documented, Qualys TruRisk Eliminate / Enterprise TruRisk Management — OT coverage not documented, Trend Vision One Cyber Risk Exposure Management (ASRM) — OT coverage not documented and Mitigata VAPT — OT coverage not documented — marked, not removed. **Risk-based prioritisation.** Rules out Rapid7 InsightAppSec and Action1 Vulnerability Remediation — severity-led; documented threat-intel risk scoring absent; Qualys Patch Management — a remediation tool, not a prioritiser. That leaves Rapid7 InsightVM, Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Web Application Scanning, Tenable Vulnerability Management, Tenable Nessus Professional, Tenable One (Exposure Management), Tenable OT Security, CrowdStrike Falcon Exposure Management, Trend Vision One Cyber Risk Exposure Management (ASRM), Mitigata VAPT and Sophos Managed Risk (powered by Tenable). **Agentless only.** Rules out Qualys Patch Management, CrowdStrike Falcon Exposure Management and Action1 Vulnerability Remediation — agent-based only. That leaves Rapid7 InsightVM, Rapid7 InsightAppSec, Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Web Application Scanning, Tenable Vulnerability Management, Tenable Nessus Professional, Tenable One (Exposure Management), Tenable OT Security, Trend Vision One Cyber Risk Exposure Management (ASRM), Mitigata VAPT and Sophos Managed Risk (powered by Tenable). It flags Rapid7 InsightVM — Agent and agentless, Qualys VMDR (with patching) — Agent and agentless, Qualys TruRisk Eliminate / Enterprise TruRisk Management — Agent and agentless, Tenable Vulnerability Management — Agent and agentless, Tenable One (Exposure Management) — Agent and agentless, Trend Vision One Cyber Risk Exposure Management (ASRM) — Agent and agentless and Sophos Managed Risk (powered by Tenable) — Agent and agentless — marked, not removed. **Agents for roaming endpoints.** Rules out Rapid7 InsightAppSec, Qualys Web Application Scanning, Tenable Nessus Professional, Tenable OT Security and Mitigata VAPT — no agent; scanners or a service only. That leaves Rapid7 InsightVM, Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Patch Management, Tenable Vulnerability Management, Tenable One (Exposure Management), CrowdStrike Falcon Exposure Management, Trend Vision One Cyber Risk Exposure Management (ASRM), Action1 Vulnerability Remediation and Sophos Managed Risk (powered by Tenable). **A CERT-In-empanelled report.** Rules out Rapid7 InsightVM, Rapid7 InsightAppSec, Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Web Application Scanning, Qualys Patch Management, Tenable Vulnerability Management, Tenable Nessus Professional, Tenable One (Exposure Management), Tenable OT Security, CrowdStrike Falcon Exposure Management, Trend Vision One Cyber Risk Exposure Management (ASRM), Action1 Vulnerability Remediation and Sophos Managed Risk (powered by Tenable) — not a CERT-In-empanelled audit provider; reports are the tool's, not an empanelled auditor's. That leaves Mitigata VAPT. **Vendor-published list price.** Rules out Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Web Application Scanning, Qualys Patch Management, Tenable One (Exposure Management), Tenable OT Security, CrowdStrike Falcon Exposure Management, Trend Vision One Cyber Risk Exposure Management (ASRM) and Sophos Managed Risk (powered by Tenable) — quote-only (reported ranges or credits). That leaves Rapid7 InsightVM, Rapid7 InsightAppSec, Tenable Vulnerability Management, Tenable Nessus Professional, Action1 Vulnerability Remediation and Mitigata VAPT. **Above 10,000 assets.** Rules out Tenable Nessus Professional — a single-scanner product; enterprise management is Tenable VM / Security Center. That leaves Rapid7 InsightVM, Rapid7 InsightAppSec, Qualys VMDR (with patching), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Qualys Web Application Scanning, Qualys Patch Management, Tenable Vulnerability Management, Tenable One (Exposure Management), Tenable OT Security, CrowdStrike Falcon Exposure Management, Trend Vision One Cyber Risk Exposure Management (ASRM), Action1 Vulnerability Remediation, Mitigata VAPT and Sophos Managed Risk (powered by Tenable). It flags Action1 Vulnerability Remediation — Unverified above 10,000 and Mitigata VAPT — A service, priced per application — marked, not removed. **Compliance reporting for RBI, SEBI CSCRF and ISO.** Every scanner here ships compliance templates (PCI, ISO, CIS); what the Indian regulator often wants is the empanelled auditor's report, which is Mitigata's line. Qualys and Tenable reports satisfy many ISO and internal audits; whether your regulator accepts a tool report or requires an empanelled VAPT is a question for the circular, not the datasheet. **India data residency.** Documented: Qualys (India platform), Mitigata (India). Tenable, CrowdStrike (announced in-country cloud, January 2026), Trend, Action1 and Sophos do not document an India region for vulnerability data — flagged, not ruled out. **Scale behaviour.** Qualys, Tenable VM / One, CrowdStrike and Trend document estates well above 10,000 assets; Nessus Professional is a single scanner by design; Action1 is unverified above 10,000 endpoints; Mitigata is priced per application. Where a specific console strains for your estate is delivery-team experience: [TechBag to confirm]. ## Eight situations, eight shortlists — starting from who fixes things Every shortlist asks first whether your gap is discovery, prioritisation or remediation capacity. The vendor comes after. ### You have thousands of findings and nobody patches them **Shortlist:** Action1 Vulnerability Remediation, Qualys VMDR (with patching), Qualys Patch Management **Why:** The gap is remediation capacity, not discovery: Action1 finds and patches endpoints from one agent (free to 200); Qualys VMDR bundles one-click patching on the Cloud Agent; Qualys Patch Management closes the loop for Qualys estates. **Trade-off:** Action1 is endpoints only and severity-led; Qualys is per-asset priced with separate SKUs for web and cloud. Buying another scanner would not have helped. ### RBI / SEBI CSCRF / IRDAI audit — the regulator wants an empanelled report **Shortlist:** Mitigata VAPT, Qualys VMDR (with patching), Tenable Vulnerability Management **Why:** Mitigata's CERT-In-empanelled VAPT is the document the regulator names; Qualys and Tenable provide the continuous scanning and compliance reporting between audits. **Trade-off:** A VAPT is a point-in-time service priced per application; continuous scanning is the platform. Most regulated estates need both — and should not confuse one for the other. ### Twenty vulnerabilities that actually matter out of twenty thousand **Shortlist:** Qualys VMDR (with patching), Tenable Vulnerability Management, CrowdStrike Falcon Exposure Management **Why:** TruRisk, VPR and ExPRT.AI all fold exploit activity, threat intelligence and asset context into the score — cutting the actionable list by half or more against raw CVSS. **Trade-off:** Three different risk models; none knows your compensating controls unless you tell it. Falcon's view is the sensor's hosts only. ### Web apps and APIs are the exposed surface **Shortlist:** Qualys Web Application Scanning, Tenable One (Exposure Management), Mitigata VAPT **Why:** Qualys WAS scans web apps and APIs at scale; Tenable One includes web scanning in the exposure view; Mitigata's VAPT adds manual testing a DAST cannot. **Trade-off:** Host scanners with 'web' on the datasheet (Nessus, VMDR, Tenable VM) run basic checks or need the separate WAS SKU — read the card. ### You already run CrowdStrike, Trend or Sophos **Shortlist:** CrowdStrike Falcon Exposure Management, Trend Vision One Cyber Risk Exposure Management (ASRM), Sophos Managed Risk (powered by Tenable) **Why:** Vulnerabilities from the sensor you already run, prioritised in the console you already watch — no scan window, no second agent. **Trade-off:** Coverage is wherever the sensor is: no network scanner, web DAST or unmanaged-device discovery; Trend is credit-priced; Sophos Managed Risk advises, you fix. ### Plants, utilities, OT networks **Shortlist:** Tenable OT Security, Tenable One (Exposure Management) **Why:** Passive monitoring and safe active querying of industrial controllers — the agentless approach OT requires; Tenable One brings the OT findings into the enterprise exposure view. **Trade-off:** OT only needs an IT VM beside it; quote-only and on-prem appliances you run. Qualys and Mitigata may cover OT — not documented here, so not ruled in. ### A consultant, an auditor, or a small team with no per-asset budget **Shortlist:** Tenable Nessus Professional, Action1 Vulnerability Remediation, Tenable Vulnerability Management **Why:** Nessus Professional is a flat $4,790 per scanner with unlimited IPs (Essentials free for 16); Action1 is free to 200 endpoints; Tenable VM publishes a per-asset list from $3,700 / 100 assets. **Trade-off:** Nessus has no central console, agents or remediation; Action1 is endpoints only; Tenable VM reports, it does not fix. ### Enterprise — one exposure view across hosts, cloud, identity and OT **Shortlist:** Tenable One (Exposure Management), Qualys TruRisk Eliminate / Enterprise TruRisk Management, Trend Vision One Cyber Risk Exposure Management (ASRM) **Why:** Exposure platforms that aggregate several scanners into one risk view with attack-path context; each assumes you run the underlying vendor's products. **Trade-off:** You are buying several products at once: enterprise-priced, quote-only, and the view is only as complete as the sensors feeding it. ## At scale Findings scale faster than assets. Prioritisation and remediation capacity are what keep the programme from becoming a report nobody opens. ### 500 assets — The list is the constraint - Any scanner finds thousands; without a risk model and an owner for the top twenty, the programme is a monthly PDF. - Nessus Professional, Action1 (free to 200), Tenable VM's published per-asset list and Mitigata per application fit this band. - Authenticated scanning is the first thing to get right — and the first thing to silently break. **The test:** Run an authenticated scan and confirm it authenticated; take the top ten by the vendor's risk model and see whether your team would patch them this week. ### 5,000 assets — Coverage and ownership are the constraint - Web apps, cloud accounts and roaming laptops are now separate surfaces — separate SKUs at most vendors; agents for the laptops, scanners for the rest. - Findings need owners by business unit and SLAs by risk tier, or the remediation rate is the only number that matters and it is falling. - Per-asset pricing starts to matter; volume discounts start to exist. **The test:** Measure mean time to remediate for critical-risk findings over a quarter; ask each vendor how their model would shrink that queue. ### 50,000 assets — Architecture and exposure are the constraint - One exposure view across scanners, cloud, identity and OT (Tenable One, Qualys TruRisk) or you are reconciling spreadsheets. - Scan windows, agent fleets, API limits and regional data become engineering problems; OT needs its own passive approach. - The regulator's empanelled VAPT and the continuous platform are two budgets, both mandatory. **The test:** Pull the full asset inventory through the API and reconcile it against the CMDB; price the exposure platform against the cost of the reconciliation you do today. Qualys, Tenable VM / One, CrowdStrike and Trend document estates well above 10,000 assets; Nessus Professional is a single scanner by design; Action1 is unverified above 10,000 endpoints; Mitigata and Sophos Managed Risk are services. Which scanner or platform starts to strain at your asset count is delivery-team experience: [TechBag to confirm]. ## Switching scanners is cheap; losing the history is not Scanners and agents redeploy in weeks. The trend lines, the exceptions, the risk-acceptance records and the integrations into ticketing are what the next tool starts without. **Scanners and agents** — Deploy the new agent through your UEM / RMM, stand up new scanners with the same credentials, run both for a cycle, retire the old. Weeks, scriptable. *(Scriptable)* **Exceptions and risk acceptances** — Every accepted risk, compensating control and false-positive rule is rebuilt by hand — there is no import format between vendors. *(Rebuild)* **History and trend lines** — Years of remediation-rate trends, audit evidence and per-asset history stay in the old tenant. Export before the licence ends, or the audit trail ends with it. *(Export or lose)* **Integrations** — Ticketing, CMDB, patch-tool and SIEM integrations are re-wired; the prioritisation model changes, so every SLA keyed to a score is re-baselined. *(Re-wire, re-baseline)* **Cut-over weeks and exception rebuild for your estate:** [TechBag to confirm] — TechBag scopes it from your asset count, surfaces and integrations. ## Per asset, per scanner, per application — three different meters What you may already hold, the meters compared in USD and INR at three estate sizes, and what the licence leaves out — chiefly the people who patch. ### Do you already own one? Four licences you may hold already find vulnerabilities. None of them is the whole programme; one of them may be the scanner. - **Microsoft 365 E5 — Partly.** Defender Vulnerability Management is inside Defender for Endpoint P2 (E5); a standalone add-on otherwise. Good host coverage on Defender-managed devices; no network scanner, web DAST or OT. - **Your EDR vendor — Often.** CrowdStrike (Falcon Exposure), Trend (CREM), Sophos (Managed Risk), SentinelOne and Bitdefender all sell vulnerability views on the sensor you run. Host-only, no scan window, no unmanaged devices. - **Your RMM / patch tool — Partly.** Action1, NinjaOne, ManageEngine Endpoint Central and Qualys Patch Management assess and patch what their agent manages. The fix, without the wider discovery. - **Your cloud provider — Partly.** AWS Inspector, Microsoft Defender for Cloud and Google Security Command Center scan their own workloads. Cloud-native, one cloud each — the cloud guide takes it from here. If the sensor you already pay for covers the hosts, we say so — and then talk about the web apps, the cloud accounts and who patches. ### What the rest actually cost Published and reported prices (INR for scale) on three meters — per asset per year, per scanner per year, per application — then worked at 500 / 5,000 / 50,000 assets. Where a product is quote-only or credit-priced the line says so. ### What isn't in the licence price - **The patch team.** A scanner that reports needs people who patch — yours, your RMM’s, or a fixer tool. Price the remediation capacity beside the scanner; it is the larger number and the one that decides whether the programme works. - **Credentials and coverage upkeep.** Authenticated scanning needs credentials that rotate, agents that get deployed to new builds, cloud accounts that get connected — an owner’s hours every month, or coverage quietly decays. - **The empanelled report.** Where the regulator names a CERT-In-empanelled VAPT (RBI, SEBI CSCRF, IRDAI), it is a separate service priced per application (Mitigata from ₹52,000) — not a line in the scanner contract. Your scope and frequency: [TechBag to confirm]. ## What goes wrong Documented tool behaviour, cross-checked against TechBag engagements before any becomes a named case. Most are programme failures the tool could not have prevented. - **Scan results nobody actions.** Twenty thousand findings, a monthly PDF, no owner. The tool worked; the programme did not. Prioritisation model plus named owners plus SLAs — or do not buy the scanner. - **Authenticated scans that were never actually authenticated.** Credentials expired or were wrong; the scanner fell back to unauthenticated and reported a clean, shallow picture for a year. Check the authentication status on every scan. - **Agentless coverage gaps.** Laptops off the network at scan time, cloud workloads spun up between windows, containers that lived for an hour. Scanners see what is there when they look; agents see what they are on. - **Prioritisation that ignores compensating controls.** The score said critical; the host was isolated behind three controls. No model knows your mitigations unless you tell it — exceptions are part of the programme. - **Buying a scanner when the gap was remediation capacity.** A better list did not get patched faster. The purchase that would have helped was the fixer (Action1, Qualys patching) or the patch team. - **Per-asset meter surprise.** Cloud workloads and containers counted as assets; the renewal doubled. Ask how ephemeral workloads are metered before the first cloud connector. - **Tool report offered where the regulator wanted an empanelled VAPT.** The scanner's compliance PDF was not the CERT-In-empanelled report the circular named. Two documents, two budgets. - **Single scanner stretched to the enterprise.** Nessus Professional on five laptops with five spreadsheets. The enterprise tier exists for a reason; the meter changes with it. ## Questions this guide answers ### What is the difference between vulnerability scanning, exposure management, a pentest and BAS? Scanning finds and ranks known weaknesses continuously and broadly (Nessus, Tenable VM, Qualys VMDR). Exposure management aggregates scanning with cloud posture, identity, OT and external attack surface into one risk view with attack paths (Tenable One, Qualys TruRisk, Trend CREM). A pentest (VAPT) is humans proving, point-in-time, that an attacker can get in — often required by Indian regulators as a CERT-In-empanelled report (Mitigata). BAS runs attacker techniques continuously to test what your defences catch. Adjacent and widening scopes, not tiers. ### Which vulnerability management tools also remediate? Action1 assesses and patches Windows, macOS and Linux endpoints from one agent (free to 200 endpoints, $4 per endpoint per month beyond); Qualys VMDR bundles one-click patching on the Cloud Agent and Qualys Patch Management closes the loop, with TruRisk Eliminate adding mitigations where no patch exists. Tenable, CrowdStrike Falcon Exposure and Trend CREM report and prioritise; remediation is your patch tool. Mitigata VAPT and Sophos Managed Risk advise and re-test. ### How much does vulnerability management cost per asset? Tenable Vulnerability Management publishes from $3,700 a year for 100 assets (about $28–45 per asset per year); Qualys VMDR is reported at roughly $199–250 per asset per year with volume discounts from about 1,000 assets; Nessus Professional is a flat $4,790 per scanner per year with unlimited IPs; Action1 is free to 200 endpoints then $4 per endpoint per month; Mitigata VAPT is priced per application from ₹52,000; Tenable One is reported from about $50,000 a year; CrowdStrike, Trend and Sophos are quote or credit priced. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/security/vulnerability-management* --- # SIEM pricing is a data problem, not a software problem. The licence is the small number. *SIEM & Log Management — a TechBag decision guide. Last reviewed 2026-09-07.* > A SIEM is paid for by what you feed it — gigabytes a day, sources, or events per second — for as long as a regulator says you must keep it, and it only detects what someone tuned it to detect. The meter and the tuner decide the cost; the feature list does not. **The checkable fact:** Splunk Cloud is reported at roughly $1,000 per GB / day per year at 50 GB / day; ManageEngine Log360 starts at $300 a year priced by log sources. Same logs, two different bills — and the second does not grow with volume. - Canonical: https://www.thetechbag.com/browse/security/siem-log-management - Category: [Security](https://www.thetechbag.com/browse/security) - Products compared: 30 ## What siem & log management actually is A place where the logs from everything — endpoints, firewalls, identity, cloud, mail, applications — land, are kept for as long as policy and the regulator require, and are searched and **correlated**: this login, from that country, after this alert, touching that server. The correlation rules are **detections**; the things they raise are **cases**; the team that reads them is the SOC. Log management is the first half (collect, keep, search); SIEM is the second (correlate, detect, investigate). Three things cost money and the feature grid shows none of them: the **meter** (gigabytes a day, sources, events per second, or compute), the **retention** the regulator mandates, and the **people who tune it**. An untuned SIEM is an expensive log archive. A SOAR beside it automates whatever the detections raise — good or noise. The [MDR guide](https://www.thetechbag.com/browse/security/managed-detection-response) is where the people come from if you do not have them. **The most common mis-purchase.** **Ingest-based vs node-based vs flat pricing** decides total cost more than any capability. Per-GB grows with volume forever; per-source and per-EPS flatten; workload compute sits in between. Estimate your daily volume and your retention before you read a datasheet. ## SIEM vs XDR vs log management · SIEM vs SOAR Four terms this buyer confuses, and nothing more. They are adjacent and widening scopes — each one records more or acts more, costs more, and needs more people to run. None is a better version of another. ### Log management Collect, keep, search. The storage and the retention mandate live here; so does the first half of every meter. Splunk's platform, FortiAnalyzer, Log360's entry tiers. Not a SIEM until correlation, detections and cases sit on top. ### SIEM Log management plus correlation across sources, detection content, cases and compliance reporting. Vendor-neutral by design — it ingests everything you run. Splunk ES, Microsoft Sentinel, Log360, FortiSIEM, Falcon Next-Gen SIEM, SentinelOne AI SIEM, KUMA. Needs a tuner or it is an archive. ### XDR Correlation too — but from one vendor's sensors (endpoint, email, cloud, identity) inside their platform, pre-tuned by them. Narrower than a SIEM, far less work; the 'X' often means 'our stack'. Platform vendors sell XDR as the reason you do not need a SIEM; regulators and third-party logs often disagree. Cortex XSIAM is the most explicit version of that argument — it is sold as the SIEM replacement, not a companion. ### SOAR Automation and case management over whatever raises alerts: playbooks that enrich, contain, notify, close. Adjacent, not a SIEM — it acts on detections, it does not make them. Included at CrowdStrike and SentinelOne; separate at Splunk and Fortinet; workflow-grade inside Log360 and KUMA. **Widening scopes, not tiers.** Log management → SIEM adds correlation and detections; XDR is a vendor’s pre-tuned subset; SOAR acts on what either raises. Broader ingests more, costs more per gigabyte and per engineer, and only earns it if someone tunes the detections. Buy the scope your people can run — and let the MDR guide supply the people if they do not exist. ## The decision variables Six variables decide this purchase. The instrument tests the meter, deployment, automation and the India line; retention, content and who tunes it are prose because the honest answers are “your mandate”, “everyone ships content” and “your headcount”. **Ingest-based vs node-based vs flat pricing.** Per GB / day grows with volume forever (Splunk, Microsoft Sentinel, CrowdStrike, SentinelOne, FortiSIEM's GB option); per source, device or EPS flattens (Log360, FortiSIEM, KUMA); workload compute (Splunk SVCs) sits between. Decides total cost more than any feature. **Log retention requirements.** CERT-In's 180 days in India; RBI and SEBI CSCRF add theirs; your sector may add more. Retention × ingest is the cloud bill; retention × disk is the on-prem one. **Detection content out of the box vs built by you.** Every SIEM ships content; the gap between a SIEM and an archive is who tunes it against your estate. **Who tunes it.** The headcount that decides whether you bought a SIEM or a log archive. If nobody, the MDR guide — or a platform-native XDR — is the honest purchase. **SOAR and automation depth.** Included (CrowdStrike Fusion, SentinelOne Hyperautomation), workflow-grade (Log360, FortiSIEM, KUMA) or a separate SKU (Splunk SOAR, FortiSOAR). Automation over untuned detections automates noise. **Deployment model and India residency.** On-prem (Splunk Enterprise, Log360, FortiSIEM, FortiAnalyzer, KUMA) satisfies residency by definition; documented India cloud regions are FortiSIEM Cloud and SentinelOne (Mumbai) and Log360 Cloud; CrowdStrike is announced. ## The 30 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Splunk Enterprise Security — Splunk - **Who it's for:** SOCs that want the reference SIEM — the deepest search language, the largest content and integration ecosystem, on-prem or cloud — and have the engineers to run it. - **The honest limitation:** The licence is the small number: ingest grows, SOAR is a separate product, and an untuned Splunk is the most expensive log archive there is; India cloud region not documented. - **Price:** ~$120–225 (≈ ₹9,960) — per GB / day / year reported (platform $100–180 + ES $20–45) on Splunk Cloud or Enterprise; or workload pricing (SVCs ~$55–75k / yr each); ESCU detection content - **Details:** https://www.thetechbag.com/splunk/splunk-enterprise-security ### Splunk Platform (Enterprise / Cloud) — Splunk - **Who it's for:** Teams that need log search and analytics at scale without the SIEM application on top — yet. - **The honest limitation:** Log management and analytics, not a SIEM until you add Enterprise Security (and its price); the same ingest economics apply. - **Price:** ~$100–180 (≈ ₹8,300) — per GB / day / year reported; the data platform under ES, ITSI and Observability - **Details:** https://www.thetechbag.com/splunk/splunk-platform ### Splunk SOAR — Splunk - **Who it's for:** SOCs automating triage and response around Splunk (or another SIEM). - **The honest limitation:** A separate SKU from ES; automation only — it is not a SIEM; quote-only. - **Price:** Quote — per user / per action; playbooks and case management over ES or other SIEMs - **Details:** https://www.thetechbag.com/splunk/splunk-soar ### Microsoft Sentinel — Microsoft - **Who it's for:** Microsoft 365 and Azure estates that want SIEM and XDR in one incident queue — where the first-party logs a SOC actually watches ingest free, and a data lake tier keeps the high-volume rest affordable. - **The honest limitation:** The free ingest is Microsoft data only — noisy third-party sources (firewalls, proxies, NDR) pay full analytics rates and are where the bill escalates; SaaS on Azure only, so no on-prem or air-gapped option; SOAR is Logic Apps, billed separately; the Azure portal experience retires 31 March 2027, so the Defender portal migration is work you must scope; and note that while data is STORED in your workspace region, Microsoft documents that for workspaces outside Europe, Israel and China it PROCESSES customer data in a US region. - **Price:** ~$2.96–4.30 / GB (≈ ₹20,667) — per GB ingested (East US): ~$4.30 pay-as-you-go, ~$2.96 effective at the 100 GB / day commitment, down to ~$2.05 at 50,000 GB / day; data lake tier ~$0.05 / GB ingest and ~$0.026 / GB / month storage at 6:1 compression; Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free; 90 days retention included; Central India, Jio India West and Jio India Central regions (data lake: Central India) - **Details:** https://www.thetechbag.com/microsoft/microsoft-sentinel ### Palo Alto Cortex XSIAM — Palo Alto Networks - **Who it's for:** SOCs that have concluded the alert-triage model is the problem, and want AI-led detection and automated response to replace the SIEM rather than sit on top of it. - **The honest limitation:** It is a platform bet, not a drop-in SIEM: the value depends on giving it your data and letting its automation act, which is a bigger operating change than a migration. Cloud-only, quote-only, and strongest inside a Palo Alto estate. Also the destination Palo Alto is migrating IBM QRadar SaaS customers to — useful if you are one, a consideration if you are not. - **Price:** Quote — platform subscription priced by data ingested and scope; SOAR, threat intel and attack-surface management included rather than sold alongside; credits-style consumption - **Details:** https://www.thetechbag.com/palo-alto/cortex-xsiam ### Palo Alto Cortex XSOAR — Palo Alto Networks - **Who it's for:** SOCs automating repetitive investigation and response across a mixed security stack, over whichever SIEM they already run. - **The honest limitation:** Automation only — it is not a SIEM and does not detect anything on its own; it acts on what your SIEM raises, so an untuned SIEM just gets its noise automated faster. Playbook engineering is real work and quote-only pricing. - **Price:** Quote — per-user / per-automation licensing; hundreds of product integrations; available as SaaS or self-hosted - **Details:** https://www.thetechbag.com/palo-alto/cortex-xsoar ### Google Security Operations — Google - **Who it's for:** Large or fast-growing log estates that want retention to stop being a budget argument — twelve months hot and searchable, with SOAR and Mandiant intelligence in the same platform rather than two more contracts. - **The honest limitation:** SaaS on Google Cloud only — no on-premises or air-gapped option at all; YARA-L is a rule language your team must learn, with a smaller talent pool than SPL or KQL; and it asks for a platform commitment rather than slotting beside what you run. Quote-only, and any comparison written before 2026 describes the retired per-employee model. - **Price:** Quote — a package (Standard / Enterprise / Enterprise Plus) bought against a data cap in GB; twelve months of hot retention included on every tier, longer billed separately; the older per-employee metering has been retired; no published US list price - **Details:** https://www.thetechbag.com/google/google-security-operations ### Datadog Cloud SIEM — Datadog - **Who it's for:** Teams already running Datadog for observability who want threat detection on the logs they are collecting anyway — security signals correlated with the metrics and traces from the same incident, in one console. - **The honest limitation:** It is a pillar of Datadog Cloud Security rather than a standalone SIEM, and it sits ON TOP of Log Management — so the Cloud SIEM line is the small half of the bill and the log ingestion and indexing underneath it is the real cost. Datadog’s per-module, per-unit billing is the thing buyers most often underestimate. Cloud-only, and weakest as a choice if you are not already a Datadog estate. - **Price:** ~$0.20 / GB — reported ~$0.20 per GB of ANALYSED logs (also quoted as ~$5 per million analysed events, annual billing) on top of Log Management, which is billed separately by ingest and indexing; Flex Logs gives 3-15 months retention without rehydration and Cloud SIEM detections still run against it. Part of the Datadog Cloud Security platform, not a standalone SKU - **Details:** https://www.thetechbag.com/datadog/datadog-cloud-security ### Elastic Security — Elastic - **Who it's for:** Estates that need on-premises or air-gapped and find the cloud-only SIEMs are therefore not candidates at all — and teams already running Elasticsearch, for whom adopting it is closer to enabling than migrating. - **The honest limitation:** Named a Visionary, not a Leader, in the 2025 Gartner MQ for SIEM: out-of-the-box detection content is narrower than Splunk’s and the security talent pool is smaller than for SPL or KQL, so expect to write more of your own rules. And the free tier is what makes teams underestimate the rest — running Elasticsearch well at scale is real engineering work unless you buy Elastic Cloud. - **Price:** Free → quote — engine free and open source under AGPL; you pay for a subscription tier (Standard / Gold / Platinum / Enterprise). Self-managed on your own hardware including air-gapped; Elastic Cloud Hosted priced on provisioned resources (reported ~$99/mo Standard to ~$184/mo Enterprise at entry size, scaling with resources); Serverless from a reported ~$0.50/GB ingested. Not metered per GB/day on self-managed - **Details:** https://www.thetechbag.com/elastic/elastic-security ### Exabeam New-Scale SIEM — Exabeam - **Who it's for:** Estates where log volume is large relative to security headcount — the user-based meter is built for exactly that shape, and inverts the cost curve of ingest-priced SIEMs. - **The honest limitation:** The meter cuts both ways: a large workforce generating modest logs pays more here than on an ingest-priced SIEM, so you must model both. Cloud-only (LogRhythm SIEM is the self-hosted half), the talent pool is smaller than for Splunk or Microsoft, and a two-platform portfolio after a merger deserves a written roadmap question. - **Price:** Quote — metered on MONITORED USERS plus sources plus modules rather than gigabytes ingested — quote-only, no published list. The cloud platform the July 2024 LogRhythm merger standardised on; LogRhythm’s competing Axon was retired in its favour - **Details:** https://www.thetechbag.com/exabeam/exabeam-new-scale-siem ### LogRhythm SIEM — Exabeam - **Who it's for:** Regulated estates where the mandate rules out SaaS entirely — self-hosting answers BOTH storage and processing residency by definition, because the data never leaves. - **The honest limitation:** You buy, run, patch and capacity-plan the infrastructure, and under-sizing storage in year one is the commonest regret. It is also the self-hosted half of a two-platform portfolio after a merger, so ask for the roadmap in writing — Axon’s retirement shows this vendor consolidates where products overlap. - **Price:** Quote — self-hosted licensing, quote-only; you supply and run the infrastructure. Exclusively on-premises since the Exabeam merger — 1,100+ prebuilt correlation rules mapped to MITRE ATT&CK, with compliance reporting for ISO 27001, PCI DSS, HIPAA, SOX, NIST and CIS - **Details:** https://www.thetechbag.com/exabeam/logrhythm-siem ### Rapid7 Incident Command (formerly InsightIDR) — Rapid7 - **Who it's for:** Mid-market teams of roughly 500–5,000 endpoints with a security team in single figures and no detection-engineering function. Rapid7 writes and maintains the detection content itself, so the platform produces useful alerts in days rather than months — IDC named it a Leader for SIEM in the SMB segment specifically. - **The honest limitation:** NO INDIA DATA REGION — five regions (US, Canada, Europe, Japan, Australia), so an Indian entity holds its logs in Tokyo or further. 13-month retention exceeds CERT-In’s 180 days on duration and fails on location. Cloud-only, so no air-gap at any price. Gartner rates it a CHALLENGER not a Leader, citing no supervised ML or custom deep-learning models; reports group by one field at a time; default cap of 200 custom detection rules. - **Price:** Quote — Per MONITORED ASSET rather than per GB ingested — a host with a workstation or server OS that reported data in the last 30 days — so a verbose log source does not move the licence. Three tiers: Essential (90-day log retention), Advanced and Ultimate (180 days); alert and audit data 13 months on all tiers. Rapid7’s own AWS Marketplace listings publish ~$21,479 / $33,682 / $46,149 for 12 months at up to 500 assets - **Details:** https://www.thetechbag.com/rapid7/rapid7-incident-command ### Wazuh Professional Support — Wazuh - **Who it's for:** Organisations whose mandate rules out SaaS entirely — RBI, SEBI and IRDAI-regulated entities, government, and anyone contractually barred from sending security telemetry offshore — who have real platform-engineering capacity but need the vendor contractually accountable. Also estates above ~500 agents where per-agent cloud tiers stop making sense. - **The honest limitation:** This is SUPPORT, not a managed service and definitively not MDR — you still run the cluster, own the upgrades and carry the pager, and nobody is watching your alerts. Conflating those three is the commonest disappointment here. The real cost is your infrastructure plus 0.3–0.5 FTE on top of the contract. And self-hosting lets you place the indexer in India — it does not do it for you. - **Price:** Quote — A bespoke annual support contract on a platform whose licence stays free under GPLv2 — you are buying accountability, not software. Standard is 8/5 with an 8-hour response SLA and two health checks a year; Premium is 24/7 on critical issues with a 4-hour SLA and four health checks. Both include architecture guidance, upgrade planning, custom rules and decoders, and a named CSM. No published price - **Details:** https://www.thetechbag.com/wazuh/wazuh-professional-support ### Exabeam New-Scale Analytics (UEBA) — Exabeam - **Who it's for:** Teams whose threat model centres on credentials and people rather than malware — insider misuse and account takeover, where the attacker logs in correctly and does permitted things, so no rule fires. This is the gap rule-based detection structurally cannot close. - **The honest limitation:** Not a SIEM on its own — it is the analytics layer and needs the platform underneath. Its output is bounded by your identity data: peer groups built on a stale directory mean little, and service accounts need owners before they need baselines. Models need 8–16 weeks observing normal before their output should be acted on, and teams that judge it in week two decide on bad evidence. - **Price:** Quote — Priced on monitored users and log sources rather than data volume, which is the structural difference from ingest-metered SIEM — your bill tracks headcount, not how chatty your firewall is. Sold as the behavioural analytics layer of New-Scale rather than a standalone SIEM - **Details:** https://www.thetechbag.com/exabeam/exabeam-new-scale-analytics ### Exabeam Nova (agentic AI) — Exabeam - **Who it's for:** Existing Exabeam customers wanting AI-assisted triage and investigation summarisation on top of a platform they already run. - **The honest limitation:** Emerging rather than proven — treat vendor productivity statistics as unaudited, and do not let an AI layer become the reason to buy the platform underneath it. It cannot analyse data the platform did not collect. - **Price:** Quote — An agentic AI layer over the Exabeam platform rather than a separately deployable product; commercial terms are quoted with the platform - **Details:** https://www.thetechbag.com/exabeam/exabeam-nova ### Securonix UEBA — Securonix - **Who it's for:** Organisations whose threat model centres on credentials and insiders, and who want behavioural scoring integrated with the SIEM rather than bolted alongside it — the analyst moves from a risk score to the raw events without switching tools. - **The honest limitation:** Bounded by identity-data quality: peer groups are only as good as your directory, and service accounts need named owners first. Needs 8–16 weeks of baselining before its output is trustworthy. And it inherits the platform’s hard limit — no air-gapped or on-premises deployment in any configuration. - **Price:** Quote — Included in the Unified Defense entitlement rather than metered separately, so the commercial question is the platform’s GB/day band rather than a per-user analytics licence - **Details:** https://www.thetechbag.com/securonix/securonix-ueba ### Securonix Autonomous Threat Sweeper — Securonix - **Who it's for:** Teams that want retrospective hunting automated rather than dependent on someone remembering to re-run a query after a disclosure — when an indicator becomes public, the sweep happens whether or not anyone thought of it. - **The honest limitation:** It can only re-hunt data you actually ingested. Every source filtered out to control the GB/day bill is a source no future sweep can reach — and a blind sweep looks exactly like a clean one. That tension between cost control and retrospective coverage is real and deserves a deliberate decision rather than a default. - **Price:** Quote — Included in the Unified Defense entitlement; retro-hunts historical data when new threat intelligence lands, which is why the platform’s 365 days of hot searchable data is the feature that makes it useful - **Details:** https://www.thetechbag.com/securonix/securonix-autonomous-threat-sweeper ### Gurucul Next-Gen SIEM — Gurucul - **Who it's for:** The buyer a mandate has cornered. Gurucul was named a Leader in the 2025 Gartner MQ for SIEM (its first year, after three as a Visionary) AND — confirmed in Gartner’s own report text — runs SaaS, cloud or SELF-HOSTED. Of the six 2025 Leaders, the other five are cloud-only or cloud-only where the analytics run, so this is the only analyst-recognised Leader a regulated Indian buyer under an on-premises mandate can actually deploy. Behavioural analytics is the founding capability from 2010 rather than an acquisition, and Pune has been the engineering base since 2013. - **The honest limitation:** A bootstrapped sub-$100M boutique competing with Microsoft, Google and Cisco — no investor pressure, but no war chest either, and vendor scale is a question your risk function should answer deliberately. Analyst strength is Gartner-SPECIFIC: absent from the June 2025 Forrester Wave where the other five Leaders all appear, and its KuppingerCole Leader award is the 2024 report. We found no evidence of a vendor-run India data region — the India answer is self-hosting. And a genuine AIR-GAP is marketed but UNVERIFIED; self-hosted is not the same thing, so get it in writing. - **Price:** Quote — Quote-only. Gartner records the metering axes as all-inclusive per-asset and per-user pricing, ELAs, module-based, data-volume/EPS-based and platform-based. The per-asset and per-user axes break the dynamic where better logging costs more — but note the precision: they are offered AS AN ALTERNATIVE to per-GB, not instead of it, so which axis your order form specifies is the highest-value clause in the contract - **Details:** https://www.thetechbag.com/gurucul/gurucul-next-gen-siem ### Gurucul UEBA — Gurucul - **Who it's for:** Threat models centred on credentials and people rather than malware. This is the capability Gurucul was founded on in 2010 — it built the analytics first and grew a SIEM around them, which is the reverse of how most of this market was assembled. The practical consequence is that a risk score and the events that produced it live on one platform, so an analyst investigating a borderline score clicks through rather than filing an export request. - **The honest limitation:** Bounded by identity-data quality — peer groups built on a stale directory produce confident nonsense, and service accounts need named owners before they need baselines. Models also need WEEKS observing normal before their output should be acted on; teams judging alert quality in week two are deciding on bad evidence. Neither is a product fault and both are true of every UEBA product, but both are where deployments actually fail. Not sold standalone. - **Price:** Included — Part of the REVEAL platform entitlement rather than a separate meter, so the commercial question is the platform’s pricing axis rather than a per-user analytics licence - **Details:** https://www.thetechbag.com/gurucul/gurucul-ueba ### Gurucul Open XDR — Gurucul - **Who it's for:** Heterogeneous estates assembled over a decade, where real telemetry sits across an EDR chosen three years ago, a firewall estate from a different decision and an identity provider nobody will migrate off. Open XDR ingests from what you already run rather than demanding its own agent everywhere — which is why so many XDR pilots stall — then layers identity and behavioural analytics on top. - **The honest limitation:** Test the openness rather than believing it. Every XDR vendor claims it, and rich normalised telemetry and forwarded alerts are BOTH called integrations — only one supports an investigation. Check your two or three most depended-on tools during the PoC. Also: it is not MDR (nobody watches your alerts), not an EDR (it consumes endpoint telemetry, it does not prevent), and not sold standalone. Single-vendor stacks get deeper native integration from CrowdStrike or Microsoft. - **Price:** Included — Part of the REVEAL platform rather than a separate purchase with its own meter — no second data lake sitting beside your SIEM, and one query surface rather than two - **Details:** https://www.thetechbag.com/gurucul/gurucul-open-xdr ### Gurucul Identity Analytics — Gurucul - **Who it's for:** BFSI buyers who can list who has access but cannot say which access is DANGEROUS. It scores entitlements and access patterns for risk rather than cataloguing them — excess privilege, dormant high-risk access, and the permissions that accumulate across a decade of role changes and never get removed. That last one is the real problem: no individual grant was wrong, and the aggregate is invisible to a review that examines grants one at a time. Maps onto RBI and SEBI access-review evidence. - **The honest limitation:** This is ANALYTICS, NOT IDENTITY GOVERNANCE, and the categories are adjacent enough that vendors blur them. It tells you what access is risky and evidences it. It does not provision or deprovision accounts, does not run joiner-mover-leaver workflow, and does not own certification campaigns end to end. It complements SailPoint, Saviynt or One Identity rather than replacing one — and if you have no governance platform at all, fix provisioning first or you will get an accurate description of chaos. - **Price:** Included — Part of the REVEAL platform entitlement; shares one identity model with the SIEM and UEBA, so access risk and threat detection reason over the same picture of who your users are - **Details:** https://www.thetechbag.com/gurucul/gurucul-identity-analytics ### Wazuh — Wazuh - **Who it's for:** Two quite different buyers. Estates where an ingestion meter is currently shaping what gets collected — removing that meter is the strongest single argument in the category. And regulated Indian buyers whose mandate rules out SaaS entirely: Wazuh self-hosts on-premises or fully air-gapped, with documented offline installation and offline CVE feeds, which is where the cloud-only SIEMs simply cannot go at any price. - **The honest limitation:** The licence is free; the system is not. Infrastructure plus 0.3–0.5 FTE means self-hosting lands around ₹8–11 lakh a year at 250 agents — roughly LEVEL with the Cloud subscription, not the saving people assume. Also: no machine-learning-driven detections and a simpler query model than Elastic; real tuning effort in week one because collection is broad; and Wazuh does not sell MDR at all. Wazuh Cloud has no publicly documented India region — confirm in writing before trialling, or self-host. - **Price:** Free core — The platform itself is free under GPLv2 — no agent cap, no ingestion metering, no feature paywall, and no enterprise edition holding detection back. What is sold is operation: Wazuh Cloud from a reported ~$571/mo for 100 agents (1 month indexed, 3 months archive), ~$923 for 250 (3 months indexed, 1 year archive), ~$1,467 for 500. Professional Support is a bespoke annual contract with no published price. Note that retention forces the tier more often than agent count does - **Details:** https://www.thetechbag.com/wazuh/wazuh-cloud ### Securonix Unified Defense SIEM — Securonix - **Who it's for:** Cloud-accepting estates that want retention solved rather than negotiated — a full year of hot data means the investigation reaching back eleven months is a query, not a restore ticket — and that value behavioural detection enough to build around it. - **The honest limitation:** No air-gapped or on-premises deployment in ANY configuration. BYO-AWS and BYO-Snowflake let your own account hold the data lake, which can answer an India-residency obligation, but the analytics control plane is always Securonix’s cloud — so an air-gap mandate rules it out entirely. Also: three CEOs in two years, and the 120% default overage is the commonest avoidable cost in the contract. - **Price:** Quote — GB/day in tiered bands, hybrid commitment plus pay-as-you-go with pre-negotiated overages — but note the licensing terms default overage to 120% of your GB/day rate where the order form specifies no rate. 365 days of hot searchable data included as standard; Data Pipeline Manager flexes one entitlement across Analytics 1.0x, Investigation 0.5x and Basic 0.25x tiers - **Details:** https://www.thetechbag.com/securonix/securonix-unified-defense-siem ### ManageEngine Log360 (on-prem) / Log360 Cloud — ManageEngine - **Who it's for:** Mid-market and regulated Indian estates that want a SIEM with UEBA and compliance reports priced by sources, not gigabytes, from an India-built vendor. - **The honest limitation:** Predictable and cheap until the source count climbs; SOAR is built-in workflows rather than a full automation platform; documented scale tops out below the hyperscale SIEMs. - **Price:** $300–1,995 (≈ ₹24,900) — per year entry tiers (Basic $300 · Standard $995 · Professional $1,995; MSSP $194 / mo); priced by log sources, unlimited users; Zoho-hosted cloud with India data centres - **Details:** https://www.thetechbag.com/manageengine/manageengine-log360 ### Fortinet FortiSIEM — Fortinet - **Who it's for:** Fortinet Security Fabric estates that want SIEM plus CMDB-style asset context, on appliances or in a Mumbai-hosted cloud. - **The honest limitation:** Full SOAR is FortiSOAR (separate); strongest inside a Fortinet estate; quote-only across several meters. - **Price:** Quote — per device / EPS or per GB / day subscription; appliance, VM or FortiSIEM Cloud (Mumbai region); FortiSOAR separate - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortisiem ### Fortinet FortiAnalyzer — Fortinet - **Who it's for:** Fortinet estates that need fabric logging, reporting and automation before (or instead of) a full SIEM. - **The honest limitation:** Log analytics for the Fortinet fabric — third-party breadth and SIEM correlation are FortiSIEM's job. - **Price:** Quote — appliance / VM / cloud licensed by devices and GB / day; Fortinet-centric logging, analytics and playbooks - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortianalyzer ### CrowdStrike Falcon Next-Gen SIEM — CrowdStrike - **Who it's for:** Falcon estates that want SIEM on the data already in the platform, with third-party ingestion priced per GB and SOAR in the box. - **The honest limitation:** Cloud-only; third-party ingest beyond the included 10 GB / day is where the bill lives; India in-country cloud announced, not yet documented live. - **Price:** ~$5.95 / GB — AWS Marketplace pay-as-you-go $5.95 / GB (13-month retention); list reported ~$2,700 per GB / day / year for third-party data; 10 GB / day of third-party data included with Falcon Insight; Fusion SOAR included - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-falcon-next-gen-siem ### CrowdStrike Charlotte Agentic SOAR — CrowdStrike - **Who it's for:** Falcon SOCs pushing triage and response automation beyond playbooks. - **The honest limitation:** Falcon-only; quote-only; not a SIEM on its own. - **Price:** Quote — agentic automation over Falcon Next-Gen SIEM and Fusion workflows - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-charlotte-agentic-soar ### SentinelOne Singularity AI SIEM — SentinelOne - **Who it's for:** SentinelOne estates that want SIEM on the Singularity Data Lake with automation and an AI analyst in the same console, with a Mumbai data region. - **The honest limitation:** Rates are not published — the per-GB consumption is a quote; cloud-only; strongest when SentinelOne is already the agent. - **Price:** Quote — consumption per GB / day of ingested data (rates not published); Singularity Data Lake; Hyperautomation (SOAR) and Purple AI included in platform packages; Mumbai region - **Details:** https://www.thetechbag.com/sentinelone/sentinelone-singularity-ai-siem ### Kaspersky SIEM (KUMA) — Kaspersky - **Who it's for:** Estates that want a high-throughput on-prem SIEM priced by EPS rather than gigabytes, with Kaspersky's detection content. - **The honest limitation:** Procurement-sensitive in some sectors and countries (check your regulator); automation is playbook-grade rather than a full SOAR; quote-only. - **Price:** Quote — licensed by events per second (EPS); on-prem; documented 300,000+ EPS per correlation node - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-siem ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **A full SIEM.** Rules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM. That leaves Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam New-Scale Analytics (UEBA), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA). **Ingest-based pricing.** Rules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Exabeam New-Scale Analytics (UEBA), Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, ManageEngine Log360 (on-prem) / Log360 Cloud and Kaspersky SIEM (KUMA) — priced per source / EPS, not by data volume; Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support and Wazuh — no ingestion meter at all; the free core is priced by agent count for the managed edition. That leaves Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Securonix UEBA, Securonix Autonomous Threat Sweeper, Securonix Unified Defense SIEM, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM. It flags Splunk Enterprise Security — Also offers workload (compute) pricing and Fortinet FortiSIEM — GB / day subscription is one of its meters; device / EPS is the other — marked, not removed. **Per source / device / EPS pricing.** Rules out Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Securonix Unified Defense SIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM — ingest or workload-compute pricing, not per source; Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support and Wazuh — priced per agent count, not per source; and the core licence is free regardless. That leaves Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Exabeam New-Scale Analytics (UEBA), ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM and Kaspersky SIEM (KUMA). It flags Fortinet FortiSIEM — Device / EPS meter available; GB / day is the other — marked, not removed. **Self-hosted or on-prem.** Rules out Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Exabeam New-Scale SIEM, Rapid7 Incident Command (formerly InsightIDR), Exabeam New-Scale Analytics (UEBA), Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Securonix Unified Defense SIEM, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR and SentinelOne Singularity AI SIEM — cloud-only. That leaves Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Palo Alto Cortex XSOAR, Elastic Security, LogRhythm SIEM, Wazuh Professional Support, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer and Kaspersky SIEM (KUMA). **SOAR included.** Rules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Microsoft Sentinel and Exabeam New-Scale Analytics (UEBA) — SOAR is a separate product from this vendor. That leaves Splunk SOAR, Palo Alto Cortex XSIAM, Palo Alto Cortex XSOAR, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA). It flags Elastic Security — Built-in workflows / playbooks rather than a full SOAR platform, Exabeam New-Scale SIEM — Built-in workflows / playbooks rather than a full SOAR platform, LogRhythm SIEM — Built-in workflows / playbooks rather than a full SOAR platform, ManageEngine Log360 (on-prem) / Log360 Cloud — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiSIEM — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiAnalyzer — Built-in workflows / playbooks rather than a full SOAR platform and Kaspersky SIEM (KUMA) — Built-in workflows / playbooks rather than a full SOAR platform — marked, not removed. **India-built vendor.** Rules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Microsoft Sentinel, Palo Alto Cortex XSIAM, Palo Alto Cortex XSOAR, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam New-Scale Analytics (UEBA), Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA) — not an India-built vendor. That leaves ManageEngine Log360 (on-prem) / Log360 Cloud. **Above 1 TB / day.** Rules nothing out on published terms. It flags Exabeam Nova (agentic AI) — Documented scale is mid-market, Gurucul Open XDR — Documented scale is mid-market and ManageEngine Log360 (on-prem) / Log360 Cloud — Documented scale is mid-market — marked, not removed. **India data residency (cloud).** Documented: FortiSIEM Cloud (Mumbai region), SentinelOne Singularity (Mumbai), ManageEngine Log360 Cloud (Zoho India data centres), Microsoft Sentinel (Central India, Jio India West, Jio India Central). Sentinel is the one to read carefully: it STORES data in the workspace region, but Microsoft documents that for workspaces outside Europe, Israel and China it PROCESSES customer data in a US region — storage residency is not processing residency, and which one your regulator means is worth settling before the PoC. CrowdStrike's India in-country cloud is announced (January 2026), not yet documented live; Splunk Cloud publishes no Mumbai region; Kaspersky SIEM is on-prem. Nothing is ruled out on it — on-prem satisfies residency by definition, which is half the reason Log360, FortiSIEM and KUMA are on Indian shortlists. **Detection content out of the box vs built by you.** Rules nothing out: every SIEM here ships detection content (Splunk ESCU, Log360 correlation rules and UEBA, FortiSIEM rules, Falcon detections, SentinelOne content, Kaspersky rules). What differs is who tunes it against your estate — and an untuned SIEM is an expensive log archive. The tuning headcount is the variable, and it is prose because it is yours. **Log retention mandates.** Not a chip — retention is a configuration and a storage bill, not a capability: CERT-In's 2022 directions require 180 days of ICT logs in India; RBI and SEBI CSCRF add their own. Every product here retains; what you pay is ingest × retention (cloud) or disk (on-prem). Confirm the mandate before the ingest estimate, not at the audit. ## Eight situations, eight shortlists — starting from the meter Each shortlist begins with how you will pay (gigabytes, sources, EPS) and where the logs may live. The feature list comes after. ### Mid-market, regulated, India — predictable price, logs in India **Shortlist:** Elastic Security, LogRhythm SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Kaspersky SIEM (KUMA) **Why:** Per-source or per-EPS pricing, on-prem or an India-hosted cloud, compliance reports for the Indian regulators — and an India-built vendor in Log360. **Trade-off:** Documented scale tops out below the hyperscale SIEMs; SOAR is built-in workflows rather than a platform; KUMA carries procurement caveats in some sectors. ### You already run CrowdStrike Falcon **Shortlist:** CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR **Why:** Falcon data is already in the platform; 10 GB / day of third-party data is included with Insight, Fusion SOAR is in the box, and the per-GB meter is published on AWS Marketplace. **Trade-off:** Third-party ingest beyond the included volume is the bill; cloud-only; India in-country cloud announced, not yet live. ### You already run SentinelOne **Shortlist:** SentinelOne Singularity AI SIEM **Why:** Singularity Data Lake with AI SIEM, Hyperautomation and Purple AI in the same console, and a Mumbai data region. **Trade-off:** Consumption rates are not published — the per-GB price is a quote; one survivor here is the platform answer, not a gap. Splunk or Log360 remain the vendor-neutral alternatives. ### You already run Microsoft 365 E5 and Azure **Shortlist:** Microsoft Sentinel **Why:** Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free, so much of what the SOC watches costs nothing to collect; Sentinel and Defender XDR alerts land in one incident queue in the Defender portal; the data lake tier keeps high-volume logs at ~$0.05 / GB. **Trade-off:** One survivor is the estate answer, not a gap — and it only holds while your volume is Microsoft-shaped: third-party firewall and proxy logs pay full analytics rates. Cloud-only, so on-prem residency needs Log360 or FortiSIEM instead — and Sentinel stores in-region but processes customer data in the US for Indian workspaces. Budget the 31 March 2027 Defender portal migration. ### You believe the alert-triage SOC model itself is the problem **Shortlist:** Palo Alto Cortex XSIAM, CrowdStrike Falcon Next-Gen SIEM, SentinelOne Singularity AI SIEM **Why:** These are sold as replacements for the SIEM-led SOC rather than better versions of it — AI-led detection that stitches signals into a few high-fidelity incidents, with automation included rather than bought beside it. **Trade-off:** You are buying an operating model, not a log store: the value only lands if you give the platform your data and let its automation act. All three are cloud-only and quote-only, and each is strongest inside its own vendor’s estate. ### You already run Datadog for observability **Shortlist:** Datadog Cloud SIEM **Why:** Threat detection on logs you are already collecting and paying to index, with security signals correlated against the metrics and traces from the same incident — and Flex Logs keeps 3-15 months searchable without rehydration while detections still run against it. **Trade-off:** One survivor is the estate answer, not a gap. Cloud SIEM is priced on analysed logs on top of Log Management, so the ingestion and indexing underneath is the real bill — Datadog’s per-module billing is what buyers underestimate. If you are not already a Datadog estate, the vendor-neutral SIEMs are the honest comparison. ### A real SOC, with engineers, that wants the deepest search and content **Shortlist:** Splunk Enterprise Security, Splunk SOAR, CrowdStrike Falcon Next-Gen SIEM **Why:** Splunk ES is the reference — SPL, ESCU content, the integration ecosystem — with SOAR alongside; Falcon Next-Gen SIEM is the platform-native alternative for Falcon estates. **Trade-off:** Splunk's ingest economics and the tuning headcount are the contract; without engineers it is the most expensive archive in security. ### Fortinet fabric estate **Shortlist:** Fortinet FortiSIEM, Fortinet FortiAnalyzer **Why:** FortiAnalyzer for fabric logging and playbooks; FortiSIEM for correlation, CMDB context and third-party sources, on appliances or in the Mumbai cloud region. **Trade-off:** Strongest inside Fortinet; full SOAR is FortiSOAR, separate; several meters to match at quote. ### Log management first, SIEM maybe later **Shortlist:** Splunk Platform (Enterprise / Cloud), Fortinet FortiAnalyzer, ManageEngine Log360 (on-prem) / Log360 Cloud **Why:** Search and retention at scale without the SIEM application's price — Splunk's platform, FortiAnalyzer for Fortinet estates, Log360's entry tiers for everyone else. **Trade-off:** A log platform is not a SIEM until correlation, detections and cases are on it — and the ingest meter is the same. ### Retention is the problem — you keep deleting data you later need **Shortlist:** Google Security Operations, Securonix Unified Defense SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Kaspersky SIEM (KUMA) **Why:** Google SecOps includes twelve months of hot, searchable retention in every package, so the keep-or-delete decision leaves the budget conversation; Log360 and KUMA get there differently, by not metering gigabytes at all. **Trade-off:** Google SecOps is cloud-only on Google Cloud and quote-only, and beyond twelve months retention is billed by volume again. The per-source and per-EPS meters trade volume risk for scale ceilings. ### Ingest is exploding and the bill is the problem **Shortlist:** ManageEngine Log360 (on-prem) / Log360 Cloud, Kaspersky SIEM (KUMA), Fortinet FortiSIEM **Why:** Meters that are not gigabytes: per source (Log360), per EPS (KUMA), per device (FortiSIEM) — the cost curve flattens as volume grows. **Trade-off:** Predictable meters trade volume risk for scale ceilings and narrower ecosystems; the honest alternative is filtering and tiering data before a per-GB SIEM, not abandoning it. ### SOAR first — automate the triage you already have **Shortlist:** Splunk SOAR, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM **Why:** Splunk SOAR over ES or another SIEM; Charlotte Agentic SOAR and SentinelOne Hyperautomation included with their platforms. **Trade-off:** Automation needs the detections to be good first — SOAR over an untuned SIEM automates noise. ## At scale SIEMs scale by data, not by seats. Each step changes which meter survives and how many people the detections need. ### 50 GB / day — The meter is the constraint - Per-GB is survivable; per-source is cheaper; the difference is the retention mandate times the volume. - Log360, FortiSIEM, KUMA and the platform-native SIEMs with included data fit this band; Splunk ES is rarely the cheapest here. - One engineer tunes part-time — or nobody does, and it becomes an archive. **The test:** Estimate your real volume from a week of sources; price it at 180 days and at your mandate; compare per-GB against per-source with the same sources. ### 500 GB / day — Tuning and filtering are the constraint - Filtering and tiering at the source decide whether per-GB is affordable; workload pricing starts to make sense. - Detections need an owner; alert fatigue is now a staffing problem, not a tool problem. - Third-party ingest is where platform-native SIEMs stop being 'included'. **The test:** Measure alerts per analyst per day for a month; ask each vendor what the bill is with 30% of volume filtered or tiered. ### 5,000 GB / day — Architecture and sovereignty are the constraint - Multi-tenant, multi-region SIEM with delegated access; residency per source; EPS-based or workload pricing on the table. - Detection engineering is a team with a pipeline; SOAR is mandatory to survive the volume. - Migration now means rewriting every detection rule — plan the exit before signing the entry. **The test:** Load-test your peak EPS; confirm region sharding and retention tiers in writing; price the exit. Splunk, CrowdStrike, SentinelOne, FortiSIEM and KUMA document very large deployments (KUMA 300,000+ EPS per node); Log360’s documented scale is mid-market — flagged, not ruled out. Where a specific console strains for your volume: [TechBag to confirm]. ## Migration means rewriting every detection rule Sources re-point in weeks. The detections, the parsers, the dashboards and the years of logs under a retention mandate are what make a SIEM migration a year, not a quarter. **Sources and collectors** — Re-point syslog, agents and API connectors; re-parse each source's format for the new platform. Weeks per estate, scriptable in parts. *(Re-point, re-parse)* **Detections and dashboards** — Every correlation rule, every tuned exclusion and every compliance dashboard is rewritten in the new language — SPL is not KQL is not Log360's rules. The year. *(Rewrite)* **Retained logs** — Logs under a mandate must stay searchable for the mandate; either keep the old SIEM in read-only for the period or export and re-index. Both cost. *(Keep or re-index)* **Playbooks and integrations** — SOAR playbooks, ticketing and MDR integrations are rebuilt; the MDR may have to re-onboard the new SIEM as a source. *(Rebuild)* **Detection-rewrite months and retained-log strategy for your estate:** [TechBag to confirm] — TechBag scopes it from your rule count, sources and mandate. ## The licence is the small number What you may already hold, the meters compared in USD and INR at three daily volumes, and what the licence leaves out — retention, tuning, and the exit. ### Do you already own one? Four places a SIEM — or enough of one — may already be on your invoice. - **Microsoft 365 E5 — Partly.** E5 carries Defender XDR (correlation across Microsoft sensors) and Sentinel benefits (a daily data grant for Microsoft 365 logs). Sentinel itself is Azure consumption per GB — a SIEM you already half-pay for if the estate is Microsoft. - **Your EDR platform — Often.** CrowdStrike (Next-Gen SIEM with 10 GB / day of third-party data included with Insight), SentinelOne (AI SIEM on the Data Lake), Trend, Sophos and Palo Alto all sell SIEM or XDR on the sensor you run. The included part is the vendor’s data; the bill is the rest. - **Your firewall vendor — Sometimes.** FortiAnalyzer logs the Fortinet fabric and runs playbooks; FortiSIEM adds correlation. Check Point, Cisco and Palo Alto have their own. Fabric logging is not a SIEM until third-party sources are in. - **Your cloud provider — Partly.** AWS Security Lake, Microsoft Sentinel and Google Security Command Center / Google Security Operations ingest their own clouds cheaply. One cloud each — the vendor-neutral SIEM question remains. If the logs you must keep are already sitting somewhere you pay for, we say so — and then price what it costs to keep them for the mandate. ### What the rest actually cost Reported and published rates per meter (INR for scale), then worked at 50 / 500 / 5,000 GB a day. Per-source and per-EPS products cannot be expressed per gigabyte — the grid says so rather than inventing a conversion. ### What isn't in the licence price - **Retention beyond the included window.** Per-GB meters quote a retention (CrowdStrike 13 months PAYG; Splunk by tier); the mandate may want 180 days hot and years cold. Retention × volume is the part of the bill that grows after year one — and it multiplies at renewal. - **The tuner.** Detection engineering is a role at 2,000 endpoints and a team at a TB / day. Budget it beside the licence or buy the people through the MDR guide; a SIEM nobody tunes is an archive with a dashboard. - **The rewrite.** Leaving means rewriting every detection in the new language and keeping the old logs searchable for the mandate — [the switching-cost section](#migration). Your rule count and months: [TechBag to confirm]. ## What goes wrong Documented meter behaviour and programme failures, cross-checked against TechBag engagements before any becomes a named case. Most are visible in the quote if you know where to look. - **Ingest costs multiplying after year one.** Volume grew, retention stayed, the per-GB meter did what it said. Filtering and tiering at the source were never designed in. - **Retention mandates discovered at audit.** CERT-In's 180 days, RBI's and SEBI's retention — found when the regulator asked, after the cheapest retention tier was chosen. - **No engineering capacity to write detections.** Content shipped; nobody mapped sources or suppressed noise; the SIEM became a log archive with an invoice. - **Alert fatigue at volume.** Untuned detections at 500 GB a day outran the team; real alerts drowned. A staffing problem bought as a tool. - **Migration meaning every detection rule rewritten.** Years of tuning in one vendor's language; the new platform started empty. The exit nobody priced. - **'Included' SIEM that wasn't.** The platform's SIEM was free for the platform's data; the firewall and identity logs were the bill. Name the third-party volume before signing. - **XDR sold as a SIEM replacement.** Pre-tuned correlation from one vendor's sensors covered their stack; the regulator wanted everything, retained in India. Different scope. - **SOAR over untuned detections.** Playbooks automated the noise faster. Automate after the detections are good. ## Questions this guide answers ### What is the difference between SIEM, XDR, log management and SOAR? Log management collects, keeps and searches logs. A SIEM adds correlation across sources, detection content, cases and compliance reporting — vendor-neutral, ingesting everything you run, and needing someone to tune it. XDR is correlation from one vendor's own sensors inside their platform, pre-tuned and narrower. SOAR is automation and case management over whatever raises alerts; it acts on detections, it does not make them. Widening and adjacent scopes, not tiers. ### How is SIEM priced — per GB, per source or per EPS? Splunk prices by ingest (GB / day, reported roughly $100–180 per GB / day per year for the platform plus $20–45 for Enterprise Security; Splunk Cloud near $1,000 per GB / day per year at 50 GB / day) or by workload compute; CrowdStrike Falcon Next-Gen SIEM per GB ($5.95 / GB pay-as-you-go, ~$2,700 per GB / day per year list for third-party data, 10 GB / day included with Insight); SentinelOne per GB with unpublished rates; ManageEngine Log360 per log source ($300–1,995 per year entry tiers); FortiSIEM per device / EPS or per GB / day; Kaspersky KUMA per EPS. The meter decides total cost more than any feature. ### Which SIEMs keep logs in India? On-prem deployments (Splunk Enterprise, ManageEngine Log360, FortiSIEM, FortiAnalyzer, Kaspersky KUMA) keep logs in India by construction. Documented India cloud regions: FortiSIEM Cloud (Mumbai), SentinelOne Singularity (Mumbai) and ManageEngine Log360 Cloud (Zoho India data centres). CrowdStrike's India in-country cloud is announced (January 2026); Splunk Cloud publishes no Mumbai region. CERT-In's 2022 directions require 180 days of ICT logs maintained in India. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/security/siem-log-management* --- # An agent on a laptop and an agent on a container are not the same problem. Most endpoint vendors sell you the former and call it cloud security. *Cloud & Workload Security — a TechBag decision guide. Last reviewed 2026-09-07.* > Cloud security is two purchases wearing one name: **posture** — what is misconfigured, over-privileged or vulnerable across your accounts, read agentlessly from APIs — and **protection** — something running on the workload or in the cluster that can block and respond. Every vendor sells one well and the other as a module. **The checkable fact:** Tenable Cloud Security is 100% agentless by design and provides no runtime protection. Wiz Defend needs the Wiz Sensor to act at runtime. Same category; opposite halves. - Canonical: https://www.thetechbag.com/browse/security/cloud-workload-security - Category: [Security](https://www.thetechbag.com/browse/security) - Products compared: 16 ## What cloud & workload security actually is Your workloads are in someone else’s data centre, built by engineers, changed by pipelines, and exposed by configuration rather than by malware. Two disciplines grew up around that. **Posture** reads your cloud accounts through their APIs — with no agent — and finds misconfiguration, vulnerable images, over-privileged identities and the paths that join them. **Workload protection** runs on the VM, the container host or in the Kubernetes cluster and can block, isolate and respond at runtime. The market has stitched them into one word, CNAPP — but every product here has a home half. The agentless specialists (Wiz, Tenable, Check Point) are posture-first and add runtime by module or agent; the endpoint vendors (CrowdStrike, SentinelOne, Trend, Sophos, Bitdefender, Kaspersky) are runtime-first and add posture by acquisition; the vulnerability vendors (Qualys, Tenable) extend their risk model into the cloud. Knowing which half a vendor was born in tells you where its depth is. **The most common mis-purchase.** A **laptop agent** watches one user’s machine; a **workload sensor** must survive immutable images, autoscaling, ephemeral containers and Kubernetes admission — and often is not allowed at all. Ask every endpoint vendor how their cloud product works *without* their agent; ask every agentless vendor what happens *at runtime*. ## CSPM vs CWPP vs CIEM vs CNAPP Four acronyms this buyer confuses, and nothing more. Three are scopes; the fourth is the bundle. None is a tier of quality — each adds something to read or run, costs more, and needs more owners on your side. ### CSPM — Cloud Security Posture Management Reads your cloud accounts through their APIs and finds misconfiguration, exposure and drift against benchmarks — agentless by nature. The foundation, and the half the agentless specialists were born in. Finds; does not block. ### CWPP — Cloud Workload Protection Platform Runs on the VM, the container host or in the cluster: vulnerability and malware detection, runtime behaviour, blocking and response. The half the endpoint vendors were born in. Needs something installed — a sensor, an agent, an admission controller. ### CIEM — Cloud Infrastructure Entitlement Management Who (human or machine) can do what, to which resource, across accounts — effective permissions, toxic combinations, least-privilege recommendations. Identity is the cloud's perimeter; CIEM is the only scope that reads it. Agentless; findings need an owner in the platform team. ### CNAPP — Cloud-Native Application Protection Platform The bundle: CSPM + CWPP + CIEM, usually plus code / IaC scanning and data posture, on one risk graph. Not a product you can buy whole from most vendors — it is the label on whichever half they started with plus the modules they added. **Scopes, not tiers.** CSPM reads, CWPP runs, CIEM reads identity, CNAPP is the label for all of them together. Each adds cost and an owner; the posture-only buyer and the runtime-only buyer are both buying half — deliberately is fine, by accident is the failure mode of this category. ## The decision variables Six variables decide this purchase. The instrument tests posture-vs-runtime, agentless-vs-agent, CIEM, code scanning, on-prem coverage and the small-estate floor; cloud depth and container depth are prose because every datasheet lists all three clouds and every product scans images. **CSPM vs CWPP vs CIEM vs code — what's actually included.** Every vendor sells the bundle name; the chips name which scopes each SKU actually contains, and which are separate modules. **Agentless vs agent-based vs both.** Agentless reads accounts in hours with nothing installed and cannot block; agents run on the workload and can. Most vendors now do both — the chip shows which side is native. **Which clouds are genuinely covered at depth.** All list AWS, Azure, GCP; depth follows where each vendor's customers live. Ask for the supported-services list per cloud and test your smallest one. **Container and Kubernetes depth.** Image scanning is universal; admission control and in-cluster runtime are not. Kaspersky Container Security, Wiz Defend, CrowdStrike, SentinelOne, Trend, FortiCNAPP, Check Point and Qualys document runtime. **Shift-left / IaC scanning.** Terraform, CloudFormation, Kubernetes manifests and images scanned in CI, tied to the production graph — only worth it if engineering wires the gate in. **Runtime protection vs posture only.** The honest split: Tenable and the Wiz posture modules never block; the endpoint-heritage vendors and Wiz Defend do. Buying half is fine if you know which half. ## The 16 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Wiz CSPM (Wiz Essential / Advanced) — Wiz - **Who it's for:** The agentless reference: posture, vulnerabilities and attack paths across AWS, Azure and GCP in hours, with no agent — and the Security Graph everyone else now copies. - **The honest limitation:** Posture SKU — runtime protection is Wiz Defend with the Sensor, and CIEM, Code and DSPM are separate modules; reported minimums rule out very small estates; India region not documented. - **Price:** ~$15–30 (≈ ₹1,245) — per workload / year reported under 500 workloads (Essential ~$24k / yr for 100; $8–20 at 2,000–10,000; $6–15 above); agentless snapshot scanning; Google-owned (2026) - **Details:** https://www.thetechbag.com/wiz/wiz-cspm ### Wiz CIEM — Wiz - **Who it's for:** Wiz estates that need to know which identity can reach which data, and what to take away. - **The honest limitation:** A module over Wiz's graph — not standalone; findings need an owner or they age. - **Price:** Module — add-on module to Wiz — identities, entitlements, effective permissions, least-privilege recommendations - **Details:** https://www.thetechbag.com/wiz/wiz-ciem ### Wiz Code — Wiz - **Who it's for:** Teams fixing cloud risk in the pull request rather than in production. - **The honest limitation:** A module; useful only with engineering adoption; priced as an enterprise add-on. - **Price:** Module — add-on (reported ~$58,500 / yr) — IaC, container images, secrets and code-to-cloud tracing in CI - **Details:** https://www.thetechbag.com/wiz/wiz-code ### Wiz Defend (runtime, with Wiz Sensor) — Wiz - **Who it's for:** Wiz estates that need runtime detection and response, not just a prioritised posture list. - **The honest limitation:** Needs the Sensor on the workloads — the agentless story ends here; on-prem coverage not documented; priced as modules on top of Wiz. - **Price:** Module — add-on (reported ~$18,000 / yr) + Wiz Sensor (eBPF, reported ~$28,000 / yr) — cloud detection and response on running workloads and Kubernetes - **Details:** https://www.thetechbag.com/wiz/wiz-defend ### Wiz DSPM — Wiz - **Who it's for:** Wiz estates that want the sensitive data in the graph next to the path to it. - **The honest limitation:** Data posture, not data protection — it finds and ranks; it does not encrypt or block; a module. - **Price:** Module — add-on — data discovery and classification in cloud stores, joined to exposure paths - **Details:** https://www.thetechbag.com/wiz/wiz-dspm ### Check Point CloudGuard CNAPP — Check Point - **Who it's for:** Check Point estates wanting a prevention-first CNAPP — posture, entitlements and code scanning agentless, runtime where you deploy agents. - **The honest limitation:** Quote-only consumption pricing; depth of runtime is agent-dependent; India region not documented. - **Price:** Quote — consumption-based per billable asset; Agentless Workload Posture (AWP), CIEM, Effective Risk Management, pipeline security; runtime via workload agents - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-cloudguard-cnapp ### Qualys TotalCloud — Qualys - **Who it's for:** Qualys estates extending VMDR's TruRisk into cloud posture, workload protection and IaC — one tenant for hosts and clouds. - **The honest limitation:** Quote-only on two meters; strongest for Qualys customers; CIEM is newer than the rest of the suite. - **Price:** Quote — per cloud connector (CSPM) + per workload (CWPP); FlexScan agent and agentless; TruRisk scoring; India platform - **Details:** https://www.thetechbag.com/qualys/qualys-totalcloud ### Tenable Cloud Security — Tenable - **Who it's for:** Tenable estates — and anyone who wants posture, entitlements and vulnerabilities with nothing installed — and accepts there is no runtime blocking. - **The honest limitation:** Posture only by design: 100% agentless means no runtime protection on the workload; quote-only; India region not documented. - **Price:** Quote — per billable resource (VMs, container hosts, functions, images, data stores); 100% agentless; CSPM + CIEM (Ermetic lineage) + vulnerability + IaC - **Details:** https://www.thetechbag.com/tenable/tenable-cloud-security ### Trend Vision One Cloud Security — Trend Micro - **Who it's for:** Trend estates — including on-prem VMware servers — wanting posture and agent-based runtime in the same XDR as endpoint and email. - **The honest limitation:** Credit-priced and opaque until you run it; CIEM depth not documented; strongest inside Vision One. - **Price:** Credits — Vision One credits — Conformity posture (agentless), workload protection agents (Deep Security lineage), container security, template scanning - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-cloud-security ### Fortinet FortiCNAPP (Lacework) — Fortinet - **Who it's for:** Fortinet estates — and Lacework's behavioural-anomaly fans — wanting a CNAPP with a published starter price. - **The honest limitation:** A starter-pack floor, then quote; on-prem coverage via the agent is not documented here; India region not documented. - **Price:** from ~$25,000 (≈ ₹20,75,000) — per year starter pack (annual or BYOL); agentless + Lacework agent; CSPM, CIEM, CWPP, code; Security Fabric integration - **Details:** https://www.thetechbag.com/fortinet/fortinet-forticnapp ### Bitdefender GravityZone Cloud Security (CSPM+) — Bitdefender - **Who it's for:** GravityZone estates adding cloud posture to the workload protection they already run on VMs and containers, cloud or on-prem. - **The honest limitation:** CIEM and code scanning are not documented; quote-only; cloud posture is newer than the workload protection. - **Price:** Quote — CSPM+ (agentless posture) per account; workload and container protection via GravityZone agents incl. on-prem virtualised servers - **Details:** https://www.thetechbag.com/bitdefender/bitdefender-cloud-security ### SentinelOne Singularity Cloud Security — SentinelOne - **Who it's for:** SentinelOne estates wanting agentless posture plus the Singularity agent's runtime on servers and Kubernetes, with an India region. - **The honest limitation:** Quote-only; CNAPP breadth is newer than the endpoint heritage; strongest when SentinelOne is already the agent. - **Price:** Quote — agentless CNAPP (PingSafe lineage) + Cloud Workload Security agent; CSPM, CIEM, IaC, Kubernetes runtime; Mumbai region - **Details:** https://www.thetechbag.com/sentinelone/sentinelone-singularity-cloud-security ### CrowdStrike Falcon Cloud Security — CrowdStrike - **Who it's for:** Falcon estates that want the sensor's runtime on servers and containers plus agentless posture in the same console as endpoint. - **The honest limitation:** Quote-only; agentless is a fallback for where the sensor cannot go, not the design centre; India in-country cloud announced, not yet documented live. - **Price:** Quote — Falcon sensor for workload protection + agentless snapshot scanning; CSPM, CIEM, IaC, cloud detection and response; quote-only - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-falcon-cloud-security ### Kaspersky Hybrid Cloud Security — Kaspersky - **Who it's for:** Estates that want agent-based workload protection across private and public clouds from one console, including VMware and OpenStack. - **The honest limitation:** Workload protection, not a CNAPP — no CSPM, CIEM or code scanning; procurement caveats in some sectors; quote-only. - **Price:** Quote — per node (VM / server), agent-based; VMware, Hyper-V, OpenStack and AWS / Azure / GCP workloads - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-hybrid-cloud-security ### Kaspersky Container Security — Kaspersky - **Who it's for:** Kubernetes estates — on-prem included — wanting image, admission and runtime security from one vendor. - **The honest limitation:** Containers only; no cloud posture or entitlements; procurement caveats; quote-only. - **Price:** Quote — per node; image scanning in CI / registry, admission control, runtime for Kubernetes on-prem or in cloud - **Details:** https://www.thetechbag.com/kaspersky/kaspersky-container-security ### Sophos Cloud Native Security — Sophos - **Who it's for:** Sophos Central estates that want server runtime (Intercept X) and cloud posture (Cloud Optix) beside their MDR — and a published PAYG meter. - **The honest limitation:** Posture depth trails the agentless specialists; PAYG rates are on the marketplace, not a list; strongest inside Sophos. - **Price:** PAYG — per user and per server, pay-as-you-go on AWS Marketplace or via partners; Intercept X for Server runtime + Cloud Optix posture / IAM visualisation / IaC; Sophos Central (Mumbai region) - **Details:** https://www.thetechbag.com/sophos/sophos-cloud-native-security ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Runtime protection on the workload.** Rules out Wiz CSPM (Wiz Essential / Advanced) — a posture SKU; runtime is a separate module (Wiz Defend + Sensor) from the same vendor; Wiz CIEM, Wiz Code, Wiz DSPM and Tenable Cloud Security — posture and visibility only; nothing runs on the workload to block or respond. That leaves Wiz Defend (runtime, with Wiz Sensor), Check Point CloudGuard CNAPP, Qualys TotalCloud, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security, Kaspersky Hybrid Cloud Security, Kaspersky Container Security and Sophos Cloud Native Security. **Agentless only.** Rules out Wiz Defend (runtime, with Wiz Sensor), Kaspersky Hybrid Cloud Security and Kaspersky Container Security — agent-based only. That leaves Wiz CSPM (Wiz Essential / Advanced), Wiz CIEM, Wiz Code, Wiz DSPM, Check Point CloudGuard CNAPP, Qualys TotalCloud, Tenable Cloud Security, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security and Sophos Cloud Native Security. It flags Check Point CloudGuard CNAPP — Agentless posture; runtime protection needs its agent / sensor, Qualys TotalCloud — Agentless posture; runtime protection needs its agent / sensor, Trend Vision One Cloud Security — Agentless posture; runtime protection needs its agent / sensor, Fortinet FortiCNAPP (Lacework) — Agentless posture; runtime protection needs its agent / sensor, Bitdefender GravityZone Cloud Security (CSPM+) — Agentless posture; runtime protection needs its agent / sensor, SentinelOne Singularity Cloud Security — Agentless posture; runtime protection needs its agent / sensor, CrowdStrike Falcon Cloud Security — Agentless posture; runtime protection needs its agent / sensor and Sophos Cloud Native Security — Agentless posture; runtime protection needs its agent / sensor — marked, not removed. **CIEM.** Rules out Wiz CSPM (Wiz Essential / Advanced), Wiz Code, Wiz Defend (runtime, with Wiz Sensor), Wiz DSPM, Kaspersky Hybrid Cloud Security and Kaspersky Container Security — no cloud identity / entitlement management in this SKU. That leaves Wiz CIEM, Check Point CloudGuard CNAPP, Qualys TotalCloud, Tenable Cloud Security, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security and Sophos Cloud Native Security. It flags Trend Vision One Cloud Security — CIEM depth not documented and Bitdefender GravityZone Cloud Security (CSPM+) — CIEM depth not documented — marked, not removed. **Shift-left and IaC scanning.** Rules out Wiz CSPM (Wiz Essential / Advanced), Wiz CIEM, Wiz Defend (runtime, with Wiz Sensor), Wiz DSPM and Kaspersky Hybrid Cloud Security — no IaC / code scanning in this SKU. That leaves Wiz Code, Check Point CloudGuard CNAPP, Qualys TotalCloud, Tenable Cloud Security, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security, Kaspersky Container Security and Sophos Cloud Native Security. It flags Bitdefender GravityZone Cloud Security (CSPM+) — Code scanning not documented — marked, not removed. **Private-cloud and on-prem workloads.** Rules out Wiz CSPM (Wiz Essential / Advanced), Wiz CIEM, Wiz Code, Wiz DSPM and Tenable Cloud Security — public-cloud accounts only. That leaves Wiz Defend (runtime, with Wiz Sensor), Check Point CloudGuard CNAPP, Qualys TotalCloud, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security, Kaspersky Hybrid Cloud Security, Kaspersky Container Security and Sophos Cloud Native Security. It flags Wiz Defend (runtime, with Wiz Sensor) — On-prem workload coverage not documented, Check Point CloudGuard CNAPP — On-prem workload coverage not documented and Fortinet FortiCNAPP (Lacework) — On-prem workload coverage not documented — marked, not removed. **Under 100 workloads.** Rules nothing out on published terms. It flags Wiz CSPM (Wiz Essential / Advanced) — Essential ≈ $24,000 / yr for 100 workloads, Wiz Code — Reported ~$58,500 / yr add-on, Wiz Defend (runtime, with Wiz Sensor) — Reported ~$18,000 / yr add-on; Sensor ~$28,000 / yr and Fortinet FortiCNAPP (Lacework) — Starter packs from ~$25,000 / yr — marked, not removed. **Which clouds are genuinely covered at depth.** Rules nothing out on documentation — every product here lists AWS, Azure and GCP. Depth is the question the datasheet cannot answer: the agentless specialists (Wiz, Tenable, Check Point AWP) document the widest service coverage across all three; the endpoint-heritage vendors are deepest on the cloud their customers run most; Kaspersky Hybrid Cloud is deepest on private virtualisation. Ask for the list of supported services per cloud, and test the one you use least. **Containers and Kubernetes depth.** Rules nothing out as a chip because every product here scans images; what differs is admission control and runtime in the cluster: Kaspersky Container Security, Wiz Defend, CrowdStrike, SentinelOne, Trend, FortiCNAPP, Check Point and Qualys document runtime; Tenable and the Wiz posture modules scan images and configuration without running in the cluster; Bitdefender and Sophos run via their server agents. Ask which Kubernetes distributions and which node types. **India data residency.** Documented: SentinelOne (Mumbai), Sophos Central (Mumbai), Qualys (India platform). CrowdStrike's India in-country cloud is announced (January 2026); Wiz, Check Point, Tenable, Trend, Fortinet, Bitdefender and Kaspersky do not document an India region for cloud-security telemetry — flagged, not ruled out. Note that the workloads themselves already live in a region; the question is where the findings and snapshots are stored. ## Eight situations, eight shortlists — starting from whether agents are allowed Every shortlist begins with posture or protection, agent or not. The vendor's home half follows. ### Three clouds, no agents allowed, answer in a week **Shortlist:** Wiz CSPM (Wiz Essential / Advanced), Tenable Cloud Security, Check Point CloudGuard CNAPP **Why:** Agentless posture, vulnerabilities, entitlements and attack paths across AWS, Azure and GCP from API access alone — Wiz's design centre, Tenable's 100%-agentless stance, Check Point's AWP. **Trade-off:** Posture only: nothing blocks at runtime until you add Wiz Defend's Sensor or Check Point's agents; Tenable never does. Reported minimums put Wiz out of reach below ~100 workloads. ### Something is running in the cluster and must be stopped **Shortlist:** Wiz Defend (runtime, with Wiz Sensor), CrowdStrike Falcon Cloud Security, SentinelOne Singularity Cloud Security **Why:** Runtime detection and response on workloads and Kubernetes: Wiz Defend with the eBPF Sensor, the Falcon sensor, the Singularity agent — the endpoint vendors' strength. **Trade-off:** All three need something installed; the agentless story ends at runtime. Kaspersky Container Security and Trend are the on-prem-friendly alternatives. ### You already run CrowdStrike, SentinelOne, Trend or Sophos on servers **Shortlist:** CrowdStrike Falcon Cloud Security, SentinelOne Singularity Cloud Security, Trend Vision One Cloud Security **Why:** The sensor you already run becomes the workload-protection agent, with agentless posture added in the same console — one agent estate, one XDR. **Trade-off:** Posture depth trails the agentless specialists; quote-only (Trend in credits); an agent on a laptop is still not an agent on a container — test the Kubernetes story specifically. ### You already run Qualys or Tenable for vulnerabilities **Shortlist:** Qualys TotalCloud, Tenable Cloud Security **Why:** TruRisk or VPR extended into cloud accounts and workloads from the tenant you already use — one risk model for hosts and clouds. **Trade-off:** Qualys meters per connector and per workload on quote; Tenable is posture only with no runtime. Neither is a reason to skip runtime protection if you need it. ### Private cloud — VMware, OpenStack, on-prem Kubernetes **Shortlist:** Kaspersky Hybrid Cloud Security, Kaspersky Container Security, Bitdefender GravityZone Cloud Security (CSPM+) **Why:** Agent-based workload and container protection that documents VMware, Hyper-V and OpenStack alongside the public clouds; Trend and Sophos server agents are the other on-prem-friendly paths. **Trade-off:** Kaspersky carries procurement caveats in some sectors and brings no posture or CIEM; Bitdefender's posture is newer than its workload protection. ### Cloud identity is the attack surface — who can reach what **Shortlist:** Wiz CIEM, Tenable Cloud Security, Check Point CloudGuard CNAPP **Why:** Entitlement analysis and least-privilege recommendations: Wiz's CIEM module, Tenable's Ermetic lineage, CloudGuard's CIEM with effective risk. **Trade-off:** CIEM findings need an owner in the platform team; a list of over-privileged roles nobody removes is the cloud version of scan results nobody actions. ### Fix it in the pull request — IaC, images, secrets **Shortlist:** Wiz Code, Check Point CloudGuard CNAPP, Fortinet FortiCNAPP (Lacework) **Why:** Shift-left scanning tied to the same risk graph as production: Wiz Code's code-to-cloud tracing, CloudGuard pipeline security, FortiCNAPP's IaC and image scanning — CrowdStrike, SentinelOne, Qualys, Trend and Tenable also scan IaC. **Trade-off:** Engineering adoption decides the value; a CI gate nobody wired in is a licence. Wiz Code is priced as an enterprise add-on. ### Published price, Fortinet fabric, or a PAYG meter **Shortlist:** Fortinet FortiCNAPP (Lacework), Sophos Cloud Native Security, Wiz CSPM (Wiz Essential / Advanced) **Why:** FortiCNAPP publishes a ~$25,000 starter pack; Sophos Cloud Native Security is pay-as-you-go per user and server on AWS Marketplace; Wiz's tiers are reported by resellers (~$24k Essential for 100 workloads). **Trade-off:** Starter packs and PAYG are floors, not ceilings; the rest of the field is quote-only or credit-priced — the normal state of this market. ## At scale Cloud estates scale by workloads that appear and vanish hourly. The meter, the alert volume and the number of owners are what change. ### 100 workloads — The floor is the constraint - Reported minimums (Wiz Essential ~$24k / yr for 100 workloads; FortiCNAPP ~$25k starter) decide the field before features do. - Your cloud provider's native tools (Defender for Cloud, Inspector, Security Command Center) may be the honest posture layer at this size. - One platform engineer owns everything — including the findings. **The test:** Connect one account to a trial, count the findings, and ask who will close the top ten this week. ### 1,000 workloads — Ownership and noise are the constraint - Intentional misconfigurations (public buckets that are meant to be public) generate alerts nobody wants; exceptions need an owner. - CIEM findings pile up in the platform team's queue; runtime alerts in the SOC's — two owners, one graph. - Agent rollout into autoscaling groups and clusters is an engineering project, not a security one. **The test:** Measure alert volume per owner for a month; test the exception workflow; deploy the agent through your image pipeline, not by hand. ### 10,000 workloads — Multi-cloud depth and meters are the constraint - Per-workload and per-resource meters climb with ephemeral workloads; ask how short-lived containers are counted. - Depth on your second and third cloud is where the agentless specialists and the endpoint lineage diverge most. - Data residency for snapshots and findings becomes a question — three vendors document an India region. **The test:** Pull the full inventory through the API and reconcile it with the cloud billing export; price ephemeral workloads explicitly. Wiz, CrowdStrike, SentinelOne, Check Point, Qualys, Tenable, Trend and FortiCNAPP document very large estates; Bitdefender’s and Sophos’s cloud posture and Kaspersky’s container product document less at scale — flagged in prose, not ruled out. Where a specific console strains for your estate: [TechBag to confirm]. ## Switching posture tools is a re-connect; switching runtime is a re-deploy Agentless products leave in an afternoon; agents leave with the next image build. The findings, exceptions and pipeline gates are what move slowly. **Agentless connectors** — Revoke the old read-only roles, grant the new; findings repopulate in hours. The lightest switch in security — which is also why agentless vendors fight hardest on renewals. *(Re-connect)* **Agents and sensors** — Rebuild images, roll autoscaling groups, redeploy DaemonSets; the old sensor lingers on long-lived VMs until someone removes it. *(Re-deploy)* **Exceptions and risk acceptances** — Every accepted public bucket, every tolerated permission and every suppressed rule is rebuilt by hand in the new graph. *(Rebuild)* **Pipeline gates and integrations** — CI gates, ticketing, SIEM and MDR integrations are re-wired; a different risk model re-baselines every SLA. *(Re-wire)* **Re-connect, re-deploy and exception-rebuild effort for your estate:** [TechBag to confirm] — TechBag scopes it from your accounts, clusters and pipeline. ## Per workload, per resource, per connector, per credit — and the native tools you already pay for What your cloud already includes, the meters compared in USD and INR at three estate sizes, and what the licence leaves out. ### Do you already own one? Four places posture or protection may already be on the invoice. - **Your cloud provider — Partly.** AWS (Inspector, GuardDuty, Security Hub), Azure (Defender for Cloud) and Google (Security Command Center) each secure their own cloud natively, on consumption. One cloud each, deep on their services — the honest posture layer at small scale. - **Your endpoint vendor — Often.** CrowdStrike, SentinelOne, Trend, Sophos, Bitdefender and Kaspersky all sell the workload half on the sensor you run; posture is the newer add-on. - **Your vulnerability vendor — Often.** Qualys TotalCloud and Tenable Cloud Security extend the risk model you already pay for into cloud accounts. Tenable stays posture-only. - **Microsoft 365 E5 — No.** E5 is endpoints, mail and identity. Defender for Cloud is a separate Azure consumption bill — and it covers AWS and GCP too, which is why it is the comparator for every agentless quote on an Azure-heavy estate. If the native tool covers your one cloud, we say so — and then talk about the second cloud and the runtime half. ### What the rest actually cost Reported and published meters (INR for scale), then worked at 100 / 1,000 / 10,000 workloads. Most of this market is quote-only or credit-priced; the grid says so rather than inventing a number. ### What isn't in the licence price - **The owners.** Posture findings belong to the platform team; runtime alerts to the SOC; CIEM findings to identity; pipeline gates to engineering. A CNAPP without four owners is four queues nobody reads. - **The agent rollout.** Runtime protection means a sensor in images, autoscaling groups and clusters — an engineering project the security licence does not include. Price it as one. - **The exceptions.** Intentional public buckets, tolerated permissions, accepted CVEs — the exception workflow is the product in year two. It is rebuilt by hand if you switch ([switching cost](#migration)); your count is [TechBag to confirm]. ## What goes wrong Documented architectural behaviour, cross-checked against TechBag engagements before any becomes a named case. Most of these are halves bought as wholes. - **Posture-only tools mistaken for runtime protection.** The graph was perfect; the cryptominer ran for a week. Tenable and the Wiz posture modules never block — by design. Know which half you bought. - **Agentless blind spots at runtime.** Snapshots every few hours miss what happens between them. Agentless is for posture; runtime needs something running. - **Multi-cloud support deep on one and thin elsewhere.** All three logos on the datasheet; service coverage on the third cloud was a checklist. Test your smallest cloud first. - **CIEM findings nobody owns.** A list of over-privileged roles in the security console; the platform team never saw it. Findings need an owner in the team that can change the role. - **Alert volume from intentional misconfigurations.** Public buckets that should be public, open ports that are meant to be open — flagged forever until exceptions are designed in. - **An endpoint agent sold as cloud security.** The laptop sensor would not survive the immutable image; the container story was a roadmap. Ask every endpoint vendor how it works without the agent. - **Ephemeral workloads on a per-workload meter.** Containers that lived an hour counted like servers; the renewal was a surprise. Ask how the meter counts before the first connector. - **The native tool already switched on.** Defender for Cloud or Security Hub was already doing the posture the new tool was bought for. Compare against the native tool first. ## Questions this guide answers ### What is the difference between CSPM, CWPP, CIEM and CNAPP? CSPM reads cloud accounts through their APIs and finds misconfiguration, exposure and drift — agentless, finds but does not block. CWPP runs on the VM, container host or Kubernetes cluster and can detect, block and respond at runtime — needs something installed. CIEM reads identities and entitlements — who can do what to which resource. CNAPP is the label for the bundle of all three plus code / IaC scanning and data posture on one risk graph. Scopes, not tiers; most vendors sell the half they were born in plus modules. ### Agentless or agent-based cloud security? Agentless (Wiz, Tenable, Check Point AWP, Qualys FlexScan, CrowdStrike snapshot scanning and others) connects every account in hours with nothing installed, but cannot block at runtime and has a blind spot between snapshots. Agent-based (the Falcon and Singularity sensors, Trend, Sophos, Bitdefender, Kaspersky, the Wiz Sensor, Lacework and CloudGuard agents) gives live runtime detection and blocking but must be deployed into images, autoscaling groups and clusters. Most vendors now offer both; the question is which side is native. Tenable is 100% agentless by design and offers no runtime protection. ### How much does Wiz cost? Wiz does not publish a list. Reseller and buyer reports put Wiz Essential at roughly $24,000 a year for 100 workloads and Advanced at about $38,000; under 500 workloads around $15–30 per workload per year, $8–20 at 2,000–10,000 and $6–15 above; Wiz Sensor, Wiz Code and Wiz Defend are separate add-ons reported at roughly $28,000, $58,500 and $18,000 a year. FortiCNAPP publishes a starter pack from about $25,000 a year; Sophos Cloud Native Security is pay-as-you-go on AWS Marketplace; the rest of the field is quote or credit priced. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/security/cloud-workload-security* --- # Security — prevention, detection or response — which of the six security routes is yours *A TechBag category guide. Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/security - Routes: 6 ## The routes ### Endpoint Protection EPP and EDR answer different questions. Most buyers purchase one believing they bought both. - 36 products compared - Guide: https://www.thetechbag.com/browse/security/endpoint-protection - Boundary terms resolved: EPP — Endpoint Protection Platform · EDR — Endpoint Detection & Response · XDR — Extended Detection & Response ### Managed Detection & Response You’re not buying software. You’re buying whether someone picks up the phone at 2am — and what they’re permitted to do. - 13 products compared - Guide: https://www.thetechbag.com/browse/security/managed-detection-response - Boundary terms resolved: MDR vs EDR you operate yourself · MDR vs MSSP · MDR vs MXDR ### Email Security Your mail platform already filters spam. What it doesn’t stop is a message with no attachment, no link and no malware. - 22 products compared - Guide: https://www.thetechbag.com/browse/security/email-security - Boundary terms resolved: Gateway (MX) deployment · API deployment · What the platform already filters ### Vulnerability Management Finding vulnerabilities is the easy part. The question is which twenty matter, and who fixes them. - 15 products compared - Guide: https://www.thetechbag.com/browse/security/vulnerability-management - Boundary terms resolved: Vulnerability scanning · Exposure management · Penetration testing (VAPT) · Breach & attack simulation (BAS) ### SIEM & Log Management SIEM pricing is a data problem, not a software problem. The licence is the small number. - 30 products compared - Guide: https://www.thetechbag.com/browse/security/siem-log-management - Boundary terms resolved: Log management · SIEM · XDR · SOAR ### Cloud & Workload Security An agent on a laptop and an agent on a container are not the same problem. Most endpoint vendors sell you the former and call it cloud security. - 16 products compared - Guide: https://www.thetechbag.com/browse/security/cloud-workload-security - Boundary terms resolved: CSPM — Cloud Security Posture Management · CWPP — Cloud Workload Protection Platform · CIEM — Cloud Infrastructure Entitlement Management · CNAPP — Cloud-Native Application Protection Platform --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/security* --- # Every product here backs things up. What separates them is the day you actually need a restore — at volume, under pressure. *Backup & Recovery — a TechBag decision guide. Last reviewed 2026-09-07.* > A backup product is four decisions: what it can protect, where it runs, how fast and how granular the restore is, and what unit it bills by. Vendors compete on the first; buyers suffer on the third and fourth. **The checkable fact:** Commvault publishes a SaaS list of $58.50–90 per TB per month. Veeam is reported at $250–450 per workload per year. Neither number includes the storage the backups sit on — and that is frequently the larger bill. - Canonical: https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery - Category: [Backup & Cyber Resilience](https://www.thetechbag.com/browse/backup-cyber-resilience) - Products compared: 16 ## What backup & recovery actually is A product that copies your workloads — VMs, physical servers, databases, file shares, cloud instances, laptops — on a schedule, keeps the copies for a retention period, and can put them back: one file, one mailbox, a whole VM booted straight from the backup, or a thousand VMs in an afternoon. The copying is table stakes. **The restore is the product.** Four things decide the purchase. **What it can protect** — the workload list varies more than you expect (Kubernetes, NAS at scale, Proxmox, endpoints). **Where it runs** — software you install, an appliance you rack, or a service with nothing to run. **Restore granularity and speed** — item-level, full VM, or instant recovery that boots from the repository. **The meter** — per workload, per TB front-end, per TB after dedupe, per socket, per device. SaaS data (Microsoft 365, Google Workspace, Salesforce) is its own purchase: the [SaaS backup guide](https://www.thetechbag.com/browse/backup-cyber-resilience/saas-backup). **The most common mis-purchase.** A backup that succeeds every night and a restore that fails the first time it is needed — because nobody tested it at volume, over the real network, from the real repository. **Buy the restore you have rehearsed, not the backup you have scheduled.** ## Backup vs replication vs snapshot vs archive Four words sold by the same vendors and used as if they were tiers. They are not. Each answers a different failure mode — and a tool that handles one perfectly may be useless against another. ### Backup An independent copy, on different storage, kept for a retention period, restorable to a point in time. Answers: something was lost, corrupted or deleted — days or months ago — and you need that version back. Slow relative to the others; the only one that survives the loss of the source system and its storage. ### Replication A continuously updated second copy of a running system, ready to take over. Answers: the site or the server is down and you need to run elsewhere in minutes. Faithfully replicates corruption, deletion and ransomware — which is why it is the disaster-recovery guide, not this one. ### Snapshot A point-in-time image held on the same storage as the source (hypervisor or array). Answers: roll back a change made an hour ago. Fast and cheap — and gone with the storage it lives on. A snapshot is not a backup, and every backup vendor's first slide says so. ### Archive Data moved (not copied) to cheaper storage for retention and compliance, with an index. Answers: keep it for seven years and find it for the regulator. An archive is the only copy; it is not a recovery mechanism for the live system. **These are not tiers of the same product.** Snapshots roll back, replication fails over, backup restores, archive retains. A product that handles accidental deletion perfectly can be useless against deliberate destruction — that sentence is the whole [cyber-recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery). Most estates need at least two of the four; almost none need all four from one vendor. ## The decision variables Six variables decide this purchase. The instrument tests the ones documentation can verify (workloads, delivery form, instant recovery, hypervisor, meter); restore speed at scale and immutability mode are prose because the honest answers are a PoC figure and a configuration, not a datasheet line. **What it can protect.** Physical, virtual, cloud, SaaS, containers, databases, NAS, endpoints — the list varies more than the brochures admit. Write yours down first, including the workload you forgot (the NAS, the cluster, the database on the old box). **Deployment model.** Software you install (you design the repository), an appliance you rack (capacity is in the price), a service with nothing to run (restore speed is your WAN), or cloud-managed agents through a partner. **Restore granularity and speed at scale.** Item-level vs full VM vs instant recovery that boots from the backup — and then the number nobody publishes: VMs per hour over your network. The real differentiator, and the one to test. **Licensing unit.** Per VM or workload, per TB front-end, per TB back-end, per TB deduplicated, per socket, per device, per GiB-month. The same estate can cost 3× more or less on unit choice alone. **India data residency for backup copies.** SaaS services with a documented Mumbai / Central India region (Druva, Commvault Cloud, Acronis), or your own storage where residency is your design; flagged where not documented. **Integration with the hypervisor and storage you have.** VMware and Hyper-V are universal; Nutanix AHV and Proxmox are not; storage-array snapshot integration decides backup windows at scale. ## The 16 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### N-able Cove Data Protection — N-able - **Who it's for:** MSPs backing up many small client sites who do not want a hardware conversation at each one. Cloud-first by design: no appliance to buy, size, rack, refresh — or lose alongside the site it protected. Servers, workstations and Microsoft 365 in one product and one dashboard, with DR and DRaaS alongside. - **The honest limitation:** Restore speed follows BANDWIDTH rather than local disk — that is the honest cost of having no appliance, and it is entirely testable in a trial. Model a full-site restore against your largest client's data volume and connection, then compare it to the recovery time your contracts promise. If fast local recovery of very large datasets is the binding constraint, an appliance model still wins that race. No documented India backup region — and a backup is a complete copy of everything, so establish the storage region in writing. - **Price:** Quote — Quote-only, and a separate product from N-able's RMM platforms. For backup the GROWTH terms matter more than the rate — how storage is charged as data accumulates, whether it is metered or capped, and what retention beyond the standard window costs. Model your data at three years, not today - **Details:** https://www.thetechbag.com/n-able/n-able-cove-data-protection ### Veeam Data Platform (Foundation · Advanced · Premium) — Veeam - **Who it's for:** The default for VMware and Hyper-V estates that want instant VM recovery, replication and a repository design they control — and now Nutanix AHV and Proxmox on the same licence. - **The honest limitation:** Software you run: the repository, its hardening and the immutability mode are your design, not a default; Kubernetes is a separate product (Kasten) and SaaS is Veeam Data Cloud; no published list price. - **Price:** ~$250–450 (≈ ₹20,750) — per workload (VUL) / year reported, by edition; list rose 4–8% in January 2026; storage is yours - **Details:** https://www.thetechbag.com/veeam/veeam-data-platform ### Veeam Kasten for Kubernetes — Veeam - **Who it's for:** Platform teams that need application-consistent backup, restore and mobility for Kubernetes namespaces — not a VM tool pointed at a cluster. - **The honest limitation:** Kubernetes only — it protects nothing outside the cluster; priced per node on quote; immutability is whatever object-lock target you export to. - **Price:** Quote — per worker node / year; Enterprise edition; free edition for small clusters - **Details:** https://www.thetechbag.com/veeam/veeam-kasten ### Veeam Backup for AWS · Azure · Google Cloud — Veeam - **Who it's for:** Estates on Veeam that also run EC2, RDS, Azure VMs or GCE and want native snapshots plus cost-tiered backup under the same console. - **The honest limitation:** Cloud-native workloads only, one appliance per cloud; the object-lock bucket and its mode are yours to configure; not a replacement for the on-prem product. - **Price:** VUL / marketplace — a Veeam Universal Licence per cloud instance, or per-instance marketplace billing; runs inside your cloud account - **Details:** https://www.thetechbag.com/veeam/veeam-public-cloud ### Commvault Cloud Backup & Recovery — Commvault - **Who it's for:** Mixed enterprises with the widest workload list — VMs, databases, NAS, Kubernetes, endpoints, cloud — that want one catalogue and a choice of software, appliance or SaaS. - **The honest limitation:** Breadth is the product and the learning curve: a Commvault estate needs a Commvault administrator; the SaaS list is per TB and the on-prem price is a quote; the immutability mechanism depends on the target you choose. - **Price:** $58.50–90 (≈ ₹4,856) — per TB / month SaaS list (VMs and Kubernetes → databases); on-prem by front-end TB on quote; HyperScale X appliance; SaaS available in India - **Details:** https://www.thetechbag.com/commvault/commvault-backup-recovery ### Commvault Clumio (AWS) — Commvault - **Who it's for:** AWS-first estates that want EC2, EBS, RDS, S3 and DynamoDB backed up outside their own account, with a published per-GiB meter instead of a licence. - **The honest limitation:** AWS only; the meter is gentle at rest and real at restore time (per GiB restored plus transfer); an India region for the vault is not documented. - **Price:** $0.012 (≈ ₹1) — per GiB-month of protected data, published; restores $0.08 per GiB plus AWS transfer; nothing to deploy - **Details:** https://www.thetechbag.com/commvault/commvault-clumio ### Cohesity DataProtect — Cohesity - **Who it's for:** Enterprises that want scale-out appliances with instant mass restore and one platform that also runs cyber vaulting (FortKnox) and search over the backups. - **The honest limitation:** Capacity-tiered reported pricing, no published list; the appliance form carries the platform's value — the software-only and BaaS forms are narrower; an India BaaS region is not documented. - **Price:** ~$150–400 (≈ ₹12,450) — per TB / year reported (licence, capacity-tiered); as-a-service $200–500+ per TB / year reported; appliance, software or BaaS - **Details:** https://www.thetechbag.com/cohesity/cohesity-dataprotect ### NetBackup (Cohesity) — Cohesity - **Who it's for:** Large, long-lived estates — mainframe to cloud — that already run NetBackup and want its workload list and operating model to continue under Cohesity. - **The honest limitation:** Enterprise-priced per front-end TB on quote; the heaviest operating model on this page; Proxmox support is not documented. - **Price:** ~$400–900 (≈ ₹33,200) — per front-end TB / year reported at enterprise tiers, declining with capacity; Flex appliances separate - **Details:** https://www.thetechbag.com/cohesity/cohesity-netbackup ### Rubrik Security Cloud — Enterprise Edition — Rubrik - **Who it's for:** Enterprises that want backup and cyber recovery as one posture — append-only storage, anomaly detection and threat containment on the same platform. - **The honest limitation:** Three-year, capacity-reviewed subscriptions with reported list around $130 per back-end TB per month — the most expensive meter here; an India data region is not documented. - **Price:** ~$130 (≈ ₹10,790) — per back-end TB / month reported (premium support, prepaid); three-year minimums typical; appliance, partner hardware or cloud cluster - **Details:** https://www.thetechbag.com/rubrik/rubrik-enterprise-edition ### Druva Hybrid Workloads — Druva - **Who it's for:** Teams that want data-centre backup with no backup server, no repository and no patching — a SaaS service with an India region and an India engineering base. - **The honest limitation:** No instant VM recovery from the cloud (restores and DRaaS instead); priced per deduplicated TB on quote; your data lives only in Druva's AWS — no on-prem copy. - **Price:** Quote — per TB / month after deduplication (Business · Enterprise · Elite); AWS Mumbai region; built in Pune — nothing to run - **Details:** https://www.thetechbag.com/druva/druva-hybrid-workloads ### Druva Cloud Workloads (AWS · Azure) — Druva - **Who it's for:** AWS and Azure estates that want snapshot orchestration, cross-account copies and Data Lock from the same SaaS console as the data centre. - **The honest limitation:** Native snapshots live in your account — your cloud root credential is the ceiling of their protection; cloud workloads only; quote-only. - **Price:** Quote — per protected resource / month; snapshots stay in your cloud account, air-gapped copies in Druva's - **Details:** https://www.thetechbag.com/druva/druva-cloud-workloads ### Druva Endpoints (inSync) — Druva - **Who it's for:** Laptop fleets that need silent, deduplicated backup with legal hold, eDiscovery and remote wipe — the endpoint half of Druva. - **The honest limitation:** Endpoints only — servers, VMs and SaaS are other Druva SKUs; reported pricing, not published; no on-prem copy. - **Price:** ~$3 (≈ ₹249) — per user / month reported (legacy inSync list; now Business · Enterprise · Elite per user); AWS Mumbai region - **Details:** https://www.thetechbag.com/druva/druva-endpoints ### Acronis Cyber Protect Cloud (backup) — Acronis - **Who it's for:** SMBs and MSP-run estates that want backup, anti-malware and patching in one agent, an India data centre and a per-workload or per-GB meter. - **The honest limitation:** Sold and billed through partners — no public rate card; petabyte-scale estates are not where it is documented; immutability in Acronis Cloud defaults to governance mode (an admin can lift it) unless compliance mode is switched on. - **Price:** ~$25 (≈ ₹2,075) — per workload / month reported (~$300 / year) or per GB, through partners; Acronis Cloud storage priced apart; Mumbai data centre - **Details:** https://www.thetechbag.com/acronis/acronis-cyber-protect-cloud ### Acronis Cyber Protect (on-prem) — Acronis - **Who it's for:** Organisations that want the Acronis agent and console on their own hardware — image backup, bare-metal restore and anti-malware without a partner in the loop. - **The honest limitation:** Your storage, your immutability target; a per-seat list that climbs quickly on servers and hosts; not documented at petabyte scale. - **Price:** ~$89+ (≈ ₹7,387) — per workstation / year list (Standard); servers and virtual hosts tiered higher; your storage - **Details:** https://www.thetechbag.com/acronis/acronis-cyber-protect ### Barracuda Backup (appliance · Vx · cloud) — Barracuda - **Who it's for:** Mid-market sites that want a backup appliance with LiveBoot recovery and a flat cloud replication price, sold through the channel. - **The honest limitation:** VMware and Hyper-V only on the hypervisor side; an India region for Barracuda Cloud backup storage is not documented; the appliance's local copies are not the immutable ones — the cloud copies are. - **Price:** $599 (≈ ₹49,717) — per socket or server / year list (Vx virtual appliance); hardware appliances from $17,698 list; replication to Barracuda Cloud $799 per TB / year - **Details:** https://www.thetechbag.com/barracuda/barracuda-data-protection ### NinjaOne Backup — NinjaOne - **Who it's for:** IT teams already on NinjaOne RMM that want endpoint and server backup from the same agent and console, with cloud copies locked by S3 Object Lock. - **The honest limitation:** No hypervisor-level VM backup, no databases, no NAS — it protects the devices the agent sits on; the local copy is not immutable, only the Ninja cloud copy; an India storage region is not documented. - **Price:** ~$1.50–3.75 (≈ ₹125) — per device / month reported, as an add-on to the RMM; image, file and folder backup for Windows, macOS and servers; Ninja cloud storage priced apart - **Details:** https://www.thetechbag.com/ninjaone/ninjaone-backup ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Virtual machines.** Rules out Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync) and NinjaOne Backup — does not protect virtual machines. That leaves N-able Cove Data Protection, Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Druva Hybrid Workloads, Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem) and Barracuda Backup (appliance · Vx · cloud). **Public-cloud workloads.** Rules out Veeam Kasten for Kubernetes, Druva Hybrid Workloads, Druva Endpoints (inSync), Acronis Cyber Protect (on-prem), Barracuda Backup (appliance · Vx · cloud) and NinjaOne Backup — does not protect public-cloud workloads. That leaves N-able Cove Data Protection, Veeam Data Platform (Foundation · Advanced · Premium), Veeam Backup for AWS · Azure · Google Cloud, Commvault Cloud Backup & Recovery, Commvault Clumio (AWS), Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Druva Cloud Workloads (AWS · Azure) and Acronis Cyber Protect Cloud (backup). **Databases.** Rules out N-able Cove Data Protection, Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync) and NinjaOne Backup — does not protect databases with application consistency. That leaves Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Druva Hybrid Workloads, Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem) and Barracuda Backup (appliance · Vx · cloud). **NAS and file shares.** Rules out N-able Cove Data Protection, Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync), Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem) and NinjaOne Backup — does not protect NAS / file shares. That leaves Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Druva Hybrid Workloads and Barracuda Backup (appliance · Vx · cloud). **Kubernetes.** Rules out N-able Cove Data Protection, Veeam Data Platform (Foundation · Advanced · Premium), Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Hybrid Workloads, Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync), Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem), Barracuda Backup (appliance · Vx · cloud) and NinjaOne Backup — does not protect Kubernetes. That leaves Veeam Kasten for Kubernetes, Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity) and Rubrik Security Cloud — Enterprise Edition. **Laptops and desktops.** Rules out Veeam Data Platform (Foundation · Advanced · Premium), Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Druva Hybrid Workloads, Druva Cloud Workloads (AWS · Azure) and Barracuda Backup (appliance · Vx · cloud) — does not protect endpoints. That leaves N-able Cove Data Protection, Commvault Cloud Backup & Recovery, Druva Endpoints (inSync), Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem) and NinjaOne Backup. **Backup as a service.** Rules out Veeam Data Platform (Foundation · Advanced · Premium), Veeam Kasten for Kubernetes, Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Acronis Cyber Protect (on-prem) and Barracuda Backup (appliance · Vx · cloud) — you run the backup server, repository or appliance. That leaves N-able Cove Data Protection, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Hybrid Workloads, Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync), Acronis Cyber Protect Cloud (backup) and NinjaOne Backup. **An appliance.** Rules out N-able Cove Data Protection, Veeam Data Platform (Foundation · Advanced · Premium), Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Hybrid Workloads, Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync), Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem) and NinjaOne Backup — software or a service, not an appliance. That leaves Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition and Barracuda Backup (appliance · Vx · cloud). It flags Commvault Cloud Backup & Recovery — Software first; also sold as an appliance (HyperScale X / Flex) and NetBackup (Cohesity) — Software first; also sold as an appliance (HyperScale X / Flex) — marked, not removed. **Software on your hardware.** Rules out N-able Cove Data Protection, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Cohesity DataProtect, Rubrik Security Cloud — Enterprise Edition, Druva Hybrid Workloads, Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync), Acronis Cyber Protect Cloud (backup), Barracuda Backup (appliance · Vx · cloud) and NinjaOne Backup — an appliance or a service, not software you install. That leaves Veeam Data Platform (Foundation · Advanced · Premium), Veeam Kasten for Kubernetes, Commvault Cloud Backup & Recovery, NetBackup (Cohesity) and Acronis Cyber Protect (on-prem). **Instant recovery.** Rules out N-able Cove Data Protection, Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Hybrid Workloads, Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync) and NinjaOne Backup — no documented instant recovery; restores copy data back first. That leaves Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem) and Barracuda Backup (appliance · Vx · cloud). **Nutanix AHV.** Rules out N-able Cove Data Protection, Acronis Cyber Protect (on-prem) and Barracuda Backup (appliance · Vx · cloud) — Nutanix AHV not documented; Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync) and NinjaOne Backup — does not protect virtual machines. That leaves Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Druva Hybrid Workloads and Acronis Cyber Protect Cloud (backup). **Proxmox VE.** Rules out N-able Cove Data Protection, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition, Druva Hybrid Workloads and Barracuda Backup (appliance · Vx · cloud) — Proxmox VE not documented; Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync) and NinjaOne Backup — does not protect virtual machines. That leaves Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Acronis Cyber Protect Cloud (backup) and Acronis Cyber Protect (on-prem). **Copies in India.** Rules nothing out on published terms. It flags N-able Cove Data Protection — India region for the service's storage not documented, Veeam Data Platform (Foundation · Advanced · Premium) — Your storage, Veeam Kasten for Kubernetes — Your storage, Veeam Backup for AWS · Azure · Google Cloud — Your storage, Commvault Clumio (AWS) — India region for the service's storage not documented, Cohesity DataProtect — India region for the service's storage not documented, NetBackup (Cohesity) — Your storage, Rubrik Security Cloud — Enterprise Edition — India region for the service's storage not documented, Acronis Cyber Protect (on-prem) — Your storage, Barracuda Backup (appliance · Vx · cloud) — India region for the service's storage not documented and NinjaOne Backup — India region for the service's storage not documented — marked, not removed. **Per workload, not per TB.** Rules out Commvault Cloud Backup & Recovery, Cohesity DataProtect, NetBackup (Cohesity), Rubrik Security Cloud — Enterprise Edition and Druva Hybrid Workloads — priced per TB (front-end or deduplicated). That leaves N-able Cove Data Protection, Veeam Data Platform (Foundation · Advanced · Premium), Veeam Kasten for Kubernetes, Veeam Backup for AWS · Azure · Google Cloud, Commvault Clumio (AWS), Druva Cloud Workloads (AWS · Azure), Druva Endpoints (inSync), Acronis Cyber Protect Cloud (backup), Acronis Cyber Protect (on-prem), Barracuda Backup (appliance · Vx · cloud) and NinjaOne Backup. **Above a petabyte.** Rules nothing out on published terms. It flags N-able Cove Data Protection — Unverified at petabyte scale, Acronis Cyber Protect Cloud (backup) — Unverified at petabyte scale, Acronis Cyber Protect (on-prem) — Unverified at petabyte scale, Barracuda Backup (appliance · Vx · cloud) — Unverified at petabyte scale and NinjaOne Backup — Unverified at petabyte scale — marked, not removed. **Restore speed at scale.** Instant recovery is documented for Veeam, Commvault, Cohesity, NetBackup, Rubrik, Acronis and Barracuda — booting or mounting from the backup. What no datasheet documents is the number that matters: how many VMs per hour come back over your network from your repository. That is a PoC figure; TechBag's delivery figures per platform are [TechBag to confirm]. **Where immutability is enforced.** Three patterns on this page. Target-enforced (Veeam, Commvault, NetBackup, Acronis on-prem, Kasten, Veeam public cloud): the product writes to object lock, a hardened repository or WORM hardware that you configure — as strong as your configuration. Vendor-controlled (Druva, Clumio, Acronis Cloud, Barracuda Cloud, NinjaOne cloud): the service's storage, locked by the vendor — read the mode (governance vs compliance). Software-enforced on the platform (Cohesity DataLock, Rubrik's append-only filesystem with Retention Lock). The cyber-recovery guide tabulates this per SKU; here it is a note because every product on this page can be made immutable — and most are not, by default. **Licensing units.** Per workload (Veeam VUL, Acronis), per TB front-end (Commvault on-prem, NetBackup), per TB back-end per month (Rubrik), per TB after deduplication (Druva), per socket (Barracuda Vx), per device (NinjaOne), per GiB-month (Clumio), per node (Kasten). The same estate can cost 3× more or less depending only on which unit the vendor chose — model your own VM count, front-end TB and growth before comparing quotes. **Storage is not in the licence.** Every line on this page excludes the storage the backups sit on — appliance capacity, object storage, cloud tiers, a second copy off-site. It is frequently larger than the licence (see the cost section). Druva, Clumio and Acronis Cloud bundle or meter storage differently; ask which. **Under 10 TB.** Rules nothing out on documentation: Acronis, NinjaOne, Barracuda Vx and Veeam Community / Foundation are sold to small estates; Commvault, Cohesity, Rubrik and NetBackup are enterprise-positioned but publish no floor. Which ones are a poor fit below 10 TB is delivery judgement: [TechBag to confirm]. ## Eight situations, eight shortlists — with the restore named Each shortlist names what the restore will look like in that estate, not only which products back it up. If your hypervisor is changing, start from that row. ### VMware or Hyper-V, 50–500 VMs, one or two sites — the common case **Shortlist:** Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Acronis Cyber Protect Cloud (backup) **Why:** Veeam is the default for this estate — instant VM recovery, replication and a repository you design; Commvault Cloud covers the same VMs with SaaS or software and a wider catalogue; Acronis brings the agent with backup and security in one, through a partner, with a Mumbai data centre. **Trade-off:** Veeam makes you the storage architect; Commvault makes you learn Commvault; Acronis makes you pick a partner. ### Leaving VMware for Nutanix AHV or Proxmox **Shortlist:** Veeam Data Platform (Foundation · Advanced · Premium), Commvault Cloud Backup & Recovery, Cohesity DataProtect **Why:** Veeam and Commvault document both AHV and Proxmox; Cohesity documents AHV. The backup product is the one thing that should not also change mid-migration. **Trade-off:** Proxmox support is newer everywhere — test the restore, not the backup, on the new hypervisor before the cut-over. ### Nothing to run — no backup server, no repository, no patching **Shortlist:** Druva Hybrid Workloads, Commvault Cloud Backup & Recovery, Acronis Cyber Protect Cloud (backup) **Why:** Druva is SaaS-only with an AWS Mumbai region and a Pune engineering base; Commvault Cloud's SaaS form is available in India; Acronis runs from its Mumbai data centre through partners. **Trade-off:** No local copy means restore speed is your internet line — size the WAN before the contract; instant VM recovery is not what SaaS backup does. ### An enterprise appliance with instant mass restore **Shortlist:** Cohesity DataProtect, Rubrik Security Cloud — Enterprise Edition, Barracuda Backup (appliance · Vx · cloud) **Why:** Cohesity's scale-out appliances document instant mass restore; Rubrik's appliances document Live Mount on append-only storage; Barracuda's appliances document LiveBoot with a flat cloud price for the smaller estate. **Trade-off:** Appliances bundle capacity into the price — you buy the next shelf, not the next TB; three-year terms (Rubrik) and capacity tiers (Cohesity) are the real negotiation. ### AWS-heavy estate — EC2, RDS, S3 are most of the data **Shortlist:** Commvault Clumio (AWS), Veeam Backup for AWS · Azure · Google Cloud, Druva Cloud Workloads (AWS · Azure) **Why:** Clumio backs up outside your account on a published per-GiB meter; Veeam Backup for AWS runs inside your account on VUL or marketplace billing; Druva orchestrates snapshots and air-gapped copies from the same console as the data centre. **Trade-off:** Native snapshots in your own account are only as safe as your root credential; an outside-the-account copy costs at restore time (per GiB and transfer). ### Kubernetes is production now **Shortlist:** Veeam Kasten for Kubernetes, Commvault Cloud Backup & Recovery, Cohesity DataProtect **Why:** Kasten is built for namespaces and application consistency; Commvault and Cohesity protect Kubernetes inside the same platform as the VMs. **Trade-off:** A Kubernetes-native tool is a second backup product to run; the platform route is one product with shallower Kubernetes depth — decide which team owns the restore. ### MSP-run SMB — laptops, a few servers, no backup administrator **Shortlist:** Acronis Cyber Protect Cloud (backup), NinjaOne Backup, Barracuda Backup (appliance · Vx · cloud) **Why:** Acronis and NinjaOne are the agent-based, RMM-adjacent options priced per workload or device through partners; Barracuda Vx puts an appliance in the rack at $599 per socket per year list. **Trade-off:** Device-level backup does not protect the hypervisor layer; if a host dies, you rebuild and restore guests one by one. ### Large estate already on NetBackup or Commvault **Shortlist:** NetBackup (Cohesity), Commvault Cloud Backup & Recovery, Rubrik Security Cloud — Enterprise Edition **Why:** NetBackup continues under Cohesity with its workload list intact; Commvault is the like-for-like alternative with the widest catalogue; Rubrik is the posture-led replacement when cyber recovery is the reason to move. **Trade-off:** Switching at this size is a retention-tail project: the old product stays read-only until its last backup expires. Price the overlap. ## At scale Backup scales by data volume and by the number of things to protect — and the two meters diverge exactly here. The bill follows the unit; the backup window follows the network. ### 10 TB TB front-end — The agent and the admin are the constraint - Any product here protects it; the question is who runs it — Acronis, NinjaOne and Barracuda Vx are built for the estate with no backup administrator. - A single repository or a SaaS target is enough; instant recovery is a convenience, not a requirement. - Per-device and per-workload meters are cheapest at this size. **The test:** Restore one full VM to a different host and time it. If nobody has ever done it, that is the finding. ### 100 TB TB front-end — The repository and the meter are the constraint - Backup windows start to depend on storage-snapshot integration and changed-block tracking — VMware and Hyper-V are universal, AHV and Proxmox are not. - The licence unit flips: per-TB products overtake per-workload ones if VMs are large; model both. - A second, immutable copy off-site becomes a line item larger than the licence — object storage at $14–24 per TB per month. **The test:** Ask for the dedupe ratio on your data, not the datasheet's, and the VMs-per-hour restore figure from a reference at your size. ### 1 PB TB front-end — Mass restore and the operating model are the constraint - Scale-out appliances (Cohesity, Rubrik) and enterprise software (NetBackup, Commvault) document petabyte estates; Acronis, NinjaOne, Barracuda and Druva Endpoints are flagged unverified here, not ruled out. - Restore orchestration — boot order, dependencies, hundreds of VMs — is the difference between a bad week and a bad quarter. - Capacity-tiered subscriptions and three-year terms are the negotiation; the list price is a starting point nobody pays. **The test:** Run a mass-restore rehearsal of 50 VMs from the immutable copy. The hours it takes is the only number the board should hear. Veeam, Commvault, Cohesity, NetBackup, Rubrik, Clumio and Druva’s data-centre products document petabyte estates; Acronis, NinjaOne, Barracuda and Druva Endpoints are flagged unverified at that size. Where a specific product strains for your estate: [TechBag to confirm]. ## Leaving a backup product is a retention-tail project Backup formats are proprietary. Switching does not migrate the old backups — it leaves them behind, readable only by the old product, until the last one expires. **The retention tail** — Every backup taken by the old product stays in its format. Keep the old product licensed (or at least installed and read-only) until the longest retention expires — seven years for some regulated data. *(Overlap for the retention period)* **Re-seeding** — The new product takes a full first backup of everything: the network and the repository feel it. Plan a seeding window; for SaaS targets, plan the WAN. *(First full backup, again)* **Agents and plugins** — Application agents (databases, Exchange, SAP) are per product and must be replaced and re-tested for consistency; hypervisor integration is re-done per host. *(Re-deploy, re-test)* **The immutable copy** — If the old product's immutable copy was the ransomware plan, it stops being refreshed on day one of the switch. The new product's immutable copy must exist before the old one is the only one. *(No gap in immutability)* **Retention tail, seeding weeks and overlap cost for your estate:** [TechBag to confirm] — TechBag scopes it from your retention policies and data volume. ## Per workload or per TB — and then the storage What you may already hold, the products priced on their own meters at three estate sizes in USD and INR, and what the licence line leaves out — which, for backup, starts with the storage the backups sit on. ### Do you already own one? Four places a backup may already seem to exist. Only one is. - **Hypervisor-native snapshots — No.** A snapshot lives on the same storage as the VM and dies with it. Useful for rollback; not a backup, not retention, not a restore from another site. - **Storage-array replication — No.** A second array that faithfully replicates corruption, deletion and encryption. That is disaster recovery’s half, not backup’s — and only if the array is elsewhere. - **Your cloud provider's backup service — Partly.** AWS Backup and Azure Backup are real backup for their own cloud, with vault lock / immutable vault. They do not reach your data centre or each other; a multi-cloud estate needs one catalogue. - **Backup inside the RMM you run — Partly.** NinjaOne Backup and Acronis through an MSP protect the devices the agent sits on — servers and laptops — not the hypervisor, the database or the NAS. If a copy you already pay for is enough for your failure modes, we say so. It costs us a sale and saves you one. ### What the rest actually cost Published and reported meters (INR for scale), then worked at three estate sizes — each product on its own unit, so the grid shows what the unit does to the bill. Storage is a separate block below it, on purpose. ### What isn't in the licence price - **The storage.** Object storage, appliance capacity, a second copy off-site — see the block above. At 100 TB the second copy alone is $16800 ≈ ₹13,94,400–$28800 ≈ ₹23,90,400 a year at vault list prices, before the hardware under the first. - **Egress and restore fees.** Per-GiB restore charges (Clumio $0.08), hyperscaler transfer out, and the WAN upgrade a SaaS restore turns out to need. Price a full 10 TB restore, not a file. - **Restore testing, in hours.** A quarterly full-VM restore, an annual mass-restore rehearsal, and a person to own the results. Vendors automate verification (Veeam SureBackup, Commvault, Cohesity, Rubrik); the rehearsal is still yours. Your hours: [TechBag to confirm]. ## What goes wrong Documented behaviour and cost curves, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover on the day. - **Backups that succeed and restores that fail.** Green dashboard every night; the first real restore hits a corrupt chain, a missing agent or an untested application-consistency step. Nobody had restored at volume. Rehearse it. - **Per-TB pricing scaling in a way nobody modelled.** Front-end TB grew 40% a year; the licence followed; the budget did not. Model the meter on your growth curve to year three before signing. - **Agent coverage gaps on the one workload that mattered.** The NAS, the old database server, the Proxmox cluster — outside the product's list or never licensed. Write the workload list down, including the one you forgot. - **Restore times that meet the SLA on paper and not on the network.** Instant recovery boots the VM; full performance waits on data migrating over a 1 Gbps link from a repository built for writes. Measure VMs per hour, not seconds to boot. - **Backup windows that stop fitting.** Full backups that used to finish by 6am now run into the working day — no storage-snapshot integration, no changed-block tracking on the new hypervisor. The window is a design, not a setting. - **Storage larger than the licence, discovered at renewal.** The licence was negotiated hard; the object storage, the second appliance shelf and the egress were not in the business case. They were most of the bill. - **A snapshot mistaken for a backup.** The array died, or the hypervisor datastore was encrypted — and every snapshot went with it. Snapshots roll back; they do not restore from elsewhere. - **Immutability assumed, never enabled.** The product supported object lock; the bucket was created without it. Support is not a default — the cyber-recovery guide is the checklist. ## Questions this guide answers ### What is the difference between backup, replication, a snapshot and an archive? Backup is an independent copy on different storage, kept for a retention period and restorable to a point in time — it survives the loss of the source. Replication is a continuously updated second copy of a running system for fast failover — it faithfully copies corruption and ransomware too. A snapshot is a point-in-time image on the same storage as the source — fast rollback, gone with the storage. An archive moves data to cheaper indexed storage for retention — it is the only copy, not a recovery mechanism. They answer different failure modes and are not tiers of one product. ### Per workload or per TB — which backup licensing is cheaper? It depends only on your estate's shape. Per workload (Veeam VUL, Acronis) is cheap for few large VMs and expensive for hundreds of small ones; per front-end TB (Commvault on-prem, NetBackup) is the reverse and grows with data regardless of VM count; per back-end or deduplicated TB (Rubrik, Druva) rewards compressible data. Model your own VM count, front-end TB and three-year growth on every unit before reading a quote — and add storage, which is priced apart from the licence everywhere. ### Which backup products keep copies in India? Druva (AWS Mumbai region, engineering in Pune), Commvault Cloud's SaaS form (available in India) and Acronis Cyber Protect Cloud (Mumbai data centre) document India-resident copies. Veeam, NetBackup, Kasten and Acronis on-prem are software — residency is your storage design. Cohesity's BaaS, Rubrik, Clumio, Barracuda Cloud and NinjaOne cloud storage do not document an India region; the guide flags them rather than ruling them out. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery* --- # Microsoft’s shared-responsibility model says they keep the service running. Securing your data is explicitly your job. *SaaS Backup — a TechBag decision guide. Last reviewed 2026-09-07.* > A SaaS backup product copies your Microsoft 365, Google Workspace, Salesforce or Entra ID data out of the platform on a schedule and can put it back — an item, a mailbox, a site, an org’s metadata — after the recycle bin and the retention window have passed, or after an admin or an attacker emptied them. **The checkable fact:** Microsoft’s own Service Agreement recommends third-party backup. Commvault publishes $1.70–4.50 per user per month; Barracuda $3.40 with unlimited storage. Microsoft’s native Microsoft 365 Backup is $0.15 per GB per month — real backup, inside the same tenant. - Canonical: https://www.thetechbag.com/browse/backup-cyber-resilience/saas-backup - Category: [Backup & Cyber Resilience](https://www.thetechbag.com/browse/backup-cyber-resilience) - Products compared: 11 ## What saas backup actually is Your mail, files, chats, CRM records and directory live in someone else’s cloud. That vendor promises uptime, redundancy and security of the service — and in the same contract says that **the data is yours to protect**. A SaaS backup product takes an independent copy out of the platform every day, keeps it for as long as you decide, and restores it in place: one item, one mailbox, one SharePoint site, one Salesforce object’s metadata, one Entra ID group with its members and policies. Four things decide the purchase. **Which platforms are covered at depth** — Microsoft 365 beyond mail, Google Workspace, Salesforce with metadata, Dynamics, and Entra ID, which almost nobody offers and everyone needs. **Restore granularity** — in-place restore versus export. **Where the copy lives** — vendor storage, your storage, and whether India is documented. **Seat behaviour** — what a dormant or departed user costs. The data-centre half of this decision is the [backup and recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery); the directory, when it is the incident, is on both. **The most common mis-purchase.** Assuming a retention policy is a backup. Retention keeps what exists from being deleted before a date; it does not give you back a mailbox an admin purged, a site an attacker encrypted, or the tenant’s state as of last Tuesday. **Governance control, not recovery control.** ## Recycle bin vs native retention vs true backup — and the shared-responsibility model Four things that get called “backup” in a Microsoft 365 or Google Workspace tenant. They answer different failure modes; only one of them is an independent copy. ### Recycle bin and versioning Deleted items wait 30–93 days (platform and workload dependent) and files keep versions. Answers: a user deleted something last week. Fails: an admin emptied it, a retention window passed, an attacker encrypted the versions too, or the account itself is gone. ### Native retention policies Microsoft Purview retention, Google Vault holds. Keep content from being destroyed until a date, for compliance. Answers: the regulator asks for this in three years. Fails: point-in-time restore of a mailbox or site, bulk recovery after ransomware, anything after the policy ends — Google states Vault is not a backup; Microsoft recommends third-party backup. ### True backup An independent, scheduled copy held outside the production tenant (or in a separate, locked store), restorable in place to a point in time — item, mailbox, site, org, directory. Answers: it is gone, or corrupted, or encrypted, and you need last Tuesday back. Microsoft's own Microsoft 365 Backup ($0.15 per GB per month) is real backup too — inside the same tenant. ### The shared-responsibility model The platform vendor is responsible for the service — uptime, infrastructure, security of the platform. You are responsible for the data — access, retention, backup, recovery. Microsoft's Service Agreement says it in plain words. Answers: whose fault is it? Yours, contractually, unless you bought the copy. **These are not tiers of the same product.** The recycle bin rolls back a mistake; retention satisfies a regulator; backup restores after loss; the shared-responsibility model says who is holding the bag. A tenant with perfect retention and no backup handles accidental deletion and fails at deliberate destruction — which is the [cyber-recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery)’s subject. ## The decision variables Six variables decide this purchase. The instrument tests the ones documentation can verify (platforms and depth, Entra ID, Salesforce metadata, storage ownership and inclusion, India); restore granularity, leaver pricing and the Teams API are prose because the honest answer is a contract line or a configuration. **Which SaaS platforms are covered at depth.** Microsoft 365 (mail is easy; Teams, SharePoint and OneDrive are where products thin out), Google Workspace, Salesforce, Dynamics 365 and Entra ID are different engineering problems. A product that does one well may do another at export-only depth. **Retention period and the cost curve.** Unlimited retention at a flat price (Barracuda, AvePoint) versus storage metered or licensed separately (Rubrik, Cohesity's capacity option, Microsoft per GB). Retention is where seven-year mailboxes live. **Restore granularity.** Item, mailbox, site, channel, org metadata — restored in place, or exported to a file you then re-import. Export-only is the tell. **Where the backup is stored and India residency.** Vendor-held (most), your own storage (Veeam self-hosted, Commvault and AvePoint bring-your-own, Cohesity on your cluster), and whether an India region is documented (Druva, Barracuda, Commvault, Acronis, Veeam). **Entra ID / directory object backup.** Users, groups, roles, conditional-access policies and app registrations — the blast radius of a compromised admin. Offered by few; needed by everyone; sometimes a separate SKU. **Seat-based pricing with dormant and departed users.** Per-user pricing meets seven-year retention when a leaver's mailbox must be kept. Capacity pricing (Cohesity) and unlimited-storage models (AvePoint, Barracuda) answer it differently; the rest is contract language. ## The 11 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium) — Veeam - **Who it's for:** Microsoft 365 tenants that want the most-deployed M365 backup engine either as Veeam-hosted SaaS with storage included or self-hosted on storage they own. - **The honest limitation:** Microsoft 365 only in this SKU (Salesforce and Entra ID are siblings — Entra ID also listed at $14.10 per user per year); Google Workspace is not offered; Premium is the tier with unthrottled restore. - **Price:** $2.63–3.50 (≈ ₹218) — per user / month Foundation list by volume (251+ → 10–50 users); Advanced adds Entra ID; Central India Azure region; self-hosted Veeam Backup for Microsoft 365 is the bring-your-own-storage form - **Details:** https://www.thetechbag.com/veeam/veeam-microsoft-365 ### Veeam Backup for Salesforce — Veeam - **Who it's for:** Salesforce estates that want records and metadata backed up into storage they control, with compare-and-restore into the org and sandbox seeding. - **The honest limitation:** Salesforce only; you run the server and own the database; quote-only — and immutability is whatever your storage enforces. - **Price:** Quote — per Salesforce user / year; software you deploy (Linux + PostgreSQL) in your own cloud or data centre — the data never leaves your storage - **Details:** https://www.thetechbag.com/veeam/veeam-salesforce ### Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce) — Commvault - **Who it's for:** Organisations that want Microsoft 365, Dynamics 365 and Salesforce backed up by the same platform that protects the data centre — with a published list price and included immutable storage. - **The honest limitation:** Entra ID is a sibling SKU (Backup for Active Directory & Entra ID), not this one; Google Workspace is not offered; the lowest list tier is mail-centric — read which workloads each tier includes. - **Price:** $1.70–4.50 (≈ ₹141) — per user / month published list for Microsoft 365 by tier; Salesforce $3.60 per user / month; Azure storage (Air Gap Protect) included; SaaS available in India; bring-your-own storage optional - **Details:** https://www.thetechbag.com/commvault/commvault-saas-backup ### Commvault Cloud Backup for Active Directory & Entra ID — Commvault - **Who it's for:** Estates where the directory is the blast radius: Entra ID and Active Directory objects backed up, compared and restored — including a full forest rebuild. - **The honest limitation:** Identity only — mail, files and Teams are the sibling SaaS SKU; quote-only; Okta is not in this product. - **Price:** Quote — per user / object, on quote; on-prem AD forest recovery and Entra ID objects, attributes, groups, roles and policies - **Details:** https://www.thetechbag.com/commvault/commvault-active-directory ### Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce) — Druva - **Who it's for:** Organisations on Microsoft 365 or Google Workspace — often both — that want one SaaS console for mail, files, Teams, Drive and Salesforce with an India region and no infrastructure. - **The honest limitation:** Reported not published pricing; Dynamics 365 is not covered; Entra ID protection is a separate Identity Resilience SKU rather than in the per-user SaaS price; no bring-your-own storage. - **Price:** ~$3 (≈ ₹249) — per user / month reported (Microsoft 365 and Google Workspace; Salesforce ~$3.50 reported); AWS Mumbai region; Entra ID, AD and Okta are the separate Identity Resilience plans - **Details:** https://www.thetechbag.com/druva/druva-saas-apps ### AvePoint Cloud Backup — AvePoint - **Who it's for:** Estates with the widest SaaS surface — Microsoft 365, Entra ID, Dynamics 365, Power Platform, Google Workspace, Salesforce, Azure — that want one backup contract across all of it, with unlimited storage. - **The honest limitation:** Indicative partner pricing rather than a public list; an India data region is not documented; how immutability is enforced on the included storage is not established from documentation — marked unknown, not assumed. - **Price:** ~$2–3.50 (≈ ₹166) — per user / month indicative through partners (UK G-Cloud lists £1.50 per user / month for Microsoft 365); unlimited storage; bring-your-own Azure / AWS storage optional - **Details:** https://www.thetechbag.com/avepoint/avepoint-cloud-backup ### Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup — Acronis - **Who it's for:** MSP-run organisations that want Microsoft 365 and Google Workspace backup from the same partner, console and India data centre as their endpoint backup and security. - **The honest limitation:** Sold and priced through partners only; Salesforce and Dynamics are not covered; Entra ID object backup and whether storage is inside the per-seat price are not established from documentation — flagged, not assumed. - **Price:** ~$3–4 (≈ ₹249) — per seat / month through MSPs (agentless for Exchange, OneDrive, SharePoint, Teams, Gmail, Drive, Contacts, Calendar); Mumbai data centre - **Details:** https://www.thetechbag.com/acronis/acronis-cyber-protect-cloud ### Barracuda Cloud-to-Cloud Backup — Barracuda - **Who it's for:** Microsoft 365 tenants that want a flat per-user price with unlimited storage, Entra ID included, and the data held in India. - **The honest limitation:** Microsoft 365 only — no Google Workspace, Salesforce or Dynamics; storage is Barracuda's, with no bring-your-own option. - **Price:** $3.40 (≈ ₹282) — per user / month list; unlimited storage and retention; Exchange, OneDrive, SharePoint, Teams and Entra ID; India regional data centre (2022) - **Details:** https://www.thetechbag.com/barracuda/barracuda-data-protection ### Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition) — Rubrik - **Who it's for:** Enterprises already on Rubrik Security Cloud that want Microsoft 365 under the same posture — anomaly detection, sensitive-data discovery and threat hunting on the tenant's data. - **The honest limitation:** Backup storage is a separate licence on top of the per-user price; an India data region is not documented; Entra ID is a separate product. - **Price:** ~$3.80 (≈ ₹315) — per user / month Foundation list reported (premium support, prepaid) plus a backup-storage licence; Rubrik-hosted in Azure; Entra ID is the separate Identity Resilience product - **Details:** https://www.thetechbag.com/rubrik/rubrik-enterprise-edition ### Rubrik Identity Resilience (Entra ID · Active Directory · Okta) — Rubrik - **Who it's for:** Estates where a hijacked directory is the incident: Entra ID, AD and Okta objects backed up, compared, and restored object-by-object or as a forest. - **The honest limitation:** Identity only; quote-only; an India data region is not documented. - **Price:** Quote — per identity / year on quote; Entra ID, on-prem AD forest recovery and Okta objects with risk posture - **Details:** https://www.thetechbag.com/rubrik/rubrik-identity-resilience ### Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) — Cohesity - **Who it's for:** Cohesity estates that want Microsoft 365 in the same platform, with the option of capacity pricing instead of per user — which stops departed-user seats from costing anything. - **The honest limitation:** Quote-only; an India BaaS region and Entra ID coverage are not documented; how immutability is enforced on the BaaS storage is not established from documentation — marked unknown. - **Price:** Quote — per user / month or per TB of protected capacity (Cohesity documents ~6 GB per user on average); Exchange, OneDrive, SharePoint, Teams and Groups; Cohesity-managed cloud or your own cluster - **Details:** https://www.thetechbag.com/cohesity/cohesity-dataprotect ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Microsoft 365 beyond mail.** Rules out Veeam Backup for Salesforce, Commvault Cloud Backup for Active Directory & Entra ID and Rubrik Identity Resilience (Entra ID · Active Directory · Okta) — does not back up Microsoft 365. That leaves Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), AvePoint Cloud Backup, Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup, Barracuda Cloud-to-Cloud Backup, Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition) and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster). **Google Workspace.** Rules out Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Veeam Backup for Salesforce, Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Commvault Cloud Backup for Active Directory & Entra ID, Barracuda Cloud-to-Cloud Backup, Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition), Rubrik Identity Resilience (Entra ID · Active Directory · Okta) and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) — does not back up Google Workspace. That leaves Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), AvePoint Cloud Backup and Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup. **Salesforce with metadata.** Rules out Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Commvault Cloud Backup for Active Directory & Entra ID, Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup, Barracuda Cloud-to-Cloud Backup, Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition), Rubrik Identity Resilience (Entra ID · Active Directory · Okta) and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) — does not back up Salesforce. That leaves Veeam Backup for Salesforce, Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce) and AvePoint Cloud Backup. **Entra ID objects.** Rules out Veeam Backup for Salesforce, Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce) and Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition) — Entra ID objects not covered by this SKU. That leaves Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Commvault Cloud Backup for Active Directory & Entra ID, Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), AvePoint Cloud Backup, Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup, Barracuda Cloud-to-Cloud Backup, Rubrik Identity Resilience (Entra ID · Active Directory · Okta) and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster). It flags Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup — Entra ID object backup not documented for this product and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) — Entra ID object backup not documented for this product — marked, not removed. **Dynamics 365.** Rules out Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Veeam Backup for Salesforce, Commvault Cloud Backup for Active Directory & Entra ID, Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup, Barracuda Cloud-to-Cloud Backup, Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition), Rubrik Identity Resilience (Entra ID · Active Directory · Okta) and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) — does not back up Dynamics 365. That leaves Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce) and AvePoint Cloud Backup. **Storage you own.** Rules out Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup, Barracuda Cloud-to-Cloud Backup, Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition) and Rubrik Identity Resilience (Entra ID · Active Directory · Okta) — vendor-held storage only, no bring-your-own option. That leaves Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Veeam Backup for Salesforce, Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Commvault Cloud Backup for Active Directory & Entra ID, AvePoint Cloud Backup and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster). **Storage in the seat price.** Rules out Veeam Backup for Salesforce, Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition), Rubrik Identity Resilience (Entra ID · Active Directory · Okta) and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) — storage is licensed or metered apart from the per-user price. That leaves Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Commvault Cloud Backup for Active Directory & Entra ID, Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), AvePoint Cloud Backup, Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup and Barracuda Cloud-to-Cloud Backup. It flags Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup — Whether storage is inside the seat price is not documented — marked, not removed. **Backups in India.** Rules nothing out on published terms. It flags Veeam Backup for Salesforce — Your storage, AvePoint Cloud Backup — India data region not documented, Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition) — India data region not documented, Rubrik Identity Resilience (Entra ID · Active Directory · Okta) — India data region not documented and Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) — India data region not documented — marked, not removed. **Above 10,000 seats.** Rules nothing out on published terms. It flags Veeam Backup for Salesforce — Unverified above 10,000 seats, Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup — Unverified above 10,000 seats and Barracuda Cloud-to-Cloud Backup — Unverified above 10,000 seats — marked, not removed. **Dormant and departed users.** Every per-user product bills per protected user; what happens to a leaver whose mailbox you must keep for seven years is the question that doubles a bill. Cohesity's capacity option and AvePoint's and Barracuda's unlimited-storage models are documented answers from different directions; whether a product charges for an unlicensed, retained user is contract language at Veeam, Commvault, Druva, Acronis and Rubrik rather than a datasheet line — ask, in writing, before the price. **Teams private chats and the paid API.** Teams channel messages are in every product; private chats and meeting chats go through Microsoft's Teams Export APIs, which Microsoft meters. Whether a vendor includes that cost, passes it through or skips private chats is documented unevenly — confirm for the product you shortlist. **Restore granularity.** In-place restore of a mailbox, item, site or channel is documented across the Microsoft 365 products here; export-only restore is the tell of a cheap product. For Salesforce, restoring metadata (fields, page layouts, workflows) is a different capability from restoring records — Veeam, Commvault, Druva and AvePoint document both. **Immutability, per product.** Vendor-controlled immutable storage is documented for Veeam Data Cloud, Commvault (Air Gap Protect), Druva, Acronis Cloud (governance mode by default — compliance mode must be switched on), Barracuda and Rubrik's M365 service; Veeam Backup for Salesforce inherits whatever your storage enforces; AvePoint and Cohesity's BaaS are marked unknown because the mechanism is not established from documentation. **Under 50 seats.** Rules nothing out on documentation: Acronis, Barracuda, AvePoint, Veeam and Commvault all sell to small tenants; the floor is usually a minimum seat count or an annual minimum — [TechBag to confirm] for current minimums by product. ## Eight situations, eight shortlists — with the platform named Each shortlist names which platform the product covers at depth in that situation. If the directory is the worry, start from the second row. ### Microsoft 365 only, 100–2,000 seats — the cheapest honest list **Shortlist:** Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Barracuda Cloud-to-Cloud Backup, Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium) **Why:** Commvault publishes $1.70–4.50 per user per month with storage included and an India SaaS region; Barracuda lists $3.40 flat with unlimited storage, Entra ID and an India data centre; Veeam's Foundation lists $2.63–3.50 by volume from a Central India region. **Trade-off:** Read which workloads the lowest tier includes — the cheapest line is often mail-only — and ask what a departed user costs. ### Microsoft 365 and the directory — Entra ID must be restorable **Shortlist:** Barracuda Cloud-to-Cloud Backup, Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), AvePoint Cloud Backup, Commvault Cloud Backup for Active Directory & Entra ID **Why:** Barracuda includes Entra ID in the per-user price; Veeam's Advanced tier adds it (or $14.10 per user per year standalone); AvePoint covers it in the widest SaaS list; Commvault's Active Directory & Entra ID product restores objects and rebuilds a forest. **Trade-off:** Directory backup restores objects, attributes, groups and policies — not passwords or sessions; the identity products (Rubrik, Commvault) go deeper than the M365 bundles. ### Google Workspace, or Google and Microsoft together **Shortlist:** Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), AvePoint Cloud Backup, Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup **Why:** Druva, AvePoint and Acronis are the three here that document Google Workspace — Druva and AvePoint alongside Microsoft 365 in one console, Acronis through an MSP from a Mumbai data centre. **Trade-off:** Google Vault is not backup (Google says so); these three are; Veeam, Commvault, Barracuda and Rubrik do not offer Google Workspace at all. ### Salesforce — records and metadata, with sandbox seeding **Shortlist:** Veeam Backup for Salesforce, Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), AvePoint Cloud Backup, Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce) **Why:** All four document metadata as well as records; Veeam keeps it in your own storage, Druva and AvePoint in theirs, Commvault at a published $3.60 per user per month. **Trade-off:** Veeam means running a server; the SaaS three mean the backup lives outside your org's cloud — pick the control you want. ### The backup must live in storage we own **Shortlist:** Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium), Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), AvePoint Cloud Backup, Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster) **Why:** Veeam Backup for Microsoft 365 (self-hosted), Commvault's bring-your-own storage, AvePoint's Azure/AWS storage option and Cohesity on your own cluster keep the copy under your control. **Trade-off:** Your storage means your immutability configuration and your restore bandwidth; the vendor-storage products include both in the price. ### Backups must stay in India **Shortlist:** Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce), Barracuda Cloud-to-Cloud Backup, Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup, Veeam Data Cloud for Microsoft 365 (Foundation · Advanced · Premium) **Why:** Druva's AWS Mumbai region, Barracuda's India data centre, Commvault's India SaaS availability, Acronis's Mumbai data centre and Veeam's Central India region are all documented. **Trade-off:** AvePoint, Rubrik and Cohesity's BaaS are flagged, not ruled out — ask for the region in writing. ### MSP-run SMB on Microsoft 365 or Google **Shortlist:** Acronis Cyber Protect Cloud — Microsoft 365 · Google Workspace backup, Barracuda Cloud-to-Cloud Backup, AvePoint Cloud Backup **Why:** Acronis and AvePoint are built for partner delivery; Barracuda's flat per-user price with unlimited storage is simple to resell and to budget. **Trade-off:** Partner pricing hides the list — ask the MSP what the vendor charges them per seat, and what happens to the backup if you change MSP. ### Enterprise — SaaS data under the same platform as the data centre **Shortlist:** Commvault Cloud SaaS Backup (Microsoft 365 · Dynamics 365 · Salesforce), Rubrik Microsoft 365 (Foundation · Business · Enterprise Edition), Cohesity DataProtect for Microsoft 365 (BaaS or on your cluster), Druva SaaS Apps (Microsoft 365 · Google Workspace · Salesforce) **Why:** Commvault, Rubrik, Cohesity and Druva each protect Microsoft 365 from the same console and posture as their data-centre products — one catalogue, one anomaly view. **Trade-off:** Platform pricing is per user plus storage (Rubrik) or per capacity (Cohesity) — the per-user list tells you less than the total. ## At scale SaaS backup scales by seat count and by data per seat — and the seat count includes the people who left. The bill follows the seat; the restore follows the API. ### 100 seats — Inclusion is the constraint - Any product here covers the tenant; the question is what the per-user price includes — storage, Entra ID, Teams private chats — and the minimum seats or annual floor. - Flat unlimited models (Barracuda, AvePoint) are simplest to budget; published lists (Commvault, Veeam, Barracuda) are simplest to compare. - An MSP often holds the contract: ask what the vendor charges them per seat. **The test:** Restore one mailbox and one SharePoint site in place, and one Teams channel. If the third needs an export, you have learned the product. ### 1,000 seats — Leavers and the directory are the constraint - Retained leavers become a visible share of the bill — the seat-pricing contract line matters now; capacity pricing (Cohesity) starts to compete with per-user. - Entra ID restore stops being optional: one compromised admin can remove every conditional-access policy. Include it (Barracuda, Veeam Advanced, AvePoint) or buy the identity product (Commvault, Rubrik). - Restore throughput is API-throttled by Microsoft and Google; premium tiers (Veeam Premium) buy unthrottled restore. **The test:** Ask for a documented restore rate (items per hour) for a tenant your size, and price the leaver seats for the retention term. ### 10,000 seats — Throughput and platform are the constraint - Bulk restore after an incident is an API-throughput problem; vendors that resell Microsoft 365 Backup for speed inside the tenant plus their own copy outside it are the honest enterprise shape. - One platform for SaaS and the data centre (Commvault, Rubrik, Cohesity, Druva) gives one anomaly view and one catalogue — and one negotiation. - Per-user lists matter less than the total: storage licences (Rubrik), capacity (Cohesity), Export API pass-through, and the India region in writing. **The test:** Run a 1,000-mailbox restore rehearsal. The hours it takes, and whether Microsoft throttled it, is the only number that matters. Veeam, Commvault, Druva, AvePoint, Rubrik and Cohesity document very large tenants; Acronis and Barracuda are flagged unverified above 10,000 seats, not ruled out. Where a specific product strains for your tenant: [TechBag to confirm]. ## Leaving a SaaS backup product means leaving the history behind The old product’s backups stay in its storage, in its format, readable only through it. Switching starts a new history from day one; the old history lives until its retention ends — if you keep paying. **The retained history** — Seven years of mail and files in the old vendor's storage. Keep the contract (often at reduced seats) until the retention ends, or export what the regulator may ask for — exports are per mailbox and slow. *(Overlap or export)* **The first full backup** — The new product's first pass through a large tenant is API-throttled by Microsoft and Google — days to weeks. Plan the gap. *(Seeding is throttled)* **The directory and the metadata** — Entra ID objects and Salesforce metadata history start again; a restore to a point before the switch needs the old product alive. *(History resets)* **Bring-your-own storage** — If the copy was in your own storage (Veeam self-hosted, Commvault, AvePoint, Cohesity), the data stays yours — readable only through the product that wrote it. *(Yours, still proprietary)* **Retention tail, seeding time and overlap cost for your tenant:** [TechBag to confirm] — TechBag scopes it from your retention rules and seat count. ## Per user per month — and the seat that left What you may already hold, the products priced per user at three tenant sizes in USD and INR, and what the per-user line leaves out — starting with the storage and the leavers. ### Do you already own one? Four things already in the tenant that get called backup. One is. - **Microsoft 365 retention policies — No.** Governance, not recovery. Retention keeps content from destruction until a date; it does not restore a purged mailbox, an encrypted site or last Tuesday’s tenant. Microsoft recommends third-party backup. - **Recycle bin and versioning — No.** 30–93 days for a user’s own deletions. An admin purge, an expired window, a deleted account or an attacker versioning over the files ends it. - **Microsoft 365 Backup (the paid service) — Partly.** Real backup at $0.15 per GB per month, restores free, inside the tenant — Exchange, OneDrive, SharePoint. Not a copy outside the tenant, not Teams or Entra ID, not Google or Salesforce. - **Google Vault — No.** An eDiscovery and retention tool. Google’s own FAQ answers “is Vault a backup?” with no. If what is already in the tenant covers your failure modes, we say so. It costs us a sale and saves you one. ### What the rest actually cost Published and reported per-user prices (INR for scale), then worked at 100 / 1,000 / 10,000 seats per year. Storage and the directory add-on are stated apart, on purpose; where a product is quote-only the line says so. ### What isn't in the licence price - **Storage, where it is not included.** Rubrik’s backup-storage licence, Cohesity’s capacity, Microsoft’s per GB — and the Export API Microsoft meters for Teams private chats, passed through or absorbed depending on the vendor. Ask for the total, not the seat. - **The seats that left.** Retained leavers on a strict per-user contract: by year seven of a seven-year retention rule at 10% attrition, 1.7× the live seat count. The contract line that decides the five-year bill. - **Restore time, throttled.** Microsoft and Google throttle restore APIs; a 1,000-mailbox restore is hours to days on standard tiers. Premium tiers and the in-tenant Microsoft 365 Backup buy speed. Your rehearsal figure: [TechBag to confirm]. ## What goes wrong Documented behaviour and contract lines, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover at the point of loss. - **Assuming native retention is backup.** The retention policy was set; the mailbox was purged by an admin; the policy kept nothing because nothing existed. Retention is a governance control; backup is a recovery control. - **Departed-user licences still being paid for.** Seven-year retention on a per-user contract: the leavers accumulate until they outnumber the staff. Ask what a retained, unlicensed user costs before signing. - **Teams and SharePoint coverage shallower than mail.** Channels were backed up; private chats were not (Microsoft's Export API was never enabled); the SharePoint site's permissions came back wrong. Test the non-mail workloads first. - **Restore that needs a support ticket.** The console showed the backup; the restore was an export file and a ticket to the vendor. In-place, self-service restore is the product — rehearse it before the incident. - **Salesforce metadata not covered, only records.** Records were restored into an org whose fields, flows and layouts had been deleted with them. Metadata is the org; records are the rows. - **Entra ID not in the backup.** A compromised admin removed the conditional-access policies and the groups; the M365 backup had mail and files. Directory objects are a separate capability — and usually a separate SKU. - **Google Vault mistaken for backup.** Vault held the mail for compliance and restored nothing when the Drive was encrypted. Google says it is not backup; three products here are. - **The region assumed, not documented.** The contract said cloud; the data sat in a region the regulator did not accept. Druva, Barracuda, Commvault, Acronis and Veeam document India; ask the rest in writing. ## Questions this guide answers ### Is a Microsoft 365 retention policy a backup? No. Retention is a governance control that keeps content from being destroyed until a date; backup is a recovery control that restores a mailbox, site, item or the tenant's state to a point in time after deletion, corruption or ransomware. Microsoft's shared-responsibility model makes the data your responsibility and its Service Agreement recommends third-party backup. Microsoft's own paid Microsoft 365 Backup service ($0.15 per GB per month) is real backup inside the tenant; third-party products hold an independent copy outside it. ### Which SaaS backup products cover Entra ID? Barracuda Cloud-to-Cloud Backup includes Entra ID in its per-user price; Veeam Data Cloud covers it in the Advanced tier or standalone at $14.10 per user per year; AvePoint includes it in its SaaS list; Commvault (Backup for Active Directory & Entra ID) and Rubrik (Identity Resilience, with Okta and AD) sell dedicated identity products; Druva's Identity Resilience plans are a separate SKU. Acronis and Cohesity's M365 services do not document it; the guide flags them rather than ruling them out. ### Which SaaS backup products keep data in India? Druva (AWS Mumbai region), Barracuda (India regional data centre, opened 2022), Commvault Cloud (SaaS available in India), Acronis (Mumbai data centre) and Veeam Data Cloud for Microsoft 365 (Central India Azure region) document it. Veeam Backup for Salesforce is self-hosted in your storage. AvePoint, Rubrik and Cohesity's BaaS do not document an India region; ask in writing. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/backup-cyber-resilience/saas-backup* --- # RPO and RTO are the only two numbers in this category — and most organisations have never tested whether theirs are real. *Disaster Recovery — a TechBag decision guide. Last reviewed 2026-09-07.* > A DR product keeps a second, runnable copy of your systems somewhere else — replicated continuously, periodically, or rebuilt from backups — and fails the estate over to it in an order that works, then brings it back. The copy is the easy half. The order, the network and the failback are the product. **The checkable fact:** Veeam documents continuous data protection with RPOs in seconds for vSphere. Druva documents failover into AWS Mumbai from backups it already holds, at an RPO of hours. Both are “disaster recovery”. They are not the same purchase. - Canonical: https://www.thetechbag.com/browse/backup-cyber-resilience/disaster-recovery - Category: [Backup & Cyber Resilience](https://www.thetechbag.com/browse/backup-cyber-resilience) - Products compared: 9 ## What disaster recovery actually is A way to run your systems somewhere else when the place they run is gone — power, flood, fibre cut, a hypervisor cluster that will not come back. The product keeps a second runnable copy (by continuous replication, periodic replication, or by standing up backups), fails over to it in a **dependency-ordered plan** — domain controllers before databases before applications — re-IPs and re-points what must change, and, when the site is back, fails back without losing what happened in between. Two numbers define every product here. **RPO** — how much data you lose (seconds for continuous replication, minutes for periodic, hours for backup-based). **RTO** — how long until users are working again (minutes with orchestration and a warm target; hours to days by hand). Everything else is a variable: where the target is, who hosts it, whether failback is a button or a project. The data-only half of this decision is the [backup and recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery); what to do when the second copy is also the attacker’s is the [cyber-recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery). **The most common mis-purchase.** A replication product bought as the ransomware plan. Replication copies the encryption to the second site within its RPO — seconds, if you paid for the good tier. **DR assumes the source is trustworthy. Cyber recovery assumes it is not.** ## RPO vs RTO · DR vs HA vs backup Two pairs this buyer confuses, and nothing more. The first pair is two numbers that get used interchangeably; the second is three mechanisms that get sold as tiers. They are not tiers — they answer different failure modes. ### RPO — how much you lose Recovery point objective: the age of the last good copy when the failure hits. Continuous replication (Veeam CDP, Cohesity SiteContinuity) — seconds. Periodic replication (Commvault, NetBackup) — minutes. Backup-based recovery (Druva, Acronis, Rubrik recovery plans, Barracuda) — hours. A tight RPO costs storage, WAN and a warm target; it says nothing about how fast you are back. ### RTO — how long until you are back Recovery time objective: the time from failure to users working. Orchestration with boot order, re-IP and a warm target — minutes. Hand-built failover from backups — hours to days. A product can have a five-minute RTO on paper and a two-day RTO over your network. It is measured, or it is a guess. ### HA vs DR High availability keeps a system up through a component failure — a cluster, a second node, a load balancer — in the same place, automatically, with no data loss. DR moves the estate to another place after the place itself fails. HA does not survive the site; DR does not survive a bad transaction being replicated. Most estates need both; they are different purchases. ### DR vs backup Backup restores data to a point in time, slowly, anywhere — it is the copy of record. DR restores operations, fast, to a prepared place — from replicas or from backups stood up in order. Backup without DR is a long outage; DR without backup is a fast failover to whatever was replicated, including the corruption. **These are not tiers of the same product.** HA survives a component, DR survives a site, backup survives time — and none of them survives an attacker who planned for all three, which is the [cyber-recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery). A tool that handles a flooded data centre perfectly may be useless against deliberate destruction replicated in seconds. ## The decision variables Seven variables decide this purchase. The instrument tests the ones documentation can verify (RPO class, target, orchestration, scope, India site); achievable RTO, failback time and the regulator’s expectations are prose because the honest answers come from your last drill, not a datasheet. **Achievable RPO and RTO — tested, not claimed.** Seconds / minutes / hours by mechanism; then the number you measured in a real drill with the real application stack over the real network. If it has never been measured, it is unknown. **Failover target.** A second site you own, your own cloud account (AWS, Azure, GCP, OCI), or the vendor's hosted DRaaS. Decides who pays for the target on a quiet day and on the day. **Orchestration and runbook automation vs manual failover.** Boot order, dependencies, re-IP, scripts, one click — or a wiki page and a phone tree. The RTO lives here. **Failback.** Bringing the estate home without losing what happened while you were away — and the step where most DR plans actually break. Documented as one operation at most products here; flagged where not. **Testing without disrupting production.** Isolated test networks, automated reports, drill evidence for the auditor. Documented everywhere here; done quarterly almost nowhere. **RBI and sectoral business-continuity expectations.** Documented RPO/RTO, periodic drills with evidence, data in India for regulated entities. Your design artefact on most products; hosted for you on one. **India DR site availability.** A vendor-hosted failover target in India (Druva's AWS Mumbai DRaaS), your own second Indian site or India cloud region (the rest), or not documented (flagged). ## The 9 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) — Veeam - **Who it's for:** VMware-centric estates that want replication and continuous data protection to a second site or cloud, with one-click failover plans, automated testing and documented failback — on the licence they already run for backup. - **The honest limitation:** CDP is VMware-only (vSphere); the secondary site, its hypervisor and its storage are your cost and your build; Recovery Orchestrator is Premium — Foundation has replication without the orchestration. - **Price:** ~$350–450 (≈ ₹29,050) — per workload (VUL) / year reported for Advanced (CDP) and Premium (Recovery Orchestrator, automated testing, ransomware warranty); the DR site and its compute are yours - **Details:** https://www.thetechbag.com/veeam/veeam-data-platform ### Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) — Commvault - **Who it's for:** Mixed estates that want replication, cross-hypervisor and cloud-target failover and policy-driven recovery groups from the same platform that backs them up. - **The honest limitation:** Periodic replication rather than continuous (minutes, not seconds); the failover target — second site or cloud account — is yours to run and pay for; quote-only. - **Price:** Quote — per VM / instance or per front-end TB on quote; replication to a second site or to AWS, Azure, GCP and OCI; recovery groups with boot order; the target is yours - **Details:** https://www.thetechbag.com/commvault/commvault-backup-recovery ### Commvault Cloud Rewind — Commvault - **Who it's for:** Cloud-native estates (AWS, Azure, GCP) that need the application, not only its data, rebuilt after an account compromise or region loss — with periodic rebuild tests. - **The honest limitation:** Cloud-native applications only — no VMware, no physical; RPO follows the snapshot schedule; failback to the original account after rebuild is not documented as a one-step operation. - **Price:** Quote — per protected cloud application / resources on quote; rebuilds the whole cloud application — infrastructure, configuration, dependencies — in a new account or region - **Details:** https://www.thetechbag.com/commvault/commvault-cloud-rewind ### Cohesity SiteContinuity (DataProtect DR) — Cohesity - **Who it's for:** Cohesity estates that want near-zero RPO for VMware workloads and orchestrated, tested failover to a second cluster or to AWS, from the backup platform's console. - **The honest limitation:** Continuous replication is VMware-centric; the second cluster or the AWS account is yours to own; Hyper-V and Nutanix are backup-level protection, not continuous DR here; quote-only. - **Price:** Quote — licensed on the Cohesity platform (per TB) on quote; continuous replication for VMware to a second Cohesity cluster or to AWS; application-level runbooks - **Details:** https://www.thetechbag.com/cohesity/cohesity-dataprotect ### NetBackup — Resiliency Platform & IT Analytics (Cohesity) — Cohesity - **Who it's for:** Large NetBackup estates that want cross-site and cloud recovery orchestration, rehearsal and reporting on the platform they already operate. - **The honest limitation:** Enterprise-priced and enterprise-operated; the orchestration layer is a separate licence from NetBackup itself; the DR site is yours. - **Price:** Quote — enterprise licensing on quote alongside NetBackup (per front-end TB); resiliency orchestration across data centre and cloud with rehearsals - **Details:** https://www.thetechbag.com/cohesity/cohesity-netbackup ### Rubrik Orchestrated Application Recovery — Rubrik - **Who it's for:** Rubrik estates that want application-level recovery plans — boot order, dependencies, test mode — from backups and replicas in the same console as the cyber-recovery posture. - **The honest limitation:** Recovery from backups and replicas, not continuous data protection — RPO is the backup interval, not seconds; VMware and Azure are documented, other hypervisors are not; the target site is yours. - **Price:** Included in Enterprise Edition — part of Rubrik Security Cloud Enterprise Edition (reported ~$130 per back-end TB / month on three-year terms); recovery plans with boot order and test mode for VMware and Azure - **Details:** https://www.thetechbag.com/rubrik/rubrik-enterprise-edition ### Druva Disaster Recovery as a Service (AWS) — Druva - **Who it's for:** Organisations without a second data centre that want VMware, Hyper-V and physical servers failed over into AWS — in India — from the backup copies Druva already holds, with documented failback. - **The honest limitation:** RPO is the backup frequency (hours), not replication; AWS only as the target, and the failover compute runs in your AWS account at your cost; quote-only. - **Price:** Quote — per protected VM / month on quote on top of Hybrid Workloads; failover into your AWS account (Mumbai region available); one-click runbooks, failback to on-prem; no second site to build - **Details:** https://www.thetechbag.com/druva/druva-hybrid-workloads ### Acronis Disaster Recovery (Cyber Protect Cloud add-on) — Acronis - **Who it's for:** MSP-run SMBs that want servers and VMs recoverable into Acronis Cloud in minutes with runbooks and a test failover they can actually run, on the same agent as backup and security. - **The honest limitation:** Billed in compute points and GB through a partner — no public rate card; whether the Mumbai data centre hosts DR (not only backup storage) is not documented; enterprise scale is not where it is documented. - **Price:** Compute points + storage — per-GB storage plus compute points consumed during test and production failover, through MSPs; runbooks; failover into Acronis Cloud; failback to original or new hardware - **Details:** https://www.thetechbag.com/acronis/acronis-cyber-protect-cloud ### Barracuda Backup — Cloud LiveBoot & replication — Barracuda - **Who it's for:** Mid-market sites with a Barracuda appliance that want VMs bootable from the local appliance or from Barracuda's cloud after a site loss, at a flat replication price. - **The honest limitation:** No runbook orchestration — LiveBoot is per VM, not a dependency-ordered plan; RPO is the backup interval; an India region for Barracuda Cloud is not documented; VMware and Hyper-V only. - **Price:** $799 (≈ ₹66,317) — per TB / year list for replication to Barracuda Cloud (appliance or Vx priced apart); LiveBoot runs VMs from the appliance or from Barracuda Cloud; site-to-site replication between appliances - **Details:** https://www.thetechbag.com/barracuda/barracuda-data-protection ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Seconds of RPO.** Rules out Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) and NetBackup — Resiliency Platform & IT Analytics (Cohesity) — periodic replication (minutes), not continuous; Commvault Cloud Rewind, Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — recovers from backups or snapshots (hours), not replication. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) and Cohesity SiteContinuity (DataProtect DR). **Minutes of RPO.** Rules out Commvault Cloud Rewind, Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — recovers from backups or snapshots (hours), not replication. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR) and NetBackup — Resiliency Platform & IT Analytics (Cohesity). **Vendor-hosted failover.** Rules out Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity) and Rubrik Orchestrated Application Recovery — fails over to a site or cloud account you own and run. That leaves Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication. **Your cloud account as the target.** Rules out Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — does not fail over into your cloud account. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery and Druva Disaster Recovery as a Service (AWS). **Your own second site.** Rules out Commvault Cloud Rewind, Druva Disaster Recovery as a Service (AWS) and Acronis Disaster Recovery (Cyber Protect Cloud add-on) — vendor-hosted or cloud-only failover. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery and Barracuda Backup — Cloud LiveBoot & replication. **Orchestrated runbooks.** Rules out Barracuda Backup — Cloud LiveBoot & replication — per-VM failover, no dependency-ordered plan. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS) and Acronis Disaster Recovery (Cyber Protect Cloud add-on). **Failback documented.** Rules nothing out on published terms. It flags Commvault Cloud Rewind — Failback to the original environment not documented as a single operation — marked, not removed. **Hyper-V.** Rules out Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR) and Rubrik Orchestrated Application Recovery — Hyper-V not documented for DR here. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication. **Physical servers.** Rules out Commvault Cloud Rewind and Rubrik Orchestrated Application Recovery — physical servers not documented. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication. **Cloud-native applications.** Rules out Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — on-prem workloads only. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity) and Rubrik Orchestrated Application Recovery. **DR site in India.** Rules nothing out on published terms. It flags Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) — Your second site or your cloud region, Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) — Your second site or your cloud region, Commvault Cloud Rewind — Your second site or your cloud region, Cohesity SiteContinuity (DataProtect DR) — Your second site or your cloud region, NetBackup — Resiliency Platform & IT Analytics (Cohesity) — Your second site or your cloud region, Rubrik Orchestrated Application Recovery — Your second site or your cloud region, Acronis Disaster Recovery (Cyber Protect Cloud add-on) — An India-hosted failover target is not documented and Barracuda Backup — Cloud LiveBoot & replication — An India-hosted failover target is not documented — marked, not removed. **Above 1,000 VMs.** Rules nothing out on published terms. It flags Acronis Disaster Recovery (Cyber Protect Cloud add-on) — Unverified above 1,000 VMs and Barracuda Backup — Cloud LiveBoot & replication — Unverified above 1,000 VMs — marked, not removed. **Tested, not claimed.** Every product here documents a non-disruptive test (Veeam SureReplica and Orchestrator reports, Commvault recovery validation, Cohesity and NetBackup rehearsals, Rubrik test mode, Druva and Acronis test failover, Barracuda LiveBoot). None of that is your RPO and RTO. Those are the numbers you measured the last time you failed over the real application stack and came back; if the honest answer is never, the honest RPO is unknown. TechBag's delivery figures for real failover and failback times are [TechBag to confirm]. **DR versus cyber recovery.** Replication is the fastest way to copy ransomware to the second site. A DR product assumes the source is trustworthy; the moment it is not, you need an immutable backup and a clean room — the cyber-recovery guide. Veeam, Commvault, Cohesity, Rubrik and Druva sell both halves; they are different SKUs and different rehearsals. **RBI and sectoral business-continuity expectations.** RBI's IT Governance and outsourcing directions, SEBI's CSCRF and IRDAI's guidelines expect documented RPO/RTO, periodic DR drills with evidence, and data in India for regulated entities. Druva's AWS Mumbai DRaaS is the documented India-hosted target here; every other product leaves the site in your hands, which for most regulated buyers means a second Indian data centre or an India cloud region — your design, and documented as such. **Network and DNS.** No product on this page fails over your network. Re-IP, DNS cut-over, firewall rules, identity and the VPN are your runbook's first pages; the orchestration tools (Veeam Orchestrator, Commvault, Cohesity, Rubrik, Druva, Acronis) can script the re-IP and some DNS steps — test that they did. **Under 50 VMs.** Rules nothing out on documentation: Acronis DR and Barracuda LiveBoot are built for the small estate; Druva DRaaS and Veeam replication start at any size; the orchestration products (Orchestrator, SiteContinuity, NetBackup resiliency) are enterprise-positioned. Where the small estate should stop at backup-plus-a-plan is delivery judgement: [TechBag to confirm]. ## Eight situations, eight shortlists — with the RPO named Each shortlist names the mechanism (continuous, periodic, from backups) and where the estate would run. If you have no second site, start from the second row. ### VMware, two data centres, and a real RPO in seconds **Shortlist:** Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Cohesity SiteContinuity (DataProtect DR) **Why:** Veeam CDP (Advanced) and Cohesity SiteContinuity document continuous replication for vSphere with orchestrated failover and failback to a second site you own. **Trade-off:** Continuous replication doubles the storage and the WAN; the second site's compute is the bill — and replication will faithfully copy the ransomware. ### No second data centre — fail over into a cloud we pay for only on the day **Shortlist:** Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) **Why:** Druva fails VMs over into your AWS account (Mumbai available) from copies it already holds; Acronis fails over into Acronis Cloud through an MSP on compute points; Veeam replicates to a cloud target you run. **Trade-off:** RPO is hours for the DRaaS pair (backup frequency, not replication); the cloud compute during a real event is the number nobody modelled. ### Mixed hypervisors and clouds — one orchestration layer **Shortlist:** Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) **Why:** Commvault replicates across VMware, Hyper-V, Nutanix and into AWS, Azure, GCP and OCI with recovery groups; NetBackup's resiliency layer orchestrates across data centre and cloud for large estates; Veeam Orchestrator covers replicas, CDP replicas, backups and storage snapshots in one plan. **Trade-off:** Breadth is periodic (minutes) rather than continuous; the plan is only as good as the last rehearsal — and someone has to own it. ### Cloud-native — an AWS or Azure account or region is the thing that can be lost **Shortlist:** Commvault Cloud Rewind, Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) **Why:** Cloud Rewind rebuilds the application — infrastructure, configuration, dependencies — in a new account or region; Commvault and Veeam replicate and recover cloud instances and data. **Trade-off:** Rebuilding the application is a different test from restoring its data — run the rebuild quarterly, and price the second region's compute for the day. ### Rubrik estate — recovery plans without a replication product **Shortlist:** Rubrik Orchestrated Application Recovery, Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) **Why:** Rubrik's Orchestrated Application Recovery gives boot order, dependencies and test mode over backups and replicas in the console you already run; Commvault is the like-for-like if continuous replication becomes the requirement. **Trade-off:** RPO is the backup interval — honest for most applications, wrong for the one database that cannot lose an hour. ### The regulator wants an India DR site and drill evidence **Shortlist:** Druva Disaster Recovery as a Service (AWS), Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) **Why:** Druva's AWS Mumbai DRaaS is the documented India-hosted target; Veeam and Commvault fail over to the second Indian site or India cloud region you design, with test reports as drill evidence. **Trade-off:** Only one product here hosts the India site for you; the rest make the site your cost and your compliance artefact — which many regulated buyers prefer. ### MSP-run SMB with a few servers and no DR plan at all **Shortlist:** Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Druva Disaster Recovery as a Service (AWS) **Why:** Acronis DR adds runbooks and cloud failover to the agent the MSP already runs; Barracuda LiveBoot boots VMs from the appliance or the cloud at a flat replication price; Druva DRaaS needs no second site. **Trade-off:** Barracuda has no dependency-ordered runbooks; Acronis is billed in compute points through the partner — ask what a week of production failover costs. ### Enterprise on NetBackup or Commvault with a DR audit due **Shortlist:** NetBackup — Resiliency Platform & IT Analytics (Cohesity), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) **Why:** NetBackup's resiliency orchestration and Commvault's recovery groups produce the rehearsal evidence auditors ask for across the estates those platforms already protect; Veeam Orchestrator does the same for the VMware share. **Trade-off:** Orchestration licences sit on top of the backup licence; the drill is a project with an owner, not a feature. ## At scale DR scales by the number of things that must come up in order, and by the network they must come up across. The bill follows the target; the RTO follows the runbook. ### 50 protected VMs — The plan is the constraint - Any product here covers it; the difference is whether there is a plan at all. DRaaS (Druva, Acronis) and LiveBoot (Barracuda) give the small estate a target without a second site. - RPO of hours is honest for most small estates — say so and buy accordingly. - The drill is a day's work; do it once a year at minimum. **The test:** Fail over the three servers that matter into the test network and time it. Then fail back. The second number is the finding. ### 500 protected VMs — Dependencies and the target's cost are the constraint - Boot order, re-IP and application dependencies stop being a wiki page — orchestration (Veeam Orchestrator, Commvault recovery groups, Cohesity runbooks, Rubrik plans) earns its licence. - A warm second site or a cloud account with reserved capacity becomes a standing bill; continuous replication doubles the storage and the WAN. - The tier matters: Veeam Foundation replicates, Premium orchestrates; Rubrik plans are in Enterprise Edition. **The test:** Ask for a recovery-plan report from an automated test on an estate your size, and the cost of the target on a quiet month and a failover month. ### 5,000 protected VMs — Sovereignty, evidence and the operating model are the constraint - Multi-site, multi-cloud, multiple regulators: the DR site's location, the drill evidence and the RPO per application class become board and audit material. - Enterprise orchestration (NetBackup resiliency, Commvault, Veeam Orchestrator at scale) plus a named DR owner and a quarterly drill calendar is the honest shape. - Cyber recovery is now a separate rehearsal: the replica is the attacker's copy too. **The test:** Run a full application-stack failover and failback in a quarter, with measured RPO and RTO per tier. Those two numbers are the only slide. Veeam, Commvault, Cohesity, NetBackup, Rubrik and Druva document large estates; Acronis and Barracuda are flagged unverified above 1,000 VMs, not ruled out. Where a specific product strains for your application tiers: [TechBag to confirm]. ## Leaving a DR product means re-seeding the second copy Replicas and recovery plans are product-specific. Switching means the new product takes its own first copy of everything and you rebuild the runbooks — while the old protection keeps running until the new one has been tested. **The re-seed** — The new product's first replication or backup of the whole estate crosses the WAN once more; for continuous replication the target storage is built again. Plan the window and the bandwidth. *(First copy, again)* **The runbooks** — Boot orders, re-IP rules, scripts and dependencies live inside the orchestration product; export the logic as a document before you leave and rebuild it — then test it. *(Rebuild and re-test)* **The target** — A vendor-hosted target (Druva's AWS account pattern, Acronis Cloud) disappears with the contract; your own second site or cloud account stays and is re-pointed. *(Keep yours, lose theirs)* **The overlap** — Run both until the new product has passed a full drill. Two DR bills for a quarter is the honest cost of not being unprotected for one. *(One tested quarter, twice)* **Re-seed bandwidth, runbook rebuild and overlap cost for your estate:** [TechBag to confirm] — TechBag scopes it from your application tiers and WAN. ## The licence is the small number — the target is the bill What you may already hold, the products priced the way they are sold in USD and INR, and what the licence line leaves out — which, for DR, is the second site or the cloud compute on the day. ### Do you already own one? Four places a DR capability may already sit. None of them is a plan. - **Hypervisor replication (vSphere Replication, Hyper-V Replica) — Partly.** Per-VM replication built into the hypervisor, RPO in minutes, no orchestration, no failback plan. A mechanism, not a DR product — and it replicates the corruption. - **Storage-array replication — Partly.** Array-to-array replication is fast and faithful. It gives you a second copy of the LUNs, not a running estate in order; and it needs a second array somewhere else. - **Your cloud provider's DR service — Partly.** Azure Site Recovery and AWS Elastic Disaster Recovery replicate servers into that cloud with runbooks, on consumption. Real DR for that cloud as the target; nothing for the other cloud or a second site. - **Your backup product's tier — Often.** Veeam Advanced/Premium, Commvault, Cohesity, NetBackup, Rubrik Enterprise Edition and Druva all sell DR on the licence you already run. Read the tier — Foundation replicates without orchestrating. If the mechanism you already own is enough for your RPO and a plan is what is missing, we say so. It costs us a sale and saves you one. ### What the rest actually cost Reported and list meters (INR for scale). The licence is the smaller half everywhere here; the three plates price the target — a warm second site, your cloud on the day, or the vendor’s — at three estate sizes, with the licence lines under it. Where a product is quote-only the line says so. ### What isn't in the licence price - **The DR site.** A second data centre or reserved cloud capacity — $420000 ≈ ₹3,48,60,000 a year indicative for a warm 500-VM cloud target before the licence, or a building. The largest line in most DR budgets, and the one most often left out of the business case. - **Cloud cost during an actual event.** Production-size compute, storage and egress for the duration of the failover, then the transfer back. Nobody models a two-week event; model it. - **The drill.** A quarterly application-stack failover and failback with measured RPO and RTO, an owner, and the evidence for the auditor. Tools automate the report; the rehearsal is still yours. Your hours: [TechBag to confirm]. ## What goes wrong Documented behaviour and drill outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover mid-failover. - **DR plans never tested end to end.** Individual VMs failed over in a test network; the whole application stack never did. The first real failover found the dependency nobody drew. Drill the stack, quarterly. - **Failback taking longer than failover.** Failover was a button; bringing the estate home with a week of new data was a project. Ask to see failback in the demo — flagged here where it is not documented. - **Cloud DR costs during an actual event.** The target was cheap while it slept; production-size compute for three weeks was not in the budget. Price a fortnight, not an hour. - **Dependency ordering wrong on failover.** Applications booted before the database, the database before the domain controller. Boot order is the runbook; the runbook is the product. - **Network and DNS not part of the plan.** Every VM came up at the second site with the old IPs and nobody could reach them. Re-IP, DNS and firewall rules are pages one to three. - **Replication trusted as the ransomware plan.** The encryption replicated to the DR site in seconds. DR assumes the source is trustworthy; the cyber-recovery guide is for when it is not. - **RPO quoted from the datasheet.** Seconds on the slide; the WAN could not sustain the change rate and the journal fell hours behind. Measure the change rate before buying continuous replication. - **The India site assumed.** The regulator asked where the failover would run; the answer was a region in another country. Druva documents Mumbai; the rest is your design, documented as such. ## Questions this guide answers ### What is the difference between RPO and RTO? RPO (recovery point objective) is how much data you can lose — the age of the last good copy when the failure hits: seconds with continuous replication (Veeam CDP, Cohesity SiteContinuity), minutes with periodic replication (Commvault, NetBackup), hours with backup-based recovery (Druva DRaaS, Acronis DR, Rubrik recovery plans, Barracuda LiveBoot). RTO (recovery time objective) is how long until users are working again — minutes with orchestrated runbooks and a warm target, hours to days by hand. Both are measured in a drill or they are unknown. ### Is disaster recovery the same as backup, or as high availability? No. Backup restores data to a point in time, slowly, anywhere — the copy of record. High availability keeps a system running through a component failure in the same place, automatically. Disaster recovery moves the estate to another place after the place itself fails, from replicas or from backups stood up in order, and brings it back. They answer different failure modes; most estates need backup and DR, many need HA for specific systems, and none of the three survives an attacker who targets the copies — that is cyber recovery. ### Which DR products can fail over into India? Druva Disaster Recovery as a Service fails VMs over into your AWS account, with the Mumbai region available — the one documented vendor-hosted India target on the guide. Veeam, Commvault, Cohesity, NetBackup and Rubrik replicate or recover to a second Indian data centre or an India cloud region you design. Whether Acronis's Mumbai data centre hosts DR compute and whether Barracuda Cloud has an India region are not documented; the guide flags them rather than ruling them out. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/backup-cyber-resilience/disaster-recovery* --- # Ransomware operators target backups first. If your backup can be deleted by an admin credential, it is not a recovery plan. *Cyber Recovery — a TechBag decision guide. Last reviewed 2026-09-07.* > Cyber recovery is four questions the backup product never asked: can anyone with admin rights delete or shorten the copy; is the copy somewhere the attacker’s credentials cannot reach; will you know the data was encrypted before you restore it; and do you have somewhere clean to restore into. Vendors describe materially different answers with the same word. **The checkable fact:** Acronis documents that its immutable storage is in governance mode by default — an administrator can disable it, with a 14-day grace — and that compliance mode cannot be disabled by anyone, including Acronis support. Rubrik documents that Retention Lock can be removed only by Rubrik Support with two authorised customer officers. Both say “immutable”. - Canonical: https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery - Category: [Backup & Cyber Resilience](https://www.thetechbag.com/browse/backup-cyber-resilience) - Products compared: 15 ## What cyber recovery actually is A modern ransomware operator spends days inside the estate before encrypting anything. In those days they find the backup server, its console and its credentials — and delete, shorten or encrypt the backups first, so that the ransom is the only way back. Cyber recovery is the set of controls that survive that: **a copy nobody with admin rights can remove inside its retention**; an isolation the attacker’s credentials cannot cross; detection that the data in the backups was already encrypted or infected; and somewhere clean to restore into, because the production network is still theirs. Two things are true at once. Every backup product on the [backup guide](https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery) can be made immutable — and **almost none is, by default**. And “immutable” covers four materially different guarantees — hardware WORM or object lock in compliance mode (the storage refuses), vendor-controlled (a custodian you cannot reach refuses), software-enforced on the platform (the product refuses, with quorum), and a software flag an administrator can clear (governance mode). The [DR guide](https://www.thetechbag.com/browse/backup-cyber-resilience/disaster-recovery) assumes the copy is trustworthy; this page assumes it is not. Prevention — the endpoint and the backup server’s own EDR — is the [endpoint-protection guide](https://www.thetechbag.com/browse/security/endpoint-protection). **The most common mis-purchase.** “Immutable” that a domain administrator can override — because the product supported compliance mode and the default was governance, or the bucket was created without object lock, or the hardened repository’s console was reachable with the same credentials as everything else. **Support is not a default. Ask who can delete a backup, and what it takes.** ## Immutable vs air-gapped vs WORM · cyber recovery vs DR Three words vendors use interchangeably, and one pair of disciplines buyers merge. None of these is a tier. They answer different failure modes, and a tool that handles one perfectly may be useless against another. ### Immutable The copy cannot be modified or deleted inside its retention. The question is who enforces that: the storage (object lock in compliance mode, hardware WORM — the strongest), a custodian you cannot reach (vendor-operated vaults), the backup platform itself (append-only filesystems, DataLock with quorum), or a software flag (governance mode — an administrator can clear it). Same word, four guarantees. ### Air-gapped The copy sits where the attacker's credentials and network cannot reach. Logical: a separate tenant, separate credentials, no path from production (every vault here). Physical: offline — tape, a rotated drive, a powered-down system (Veeam and the base backup products document tape). A firewall rule between two systems that share an admin is marketing. ### WORM Write once, read many: the storage medium or service refuses overwrites and deletes for a period, at the hardware or object layer — tape WORM, object lock, appliance WORM modes. WORM is one implementation of immutability, not a synonym; software immutability without WORM underneath is as strong as the software's admin model. ### Cyber recovery vs DR Disaster recovery assumes the backup or replica is trustworthy and optimises for speed — and replicates the encryption within its RPO. Cyber recovery assumes the copy, the network and the credentials may all be compromised: lock the copy, isolate it, scan it, restore into a clean room. Different rehearsals, different products, often the same vendor. **These are not tiers of the same product.** Immutable says the copy cannot change; air-gapped says it cannot be reached; WORM says how the storage enforces it; DR says how fast you come back if all three were unnecessary. An estate with perfect DR and governance-mode immutability handles a flooded data centre perfectly and is useless against a patient attacker with the backup admin’s password. ## The decision variables Seven variables decide this purchase. The instrument tests the ones documentation establishes (who can lift the lock, custodian, detection, scanning, clean room, delivery form, India); air gap type, retention-lock duration and recovery time from the immutable copy are prose because the honest answers are a configuration and a rehearsal. **Immutability implementation.** Hardware WORM or object lock in compliance mode (the storage refuses); vendor-controlled (a custodian you cannot reach); software-enforced on the platform (append-only filesystem, DataLock with quorum); or a software flag an administrator can clear (governance mode). Vendors describe all four identically. The depth section tabulates which is which, from documentation. **Air gap: logical, physical, or marketing.** Separate credentials and tenant (logical — every vault here); offline or tape (physical — documented at Veeam and the base backup products); a firewall rule between systems sharing an admin (marketing). **Anomaly and encryption detection in the backup itself.** Does this SKU notice that last night's backup is 40% encrypted, or that a decoy was touched — or is detection another product? Separated from storage in the instrument, on purpose. **Clean-room recovery capability.** An isolated environment to restore into while production is still the attacker's — documented at Commvault (Cleanroom Recovery), Rubrik (isolated recovery environments) and Veeam (Recovery Orchestrator clean room). **Who can delete a backup, and what it takes.** Nobody inside retention; two officers and the vendor; quorum and MFA; an administrator by design; not established. The single most important line on this page. **Retention-lock duration.** Configurable everywhere; who can shorten it is the question above. **Recovery time from the immutable copy versus a normal one.** A vault in another tenant restores across a network — slower by design. Measured in the rehearsal or unknown. ## The 15 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware — Veeam - **Who it's for:** Veeam estates that want the ransomware layer on the licence they run: inline malware detection, Recon Scanner for the backup infrastructure, YARA scanning before restore, clean-room orchestration and Coveware's responders on retainer. - **The honest limitation:** Immutability is your build — a hardened repository an attacker with root and console access can still reach, or object lock whose mode (compliance vs governance) you chose; nothing is immutable by default; Premium-tier pricing on quote. - **Price:** ~$450 (≈ ₹37,350) — per workload (VUL) / year reported for Premium; immutability is the hardened Linux repository (immutable attribute, single-use credentials) or object lock in the mode you choose; tape for an offline copy; Coveware incident-response retainer separate - **Details:** https://www.thetechbag.com/veeam/veeam-coveware ### Veeam Data Cloud Vault — Veeam - **Who it's for:** Veeam estates that want the off-site immutable copy to exist without building one — a fixed per-TB price, no egress surprises on the Advanced tier, and nothing to harden. - **The honest limitation:** Storage only — detection, scanning and the restore engine are the Veeam licence; Veeam's own product only; the Foundation tier meters restores. - **Price:** $14 · $24 (≈ ₹1,162) — per TB / month list (Foundation locally redundant · Advanced zone-redundant, unlimited restore); always-on immutability in Veeam-managed Azure storage; India Central region - **Details:** https://www.thetechbag.com/veeam/veeam-data-cloud-vault ### Commvault Cloud Air Gap Protect — Commvault - **Who it's for:** Commvault estates that want the isolated immutable copy managed for them — no storage account, no credentials, no bucket policy to get wrong. - **The honest limitation:** Storage only and Commvault only; detection (Threat Scan, ThreatWise) and the clean room are separate SKUs; per-TB quote. - **Price:** Quote — per TB / month on quote, or included with Commvault Cloud SaaS plans; Commvault-managed immutable storage on Azure, AWS or OCI, isolated from your tenant; India via Commvault's SaaS regions - **Details:** https://www.thetechbag.com/commvault/commvault-air-gap-protect ### Commvault Cloud Cleanroom Recovery — Commvault - **Who it's for:** Regulated and insured estates that must prove recovery works: a clean room stood up on demand, tested on a schedule, with evidence — without keeping a second data centre idle. - **The honest limitation:** Commvault copies only; the cleanroom's Azure region for Indian buyers is not documented; compute for tests and for a real recovery is metered apart. - **Price:** Quote — per protected workload on quote; an on-demand isolated Azure environment, built clean, for recovery testing, forensics and production failover — from Air Gap Protect copies - **Details:** https://www.thetechbag.com/commvault/commvault-cleanroom-recovery ### Commvault Cloud ThreatWise — Commvault - **Who it's for:** Estates that want early warning inside the network — attackers touching a decoy backup server or share before they reach the real ones. - **The honest limitation:** Detection, not storage and not recovery — it holds nothing immutable; Commvault-sold, though decoys are vendor-neutral; quote-only. - **Price:** Quote — per sensor / environment on quote; deception decoys that look like production and backup assets, firing before encryption starts - **Details:** https://www.thetechbag.com/commvault/commvault-threatwise ### Cohesity DataProtect — DataLock, anomaly detection, CyberScan — Cohesity - **Who it's for:** Cohesity estates that want the appliance's own storage to be the immutable copy, with detection and scanning built into the platform and FortKnox as the off-site vault. - **The honest limitation:** Software-enforced on the platform you operate — strong (quorum, MFA, WORM on the filesystem) but not a separate custodian; an India region for the BaaS form is not documented. - **Price:** ~$150–400 (≈ ₹12,450) — per TB / year reported (licence); DataLock WORM on the SpanFS filesystem with quorum / MFA for privileged change; ML anomaly detection and CyberScan on the backups - **Details:** https://www.thetechbag.com/cohesity/cohesity-dataprotect ### Cohesity FortKnox — Cohesity - **Who it's for:** Cohesity estates that want a second, vendor-operated immutable copy outside their tenant with a documented clean-recovery path to an alternate cluster or cloud. - **The honest limitation:** Cohesity only; storage and recovery path, not detection (that is DataProtect); India region not documented; quote-priced per TB. - **Price:** ~$150–300+ (≈ ₹12,450) — per TB / year reported; SaaS cyber vault on AWS S3 Object Lock or Azure immutable storage (irrevocable DataLock), Cohesity-operated, virtual air gap with a transfer window; recovery to the source cluster or an alternate location - **Details:** https://www.thetechbag.com/cohesity/cohesity-fortknox ### Veritas Alta Recovery Vault (Cohesity) — Cohesity - **Who it's for:** NetBackup estates that want the immutable off-site copy operated for them rather than built on their own object storage. - **The honest limitation:** NetBackup only; storage, not detection; India region not documented; quote-only. - **Price:** Quote — per TB / month on quote; Veritas-managed immutable cloud storage for NetBackup, isolated from the NetBackup domain - **Details:** https://www.thetechbag.com/cohesity/cohesity-veritas-alta ### Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) — Rubrik - **Who it's for:** Enterprises that want backup and cyber recovery to be one posture — the storage cannot be written over, the lock needs two people and the vendor, the snapshots are scanned, and the recovery can be rehearsed in an isolated environment. - **The honest limitation:** The most expensive meter on this page on three-year terms; the platform is the custodian (strong, but one vendor for data and lock); India region not documented. - **Price:** ~$130 (≈ ₹10,790) — per back-end TB / month reported on three-year terms; append-only filesystem by design, Retention Lock removable only by Rubrik Support with two authorised customer officers; anomaly detection, threat monitoring, quarantine of infected snapshots, isolated recovery environments - **Details:** https://www.thetechbag.com/rubrik/rubrik-enterprise-edition ### Rubrik Cloud Vault — Rubrik - **Who it's for:** Rubrik estates that want the off-site immutable copy hosted by Rubrik with no storage account of their own to protect. - **The honest limitation:** Rubrik only; storage, not detection; India region not documented; quote-only. - **Price:** Quote — per TB on quote; Rubrik-hosted immutable storage in Azure, isolated from your tenant, under the same Retention Lock rules - **Details:** https://www.thetechbag.com/rubrik/rubrik-cloud-vault ### Rubrik Threat Hunting — Rubrik - **Who it's for:** Rubrik estates that need to answer 'which snapshot is clean, and since when' before restoring — without mounting and scanning each one by hand. - **The honest limitation:** Scanning, not storage — it finds the clean point; the immutability is Enterprise Edition's; Rubrik data only. - **Price:** In Enterprise Edition — part of Rubrik Security Cloud Enterprise Edition; IOC / YARA hunts across the backup history to find the last clean snapshot and the point of entry - **Details:** https://www.thetechbag.com/rubrik/rubrik-threat-hunting ### Druva Cyber Resilience — Accelerated Ransomware Recovery — Druva - **Who it's for:** Druva estates — SaaS-only, no storage of their own — that want the air gap, the lock, the detection and the clean restore point as a service in India. - **The honest limitation:** Druva-protected data only; no isolated clean-room environment as a product (recovery is into your environment or DRaaS); plan-tier pricing rather than a list. - **Price:** Plan tier / quote — included in or added to Druva's Enterprise / Elite plans; Druva-operated AWS with Data Lock that cannot be disabled once set, UEBA and unusual-activity detection, Curated Recovery building a clean restore point, quarantine and rollback actions; AWS Mumbai region - **Details:** https://www.thetechbag.com/druva/druva-cyber-resilience ### Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Acronis - **Who it's for:** MSP-run estates that want backup, anti-malware and an immutable cloud copy under one agent and one partner, in India — with the lock mode chosen deliberately. - **The honest limitation:** Governance mode is the default: until compliance mode is switched on, an administrator can lift the immutability; partner pricing; enterprise scale is not where it is documented. - **Price:** Per GB + per workload — Acronis Cloud storage per GB plus the per-workload licence, through MSPs; immutable storage in governance mode by default (an admin can disable it, 14-day grace) or compliance mode (nobody, including Acronis support); Safe Recovery scans backups; Mumbai data centre - **Details:** https://www.thetechbag.com/acronis/acronis-cyber-protect-cloud ### Barracuda Backup — immutable cloud copies — Barracuda - **Who it's for:** Barracuda appliance sites that want the off-site copy to be the one an attacker on the appliance cannot reach. - **The honest limitation:** Who can delete a cloud copy inside retention, and through what process, is not established from documentation — marked unknown; local copies are mutable; no detection or scanning. - **Price:** $799 (≈ ₹66,317) — per TB / year list for replication to Barracuda Cloud; cloud copies written once and not modifiable through the appliance or API; local appliance copies are not the immutable ones - **Details:** https://www.thetechbag.com/barracuda/barracuda-data-protection ### NinjaOne Backup — S3 Object Lock in the Ninja cloud — NinjaOne - **Who it's for:** NinjaOne RMM estates that want the endpoint and server backups' cloud copy locked at the storage layer, from the console they already run. - **The honest limitation:** Devices and servers only (no hypervisor-level VMs); the lock mode is a choice — governance can be lifted by the tenant for a period; no detection or scanning; India region not documented. - **Price:** Add-on — per device / month on top of the RMM plus Ninja cloud storage; AWS S3 Object Lock in governance or compliance mode; cloud copy only — the local copy is not locked - **Details:** https://www.thetechbag.com/ninjaone/ninjaone-backup ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **No single admin can lift it.** Rules out Commvault Cloud ThreatWise and Rubrik Threat Hunting — a detection or scanning product, not a storage mechanism. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud. It flags Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware — Depends on the mode you chose, Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Depends on the mode you chose, Barracuda Backup — immutable cloud copies — Who can delete inside retention is not established from documentation and NinjaOne Backup — S3 Object Lock in the Ninja cloud — Depends on the mode you chose — marked, not removed. **A vendor-operated custodian.** Rules out Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Cohesity DataProtect — DataLock, anomaly detection, CyberScan and Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) — immutability is enforced on storage you operate: your configuration, your credentials; Commvault Cloud ThreatWise and Rubrik Threat Hunting — a detection or scanning product, not a storage mechanism; NinjaOne Backup — S3 Object Lock in the Ninja cloud — object lock in the vendor's cloud but the mode and lifting are in your tenant's hands. That leaves Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security and Barracuda Backup — immutable cloud copies. It flags Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Acronis-operated storage; the mode (governance vs compliance) is set by your tenant — marked, not removed. **Detects anomalies itself.** Rules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Rubrik Threat Hunting, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — storage or recovery only; detection comes from another product. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Druva Cyber Resilience — Accelerated Ransomware Recovery and Acronis Cyber Protect Cloud — immutable storage + Advanced Security. **Clean restore point.** Rules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud ThreatWise, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — no documented malware / IOC scan of the backup data. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud Cleanroom Recovery, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Rubrik Threat Hunting, Druva Cyber Resilience — Accelerated Ransomware Recovery and Acronis Cyber Protect Cloud — immutable storage + Advanced Security. **An isolated clean room.** Rules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Rubrik Threat Hunting, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — recovery is into your environment or an alternate site; no isolated recovery environment documented for this SKU. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud Cleanroom Recovery and Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery). **Vault as a service.** Rules out Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) and Rubrik Threat Hunting — enforced on a platform or repository you run. That leaves Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud. **Immutable copy in India.** Rules nothing out on published terms. It flags Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware — Your repository or bucket, Commvault Cloud Cleanroom Recovery — India region not documented for this service, Commvault Cloud ThreatWise — India region not documented for this service, Cohesity DataProtect — DataLock, anomaly detection, CyberScan — India region not documented for this service, Cohesity FortKnox — India region not documented for this service, Veritas Alta Recovery Vault (Cohesity) — India region not documented for this service, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) — India region not documented for this service, Rubrik Cloud Vault — India region not documented for this service, Rubrik Threat Hunting — India region not documented for this service, Barracuda Backup — immutable cloud copies — India region not documented for this service and NinjaOne Backup — S3 Object Lock in the Ninja cloud — India region not documented for this service — marked, not removed. **Petabyte-scale vaults.** Rules nothing out on published terms. It flags Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Unverified at petabyte scale, Barracuda Backup — immutable cloud copies — Unverified at petabyte scale and NinjaOne Backup — S3 Object Lock in the Ninja cloud — Unverified at petabyte scale — marked, not removed. **Air gap: logical, physical, or marketing.** Every product here documents a logical air gap — separate credentials, separate tenant, no network path from production to the copy. A physical (offline) copy — tape, a rotated drive — is documented for Veeam Data Platform (and for Commvault's and NetBackup's base products, which are on the backup guide). A firewall rule between two systems that share an admin is not an air gap; a vendor-operated vault your tenant cannot reach with any credential is. Ask which one the word means in the proposal. **Retention-lock duration.** Configurable everywhere (days to years); the question is who can shorten it. Nobody inside retention: Veeam Vault, Air Gap Protect, FortKnox, Alta Recovery Vault, Druva, Acronis in compliance mode. Two people and the vendor: Rubrik. Quorum and MFA: Cohesity DataLock. An administrator, by design: governance modes (Acronis default, NinjaOne's choice, object lock in governance on Veeam targets). Not established: Barracuda. **Recovery time from the immutable copy.** A vault in another tenant or cloud restores across a network — slower than the local copy, by design. FortKnox, Air Gap Protect, Veeam Vault, Alta and Rubrik Cloud Vault all document restore paths; what they do not document is your hours-per-TB over your line. Measure it in the rehearsal; TechBag's delivery figures per platform are [TechBag to confirm]. **Detection is a different product from storage.** Commvault sells the vault (Air Gap Protect), the early warning (ThreatWise) and the clean room as three SKUs; Rubrik folds monitoring, hunting and isolated recovery into Enterprise Edition and sells the vault apart; Veeam puts detection in Premium and the vault in Data Cloud; Cohesity puts detection in DataProtect and the vault in FortKnox; Druva and Acronis bundle most of it into a plan. The instrument's chips separate them so a vault is never mistaken for a scanner. **Prevention belongs next door.** The backups are the last line; the endpoint is the first. Which EDR the estate runs decides how early the encryption is seen and whether the backup server itself is protected — the endpoint-protection guide. Veeam's Recon Scanner and Commvault's ThreatWise are the two products here that look at the estate before the encryption reaches the backups. ## Eight situations, eight shortlists — with the lock named Each shortlist names who can lift the lock in that estate and where the clean restore would happen. Start from the row that names your backup product — the vault decision was made when that decision was. ### Veeam estate — make the backups survive the attacker **Shortlist:** Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Veeam Data Cloud Vault **Why:** Premium adds the scanning, the secure restore and Coveware's responders on the licence already running; Veeam Vault gives the off-site copy that is immutable by default instead of by your build. **Trade-off:** Until the vault or a compliance-mode object-lock target exists, a hardened repository is as strong as its console access — test it as the attacker would. ### Commvault estate — vault, warning and a room to recover in **Shortlist:** Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Commvault Cloud ThreatWise **Why:** Air Gap Protect is the managed immutable copy, ThreatWise fires before encryption reaches it, Cleanroom Recovery stands up an isolated environment to prove the restore — three SKUs that read as one programme. **Trade-off:** Three quotes; the cleanroom's Azure region for Indian buyers is not documented — ask. ### A vault as a service — no storage of ours to protect **Shortlist:** Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Cohesity FortKnox, Rubrik Cloud Vault, Veritas Alta Recovery Vault (Cohesity) **Why:** Five vendor-operated vaults, each for its own backup product: Veeam Vault (published $14 / $24 per TB per month, India Central), Air Gap Protect, FortKnox (S3 Object Lock, irrevocable), Rubrik Cloud Vault, Alta Recovery Vault for NetBackup. **Trade-off:** Each vault is tied to its vendor's backup product — the vault decision is made when the backup decision is; only Veeam publishes the per-TB price. ### The insurer or regulator wants a clean room and evidence **Shortlist:** Commvault Cloud Cleanroom Recovery, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware **Why:** Commvault's on-demand cleanroom with scheduled tests, Rubrik's isolated recovery environments with threat hunting, and Veeam's Recovery Orchestrator clean-room flow with YARA scanning — the three documented isolated-recovery paths here. **Trade-off:** Clean-room compute is metered on the day and for every test; the evidence is only as good as the last scheduled rehearsal. ### SaaS-only estate, India, nothing to build **Shortlist:** Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security **Why:** Druva's Data Lock cannot be disabled once set and its Curated Recovery builds the clean restore point from the AWS Mumbai region; Acronis offers immutable storage and Safe Recovery from its Mumbai data centre through an MSP. **Trade-off:** Acronis is governance mode until compliance mode is switched on — make the switch part of the onboarding, in writing. ### Rubrik posture — data, lock, hunt and recovery from one vendor **Shortlist:** Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Rubrik Cloud Vault, Rubrik Threat Hunting **Why:** Append-only storage, a Retention Lock that needs two officers and Rubrik Support, monitoring, threat hunting across snapshots, and isolated recovery — with Cloud Vault as the hosted copy. **Trade-off:** One custodian for the data and the lock, on the page's most expensive meter and three-year terms. ### SMB through an MSP or RMM — lock the cloud copy **Shortlist:** Acronis Cyber Protect Cloud — immutable storage + Advanced Security, NinjaOne Backup — S3 Object Lock in the Ninja cloud, Barracuda Backup — immutable cloud copies **Why:** Acronis and NinjaOne lock the cloud copy with object lock in a mode you choose; Barracuda's cloud copies are written once and unreachable from the appliance. **Trade-off:** Modes default to governance (Acronis) or are a choice (NinjaOne); Barracuda's deletion process inside retention is not documented — three flags, not three eliminations. ### Cohesity estate — platform lock plus a separate vault **Shortlist:** Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Cohesity FortKnox **Why:** DataLock on the appliance with quorum and MFA, anomaly detection and CyberScan on the platform; FortKnox as the vendor-operated, irrevocably locked second copy with an alternate-site recovery path. **Trade-off:** Two Cohesity SKUs, two per-TB quotes; neither documents an India region for the service form. ## At scale Cyber recovery scales by the size of the copy that must sit out of reach and by how long a restore from there takes. The bill follows the vault; the confidence follows the rehearsal. ### 10 TB TB in the immutable copy — The default is the constraint - Any vault here holds it; the risk is the default — governance mode, a bucket without object lock, a hardened repository on the same credentials as everything else. - Vendor-operated vaults (Veeam Vault at $14–24 per TB per month, Acronis, Druva) remove the configuration risk for a small estate at a visible price. - A restore from the vault is hours at this size; rehearse it once a year. **The test:** Log in as the backup administrator and try to delete yesterday's copy. If you can, the attacker can. ### 100 TB TB in the immutable copy — The custodian and the scan are the constraint - The off-site immutable copy becomes a budget line of its own — object-storage rates times the retained TB — and the argument for a vendor-operated vault versus your own object lock is about who holds the keys, not the price. - Anomaly detection and a clean-restore-point scan stop being optional: restoring 100 TB of encrypted data is a week lost. - Restore time from the vault over your line is now a board number — measure it. **The test:** Ask for the restore throughput from the vault for an estate your size, and for the documentation page on who can delete inside retention. ### 1 PB TB in the immutable copy — The clean room and the evidence are the constraint - Isolated recovery environments (Commvault Cleanroom, Rubrik, Veeam Orchestrator) and scheduled tests with evidence are what the insurer and the regulator read. - Two custodians — the platform's lock plus a vendor-operated vault — is the honest enterprise shape; Acronis, NinjaOne and Barracuda are flagged unverified here, not ruled out. - The rehearsal is a programme with an owner: last clean snapshot, restore order, clean room, evidence. **The test:** Run a clean-room restore of the crown-jewel application from the vault and produce the evidence. Hours and findings are the slide. Veeam, Commvault, Cohesity, Rubrik and Druva document petabyte estates; Acronis, NinjaOne and Barracuda are flagged unverified at that size. Where a specific vault or platform strains at your size: [TechBag to confirm]. ## Leaving a vault is a retention-tail project with no gap allowed The copies in the vault are immutable by design — they will not move, and they will not be deleted early. Switching means the new immutable copy must exist before the old one stops being refreshed. **The locked tail** — Copies in the old vault stay until their retention expires — you cannot shorten it (that was the point). Budget the old vault until the last lock lifts. *(Pay until the lock expires)* **No gap** — The day the old product stops writing, the new product's immutable copy must already be current and tested. Overlap is not optional; it is the only honest plan. *(Overlap, tested)* **Vendor-tied vaults** — Veeam Vault, Air Gap Protect, FortKnox, Rubrik Cloud Vault and Alta are each for their own backup product; leaving the backup product leaves the vault. *(Vault follows the product)* **The rehearsal evidence** — Clean-room test reports and scan histories live in the old platform; export what the insurer and regulator may ask for before the contract ends. *(Export the evidence)* **Locked-tail cost, overlap and evidence export for your estate:** [TechBag to confirm] — TechBag scopes it from your retention locks and vault sizes. ## Per TB in the vault — and then the day itself What you may already hold, the vaults and platforms priced the way they are sold in USD and INR, and what the licence line leaves out — which, for cyber recovery, is the clean room on the day and the responders on the phone. ### Do you already own one? Four places immutability may already be within reach. Two of them are real if configured. - **Object lock on the cloud storage you already use — Partly.** S3 Object Lock, Azure immutable blob and AWS Backup Vault Lock / Azure immutable vault are real, storage-enforced immutability — if the bucket or vault was created with it, in compliance mode, and the backup product supports it. The storage is cheap; the configuration is the product. - **Your backup product's immutability setting — Often.** Veeam, Commvault, Cohesity, Rubrik, Acronis, NinjaOne and Barracuda all support it. Supported is not enabled; enabled is not compliance mode. Check which, today. - **Tape or an offline copy — Partly.** A physical air gap nobody argues with — slow to restore, easy to neglect, and documented at Veeam and the base backup products. Honest for the last-resort copy, not the first. - **Your EDR — No.** The endpoint product sees the encryption start and protects the backup server as a host; it holds no copy. Prevention next door, recovery here. If the lock you need is a setting you already pay for, we say so — and then we check the mode with you. It costs us a sale and saves you one. ### What the rest actually cost Published and reported vault and platform meters (INR for scale), then worked at 10 / 100 / 1,000 TB in the immutable copy per year. Only Veeam publishes a vault list; the rest are reported or quoted. The clean room, the retainer and the rehearsal are stated apart, below. ### What isn't in the licence price - **The clean room on the day.** Isolated compute for the duration of the recovery and for every scheduled test — metered, not licensed. A fortnight of production-size clean room is the number to model; most business cases model an hour. - **The responders and the retainer.** Coveware by Veeam sells an incident-response retainer with a 15-minute SLA; other vendors point to partners. Negotiation, forensics and the decision whether to pay are a separate contract — and a separate night. - **The rehearsal.** Finding the last clean snapshot, restoring the crown jewels into the clean room, producing the evidence — quarterly, with an owner. Tools automate the scan; the drill is yours. Your hours: [TechBag to confirm]. ## What goes wrong Documented defaults and modes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover with the attacker still inside. - **'Immutable' that a domain admin can override.** Governance mode by default, a role that can shorten retention, a bucket created without object lock. The product supported compliance; nobody switched it on. Ask who can delete, and what it takes — from the documentation page. - **Air gap that is a network rule, not an air gap.** A firewall between the backup server and the repository, both administered with the same credentials. The attacker had those. A custodian you cannot reach, or an offline copy, is an air gap; a rule is a rule. - **Restoring re-infected data because nobody scanned it.** The last three weeks of backups carried the implant; the restore put it back. Anomaly detection and a malware / IOC scan of the backups are products — Veeam Premium, Rubrik, Cohesity, Druva, Acronis — not assumptions. - **No clean room to restore into.** The copy was clean; the network it was restored into was still the attacker's. Commvault, Rubrik and Veeam document isolated recovery environments; the rest is your design. - **Discovering during an incident that immutability was never enabled.** The renewal said immutable; the configuration said supported. The first check in any engagement is to log in as the backup admin and try to delete yesterday's copy. - **The vault priced, the day not.** Per-TB storage was in the budget; a fortnight of clean-room compute, the responders' retainer and the egress were not. Price the event. - **Replication trusted as the plan.** The DR replica carried the encryption within seconds. DR assumes the copy is trustworthy; this page is for when it is not. - **One custodian for data and lock, unexamined.** Platform-enforced locks (append-only, DataLock) are strong and still one vendor, one appliance, one console. For the crown jewels, a second custodian — a vendor-operated vault or tape — is the honest shape. ## Questions this guide answers ### What is the difference between immutable, air-gapped and WORM backups? Immutable means the copy cannot be modified or deleted inside its retention — enforced by the storage (object lock in compliance mode, hardware WORM), by a vendor custodian you cannot reach, by the backup platform's own design (append-only filesystems, DataLock with quorum), or by a software flag an administrator can clear (governance mode). Air-gapped means the copy sits where the attacker's credentials and network cannot reach — logically (a separate tenant and credentials) or physically (tape, offline). WORM — write once, read many — is one way storage enforces immutability, not a synonym for it. They answer different failure modes and are not tiers. ### Which backup products' immutability cannot be removed by an administrator? From vendor documentation: Veeam Data Cloud Vault (always-on), Commvault Air Gap Protect, Cohesity FortKnox (irrevocable DataLock on object lock), Veritas Alta Recovery Vault and Druva (Data Lock cannot be disabled once set) allow nobody to delete inside retention; Rubrik's Retention Lock can be removed only by Rubrik Support with two authorised customer officers; Cohesity DataLock on the platform needs quorum and MFA; Acronis in compliance mode cannot be disabled by anyone including Acronis support — but Acronis is in governance mode by default, where an administrator can disable it with a 14-day grace. Veeam hardened repositories and object-lock targets, and NinjaOne's object lock, depend on the mode chosen. Barracuda's cloud-copy deletion process is not documented. ### Is disaster recovery the same as cyber recovery? No. Disaster recovery assumes the backup or replica is trustworthy and optimises for speed — replication will copy ransomware to the second site within its RPO. Cyber recovery assumes the copy, the network and the credentials may be compromised: it locks the copy where no administrator can remove it, isolates it, scans it for encryption and implants, and restores into a clean room. Veeam, Commvault, Cohesity, Rubrik and Druva sell both; they are different SKUs and different rehearsals. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery* --- # Backup & Cyber Resilience — can you get it back — and can you get it back after someone destroyed the backups too *A TechBag category guide. Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/backup-cyber-resilience - Routes: 4 ## The routes ### Backup & Recovery Every product here backs things up. What separates them is the day you actually need a restore — at volume, under pressure. - 16 products compared - Guide: https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery - Boundary terms resolved: Backup · Replication · Snapshot · Archive ### SaaS Backup Microsoft’s shared-responsibility model says they keep the service running. Securing your data is explicitly your job. - 11 products compared - Guide: https://www.thetechbag.com/browse/backup-cyber-resilience/saas-backup - Boundary terms resolved: Recycle bin and versioning · Native retention policies · True backup · The shared-responsibility model ### Disaster Recovery RPO and RTO are the only two numbers in this category — and most organisations have never tested whether theirs are real. - 9 products compared - Guide: https://www.thetechbag.com/browse/backup-cyber-resilience/disaster-recovery - Boundary terms resolved: RPO — how much you lose · RTO — how long until you are back · HA vs DR · DR vs backup ### Cyber Recovery Ransomware operators target backups first. If your backup can be deleted by an admin credential, it is not a recovery plan. - 15 products compared - Guide: https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery - Boundary terms resolved: Immutable · Air-gapped · WORM · Cyber recovery vs DR --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/backup-cyber-resilience* --- # Most PAM projects stall not because the product failed, but because nobody could get the accounts into it. *Privileged Access Management — a TechBag decision guide. Last reviewed 2026-09-07.* > A PAM platform takes the credentials that can change or destroy everything — domain administrators, root, network gear, database owners, cloud consoles, and the service accounts no human ever logs into — out of people’s hands and into a vault that brokers, records and rotates them. **The checkable fact:** CyberArk sells the human vault and Secrets Manager separately, because an application requesting a credential ten thousand times an hour is not a person checking one out. Most estates buy the first and discover the second two years later. - Canonical: https://www.thetechbag.com/browse/identity-access/privileged-access-management - Category: [Identity & Access](https://www.thetechbag.com/browse/identity-access) - Products compared: 17 ## What privileged access management actually is A vault, a broker and a recorder. The **vault** holds the credentials for accounts that can change or destroy your estate, rotating them so nobody memorises one. The **broker** gives a named person time-limited use of an account without ever showing them the password — ideally just-in-time, so no standing privilege exists between requests. The **recorder** keeps a replayable record of what was done, which is the part auditors ask for. The variable nobody prices is the **machine half**. Service accounts, API keys, pipeline credentials and the tokens AI agents now carry outnumber your administrators many times over, and a vault designed for humans checking credentials out is a poor fit for an application requesting one unattended, constantly. Read the [IAM, SSO & MFA guide](https://www.thetechbag.com/browse/identity-access/iam-sso-mfa) for who gets in at all, and the [identity governance guide](https://www.thetechbag.com/browse/identity-access/identity-governance) for proving the access granted was correct. **The most common mis-purchase.** Endpoint privilege management bought as PAM. PEDM removes local administrator rights from laptops and elevates applications — it vaults nothing. If the audit finding was about server, database or network credentials, **PEDM does not answer it**, and three products on this page are PEDM. ## PAM vs PIM vs PEDM vs secrets management Four terms sold by the same vendors, often in the same slide. They are adjacent scopes, not tiers — each answers a different question, and buying one for another is the most expensive mistake in this category. ### PAM — privileged access management The umbrella and the vault: store, rotate and broker credentials for accounts that can change or destroy things, record the sessions, prove it to an auditor. Answers: who used the domain admin account at 2am, and what did they do? This is the main purchase, and the one the regulators' language points at. ### PIM — privileged identity management The lifecycle of privileged identities: which accounts are privileged, who is eligible, for how long, with approval and expiry. Microsoft's Entra PIM made the term familiar — eligible rather than permanent roles, activated on request. Overlaps PAM heavily; where PAM vaults the credential, PIM governs the entitlement. ### PEDM — privilege elevation and delegation management No vault at all. An agent on the endpoint removes standing local administrator rights and elevates named applications or commands instead. Answers: how do we take admin away from laptops without breaking the software? A different budget, a different team, and three products on this page. ### Secrets management The machine half: credentials, API keys and certificates requested by applications, pipelines and containers, unattended and at machine speed. No interactive login, no session to record, no human to approve. A vault for people and a vault for code are different products — CyberArk sells both, separately, and that tells you what you need to know. **These are adjacent scopes, not tiers.** PAM vaults and records, PIM governs the entitlement, PEDM elevates on the endpoint, secrets management serves machines. Most regulated estates need PAM and secrets management, many need PEDM for a separate audit finding, and PIM is often already sitting in a Microsoft licence you own. A product that handles administrators perfectly can be useless for pipelines — that is the machine-identity problem, and it is this category’s real story. ## The decision variables Seven variables decide this purchase. The instrument tests what documentation establishes (platform coverage, secrets capability, deployment, recording, discovery, agent model, India origin); onboarding time, break-glass and storage are prose because the honest answers come from a project plan, not a datasheet. **Deployment model.** On-premises appliance, self-hosted software, or SaaS — decided by regulator expectations as often as by preference. Indian BFSI deployments are still frequently on-prem; ask your compliance team before your architects. **What it can vault.** Windows, Unix and Linux, network devices, databases, cloud consoles, Kubernetes, SaaS administrator accounts. Coverage varies enormously and the gap is always the system you cannot replace. **Session recording and playback depth.** Full searchable video-grade recording, basic activity capture, or none. The audit asks for playback; the storage bill arrives separately. **Secrets management for applications and CI/CD.** The machine-identity cut. Purpose-built brokering for pipelines and containers, credential storage that applications can call, or nothing. Several products here are genuinely thin — marked, never eliminated on. **Just-in-time access vs standing privilege.** Whether privilege exists between requests at all. Every vendor here documents just-in-time in some form; how far it extends beyond the flagship platform is the question. **Agent vs agentless architecture.** Agentless reaches more legacy targets with less deployment friction; agents give deeper control and offline enforcement. Most serious platforms do both. **Onboarding and discovery.** Can it find the privileged accounts nobody told you about? Discovery is the difference between a vault holding fifty accounts and one holding the estate. ## The 17 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud) — CyberArk - **Who it's for:** Large and regulated estates that want the reference vault — the deepest platform coverage, the strongest session controls, and an audit story every regulator already recognises. - **The honest limitation:** The most expensive licence here and the heaviest to deploy: reported bands run to $12,000 per privileged user per year at small volumes, and the onboarding project is measured in quarters, not weeks. Secrets management for applications is a separate product (Secrets Manager), not this SKU. - **Price:** ~$1,800–12,000 (≈ ₹1,49,400) — per privileged user / year reported — the wide band is the volume curve (small deployments at the top, 1,000+ users near the floor); Self-Hosted and Privilege Cloud are separate SKUs - **Details:** https://www.thetechbag.com/cyberark/cyberark-privileged-access-manager ### CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur) — CyberArk - **Who it's for:** Platform and DevOps teams that need the machine half — secrets for pipelines, containers and applications, rotated and brokered without a human in the loop. - **The honest limitation:** Not a human PAM product: no session recording, no privileged-user workflow. It is the second purchase alongside the vault, and it is priced and deployed as its own project. - **Price:** Quote — per application / per secret-consuming workload on quote; Conjur-derived, built for CI/CD pipelines, containers and application-to-application credentials - **Details:** https://www.thetechbag.com/cyberark/cyberark-secrets-manager ### CyberArk Endpoint Privilege Manager — CyberArk - **Who it's for:** Estates removing local administrator rights from laptops without breaking the applications that need elevation. - **The honest limitation:** PEDM, not PAM: it elevates on the endpoint and vaults nothing. Buying it expecting a credential vault for servers and network devices is the most common mis-purchase in this category. - **Price:** Quote — per endpoint / year on quote; removes local admin rights on Windows and macOS and elevates per application (PEDM), not a credential vault - **Details:** https://www.thetechbag.com/cyberark/cyberark-endpoint-privilege-manager ### CyberArk Vendor PAM — CyberArk - **Who it's for:** Organisations whose auditors ask who from which supplier touched production, and when — without issuing the supplier a VPN account. - **The honest limitation:** Third-party access only — your own administrators are the main PAM SKU. Priced per vendor, which is cheap at ten suppliers and not at two hundred. - **Price:** Quote — per external vendor / year on quote; biometric-verified access for third parties with no VPN and no agent on their machine - **Details:** https://www.thetechbag.com/cyberark/cyberark-vendor-pam ### BeyondTrust Password Safe — BeyondTrust - **Who it's for:** Estates that want a full vault with discovery and session management, and prefer paying for the machines they manage rather than the people who log in. - **The honest limitation:** The per-asset meter is cheap for a few administrators over many servers and expensive the other way round; the published figures are a public-sector schedule, not a commercial list. Application secrets are handled, but this is not a CI/CD secrets platform. - **Price:** ~$157 (≈ ₹13,031) — per managed asset / year on the US GSA public-sector schedule (about $1,355 per named user / year on the same list); commercial pricing is a quote — the per-asset meter is the one to model - **Details:** https://www.thetechbag.com/beyondtrust/beyondtrust-password-safe ### BeyondTrust Endpoint Privilege Management — BeyondTrust - **Who it's for:** Estates taking local admin away across a mixed Windows, macOS and Unix fleet with application-level rules rather than blanket elevation. - **The honest limitation:** PEDM again — it removes standing local admin, it does not vault credentials for network devices, databases or cloud consoles. The Unix server coverage is the differentiator against endpoint-only rivals. - **Price:** Quote — per endpoint / year on quote; least privilege and application control for Windows, macOS, Linux and Unix servers (PEDM) - **Details:** https://www.thetechbag.com/beyondtrust/beyondtrust-endpoint-privilege-management ### BeyondTrust Privileged Remote Access — BeyondTrust - **Who it's for:** Teams whose real problem is how administrators and suppliers reach production at all — a brokered, recorded path instead of VPN plus jump box. - **The honest limitation:** Access brokering with credential injection rather than a full enterprise vault: password rotation depth and discovery live in Password Safe, which is the companion purchase. - **Price:** Quote — per concurrent or named user / year on quote; brokered privileged sessions for insiders and vendors with full recording, no VPN - **Details:** https://www.thetechbag.com/beyondtrust/beyondtrust-privileged-remote-access ### ARCON Privileged Access Management — ARCON - **Who it's for:** Indian BFSI and regulated estates that want the vault, the auditor's report format and the support engineer in the same country, time zone and currency. - **The honest limitation:** Deepest where its market is: platform coverage and the ecosystem of integrations are narrower than CyberArk's, and Kubernetes-native secrets for CI/CD are not its strength. Quote-only, with no public list to anchor a negotiation. - **Price:** Quote (INR) — per privileged user and per managed target, quoted in INR; Mumbai-built and Mumbai-supported, with reporting shaped for RBI and SEBI CSCRF audits; on-prem is the common BFSI deployment - **Details:** https://www.thetechbag.com/arcon/arcon-pam ### ARCON Endpoint Privilege Management — ARCON - **Who it's for:** Indian estates extending least privilege to laptops and desktops from the same vendor that runs their server vault. - **The honest limitation:** Endpoint elevation only, Windows-centric, and documented scale is smaller than the server-side product's. Not a credential vault. - **Price:** Quote (INR) — per endpoint, quoted in INR; least privilege, application allow-listing and elevation on Windows endpoints - **Details:** https://www.thetechbag.com/arcon/arcon-epm ### ARCON My Vault — ARCON - **Who it's for:** Organisations that want employees' shared and personal business credentials in a managed vault rather than a spreadsheet. - **The honest limitation:** A password manager, not PAM: no session recording, no just-in-time elevation, no discovery of privileged infrastructure accounts. It sits beside the PAM purchase, never instead of it. - **Price:** Quote (INR) — per user, quoted in INR; a personal and team credential vault for business users — passwords, cards, documents — not privileged infrastructure sessions - **Details:** https://www.thetechbag.com/arcon/arcon-my-vault ### Securden Unified PAM — Securden - **Who it's for:** Mid-market and lean enterprise teams that want vault, session recording, discovery and remote access in one all-inclusive per-user number instead of six line items. - **The honest limitation:** No public list price despite the simple meter, and documented deployments are smaller than CyberArk's or BeyondTrust's — flagged rather than ruled out above 1,000 privileged accounts. Application secrets are stored and served, but this is not a CI/CD-native secrets platform. - **Price:** Quote — priced purely on the number of users — no per-target or per-connector add-ons, which is the whole pitch; quote-based, with a free Password Vault starter for up to five users - **Details:** https://www.thetechbag.com/securden/securden-unified-pam ### Securden Endpoint Privilege Manager — Securden - **Who it's for:** Teams removing local admin from laptops on the same all-inclusive commercial model as the Securden vault. - **The honest limitation:** Endpoint elevation only; no infrastructure vault. Documented scale is mid-market. - **Price:** Quote — per endpoint on quote; removes local admin rights and elevates named applications on Windows and macOS - **Details:** https://www.thetechbag.com/securden/securden-endpoint-privilege-manager ### One Identity Safeguard — One Identity - **Who it's for:** Estates that want the vault and the governance platform from one vendor, with behavioural session analytics on privileged sessions. - **The honest limitation:** Sold as an appliance-first platform with a heavier deployment than the SaaS-native options, and quote-only. Its strength is the Identity Manager pairing — standalone, it competes without that advantage. - **Price:** Quote — per user or per asset on quote; a hardened appliance heritage with session analytics, and the tightest coupling to Identity Manager for governance-plus-PAM estates - **Details:** https://www.thetechbag.com/oneidentity/oneidentity-safeguard ### One Identity Cloud PAM Essentials — One Identity - **Who it's for:** Mid-market teams that want brokered, recorded privileged sessions quickly, without an appliance project. - **The honest limitation:** Session access rather than a full enterprise vault: no discovery, no application secrets, and documented deployments are smaller. The fuller product is Safeguard. - **Price:** Quote — per user / month on quote; SaaS-delivered session-based privileged access with recording — no appliance to rack - **Details:** https://www.thetechbag.com/oneidentity/oneidentity-cloud-pam-essentials ### Okta Privileged Access — Okta - **Who it's for:** Okta estates that want just-in-time server and cloud access governed by the same identity, policy and lifecycle as everything else. - **The honest limitation:** Built for cloud and Linux/Windows server access from an Okta-centric estate: network devices, mainframes and the long tail of legacy targets that classic vaults cover are not its ground. It assumes you are already an Okta customer. - **Price:** Bundled ~$17 (≈ ₹1,411) — per user / month inside Okta's Essentials workforce bundle (list) rather than as a standalone vault; ties privileged server and cloud access to the Okta identity you already carry - **Details:** https://www.thetechbag.com/okta/okta-privileged-access ### miniOrange PAM — miniOrange - **Who it's for:** Cost-sensitive Indian estates that want a vault, session recording and web-application privileged access without an enterprise-scale licence or an enterprise-scale project. - **The honest limitation:** The value option, and priced like one: documented deployments are smaller than the enterprise vaults', deep platform coverage (mainframe, exotic network gear) is thinner, and it is not a CI/CD secrets platform. - **Price:** From ~$2.16 (≈ ₹179) — per user / month — miniOrange publishes workforce identity from ₹180 per user per month; PAM is quoted on top and remains the cheapest entry point of the vendors here, in INR, from an India-built vendor - **Details:** https://www.thetechbag.com/miniorange/miniorange-pam ### ARCON Global Remote Access — ARCON - **Who it's for:** Indian estates whose administrators and suppliers work remotely and need a recorded, controlled path into production rather than a VPN account. - **The honest limitation:** Session brokering rather than a full credential vault — rotation, discovery and the enterprise workflow live in ARCON PAM, which is the companion purchase. Documented scale is smaller than the flagship. - **Price:** Quote (INR) — per user, quoted in INR; brokered and recorded remote privileged sessions for distributed teams and third parties, without a VPN into the network - **Details:** https://www.thetechbag.com/arcon/arcon-global-remote-access ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Windows servers.** Rules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur) — does not vault Windows servers or domain accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access. **Unix and Linux.** Rules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, ARCON Endpoint Privilege Management, ARCON My Vault and Securden Endpoint Privilege Manager — does not vault Unix / Linux accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access. **Network devices.** Rules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials, Okta Privileged Access and miniOrange PAM — does not vault network device credentials. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard and ARCON Global Remote Access. **Databases.** Rules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials, Okta Privileged Access and ARCON Global Remote Access — does not vault database accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard and miniOrange PAM. **Cloud consoles.** Rules out CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, ARCON My Vault and Securden Endpoint Privilege Manager — does not vault cloud console access. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access. **SaaS admin accounts.** Rules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, Securden Endpoint Privilege Manager, One Identity Safeguard and ARCON Global Remote Access — does not vault SaaS admin accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON My Vault, Securden Unified PAM, One Identity Cloud PAM Essentials, Okta Privileged Access and miniOrange PAM. **Application and pipeline secrets.** Rules out CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials and ARCON Global Remote Access — no application or pipeline secrets capability; it vaults credentials for people. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, Okta Privileged Access and miniOrange PAM. It flags CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud) — Stores and serves application credentials, but is not a CI/CD-native secrets platform, BeyondTrust Password Safe — Stores and serves application credentials, but is not a CI/CD-native secrets platform, ARCON Privileged Access Management — Stores and serves application credentials, but is not a CI/CD-native secrets platform, Securden Unified PAM — Stores and serves application credentials, but is not a CI/CD-native secrets platform, One Identity Safeguard — Stores and serves application credentials, but is not a CI/CD-native secrets platform, Okta Privileged Access — Stores and serves application credentials, but is not a CI/CD-native secrets platform and miniOrange PAM — Stores and serves application credentials, but is not a CI/CD-native secrets platform — marked, not removed. **Kubernetes workloads.** Rules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access — Kubernetes-native secrets brokering not documented. That leaves CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur). **On-premises deployment.** Rules out CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, One Identity Cloud PAM Essentials and Okta Privileged Access — SaaS only; there is no self-hosted deployment. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, miniOrange PAM and ARCON Global Remote Access. **Pure SaaS delivery.** Rules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, miniOrange PAM and ARCON Global Remote Access — the deployment includes a self-hosted or on-premises component you run. That leaves CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, One Identity Cloud PAM Essentials and Okta Privileged Access. **Full session recording.** Rules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur) and ARCON My Vault — no session recording; CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management and Securden Endpoint Privilege Manager — basic activity capture, not full session recording with playback. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access. **Account discovery.** Rules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, One Identity Cloud PAM Essentials, Okta Privileged Access and ARCON Global Remote Access — no automated discovery of unknown privileged accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard and miniOrange PAM. **Agentless targets.** Rules out CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, Securden Endpoint Privilege Manager and Okta Privileged Access — requires an agent on the managed system. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON My Vault, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, miniOrange PAM and ARCON Global Remote Access. **India-built, INR.** Rules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, One Identity Safeguard, One Identity Cloud PAM Essentials and Okta Privileged Access — a global vendor; INR quoting is via the channel, not the vendor's own price list. That leaves ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, miniOrange PAM and ARCON Global Remote Access. **Above 1,000 privileged accounts.** Rules nothing out on published terms. It flags ARCON Endpoint Privilege Management — Unverified above 1,000 privileged accounts, ARCON My Vault — Unverified above 1,000 privileged accounts, Securden Unified PAM — Unverified above 1,000 privileged accounts, Securden Endpoint Privilege Manager — Unverified above 1,000 privileged accounts, One Identity Cloud PAM Essentials — Unverified above 1,000 privileged accounts, miniOrange PAM — Unverified above 1,000 privileged accounts and ARCON Global Remote Access — Unverified above 1,000 privileged accounts — marked, not removed. **Onboarding is the project, not the product.** Every vendor here can vault a Windows administrator account in an afternoon. What separates them is account 1,000: the service account nobody owns, the appliance whose password is in a runbook, the application that breaks when its credential rotates. Discovery (CyberArk, BeyondTrust, ARCON, Securden, One Identity Safeguard, miniOrange) finds the accounts; agreeing who owns each one is a governance conversation with your own teams, and it is where PAM projects stall. TechBag's delivery figures for accounts onboarded per week by platform are [TechBag to confirm]. **Secrets management is a different product.** Vaulting a credential a human checks out is not the same as brokering a secret an application requests ten thousand times an hour, unattended, with no interactive login. Only CyberArk Secrets Manager on this page is a purpose-built machine-identity platform; the full vaults (CyberArk PAM, BeyondTrust, ARCON, Securden, One Identity, miniOrange, Okta) store and serve application credentials but are not CI/CD-native — marked partial, flagged, never eliminated. If your pipelines and containers are the gap, price the second product now rather than discovering it in year two. **Break-glass and the day the vault is down.** Every deployment needs an emergency path when the vault, the directory or the network is unavailable — sealed credentials, an offline copy, a documented two-person procedure. Every vendor supports one; almost nobody tests it. Put the break-glass rehearsal in the implementation plan, not the runbook. **Session-recording storage.** Full recording produces video-scale data. Retention is a policy decision with a storage bill attached, and it is not in the licence — see the cost section. Ask for gigabytes per recorded hour and set retention before go-live, not after the first audit. **Under 50 privileged accounts.** Rules nothing out on published terms: Securden, miniOrange, One Identity Cloud PAM Essentials and Okta Privileged Access are sold to small estates; CyberArk and BeyondTrust publish no floor but are enterprise-positioned. Where a small estate should stop at a vault and skip the full platform is delivery judgement: [TechBag to confirm]. ## Eight situations, eight shortlists — with the onboarding named Each shortlist names what the first ninety days look like, not only which product wins a feature grid. If a regulator is driving this, start from the first row. ### Indian bank or NBFC — the auditor arrives and the report format matters **Shortlist:** ARCON Privileged Access Management, CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), Securden Unified PAM **Why:** ARCON is Mumbai-built with reporting shaped for RBI and SEBI CSCRF audits and support in the same time zone; CyberArk is the platform every regulator already recognises; Securden gives the same controls on an all-inclusive per-user number. **Trade-off:** ARCON's platform breadth and CI/CD secrets are thinner than CyberArk's; CyberArk's licence and implementation are several times the cost. The regulator cares that privileged access is controlled and evidenced — not whose logo is on it. ### The pipelines are the problem — credentials live in CI/CD variables and container images **Shortlist:** CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), Securden Unified PAM **Why:** CyberArk Secrets Manager is the only purpose-built machine-identity platform here — pipelines, containers and application-to-application credentials brokered without a human. The full vaults store application credentials but are not CI/CD-native. **Trade-off:** It is a second product with its own project and its own quote. Buying only the human vault and hoping it covers pipelines is how the machine half stays unsolved for two more years. ### Few administrators, many servers **Shortlist:** BeyondTrust Password Safe, Securden Unified PAM, ARCON Privileged Access Management **Why:** BeyondTrust's per-managed-asset meter (about $157 per asset per year on the US GSA schedule) suits a small team over a large estate; Securden's per-user-only model suits the same shape from the other direction; ARCON quotes both dimensions in INR. **Trade-off:** The two meters invert: per-asset is cheap for five admins over 500 servers and expensive for 200 admins over 50; per-user is the reverse. Model both on your real numbers before reading a quote. ### Third parties and vendors need into production **Shortlist:** CyberArk Vendor PAM, BeyondTrust Privileged Remote Access, ARCON Global Remote Access **Why:** CyberArk Vendor PAM gives biometric-verified, VPN-less access priced per supplier; BeyondTrust Privileged Remote Access brokers and records the session for insiders and vendors alike. **Trade-off:** Per-vendor pricing is cheap at ten suppliers and painful at two hundred; the brokered-session products price per user instead. Both beat issuing the supplier a VPN account nobody reviews. ### Remove local admin rights from laptops — the audit finding everyone gets **Shortlist:** CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, Securden Endpoint Privilege Manager **Why:** All three are PEDM: they take standing local administrator rights away and elevate named applications instead. BeyondTrust extends the same model to Unix and Linux servers. **Trade-off:** None of these vaults anything. If the finding was about server, database or network credentials, PEDM does not answer it — that is the vault, and it is a separate purchase. ### Already on Okta, and privileged server access is the remaining gap **Shortlist:** Okta Privileged Access, One Identity Cloud PAM Essentials, Securden Unified PAM **Why:** Okta Privileged Access puts just-in-time server and cloud access under the identity, policy and lifecycle you already run; One Identity Cloud PAM Essentials is the vendor-neutral SaaS equivalent. **Trade-off:** Okta's version assumes an Okta-centric estate and does not reach network devices, mainframes or the legacy long tail. If those matter, you are buying a classic vault regardless of who runs your SSO. ### Mid-market, no dedicated identity team, needs it running this quarter **Shortlist:** Securden Unified PAM, miniOrange PAM, One Identity Cloud PAM Essentials **Why:** Securden's all-inclusive per-user pricing and miniOrange's low INR entry point (workforce identity published from ₹180 per user per month, PAM quoted on top) are the two fastest routes to a working vault; Cloud PAM Essentials needs no appliance. **Trade-off:** All three are flagged unverified above 1,000 privileged accounts — not ruled out, but ask for a reference at your size before signing a three-year term. ### Governance and PAM bought together, one vendor, one roadmap **Shortlist:** One Identity Safeguard, CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), Okta Privileged Access **Why:** One Identity pairs Safeguard with Identity Manager more tightly than anyone here; CyberArk and Okta each sell governance beside the vault on one platform. **Trade-off:** One platform means one negotiation and one throat to choke — and one vendor's roadmap for two disciplines that are usually run by different teams on different timelines. ## At scale PAM scales by accounts onboarded, not licences bought. The bill follows the meter; the timeline follows how many owners you have to find. ### 50 privileged accounts — Getting started is the constraint - Any product here covers it; the question is how fast it stands up. Securden, miniOrange, Cloud PAM Essentials and Okta Privileged Access reach a working vault fastest. - The accounts are mostly known — domain admins, a few servers, the firewall. Discovery matters less than the workflow your administrators will actually use. - All-inclusive per-user pricing is cheapest at this size; per-asset meters rarely are. **The test:** Vault the domain administrator account and have someone use it through the broker for a week. If they route around it, the product is wrong or the workflow is. ### 250 privileged accounts — Coverage and ownership are the constraint - Discovery finds accounts nobody claims — service accounts, appliance logins, the application credential in a config file. Each needs an owner before it can be onboarded. - Platform coverage starts to bite: the one legacy system, the network gear, the database that must not have its password rotated on a schedule. - The machine half becomes visible — pipelines and applications now hold more credentials than your administrators do. **The test:** Ask for a named reference at your size and industry, and ask them how long onboarding actually took versus the plan. ### 1,000 privileged accounts — The machine half and the evidence are the constraint - Non-human identities dominate: service accounts, pipeline credentials, cloud workload identities, agent tokens. A human-only vault is now covering a minority of what signs in. - Session-recording storage and retention are a real budget line; certification evidence for the regulator is a recurring process, not a report. - Securden, miniOrange, ARCON EPM and One Identity Cloud PAM Essentials are flagged unverified at this size — not ruled out; ask for the reference. **The test:** Count your non-human identities and your human ones. If the first number is larger and only the second is vaulted, you have found the next project. CyberArk, BeyondTrust, ARCON, One Identity Safeguard and Okta document large estates; Securden, miniOrange, ARCON EPM, ARCON My Vault, Securden EPM and One Identity Cloud PAM Essentials are flagged unverified above 1,000 privileged accounts. Where a specific product strains for your estate: [TechBag to confirm]. ## Leaving a PAM platform means re-onboarding every account The vault holds credentials, workflows, approvals and years of recordings. None of it moves. Switching is the original onboarding project run a second time, with the first platform still live. **Re-onboarding** — Every account is discovered, owned, connected and tested again on the new platform. The plan that took two quarters takes two quarters. *(The project, again)* **The recordings** — Session recordings live in the old platform's format and storage. Audit and legal retention decide how long you keep it running read-only after the switch. *(Keep it for retention)* **Integrations and connectors** — Ticketing approval flows, SIEM feeds, directory joins and custom connectors are per platform and rebuilt from scratch. *(Rebuild and re-test)* **The overlap** — Both vaults run until every account is migrated and rotated. Two PAM bills for two quarters is the honest cost of not leaving a gap in the control the regulator asked for. *(Overlap, not a gap)* **Re-onboarding effort, recording retention and overlap cost for your estate:** [TechBag to confirm] — TechBag scopes it from your account inventory and audit retention rules. ## Per user, per asset, or per target — the difference is often 5× What you may already hold, the products priced on their own meters at three estate sizes in USD and INR, and what the licence line leaves out — which, for PAM, starts with the onboarding project. ### Do you already own one? Four places privileged control may already sit. Two are real; none is a vault for your infrastructure. - **Microsoft Entra ID P2 — Partly.** Privileged Identity Management gives eligible-not-permanent Entra and Azure roles with approval and expiry — real PIM, listed at about $9–10 per user per month. It governs Microsoft’s own roles; it vaults no server, database or network credential. - **Your endpoint or UEM product — No.** Some remove local admin rights (PEDM territory). None vaults, brokers or records privileged infrastructure sessions. - **A team password manager — No.** Shared credentials in a business vault — ARCON My Vault is exactly this. No rotation against the target system, no session recording, no discovery, no audit trail an auditor will accept for privileged infrastructure. - **Cloud-native privilege tools — Partly.** AWS IAM roles, Azure PIM and GCP IAM govern privilege inside that cloud, on consumption. They stop at the cloud boundary and do not reach the data centre. If what you own covers the accounts that actually worry your auditor, we say so. It costs us a sale and saves you one. ### What the rest actually cost Reported and published meters (INR for scale), worked at three estate sizes. **The meters are not comparable** — per privileged user, per managed asset and per target system can differ by 5× on the same estate, so each line states its own unit. The India-built and mid-market options are priced explicitly, because no other comparison does. ### What isn't in the licence price - **The onboarding project.** Discovery, finding an owner for every account, connectors, application testing and the rotation exceptions — measured in quarters at enterprise scale and the single largest hidden number in this category. Your figure: [TechBag to confirm]. - **Session-recording storage.** Full recording is video-scale data with a retention policy attached. It is not in the licence, it grows with adoption, and the audit that asks for playback also asks how long you keep it. Size it before go-live. - **The break-glass rehearsal and the exceptions.** The emergency path, tested; the application whose credential cannot rotate on a schedule; the legacy system that needs a bespoke connector. Every deployment has them, no licence includes them. ## What goes wrong Documented behaviour and project outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in month nine. - **Discovery finding thousands of accounts nobody will own.** The scan succeeded and produced a list no team would claim. Onboarding stalls at the ownership conversation, not the technology — start it before the purchase order. - **Break-glass procedures that were never tested.** The vault, the directory or the network was down and nobody could reach the emergency credentials. Rehearse it quarterly; write down who holds what. - **Session recording storage growing without a retention plan.** Recording was switched on for everything; a year later storage was the largest line in the programme. Set retention by system class before go-live. - **Agents that don't cover the one legacy system that mattered.** The vault covered 95% of the estate and not the mainframe, the appliance or the industrial system the auditor asked about. Write the awkward list first, and test against it. - **Buying PAM and never getting past the first fifty accounts.** The domain admins went in and the project stopped. The remaining thousands are service accounts — which is the machine-identity problem wearing a different hat. - **PEDM bought to answer a vault finding.** Local admin rights were removed from laptops; the audit was about database and network credentials. Different product, different budget, same brochure vocabulary. - **Rotation breaking the application nobody documented.** A credential rotated on schedule and a batch job failed at 3am. Application-aware exceptions are a design decision, not a support ticket. - **The pipelines never entering the vault.** Human accounts are governed; CI/CD variables, container images and cloud workload identities are not. Non-human identities outnumber humans in most estates — and are usually outside the programme entirely. ## Questions this guide answers ### What is the difference between PAM, PIM, PEDM and secrets management? PAM is the vault and broker for credentials that can change or destroy things, with session recording — the main purchase. PIM governs the lifecycle and eligibility of privileged identities (Microsoft's Entra PIM made the term familiar: eligible rather than permanent roles, activated on request). PEDM has no vault at all — an agent removes standing local administrator rights on endpoints and elevates named applications instead. Secrets management is the machine half: credentials and keys requested by applications, pipelines and containers, unattended. They are adjacent scopes, not tiers, and CyberArk selling the human vault and Secrets Manager as separate products is the clearest statement of that. ### Do Indian regulators require privileged access management? Not by that product name in every case, so read the source. The RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (issued 7 November 2023, in force 1 April 2024) requires multi-factor authentication for privileged users of critical information systems and need-based access, and defines a privileged user explicitly. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF, August 2024) sets access-management requirements including least privilege and multi-factor authentication for privileged access for regulated entities. The IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) set access-management requirements covering privileged access and periodic access reviews. In practice these are met with a PAM platform; the obligation is the control, not the product category. ### Which PAM products are India-built? ARCON (Mumbai), Securden and miniOrange are India-built and quote in INR. ARCON is the deepest of the three for regulated infrastructure — on-premises as a first-class deployment, BFSI-shaped audit reporting, local support — while being narrower than CyberArk on platform breadth, integration ecosystem and CI/CD secrets. Securden's pitch is all-inclusive per-user pricing with no per-target add-ons; miniOrange is the lowest entry point here, publishing workforce identity from ₹180 per user per month with PAM quoted on top. All three are flagged unverified above 1,000 privileged accounts rather than ruled out. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/identity-access/privileged-access-management* --- # You probably already own an identity provider. The question is whether it does what you’re about to buy — and where it stops. *IAM, SSO & MFA — a TechBag decision guide. Last reviewed 2026-09-07.* > An identity platform holds who exists, proves they are who they claim with one or more factors, and decides — per application, per device, per risk signal — whether this sign-in proceeds. Everything else on a vendor’s slide is a variation on those three jobs. **The checkable fact:** Microsoft Entra ID P1 lists at roughly $6–7 per user per month and is already inside Microsoft 365 E3. Most estates that buy a second identity provider are buying one specific gap: the VPN, the legacy application, or the SaaS Microsoft does not reach well. - Canonical: https://www.thetechbag.com/browse/identity-access/iam-sso-mfa - Category: [Identity & Access](https://www.thetechbag.com/browse/identity-access) - Products compared: 18 ## What iam, sso & mfa actually is Three layers that get sold as one. The **directory** is the list of who exists and what they belong to. **Single sign-on** lets one authenticated session open many applications, so people stop keeping a password per system. **Multi-factor authentication** adds proof beyond the password — and the kind of proof matters enormously, because a push notification can be tapped by a tired person under attack and a hardware key cannot be phished at all. The fourth thing, which no brochure leads with: **most of what signs in is not a person**. Service accounts, API consumers, CI/CD pipelines and now AI agents acting on a user’s behalf authenticate constantly, and workforce identity platforms handle them thinly. The vault-and-secrets half of that problem is the [PAM guide](https://www.thetechbag.com/browse/identity-access/privileged-access-management); proving the access anyone holds was correct is the [governance guide](https://www.thetechbag.com/browse/identity-access/identity-governance). **The most common mis-purchase.** Customer identity bought as workforce identity, or the reverse. CIAM is priced per **monthly active user** at consumer volume; workforce identity is priced per employee. Put a million customers on a workforce meter and the bill is catastrophic; put employees on a CIAM platform and you have no lifecycle, no governance and no conditional access worth the name. ## IAM vs SSO vs MFA vs directory · workforce vs customer identity Four words used interchangeably in the same sentence, plus the one split that changes the price by orders of magnitude. These are adjacent scopes, not tiers. ### Directory The list: who exists, what groups they belong to, what attributes they carry. Active Directory on premises, Entra ID, Okta Universal Directory, Google's directory. Everything else authenticates against it. Answers: does this person exist here, and what are they? It authenticates nothing on its own for modern SaaS. ### SSO — single sign-on One authenticated session opening many applications through SAML, OIDC or OAuth. Answers: how do people reach fifty applications without fifty passwords? It says nothing about how strongly the first sign-in was proved — which is why SSO without strong factors just makes one stolen password more useful. ### MFA — multi-factor authentication Proof beyond the password. Not one thing: SMS and push are phishable and vulnerable to fatigue attacks; FIDO2 security keys and passkeys are phishing-resistant by design. 'Supports MFA' is not an answer — ask which factors, and which accounts must use the strong ones. ### Workforce vs customer identity (CIAM) Same vocabulary, different products. Workforce identity governs employees and contractors: lifecycle, groups, conditional access, per-user pricing. CIAM handles customers at consumer volume: registration, social login, consent, progressive profiling, priced per monthly active user. Buying one for the other is the expensive mistake in this category. **These are adjacent scopes, not tiers.** The directory lists, SSO connects, MFA proves, and CIAM is a different product for a different population. Most estates already own a directory and some SSO; what they are actually shopping for is a specific gap — a legacy protocol, a phishing-resistant factor, or a population the incumbent cannot price. ## The decision variables Seven variables decide this purchase. The instrument tests what documentation establishes (audience, factors, legacy protocols, deployment, policy depth, India); what you already own and the machine-identity gap are prose, because the honest answer depends on your invoice and your pipelines. **What you already have, and where it stops.** Entra ID P1 or P2, Google Workspace tier, on-premises Active Directory. Each covers real ground and stops somewhere specific — usually legacy protocols, non-Microsoft SaaS depth, or governance. **Workforce vs customer identity.** Different products despite shared vocabulary, and different meters: per employee versus per monthly active user. The single most expensive thing to get wrong here. **Phishing-resistant MFA.** FIDO2 security keys and passkeys versus push and one-time codes. Push fatigue is a live attack technique, not a theoretical one — documented FIDO2 support is recorded here per product, and marked unknown where the documentation does not establish it. **Directory sync and legacy application support.** LDAP, RADIUS, header-based access and Kerberos for the applications that cannot speak SAML. This list decides shortlists more often than modern features do. **Conditional access depth.** Full risk-based policy using device, network, location and behaviour signals — versus a simple allow rule. Depth is usually tier-gated, so read which tier the demo was on. **Machine and service-account authentication.** Non-human identities outnumber human ones in most estates and workforce IAM handles them thinly. Know whether this platform is expected to cover them before you assume it does. **India residency for identity data.** India-built and India-hosted options, documented in-country tenants (Okta launched these in 2026), or not documented — flagged rather than assumed. ## The 18 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Okta Single Sign-On — Okta - **Who it's for:** Estates that want the vendor-neutral identity provider with the deepest application catalogue — thousands of pre-built integrations and no argument with any cloud. - **The honest limitation:** Priced per user per month for each capability, so the total climbs fast — a mid-size estate wanting SSO plus lifecycle plus governance is realistically $18–25 per user per month before API security or device access. Service and workload authentication is not its strength. - **Price:** ~$6 (≈ ₹498) — per user / month from the Workforce Identity starter list (SSO, adaptive MFA, Universal Directory); the Essentials bundle lists around $17 with governance and privileged access included; India in-country tenants launched 2026 - **Details:** https://www.thetechbag.com/okta/okta-single-sign-on ### Okta Adaptive MFA — Okta - **Who it's for:** Organisations moving off SMS and push onto phishing-resistant factors with risk signals deciding when to challenge at all. - **The honest limitation:** Adaptive policy depth is tied to the tier you buy, and the strongest risk signals sit in the higher bundles. It authenticates people; workloads and service accounts are another conversation. - **Price:** In the ~$6 tier (≈ ₹498) — bundled into the Workforce Identity tiers rather than sold alone; FIDO2 security keys and passkeys, device and network context, and risk-based step-up - **Details:** https://www.thetechbag.com/okta/okta-adaptive-mfa ### Okta Universal Directory — Okta - **Who it's for:** Estates consolidating several directories, or moving the source of truth out of on-premises Active Directory without a big-bang migration. - **The honest limitation:** It is a directory you rent: leaving means re-homing every profile, group and attribute mapping. Directory sync is the piece that breaks quietly, and it is your job to monitor. - **Price:** In the ~$6 tier (≈ ₹498) — included in Workforce Identity tiers; a cloud directory that can be the source of truth or sit downstream of Active Directory and HR systems - **Details:** https://www.thetechbag.com/okta/okta-universal-directory ### Okta Customer Identity (Auth0) — Okta - **Who it's for:** Product teams building sign-in for customers rather than employees — where volume is millions, not thousands, and the login page is part of the product. - **The honest limitation:** Customer identity priced per monthly active user behaves nothing like workforce identity: at consumer scale the bill is a function of your growth, and buying it as workforce IAM (or the reverse) is the classic catastrophic mis-purchase. - **Price:** Per MAU — per monthly active user, on a curve that starts free for small volumes and is quoted at scale; the Auth0 developer platform with passwordless, social login and machine-to-machine tokens - **Details:** https://www.thetechbag.com/okta/okta-customer-identity ### Okta Identity Threat Protection — Okta - **Who it's for:** Okta estates that want session hijacking and post-authentication risk handled continuously rather than only at the login prompt. - **The honest limitation:** It detects and responds; it does not authenticate. Okta-centric by design — third-party signal ingestion is partner-dependent, and it is an extra line on an already per-capability bill. - **Price:** Add-on quote — add-on to Workforce Identity on quote; continuous session risk assessment with Universal Logout — ITDR, not authentication - **Details:** https://www.thetechbag.com/okta/okta-identity-threat-protection ### miniOrange SSO — miniOrange - **Who it's for:** Indian estates that want SSO at a fraction of the global list price, including for the legacy applications that cannot speak SAML. - **The honest limitation:** The value option: documented deployments are smaller than Okta's or Microsoft's, and the application catalogue and ecosystem are narrower — flagged rather than ruled out above 10,000 users. - **Price:** From ~$2.16 (≈ ₹179) — workforce identity published from ₹180 per user / month; SAML, OAuth and OpenID Connect with unusually broad legacy support and an on-premises deployment option - **Details:** https://www.thetechbag.com/miniorange/miniorange-sso ### miniOrange MFA — miniOrange - **Who it's for:** Cost-sensitive estates rolling out MFA broadly — including to contractors and shared-device workers where per-user global pricing hurts most. - **The honest limitation:** Breadth of methods over depth of risk analytics: adaptive policy is present but less sophisticated than Okta's or Microsoft's. Mid-market scale. - **Price:** From ~$2.16 (≈ ₹179) — per user / month from the same published INR tiers; 15+ authentication methods including FIDO2 keys, passkeys, TOTP, push and hardware tokens - **Details:** https://www.thetechbag.com/miniorange/miniorange-mfa ### miniOrange CIAM — miniOrange - **Who it's for:** Indian consumer products that need customer sign-in with data kept in country and a price that survives millions of users. - **The honest limitation:** Smaller ecosystem than Auth0 for developer tooling and extensibility; documented deployments are smaller. Consumer-scale references are the thing to ask for. - **Price:** Per MAU / quote — per monthly active user or per-tenant quote, in INR; customer registration, social login, consent and progressive profiling with an India-hosted option - **Details:** https://www.thetechbag.com/miniorange/miniorange-ciam ### miniOrange Directory — miniOrange - **Who it's for:** Organisations without an on-premises directory that still need LDAP-speaking applications to authenticate someone. - **The honest limitation:** A directory rather than a full identity platform — the policy, MFA and SSO capabilities are the sibling SKUs. Phishing-resistant factors are documented at the MFA product, not here. - **Price:** Quote (INR) — per user, quoted in INR; a cloud directory and LDAP service for estates with no Active Directory, or with one they are leaving - **Details:** https://www.thetechbag.com/miniorange/miniorange-directory ### Cisco Duo — Cisco - **Who it's for:** Estates whose priority is MFA in front of everything — including the VPN, the RDP jump box and the legacy application — with device health as a condition of access. - **The honest limitation:** Authentication and device trust rather than a full identity provider: it does not replace your directory or run lifecycle. An India data region is not documented — flagged, not ruled out. - **Price:** ~$3–9 (≈ ₹249) — per user / month across the Essentials, Advantage and Premier tiers; MFA, device trust and Duo Passport, with VPN and RADIUS integration as a core strength - **Details:** https://www.thetechbag.com/cisco/cisco-duo ### ManageEngine AD360 — ManageEngine - **Who it's for:** Active Directory estates that want SSO, MFA, self-service password reset, provisioning and AD auditing on their own servers, licensed per module. - **The honest limitation:** Built around Active Directory: an AD-less, cloud-native estate is not its ground. Module licensing means the capability you add next is a new line item, and per-module lists are per component, not per user. - **Price:** From ~$595 (≈ ₹49,385) — per module / year list (ADManager Plus, ADSelfService Plus, ADAudit Plus from about $595 each) bundled as AD360; India-built (Zoho), on-premises first, priced per module rather than per user - **Details:** https://www.thetechbag.com/manageengine/manageengine-ad360 ### Fortinet FortiAuthenticator — Fortinet - **Who it's for:** Fortinet estates that want authentication, certificates and two-factor tokens inside the fabric they already run, on premises. - **The honest limitation:** Fabric-centric and appliance-shaped: as a general-purpose SSO for a SaaS-heavy estate it is far behind the identity-first vendors. Conditional access is basic compared with Okta or Entra. - **Price:** Appliance / VM — licensed by user capacity on a hardware or virtual appliance, quoted through the channel; RADIUS, SAML and certificate authority services alongside FortiToken - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortiauthenticator ### InstaSafe MFA — InstaSafe - **Who it's for:** Indian estates buying MFA together with zero-trust application access from one India-built vendor, in INR. - **The honest limitation:** Documented FIDO2 and passkey support could not be established from vendor documentation — marked unknown rather than assumed. Smaller catalogue and scale than the global options; strongest when bought with the ZTNA products. - **Price:** Quote (INR) — per user / month, quoted in INR; multi-factor authentication built alongside InstaSafe's zero-trust access products, India-built and India-hosted - **Details:** https://www.thetechbag.com/instasafe/instasafe-mfa ### InstaSafe Authenticator — InstaSafe - **Who it's for:** Estates standardising on an India-hosted authenticator app rather than a global vendor's. - **The honest limitation:** An authenticator, not an identity platform: no SSO, no directory, no lifecycle. Push-based factors are phishable — the reason phishing-resistant support matters, and it is not documented here. - **Price:** Quote (INR) — per user, quoted in INR; the authenticator application itself — push, TOTP and device binding for InstaSafe and third-party services - **Details:** https://www.thetechbag.com/instasafe/instasafe-authenticator ### eMudhra SecurePass — eMudhra - **Who it's for:** Indian regulated estates that want certificate-backed, passwordless identity from a domestic certifying authority — where the same vendor also issues the digital signatures the business already uses. - **The honest limitation:** Strongest where PKI is the requirement; as a general workforce SSO the application catalogue is narrower than the identity-first vendors'. Documented deployment scale is smaller — flagged, not ruled out. - **Price:** Quote (INR) — per user, quoted in INR; identity and access with certificate-based and passwordless authentication from an Indian licensed certifying authority, with PKI for machine and document identity alongside - **Details:** https://www.thetechbag.com/emudhra/emudhra-securepass ### Scalefusion OneIdP — Scalefusion - **Who it's for:** Scalefusion UEM estates that want sign-in conditioned on the device posture their management agent already reports, without a second vendor. - **The honest limitation:** Device-trust-first identity: it assumes you run Scalefusion UEM, and as a standalone identity provider for a mixed estate it is not the purchase. FIDO2 and passkey support is not established from documentation. - **Price:** Bundled — priced within Scalefusion's UEM plans rather than standalone; identity, conditional access and single sign-on tied to device trust from the UEM agent already on the endpoint - **Details:** https://www.thetechbag.com/scalefusion/scalefusion-oneidp ### Hexnode IdP — Hexnode - **Who it's for:** Hexnode UEM estates wanting one console for the device and the identity on it, with compliance as a sign-in condition. - **The honest limitation:** Bound to the Hexnode-managed fleet: unmanaged devices, contractors and the SaaS-only estate are not its ground. Phishing-resistant factor support is not documented. - **Price:** Bundled — priced inside Hexnode UEM plans; a directory and identity provider for managed devices, with conditional access driven by device compliance - **Details:** https://www.thetechbag.com/hexnode/hexnode-idp ### LinkShadow ITDR — LinkShadow - **Who it's for:** Estates that already have an identity provider and want behavioural DETECTION across identities — particularly alongside LinkShadow NDR, where network and identity signal correlate in one console. - **The honest limitation:** This is detection layered on identity systems you already own, NOT an identity provider — it belongs beside Okta or Entra, never instead of one, so it is listed here for completeness rather than as an SSO/MFA alternative. The thinnest of LinkShadow’s three products and duplicative if you already run Microsoft Entra ID Protection, CrowdStrike or Silverfort. No independent analyst recognition for this module (the 2026 Gartner Visionaries placement is for NDR only), no India data residency, and the vendor names no customers publicly. - **Price:** Quote — quoted as a module on the CyberMeshX platform; DETECTION of identity-based attacks and privilege misuse on top of the IAM, PAM and SSO you already run — it does not issue credentials, enforce MFA or replace an identity provider - **Details:** https://www.thetechbag.com/linkshadow/linkshadow-itdr ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Workforce identity.** Rules out Okta Customer Identity (Auth0) and miniOrange CIAM — a customer identity product, priced per monthly active user. That leaves Okta Single Sign-On, Okta Adaptive MFA, Okta Universal Directory, Okta Identity Threat Protection, miniOrange SSO, miniOrange MFA, miniOrange Directory, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, InstaSafe MFA, InstaSafe Authenticator, eMudhra SecurePass, Scalefusion OneIdP, Hexnode IdP and LinkShadow ITDR. **Customer identity.** Rules out Okta Single Sign-On, Okta Adaptive MFA, Okta Identity Threat Protection, miniOrange Directory, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, InstaSafe MFA, InstaSafe Authenticator, Scalefusion OneIdP, Hexnode IdP and LinkShadow ITDR — workforce identity; per-user pricing does not survive consumer scale. That leaves Okta Universal Directory, Okta Customer Identity (Auth0), miniOrange SSO, miniOrange MFA, miniOrange CIAM and eMudhra SecurePass. **Phishing-resistant factors.** Rules nothing out on published terms. It flags miniOrange Directory — FIDO2 / passkey support not established from vendor documentation, InstaSafe MFA — FIDO2 / passkey support not established from vendor documentation, InstaSafe Authenticator — FIDO2 / passkey support not established from vendor documentation, Scalefusion OneIdP — FIDO2 / passkey support not established from vendor documentation, Hexnode IdP — FIDO2 / passkey support not established from vendor documentation and LinkShadow ITDR — Factor support not documented — marked, not removed. **LDAP applications.** Rules out Okta Adaptive MFA, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange MFA, miniOrange CIAM, InstaSafe MFA, InstaSafe Authenticator and LinkShadow ITDR — LDAP application support not documented. That leaves Okta Single Sign-On, Okta Universal Directory, miniOrange SSO, miniOrange Directory, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, eMudhra SecurePass, Scalefusion OneIdP and Hexnode IdP. **RADIUS and VPN.** Rules out Okta Universal Directory, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange CIAM, miniOrange Directory, InstaSafe Authenticator, Scalefusion OneIdP, Hexnode IdP and LinkShadow ITDR — RADIUS support not documented. That leaves Okta Single Sign-On, Okta Adaptive MFA, miniOrange SSO, miniOrange MFA, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, InstaSafe MFA and eMudhra SecurePass. **Kerberos.** Rules out Okta Single Sign-On, Okta Adaptive MFA, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange MFA, miniOrange CIAM, Cisco Duo, InstaSafe MFA, InstaSafe Authenticator, eMudhra SecurePass, Scalefusion OneIdP, Hexnode IdP and LinkShadow ITDR — Kerberos support not documented. That leaves Okta Universal Directory, miniOrange SSO, miniOrange Directory, ManageEngine AD360 and Fortinet FortiAuthenticator. **Service and workload authentication.** Rules nothing out on published terms. It flags Okta Single Sign-On — Authenticates people well; service accounts and workloads are handled thinly, Okta Adaptive MFA — Authenticates people well; service accounts and workloads are handled thinly, Okta Universal Directory — Authenticates people well; service accounts and workloads are handled thinly, Okta Customer Identity (Auth0) — Workload authentication not established from documentation, Okta Identity Threat Protection — Authenticates people well; service accounts and workloads are handled thinly, miniOrange SSO — Authenticates people well; service accounts and workloads are handled thinly, miniOrange MFA — Authenticates people well; service accounts and workloads are handled thinly, miniOrange CIAM — Authenticates people well; service accounts and workloads are handled thinly, miniOrange Directory — Authenticates people well; service accounts and workloads are handled thinly, Cisco Duo — Authenticates people well; service accounts and workloads are handled thinly, ManageEngine AD360 — Authenticates people well; service accounts and workloads are handled thinly, Fortinet FortiAuthenticator — Authenticates people well; service accounts and workloads are handled thinly, InstaSafe MFA — Authenticates people well; service accounts and workloads are handled thinly, InstaSafe Authenticator — Authenticates people well; service accounts and workloads are handled thinly, eMudhra SecurePass — Workload authentication not established from documentation, Scalefusion OneIdP — Authenticates people well; service accounts and workloads are handled thinly, Hexnode IdP — Authenticates people well; service accounts and workloads are handled thinly and LinkShadow ITDR — Workload authentication not established from documentation — marked, not removed. **Self-hosted deployment.** Rules out Okta Single Sign-On, Okta Adaptive MFA, Okta Universal Directory, Okta Customer Identity (Auth0), Okta Identity Threat Protection, Cisco Duo, InstaSafe MFA, InstaSafe Authenticator, Scalefusion OneIdP and Hexnode IdP — SaaS only. That leaves miniOrange SSO, miniOrange MFA, miniOrange CIAM, miniOrange Directory, ManageEngine AD360, Fortinet FortiAuthenticator, eMudhra SecurePass and LinkShadow ITDR. **Conditional access.** Rules out miniOrange Directory, Fortinet FortiAuthenticator and InstaSafe Authenticator — basic policy only, not risk-based conditional access; LinkShadow ITDR — no conditional access. That leaves Okta Single Sign-On, Okta Adaptive MFA, Okta Universal Directory, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange SSO, miniOrange MFA, miniOrange CIAM, Cisco Duo, ManageEngine AD360, InstaSafe MFA, eMudhra SecurePass, Scalefusion OneIdP and Hexnode IdP. **Identity data in India.** Rules nothing out on published terms. It flags Okta Single Sign-On — Documented India residency (Okta launched in-country tenants in 2026), Okta Adaptive MFA — Documented India residency (Okta launched in-country tenants in 2026), Okta Universal Directory — Documented India residency (Okta launched in-country tenants in 2026), Okta Customer Identity (Auth0) — Documented India residency (Okta launched in-country tenants in 2026), Okta Identity Threat Protection — Documented India residency (Okta launched in-country tenants in 2026), Cisco Duo — India data residency not documented, Fortinet FortiAuthenticator — India data residency not documented and LinkShadow ITDR — India data residency not documented — marked, not removed. **Above 10,000 users.** Rules nothing out on published terms. It flags miniOrange SSO — Unverified above 10,000 users, miniOrange MFA — Unverified above 10,000 users, miniOrange CIAM — Unverified above 10,000 users, miniOrange Directory — Unverified above 10,000 users, InstaSafe MFA — Unverified above 10,000 users, InstaSafe Authenticator — Unverified above 10,000 users, eMudhra SecurePass — Unverified above 10,000 users, Scalefusion OneIdP — Unverified above 10,000 users, Hexnode IdP — Unverified above 10,000 users and LinkShadow ITDR — Unverified above 10,000 users — marked, not removed. **What you already own, and where it stops.** Microsoft Entra ID P1 (about $6–7 per user per month, and inside Microsoft 365 E3) gives SSO, full conditional access and hybrid identity; P2 (about $9–10, and inside E5) adds Privileged Identity Management and risk-based sign-in; the Entra ID Governance add-on is roughly $4–7 per user per month on top depending on the base. Google's Cloud Identity Premium lists around $6 per user per month. On-premises Active Directory gives you Kerberos, LDAP and group policy and nothing for SaaS. The honest question on this page is not 'which IdP' but 'where does the one on my invoice stop' — and the answer is usually legacy protocols, non-Microsoft SaaS depth, or governance. **Push fatigue is an attack, not an inconvenience.** Attackers with a valid password send approval prompts until someone taps accept. Number matching and context help; only phishing-resistant factors — FIDO2 security keys and passkeys — remove the class. Documented FIDO2 support here: Okta, miniOrange, Cisco Duo, ManageEngine AD360, FortiAuthenticator and eMudhra SecurePass. Not established from documentation: InstaSafe MFA and Authenticator, Scalefusion OneIdP, Hexnode IdP — flagged, never ruled out. Ask for the specific factor, not the word MFA. **The legacy exception that becomes permanent.** Every estate has applications that cannot speak SAML or OIDC — a manufacturing system, a bank's core, an application whose vendor is gone. Password vaulting, header-based access or a RADIUS bridge covers them; miniOrange, ManageEngine, FortiAuthenticator, Cisco Duo and Okta all document some path. Write that list before the demo, because it decides the shortlist more often than the modern features do. **Workforce IAM and machine identity.** Everything on this page authenticates people well. Service accounts, workload identities and the tokens applications and AI agents carry are handled thinly here by design — Okta Customer Identity (Auth0) and eMudhra document machine-to-machine credentials, the rest are limited. Non-human identities outnumber human ones in most estates: the vault and secrets side of that problem is the PAM guide, and it is a separate purchase. **Under 100 users.** Rules nothing out on published terms: miniOrange, Cisco Duo and the UEM-bundled identity products (Scalefusion OneIdP, Hexnode IdP) are sold to small estates, and Entra ID P1 or Google Cloud Identity may already cover it. Okta and ManageEngine publish no floor but carry minimums through the channel — current minimums by vendor: [TechBag to confirm]. ## Eight situations, eight shortlists — with the gap named Each shortlist names the specific gap being filled, because almost nobody arrives here with no identity provider at all. If Microsoft 365 is your estate, start from the first row. ### Microsoft 365 estate — what is the gap Entra doesn't fill? **Shortlist:** Cisco Duo, Okta Single Sign-On, miniOrange SSO **Why:** Entra ID P1 already gives SSO and conditional access for the Microsoft world. Duo adds MFA and device trust in front of VPN, RDP and legacy applications Entra does not reach; Okta and miniOrange add breadth of non-Microsoft SaaS and legacy protocol support. **Trade-off:** Adding a second identity layer to Entra means two policy engines and two places a rule can be wrong. Only do it for a gap you can name — usually the VPN, the legacy application, or the non-Microsoft SaaS estate. ### Push fatigue attacks — moving to phishing-resistant factors **Shortlist:** Okta Adaptive MFA, Cisco Duo, miniOrange MFA **Why:** All three document FIDO2 security keys and passkeys with policy that can require them for the accounts that matter most, while leaving weaker factors for the long tail. **Trade-off:** Hardware keys cost money per person and get lost; passkeys need modern devices and a recovery story. Roll out to administrators and finance first — the accounts an attacker actually wants. ### Applications that cannot speak SAML **Shortlist:** miniOrange SSO, ManageEngine AD360, Fortinet FortiAuthenticator **Why:** miniOrange documents the widest legacy coverage here (LDAP, RADIUS, header-based and Kerberos) with an on-premises option; AD360 is built around Active Directory's own protocols; FortiAuthenticator brings RADIUS and certificates inside the Fortinet fabric. **Trade-off:** Every legacy bridge is a permanent exception with its own upgrade path. Price the bridge, and put a date on the application it is bridging. ### Building customer sign-in for a consumer product **Shortlist:** Okta Customer Identity (Auth0), miniOrange CIAM **Why:** Auth0 is the developer platform with the deepest extensibility; miniOrange CIAM is the India-hosted alternative with INR pricing and a consent model built for local regulation. **Trade-off:** Per-monthly-active-user pricing is a function of your growth — model it at your three-year user projection, not today's. Never buy workforce IAM for this; the meter breaks catastrophically at consumer scale. ### India-regulated — identity data must stay in the country **Shortlist:** miniOrange SSO, eMudhra SecurePass, ManageEngine AD360 **Why:** miniOrange, eMudhra and ManageEngine are India-built with on-premises or India-hosted options; eMudhra adds certificate-based passwordless from a licensed Indian certifying authority. Okta launched in-country tenants in 2026 — confirm it covers your tenant. **Trade-off:** The India-built options are flagged unverified above 10,000 users. Residency and scale pull in opposite directions here; ask for a named reference at your size. ### The UEM is already deployed — make the device part of the sign-in **Shortlist:** Scalefusion OneIdP, Hexnode IdP, Cisco Duo **Why:** Scalefusion OneIdP and Hexnode IdP turn the management agent's compliance signal into a sign-in condition from one console; Duo does the same vendor-neutrally with device health checks. **Trade-off:** The UEM-bundled options assume that UEM. If half the estate is unmanaged — contractors, BYOD, partners — device trust cannot be the only condition, and neither product is a general identity provider. ### No Active Directory at all, or leaving it **Shortlist:** Okta Universal Directory, miniOrange Directory, Okta Single Sign-On **Why:** Okta Universal Directory can be the source of truth or sit downstream of AD during a migration; miniOrange Directory gives cloud LDAP for estates that never had a domain. **Trade-off:** A rented directory is a real lock-in: every profile, group and attribute mapping is re-homed if you leave. Decide deliberately where the source of truth lives before you sync it anywhere. ### Cost-sensitive, thousands of users, MFA everywhere **Shortlist:** miniOrange MFA, Cisco Duo, InstaSafe MFA **Why:** miniOrange publishes from ₹180 per user per month and Duo's Essentials tier starts around $3 — both survive a broad rollout where per-user global lists do not; InstaSafe is the India-built option quoted in INR. **Trade-off:** InstaSafe's FIDO2 support is not documented — if phishing-resistant factors are the goal, confirm it first. Cheap MFA everywhere beats expensive MFA on half the estate, but not if the factor is phishable. ## At scale Identity scales by populations and by exceptions, not by user count alone. The bill follows the per-user list; the work follows the applications that will not cooperate. ### 100 users — What you already own is the constraint - Entra ID P1 or Google Cloud Identity Premium may already cover the whole need — check the invoice before shopping. - miniOrange, Duo and the UEM-bundled identity products are priced for this size; enterprise minimums are the thing to ask about. - One person owns identity part-time: choose the platform whose defaults you can live with, not the one with the most policy knobs. **The test:** List every application people sign into. If more than three cannot do SAML, that list is your shortlist criterion. ### 1,000 users — Exceptions and factors are the constraint - The legacy applications now need a documented bridge — LDAP, RADIUS or header-based — and each becomes a permanent exception with an owner. - Push fatigue becomes a real risk: move administrators and finance to FIDO2 or passkeys before the general rollout. - Per-capability pricing bites — SSO plus lifecycle plus governance on a global list runs to $18–25 per user per month before extras. **The test:** Price the same estate on Okta's bundle, Entra P2 plus governance, and miniOrange. The spread will be several times, and each is defensible. ### 10,000 users — Populations and residency are the constraint - Workforce, customers, contractors and machines are four different products with four meters; the CIAM decision in particular must be modelled at three-year volume. - Identity data residency becomes a board and regulator question; in-country tenancy or an India-built vendor is a contract clause, not a preference. - miniOrange, eMudhra, InstaSafe and the UEM-bundled options are flagged unverified at this size — not ruled out; ask for the reference. **The test:** Count your non-human identities against your human ones. If services outnumber staff and only staff are governed, the next project just named itself. Okta, Cisco Duo, ManageEngine and FortiAuthenticator document large estates; miniOrange, eMudhra, InstaSafe, Scalefusion OneIdP and Hexnode IdP are flagged unverified above 10,000 users. Where a specific product strains for your user population: [TechBag to confirm]. ## Leaving an identity provider touches every application The identity provider sits in front of everything. Switching it is not a data migration — it is re-federating every application, re-enrolling every factor and re-writing every policy, while both platforms are live. **Re-federating applications** — Every SAML and OIDC integration is rebuilt and re-tested against the new provider, application by application. The catalogue size you paid for is the work you now repeat. *(Application by application)* **Re-enrolling factors** — Every user re-registers their authenticator, key or passkey. It is a communications project as much as a technical one, and the help desk feels it for a month. *(Every user, again)* **The directory and its attributes** — If the old provider was the source of truth, profiles, groups and attribute mappings are re-homed. If it merely synced, you keep the source and rebuild the sync. *(Re-home or re-sync)* **The legacy bridges** — LDAP, RADIUS and header-based exceptions are per platform and rebuilt from scratch — usually last, and usually by whoever understands the application least. *(Rebuild the exceptions)* **Application re-federation effort and factor re-enrolment plan for your estate:** [TechBag to confirm] — TechBag scopes it from your application inventory and factor mix. ## Per user per month — times the capabilities you actually need What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the licence line leaves out — which, for identity, is the migration and the exceptions. ### Do you already own one? Four places an identity provider may already sit. Three are real; the question is where each stops. - **Microsoft Entra ID P1 — Often.** SSO, full conditional access and hybrid identity at roughly $6–7 per user per month — and already inside Microsoft 365 E3. Stops at governance, and at non-Microsoft depth. - **Microsoft Entra ID P2 — Often.** Adds Privileged Identity Management and risk-based sign-in at about $9–10 per user per month (inside E5). The Governance add-on is roughly $4–7 per user per month more. - **Google Workspace / Cloud Identity Premium — Partly.** Around $6 per user per month for SSO, device management and security controls for a Google-centric estate. Thin for legacy protocols and non-Google SaaS depth. - **On-premises Active Directory — Partly.** Kerberos, LDAP and group policy for the domain — and nothing for SaaS. It is the thing most people are federating from, not to. If the identity provider on your invoice already reaches your gap, we say so. It costs us a sale and saves you one. ### What the rest actually cost Published and reported per-user lists (INR for scale), worked at 100 / 1,000 / 10,000 users per year. The India-built options are priced explicitly — they are absent from every comparison written outside India, and they are frequently a fifth of the global list. ### What isn't in the licence price - **The migration.** Re-federating every application, re-enrolling every factor, rebuilding every legacy bridge — the switching-cost section above. It is the largest number in a replacement project and appears in no licence. Your figure: [TechBag to confirm]. - **The exceptions.** Every application that cannot speak SAML needs a bridge, an owner and a review date. Each one is small; together they are why identity programmes run long. - **The factors themselves.** Hardware security keys cost money per person and get lost; passkeys need modern devices; SMS costs per message and is the weakest factor you can buy. Budget the physical layer and the recovery process, not just the licence. ## What goes wrong Documented behaviour and rollout outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover after the incident. - **MFA rolled out to everyone except the accounts that mattered.** Employees got MFA; the service accounts, the break-glass admin and the VPN's local users did not. Attackers look for the exception list first. - **Push fatigue against a rollout that assumed push was enough.** Valid password, repeated prompts, one tired approval at midnight. Number matching helps; phishing-resistant factors remove the class. - **Legacy apps that can't do SAML and become a permanent exception.** The bridge was temporary in the design document and is now four years old with no owner. Name the application, the bridge and the retirement date together. - **CIAM bought as workforce IAM and priced catastrophically at scale.** Per-employee pricing met a million customers. The meter, not the feature set, is what breaks — model at three-year volume before signing. - **Directory sync breaking silently.** Leavers stayed active for weeks because a sync job failed without alerting anyone. Monitor the sync as a production service, because it is one. - **Conditional access written once and never reviewed.** Policies accumulated exclusions until the strongest rule applied to almost nobody. Review the exclusion list quarterly — it is where the real policy lives. - **Buying a second identity provider without naming the gap.** Two policy engines, two directories to keep in step, and no capability the first one lacked. Name the gap in one sentence, or do not buy. - **Machines outside the identity programme entirely.** Every employee had MFA and every service account had a static password in a config file. Non-human identities outnumber human ones — that is the PAM and secrets problem, and it needs its own plan. ## Questions this guide answers ### What is the difference between IAM, SSO, MFA and a directory? A directory is the list of who exists and what they belong to (Active Directory, Entra ID, Okta Universal Directory). SSO lets one authenticated session open many applications via SAML, OIDC or OAuth. MFA adds proof beyond the password — and the factor type matters: SMS and push are phishable and vulnerable to fatigue attacks, while FIDO2 security keys and passkeys are phishing-resistant. IAM is the umbrella covering all three plus lifecycle and policy. They are adjacent scopes, not tiers of one product. ### Is Microsoft Entra ID enough, or do I need a separate identity provider? For a Microsoft-centric estate, often enough: Entra ID P1 (about $6–7 per user per month, and included in Microsoft 365 E3) gives SSO, full conditional access and hybrid identity; P2 (about $9–10, included in E5) adds Privileged Identity Management and risk-based sign-in. Estates buy a second provider for a specific gap — legacy protocols like LDAP, RADIUS and Kerberos, deeper non-Microsoft SaaS coverage, MFA in front of VPN and RDP, or governance. If you cannot name the gap in one sentence, you probably do not have one. ### Which identity products support phishing-resistant MFA? Documented FIDO2 security key and passkey support on this guide: Okta (SSO, Adaptive MFA, Universal Directory, Customer Identity), miniOrange (SSO and MFA), Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator and eMudhra SecurePass. Not established from vendor documentation, and therefore flagged rather than ruled out: InstaSafe MFA and Authenticator, Scalefusion OneIdP, Hexnode IdP and miniOrange Directory. 'Supports MFA' is not the same claim — push notifications and one-time codes are phishable, which is exactly what phishing-resistant factors fix. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/identity-access/iam-sso-mfa* --- # The access review nobody has time to do is the control every auditor asks for first. *Identity Governance — a TechBag decision guide. Last reviewed 2026-09-07.* > Identity governance answers a question authentication never asks: not “is this really you”, but “should you still have this at all” — who granted it, who reviewed it, who approved the exception, and where is the evidence. **The checkable fact:** The RBI Master Direction on Information Technology Governance (7 November 2023, in force 1 April 2024) requires need-based access; the IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require periodic access reviews. Both describe a process, not a product — which is why so many estates own the tool and fail the audit. - Canonical: https://www.thetechbag.com/browse/identity-access/identity-governance - Category: [Identity & Access](https://www.thetechbag.com/browse/identity-access) - Products compared: 16 ## What identity governance actually is Three processes with software wrapped around them. **Provisioning** creates and removes access when someone joins, moves or leaves — ideally from an HR event, not a ticket. **Access requests** let people ask for more, with an approval path and a record. **Certification** asks the people who should know, on a schedule, whether each person should still have what they have — and keeps the evidence that they were asked and what they answered. IGA is **not IAM done better**. Identity and access management decides whether you get in; governance decides whether you should have been able to in the first place, and proves the decision. It needs different people (business managers, not administrators), different data (HR records and entitlement meaning, not just directory groups), and far more time than buyers expect. The sign-in half is the [IAM, SSO & MFA guide](https://www.thetechbag.com/browse/identity-access/iam-sso-mfa); the most dangerous accounts are the [PAM guide](https://www.thetechbag.com/browse/identity-access/privileged-access-management). **The most common mis-purchase.** A full governance platform bought when the actual gap was **joiner-mover-leaver in HR**. If leavers keep access for weeks because nobody tells IT, you need provisioning driven by an HR event — a months-shorter, far cheaper project than a certification programme. ## IGA vs IAM · access review vs provisioning vs certification One pair buyers merge and three words used as synonyms in the same meeting. These are adjacent scopes, not tiers — and IGA is emphatically not IAM done better. ### IGA vs IAM IAM decides whether you get in: directory, single sign-on, factors, conditional access — an infrastructure purchase, run by administrators, live in weeks. IGA decides whether you should have been able to, and proves it: requests, approvals, reviews, evidence — a process purchase, run with business managers, live in months or quarters. Different question, different people, different timeline. ### Provisioning Creating, changing and removing access when someone joins, moves or leaves — ideally triggered by an HR event rather than a ticket. Answers: does the leaver still have access on Friday? The most common real gap, and available without a full governance programme. ### Access review The recurring look at who has what, usually by manager or application owner. Answers: is this still appropriate? Without usage data and peer context it becomes rubber-stamping at scale — the failure mode the auditor cannot see in the report. ### Certification The formal, evidenced version of the access review: a campaign with scope, deadlines, reviewers, decisions, revocations and an audit trail that survives scrutiny. Answers: can you prove the review happened and that what it decided was actually done? Reviews are the activity; certification is the evidence. **These are adjacent scopes, not tiers.** Provisioning moves access, reviews look at it, certification proves the looking happened, and IGA is the platform around all three. IGA is not a better IAM — a product that federates a thousand applications flawlessly can tell an auditor nothing about whether the access behind them was ever justified. ## The decision variables Seven variables decide this purchase. The instrument tests what documentation establishes (capabilities, depth, connector reach, deployment, effort class, India origin); reviewer context, connector development and HR data quality are prose because they are project realities no datasheet states. **Implementation effort.** Weeks for report-and-attest on a directory you run, months for campaigns over a connected catalogue, quarters for a modelled programme with role design and SoD. The single most underestimated variable in this category — and it depends more on your HR data than on the product. **Joiner-mover-leaver automation depth.** Provisioning triggered by an HR event, across which systems, with what removal guarantee. Often the whole of what the buyer actually needed. **Access certification workflow.** A full campaign engine with scope, deadlines, revocation and evidence — or reports the business attests to. Both satisfy some auditors; only one survives a serious one. **Role mining versus role design.** Whether roles can be derived from what people actually hold, or must be designed by committee first. Role design projects are where IGA programmes quietly stop. **Application connector coverage.** Governance is only as good as what it can reach. Broad catalogue, own ecosystem, or directory-only — and the application holding your real risk is the one to name in the demo. **Segregation-of-duties rules.** Detecting and preventing toxic combinations — the person who both creates and approves a payment. Documented, not established, or absent, per product; material for BFSI. **Reporting for RBI, SEBI CSCRF and audit.** Whether the evidence comes out in the shape the auditor asks for, or is assembled by a person each quarter. ## The 16 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### SailPoint Identity Security Cloud — SailPoint - **Who it's for:** Large regulated estates that must produce defensible access reviews — certification campaigns, segregation-of-duties policy and an attestation trail an auditor accepts. Ranked #1 by revenue in IGA by Gartner Market Share 2024, and running in the AWS Mumbai region since November 2024, which is the strongest documented India data-storage position in this category. - **The honest limitation:** Enterprise-priced and enterprise-paced: below roughly 1,000 identities the economics are hard to justify, and implementation typically costs 2–3× the licence — budget the programme, not the software. The Mumbai statement covers STORAGE; processing location is not separately documented. Thoma Bravo retains ~88%, making SailPoint a controlled company. NOTE: there is no Gartner MQ for IGA — the current research is a Market Guide, so nobody is a Leader in one. - **Price:** Quote — per identity, quote-only — no published rate card. The number that matters more: third-party reporting consistently puts IMPLEMENTATION at 2–3× licence cost, because connectors, role modelling and certification design are the real work - **Details:** https://www.thetechbag.com/sailpoint/sailpoint-identity-security-cloud ### SailPoint IdentityIQ — SailPoint - **Who it's for:** Estates where the regulator specifies where the SYSTEM runs rather than only where data rests, and air-gapped or network-isolated networks where SaaS is not on the table. Running in your own data centre answers residency AND processing by construction. Its rules engine is also more flexible than the cloud platform’s, which is why complex governance logic stays here. - **The honest limitation:** You own the operational burden — infrastructure, upgrades, tuning, availability, DR — and new capability lands in Identity Security Cloud first. IMPORTANT CORRECTION: there is NO announced end-of-life for IdentityIQ, and a typical migration takes 2–3 years with both platforms in parallel, so anyone using a date to create urgency is selling a project rather than answering a requirement. - **Price:** Quote — quote-only, on-premises licensing — plus the infrastructure, upgrade cycle, database administration, availability and DR you take on, which never appear on a licence quote. Model five years with staff time in it - **Details:** https://www.thetechbag.com/sailpoint/sailpoint-identityiq ### SailPoint Non-Employee Risk Management — SailPoint - **Who it's for:** Enterprises whose contractor, vendor and partner population has outgrown a spreadsheet. Gives non-employees what staff already have: a lifecycle, a named internal owner, an expiry that actually fires, and a place in certification campaigns — with Microsoft Entra Verified ID biometric onboarding since September 2025. In India this is frequently the population an auditor asks about first, because nobody can produce the list. - **The honest limitation:** An ADD-ON, not standalone: if contractors are your entire identity requirement with no wider governance driver, buying the SailPoint platform to get this is a heavy answer. And if your non-employee population is genuinely small and somebody maintains owners and end dates, a spreadsheet is legitimate and far cheaper — we would rather say so. - **Price:** Quote — quote-only, and an ADD-ON to Identity Security Cloud rather than a standalone product — so it assumes the platform and its economics - **Details:** https://www.thetechbag.com/sailpoint/sailpoint-non-employee-risk-management ### SailPoint Data Access Security — SailPoint - **Who it's for:** Organisations asked WHERE personal data lives and who can reach it — the DPDP-shaped question that application-level certification cannot answer, because personal data does not stay inside applications. Discovers and classifies sensitive data across cloud, on-premises and SaaS, finds over-privileged access and stale external sharing, and reviews the data assets themselves. - **The honest limitation:** Classification quality decides whether the whole thing works: over-classify and reviewers drown in false positives, under-classify and you miss what you were protecting — budget tuning as a phase, not a configuration step. It does NOT replace DLP (that is data in motion, a different question). And if data discovery is your only driver, a dedicated DSPM product costs less. - **Price:** Quote — quote-only, an ADD-ON to Identity Security Cloud — and budget a genuine CLASSIFICATION TUNING PHASE on top, because that is where these deployments succeed or fail - **Details:** https://www.thetechbag.com/sailpoint/sailpoint-data-access-security ### SailPoint CIEM — SailPoint - **Who it's for:** Multi-cloud estates whose machine identities have never been reviewed. Service accounts, workload identities and pipeline credentials typically outnumber employees, are created by automation with no approval workflow, rarely have owners, and never appear in an HR-driven campaign. Right-sizes permissions from OBSERVED USAGE rather than stated intent, which is the only control that works at cloud speed. - **The honest limitation:** SailPoint does not document which clouds are supported to what depth — confirm yours specifically rather than assuming parity. Usage-based right-sizing needs an observation window long enough to see quarterly and annual jobs, or they get trimmed wrongly. And this is entitlements ONLY — not vulnerability scanning, configuration or runtime, which is CNAPP territory. - **Price:** Quote — quote-only, an ADD-ON to Identity Security Cloud. ⚠️ Before pricing anything, confirm which of YOUR cloud platforms are supported and to what depth — SailPoint’s product page does not enumerate them - **Details:** https://www.thetechbag.com/sailpoint/sailpoint-ciem ### Okta Identity Governance — Okta - **Who it's for:** Okta estates that want access reviews and requests governed by the same platform, catalogue and lifecycle they already run — the shortest path from SSO to a defensible certification campaign. - **The honest limitation:** Governance of what Okta already connects to: applications outside the catalogue need work, and the price sits on top of a per-user identity bill that is already per-capability. Not a fit if Okta is not your identity provider. - **Price:** ~$9–11 (≈ ₹747) — per user / month reported as an add-on to Workforce Identity, or inside the Essentials bundle (~$17 per user / month list); certification campaigns, access requests and reporting on Okta's application catalogue - **Details:** https://www.thetechbag.com/okta/okta-identity-governance ### Okta Lifecycle Management — Okta - **Who it's for:** Estates whose real gap is joiner-mover-leaver — accounts created on day one and removed on the last day — rather than certification campaigns. - **The honest limitation:** Provisioning, not governance: no certification campaigns, no segregation-of-duties rules, no attestation evidence for an auditor. Frequently the product people actually needed when they went shopping for IGA. - **Price:** In the ~$17 bundle (≈ ₹1,411) — per user / month inside the Essentials bundle list; provisioning and de-provisioning driven by HR or directory events across the connected application catalogue - **Details:** https://www.thetechbag.com/okta/okta-lifecycle-management ### Idira Identity Governance (was CyberArk IGA) — Palo Alto Networks - **Who it's for:** Regulated estates already running CyberArk that want privileged accounts inside the same certification campaign as everyone else — the gap most IGA products leave open. - **The honest limitation:** RENAMED: Palo Alto Networks acquired CyberArk on 11 February 2026 and rebranded the portfolio to Idira on 12 May 2026 — cyberark.com/products/identity-governance-and-administration now redirects to paloaltonetworks.com/idira. Enterprise-priced and enterprise-paced: implementation is a quarters-long programme, and the strongest case still assumes you already run the PAM. IGA is a supporting module in a platform whose centre of gravity is PAM and machine/agentic identity — for best-of-breed IGA depth, SailPoint and Saviynt go further. An India data region is not documented. - **Price:** Quote — per identity / year on quote within the Idira platform (formerly the CyberArk Identity Security Platform); certification, access requests and provisioning that reach privileged accounts as well as standard ones - **Details:** https://www.thetechbag.com/cyberark/cyberark-identity-governance ### One Identity Manager — One Identity - **Who it's for:** Large and complex estates — often with SAP, mainframe or heavily regulated processes — that need governance modelled to their own business rules rather than a template. - **The honest limitation:** The deepest platform here and the longest project: role design and connector work are measured in quarters and frequently need a partner. Overkill for an estate whose gap is joiner-mover-leaver. - **Price:** Quote — per identity on quote, perpetual or subscription; the deep enterprise IGA platform — role modelling, attestation, SoD, SAP and mainframe connectors, on-premises or SaaS - **Details:** https://www.thetechbag.com/oneidentity/oneidentity-identity-manager ### One Identity Active Roles — One Identity - **Who it's for:** Active Directory estates that need delegated administration and automated AD account lifecycle without a full IGA programme. - **The honest limitation:** Directory-scoped: it governs Active Directory and Entra ID deeply and other applications barely. Certification is basic compared with the full IGA platforms. - **Price:** Quote — per managed account on quote; delegated administration, automated provisioning and policy enforcement for Active Directory and Entra ID specifically - **Details:** https://www.thetechbag.com/oneidentity/oneidentity-active-roles ### Securden Identity Governance and Administration — Securden - **Who it's for:** Mid-market and Indian estates that want certification campaigns and access requests without an enterprise IGA programme or an enterprise IGA price. - **The honest limitation:** Segregation-of-duties rule support could not be established from vendor documentation — marked unknown rather than assumed, and material if you are BFSI. Role mining is manual, and documented deployments are mid-market. - **Price:** Quote — priced on the number of users, all-inclusive, in line with Securden's other products; access requests, approvals, periodic reviews and reporting, self-hosted or SaaS - **Details:** https://www.thetechbag.com/securden/securden-iga ### ARCON Converged Identity — ARCON - **Who it's for:** Indian BFSI estates that want governance and the privileged vault from one India-built vendor, with the auditor's report format and the support engineer in the same country. - **The honest limitation:** Narrower connector reach than the global IGA platforms and role mining is manual; documented governance deployments are smaller than ARCON's PAM footprint — flagged, not ruled out. - **Price:** Quote (INR) — per identity, quoted in INR; identity lifecycle, access requests and periodic reviews from the Mumbai-built vendor, with reporting shaped for Indian regulatory audits and on-premises as a first-class option - **Details:** https://www.thetechbag.com/arcon/arcon-converged-identity ### ARCON Security Compliance Management — ARCON - **Who it's for:** Indian regulated estates that need continuous evidence of control posture against a baseline, alongside the identity governance programme. - **The honest limitation:** Compliance assessment, not identity governance: no joiner-mover-leaver automation and no user access certification. It produces evidence about systems, not about who has access to them. - **Price:** Quote (INR) — per device or per asset, quoted in INR; continuous configuration and compliance assessment against regulatory baselines, with audit-ready reporting - **Details:** https://www.thetechbag.com/arcon/arcon-security-compliance-management ### miniOrange Universal Directory — miniOrange - **Who it's for:** Indian organisations whose real gap is lifecycle rather than certification — accounts created on day one and revoked on the last day — and who want the identity foundation itself India-built, DPDP-aligned and deployable inside their own environment rather than only as somebody else's SaaS. - **The honest limitation:** Provisioning, not governance — the same honest caveat as Okta Lifecycle Management: no certification campaigns, no segregation-of-duties rules, and no attestation evidence to hand an auditor. If your driver is an access review your auditor asked for, this does not answer it and SailPoint, Saviynt or One Identity Manager do. It IS frequently the product people actually needed when they went shopping for IGA. - **Price:** Quote — quote-based, invoiced in INR with GST through TechBag — a cloud directory as the single authoritative source for users, groups and attributes, with HR-driven joiner-mover-leaver automation, and deployable on-premises as well as SaaS - **Details:** https://www.thetechbag.com/miniorange/miniorange-directory ### ManageEngine AD360 (governance modules) — ManageEngine - **Who it's for:** Active Directory estates that need provisioning, periodic access reports and an audit trail quickly, at a price that does not scale with headcount. - **The honest limitation:** Active Directory-centric governance: certification is report-and-attest rather than a full campaign engine, connector reach beyond the Microsoft world is narrow, and segregation-of-duties support is not established from documentation. - **Price:** From ~$595 (≈ ₹49,385) — per module / year list (ADManager Plus for provisioning and reviews, ADAudit Plus for the audit trail) — per module, not per user; India-built (Zoho), on-premises first - **Details:** https://www.thetechbag.com/manageengine/manageengine-ad360 ### Rubrik Identity Resilience — Rubrik - **Who it's for:** Estates whose governance question is the recovery one: a compromised administrator deleted the groups, roles and conditional-access policies, and someone has to put the directory back. - **The honest limitation:** Not identity governance: no certification, no access requests, no joiner-mover-leaver. It restores the directory after an incident — the adjacent problem, and one no IGA platform solves. - **Price:** Quote — per identity / year on quote; backup, comparison and object-level restore for Entra ID, Active Directory and Okta — including full forest recovery - **Details:** https://www.thetechbag.com/rubrik/rubrik-identity-resilience ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Certification campaigns.** Rules out Okta Lifecycle Management, miniOrange Universal Directory and Rubrik Identity Resilience — no access certification capability; One Identity Active Roles, ARCON Security Compliance Management and ManageEngine AD360 (governance modules) — reports and attestation rather than a full campaign engine. That leaves SailPoint Identity Security Cloud, SailPoint IdentityIQ, SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, Idira Identity Governance (was CyberArk IGA), One Identity Manager, Securden Identity Governance and Administration and ARCON Converged Identity. **Joiner-mover-leaver.** Rules out SailPoint Data Access Security, ARCON Security Compliance Management and Rubrik Identity Resilience — no joiner-mover-leaver automation; SailPoint CIEM — partial lifecycle automation only. That leaves SailPoint Identity Security Cloud, SailPoint IdentityIQ, SailPoint Non-Employee Risk Management, Okta Identity Governance, Okta Lifecycle Management, Idira Identity Governance (was CyberArk IGA), One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, miniOrange Universal Directory and ManageEngine AD360 (governance modules). **Access requests.** Rules out Rubrik Identity Resilience — neither request workflow nor certification; it solves an adjacent problem. That leaves SailPoint Identity Security Cloud, SailPoint IdentityIQ, SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, Okta Lifecycle Management, Idira Identity Governance (was CyberArk IGA), One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management, miniOrange Universal Directory and ManageEngine AD360 (governance modules). **Segregation of duties.** Rules out Okta Lifecycle Management, miniOrange Universal Directory and Rubrik Identity Resilience — no segregation-of-duties capability. That leaves SailPoint Identity Security Cloud, SailPoint IdentityIQ, SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, Idira Identity Governance (was CyberArk IGA), One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules). It flags SailPoint Non-Employee Risk Management — Segregation-of-duties support not established from vendor documentation, SailPoint Data Access Security — Segregation-of-duties support not established from vendor documentation, SailPoint CIEM — Segregation-of-duties support not established from vendor documentation, Securden Identity Governance and Administration — Segregation-of-duties support not established from vendor documentation and ManageEngine AD360 (governance modules) — Segregation-of-duties support not established from vendor documentation — marked, not removed. **Role mining.** Rules nothing out on published terms. It flags SailPoint Identity Security Cloud — Role mining capability not established, SailPoint IdentityIQ — Role mining capability not established, SailPoint Non-Employee Risk Management — Roles must be designed rather than derived, SailPoint Data Access Security — Role mining capability not established, SailPoint CIEM — Role mining capability not established, Okta Identity Governance — Role mining capability not established, Okta Lifecycle Management — Roles must be designed rather than derived, Idira Identity Governance (was CyberArk IGA) — Role mining capability not established, One Identity Manager — Role mining capability not established, One Identity Active Roles — Roles must be designed rather than derived, Securden Identity Governance and Administration — Roles must be designed rather than derived, ARCON Converged Identity — Roles must be designed rather than derived, ARCON Security Compliance Management — Roles must be designed rather than derived, miniOrange Universal Directory — Roles must be designed rather than derived, ManageEngine AD360 (governance modules) — Roles must be designed rather than derived and Rubrik Identity Resilience — Role mining capability not established — marked, not removed. **Broad connector catalogue.** Rules out Idira Identity Governance (was CyberArk IGA), Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and miniOrange Universal Directory — governs its own ecosystem well; a broad third-party catalogue is not documented; One Identity Active Roles, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience — narrow connector reach, directory-centric. That leaves SailPoint Identity Security Cloud, SailPoint IdentityIQ, SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, Okta Lifecycle Management and One Identity Manager. **Live in weeks.** Rules out SailPoint Identity Security Cloud, SailPoint IdentityIQ, Idira Identity Governance (was CyberArk IGA) and One Identity Manager — a quarters-long programme, realistically; SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity and ARCON Security Compliance Management — a months-long implementation, realistically. That leaves Okta Lifecycle Management, miniOrange Universal Directory, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience. **Months is acceptable.** Rules out SailPoint Identity Security Cloud, SailPoint IdentityIQ, Idira Identity Governance (was CyberArk IGA) and One Identity Manager — a quarters-long programme, realistically. That leaves SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, Okta Lifecycle Management, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management, miniOrange Universal Directory, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience. **Self-hosted.** Rules out SailPoint Identity Security Cloud, SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, Okta Lifecycle Management, Idira Identity Governance (was CyberArk IGA) and Rubrik Identity Resilience — SaaS only. That leaves SailPoint IdentityIQ, One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management, miniOrange Universal Directory and ManageEngine AD360 (governance modules). **India-built, INR.** Rules out SailPoint Identity Security Cloud, SailPoint IdentityIQ, SailPoint Non-Employee Risk Management, SailPoint Data Access Security, SailPoint CIEM, Okta Identity Governance, Okta Lifecycle Management, Idira Identity Governance (was CyberArk IGA), One Identity Manager, One Identity Active Roles and Rubrik Identity Resilience — a global vendor; INR quoting is via the channel, not the vendor's own price list. That leaves Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management, miniOrange Universal Directory and ManageEngine AD360 (governance modules). **Above 10,000 identities.** Rules nothing out on published terms. It flags SailPoint Data Access Security — Unverified above 10,000 identities, SailPoint CIEM — Unverified above 10,000 identities, Securden Identity Governance and Administration — Unverified above 10,000 identities, ARCON Converged Identity — Unverified above 10,000 identities, ARCON Security Compliance Management — Unverified above 10,000 identities and miniOrange Universal Directory — Unverified above 10,000 identities — marked, not removed. **Implementation effort is the variable, and it is always underestimated.** Weeks for report-and-attest on a directory you already run (ManageEngine AD360, Okta Lifecycle Management). Months for certification campaigns over a connected catalogue (Okta IGA, Securden, ARCON Converged Identity, Active Roles). Quarters for a modelled enterprise programme with role design, SoD rules and SAP or mainframe connectors (One Identity Manager, CyberArk IGA). The effort class in the instrument is this judgement, made from documented capability and deployment shape — your own timeline depends on how clean your HR data is, which is the real variable. TechBag's delivery figures per platform are [TechBag to confirm]. **Certification is only as good as the context reviewers get.** A campaign that shows a manager a list of entitlement names produces rubber-stamping, at scale, on a deadline. The platforms that reduce this show usage data, peer comparison and risk scoring next to each decision. Ask to see the reviewer's screen in the demo — not the administrator's dashboard — and ask what a reviewer sees when they do not recognise an entitlement. **Connectors are the ceiling.** Governance reaches exactly as far as its connectors. A broad catalogue (Okta, One Identity Manager) covers mainstream SaaS; ecosystem-scoped products govern their own stack well and others through custom work; directory-centric products (Active Roles, AD360) go deep on Active Directory and Entra ID and shallow elsewhere. The application holding your real risk — the core banking system, the ERP, the internally built one — is the connector to ask about by name, and custom connector development is not in any licence. **The machine identities nobody certifies.** Certification campaigns review employees. Service accounts, API consumers, pipeline credentials and AI agent tokens are rarely in scope at all — no manager owns them, no HR event ends them, and they outnumber human identities in most estates. Every product here governs people; the credentials themselves belong in the vault, which is a different purchase. If your auditor has not asked yet, they will. **Under 500 identities.** Rules nothing out on published terms: ManageEngine AD360, Okta Lifecycle Management and Securden are sold to small estates, and Microsoft's Entra ID Governance add-on (roughly $4–7 per user per month on top of P1 or P2) may already cover it. One Identity Manager and CyberArk IGA publish no floor but are enterprise-paced. Where a small estate should stop at joiner-mover-leaver and skip certification entirely is delivery judgement: [TechBag to confirm]. ## Eight situations, eight shortlists — with the timeline named Each shortlist states what could realistically be live this quarter versus next year. If an auditor is driving this, start from the first row. ### The auditor asked for evidence of periodic access reviews — and there is none **Shortlist:** Okta Identity Governance, Securden Identity Governance and Administration, ManageEngine AD360 (governance modules) **Why:** Okta IGA runs campaigns over the catalogue you already federate; Securden gives the same on an all-inclusive per-user number; AD360 produces reports and attestation on Active Directory in weeks rather than quarters. **Trade-off:** The fast options certify what they can reach — usually the directory and the federated applications. The system holding your real risk may need a connector nobody has built yet. ### The actual gap is joiner-mover-leaver, not certification **Shortlist:** Okta Lifecycle Management, ManageEngine AD360 (governance modules), One Identity Active Roles **Why:** Accounts created on day one from an HR event and removed on the last day is a provisioning problem, and all three solve it without a governance programme. **Trade-off:** None of these gives you certification evidence. Buying full IGA when the gap was leaver automation is the most expensive mistake in this subcategory — and the most common. ### Indian BFSI — RBI and SEBI CSCRF reporting, on-premises, in INR **Shortlist:** ARCON Converged Identity, Securden Identity Governance and Administration, ManageEngine AD360 (governance modules) **Why:** ARCON is Mumbai-built with on-premises as a first-class deployment and reporting shaped for Indian audits; Securden and ManageEngine are India-built with self-hosted options and INR pricing. **Trade-off:** Securden's segregation-of-duties support is not documented and AD360's is not either — material for BFSI. Confirm SoD in writing before shortlisting on price. ### SAP, mainframe or heavily modelled business rules **Shortlist:** One Identity Manager, Idira Identity Governance (was CyberArk IGA), Okta Identity Governance **Why:** One Identity Manager is the deepest platform here for modelled governance with SAP and mainframe connectors; CyberArk IGA reaches privileged accounts in the same campaigns. **Trade-off:** Both are quarters-long programmes and usually need a partner. If your timeline is a quarter, one of these will not be live in it — plan the phase, not the platform. ### Privileged accounts must be in the same certification campaign as everyone else **Shortlist:** Idira Identity Governance (was CyberArk IGA), One Identity Manager, ARCON Converged Identity **Why:** The gap most IGA products leave open: standard entitlements are certified while the administrator accounts are governed elsewhere, or not at all. These three pair governance with a vault from the same vendor. **Trade-off:** One vendor for both disciplines means one roadmap for two teams that usually work on different timelines. The alternative is two products and a reconciliation process you own. ### Already on Okta and want governance without a second platform **Shortlist:** Okta Identity Governance, Okta Lifecycle Management **Why:** Okta IGA is the shortest path from federated SSO to a defensible campaign — same catalogue, same lifecycle, same console; Lifecycle Management alone if provisioning is the real need. **Trade-off:** It governs what Okta connects to. Applications outside the catalogue are work, and the per-user add-on lands on top of an identity bill that is already priced per capability. ### A compromised admin deleted groups, roles and policies — restore the directory **Shortlist:** Rubrik Identity Resilience, One Identity Active Roles **Why:** Rubrik Identity Resilience backs up, compares and restores Entra ID, Active Directory and Okta objects, including full forest recovery — the adjacent problem no IGA platform solves. **Trade-off:** This is recovery, not governance: no certification, no requests, no lifecycle. It belongs beside an IGA purchase, never instead of one. ### Mid-market, one identity owner, needs something defensible this quarter **Shortlist:** Securden Identity Governance and Administration, ManageEngine AD360 (governance modules), Okta Identity Governance **Why:** Securden's all-inclusive pricing, AD360's per-module list (from about $595 per component per year, which does not scale with headcount) and Okta IGA if you already run Okta are the three realistic quarter-long routes. **Trade-off:** Securden and ARCON are flagged unverified above 10,000 identities. Ask for a reference at your size, and be honest about whether you need campaigns or just clean leaver automation. ## At scale Governance scales by entitlements and reviewers, not by identities alone. The bill follows the per-identity list; the programme follows how many people must make decisions. ### 500 identities — The gap definition is the constraint - Most estates this size need joiner-mover-leaver, not certification — be honest about which, because it is a months-shorter project. - Microsoft's Entra ID Governance add-on (roughly $4–7 per user per month on top of P1 or P2) may already cover it; check the invoice first. - ManageEngine's per-module list does not scale with headcount, which makes it unusually cheap here. **The test:** Run one manual access review in a spreadsheet. What made it painful is the requirement; anything else is a feature you will not use. ### 5,000 identities — Reviewer fatigue and connectors are the constraint - Campaigns now involve hundreds of reviewers on a deadline — context and risk scoring decide whether the result means anything. - The connector list stops being a checkbox: the ERP, the core system and the internally built application are where the risk and the custom work both live. - Role design becomes tempting and dangerous — mine roles from real entitlements before designing any. **The test:** Ask a vendor for a campaign completion rate from a reference at your size, and what percentage of decisions were 'approve all'. ### 25,000 identities — Modelling and evidence are the constraint - Segregation-of-duties rules, delegated administration and business-role modelling become the programme; a partner is usually involved. - Privileged accounts must join the same campaign or the auditor finds the seam; machine identities are the population still outside it. - Securden, ARCON Converged Identity and ARCON SCM are flagged unverified at this size — not ruled out; ask for the reference. **The test:** Count identities without a human owner. If nobody can name an owner for a service account, no certification campaign will ever cover it. Okta, CyberArk, One Identity and ManageEngine document large estates; Securden, ARCON Converged Identity and ARCON Security Compliance Management are flagged unverified above 10,000 identities. Where a specific platform strains at your identity count: [TechBag to confirm]. ## Leaving a governance platform means rebuilding the process, not moving data The value is in connectors, roles, rules and campaign history — none of which is portable. Switching restarts the programme with the audit clock still running. **Connectors and mappings** — Every application connection, attribute mapping and provisioning rule is rebuilt on the new platform, including the custom ones nobody documented. *(Rebuild, application by application)* **Roles and rules** — Business roles and segregation-of-duties rules were modelled for the old platform's engine. Re-modelling is the original design project, again. *(Re-model)* **Campaign history** — Past certifications are your evidence that reviews happened. Export what the regulator's retention period requires before the contract ends — it rarely migrates. *(Export the evidence)* **The gap in coverage** — Certification cycles run to a calendar the auditor knows. Time the switch so no cycle is missed; a skipped campaign is a finding regardless of the reason. *(No missed cycle)* **Connector rebuild, role re-modelling and evidence export for your estate:** [TechBag to confirm] — TechBag scopes it from your connector inventory and audit retention rules. ## Per identity per month — and then the implementation What you may already hold, the products priced per identity at three estate sizes in USD and INR, and what the licence line leaves out — which, for governance, is nearly always larger than the licence. ### Do you already own one? Four places governance may already sit. Two are real, and one of them is on most Microsoft invoices. - **Microsoft Entra ID Governance — Often.** Access reviews, entitlement management and lifecycle workflows as an add-on at roughly $4–7 per user per month on top of P1 or P2. Real governance for the Microsoft estate; thin for third-party applications. - **Microsoft Entra ID P2 — Partly.** Includes Privileged Identity Management — eligible rather than permanent roles with approval and expiry — at about $9–10 per user per month. That is privileged lifecycle, not access certification for the business. - **Your identity provider's lifecycle module — Partly.** Okta Lifecycle Management and similar provision and de-provision from HR events. Real joiner-mover-leaver; no certification, no evidence. - **Your HR system — No.** It knows who joined and left, and it is the trigger every governance programme needs. It grants and removes nothing on its own — the integration is the project. If the reviews your auditor wants can come from a licence you already hold, we say so. It costs us a sale and saves you one. ### What the rest actually cost Reported and published meters (INR for scale), worked at 500 / 5,000 / 25,000 identities per year. **The implementation is the larger number** and it is stated apart, below — a governance licence bought without an implementation budget is a shelf product. ### What isn't in the licence price - **The implementation.** Connector configuration, role design, campaign setup, reviewer training and one full cycle before the output can be trusted — weeks, months or quarters by class, and at the deep end the services line commonly rivals the licence. Your figure: [TechBag to confirm]. - **Connector development.** The application holding your real risk is frequently the one with no connector. Custom development, testing and maintenance of that integration are in no licence and on every project plan. - **The internal time to run campaigns.** Every cycle costs hundreds of reviewer-hours across the business, plus a coordinator chasing completion. It recurs quarterly or half-yearly, forever — and it is the cost that decides whether the programme survives year two. ## What goes wrong Documented behaviour and programme outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the second campaign. - **Role design projects that never finish.** A committee spent three quarters designing business roles for a moving organisation. Mine roles from what people actually hold, ship something, then refine. - **Certification campaigns rubber-stamped because reviewers have no context.** Managers approved lists of entitlement names they did not recognise, on a deadline. The audit trail is perfect and the control is fictional — ask to see the reviewer's screen. - **Connectors missing for the applications that hold the risk.** The catalogue covered mainstream SaaS; the core banking system and the ERP were manual spreadsheets. Governance reaches exactly as far as its connectors. - **Leaver automation that removes access but leaves the account.** The account was disabled in the directory and remained live in three applications and one VPN. Removal must be verified per system, not assumed from the directory. - **Buying IGA when the actual gap was joiner-mover-leaver in HR.** A months-long governance programme for a problem that needed HR to trigger provisioning. Name the gap precisely before shopping. - **Evidence that does not survive the auditor's second question.** The report showed the review happened; nobody could show that the revocations were actually executed. Decision and removal are two different records. - **Machine identities left outside every campaign.** Service accounts and pipeline credentials had no owner, no HR event and no reviewer. They outnumber the humans, and they are not in the campaign. - **A programme that stops after the first cycle.** The first campaign was resourced as a project and the second was nobody's job. Budget the recurring reviewer hours, or the control lapses quietly. ## Questions this guide answers ### What is the difference between IGA and IAM? IAM decides whether you get in — directory, single sign-on, factors, conditional access. It is an infrastructure purchase, run by administrators, typically live in weeks. IGA decides whether you should have been able to, and proves it — access requests, approvals, periodic certification, revocation and evidence. It is a process purchase, run with business managers, and realistically live in months or quarters. IGA is not IAM done better: it answers a different question, needs different people and different data, and takes far longer than buyers expect. ### Do Indian regulators require access reviews? Read the source rather than the vendor slide. The RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (issued 7 November 2023, in force 1 April 2024) requires need-based access and multi-factor authentication for privileged users of critical information systems. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF, August 2024) sets access-management requirements including least privilege for regulated entities. The IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require privileged access management and periodic access reviews. Each describes a control and an evidence expectation, not a named product — an IGA platform is how most estates satisfy it, not what the circular asks for. ### How long does an identity governance implementation take? Three honest classes. Weeks for report-and-attest over a directory you already run (ManageEngine AD360, Okta Lifecycle Management). Months for certification campaigns across the applications your identity provider already connects to (Okta Identity Governance, Securden, ARCON Converged Identity). Quarters for a modelled programme with role design, segregation-of-duties rules and SAP or mainframe connectors (One Identity Manager, CyberArk IGA), usually with a partner whose services line rivals the licence. Your own timeline depends more on how clean your HR and entitlement data is than on which product you pick. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/identity-access/identity-governance* --- # Identity & Access — who (or what) is signing in — and most of what signs in now is not a person *A TechBag category guide. Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/identity-access - Routes: 3 ## The routes ### Privileged Access Management Most PAM projects stall not because the product failed, but because nobody could get the accounts into it. - 17 products compared - Guide: https://www.thetechbag.com/browse/identity-access/privileged-access-management - Boundary terms resolved: PAM — privileged access management · PIM — privileged identity management · PEDM — privilege elevation and delegation management · Secrets management ### IAM, SSO & MFA You probably already own an identity provider. The question is whether it does what you’re about to buy — and where it stops. - 18 products compared - Guide: https://www.thetechbag.com/browse/identity-access/iam-sso-mfa - Boundary terms resolved: Directory · SSO — single sign-on · MFA — multi-factor authentication · Workforce vs customer identity (CIAM) ### Identity Governance The access review nobody has time to do is the control every auditor asks for first. - 16 products compared - Guide: https://www.thetechbag.com/browse/identity-access/identity-governance - Boundary terms resolved: IGA vs IAM · Provisioning · Access review · Certification --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/identity-access* --- # The licence is not the bill. Ingest is the bill — and it grows with your traffic, not your headcount. *Observability & APM — a TechBag decision guide. Last reviewed 2026-09-07.* > Every product here meters on volume: hosts monitored, gigabytes ingested, events captured, sessions recorded. A per-user mental model — the one that works everywhere else on this site — produces a forecast that is wrong by an order of magnitude. **The checkable fact:** Datadog publishes three different meters inside one platform: APM and Infrastructure per host, Log Management per GB ingested *plus* per million events indexed, RUM per thousand sessions. Model your volumes against the meter, not the rate. - Canonical: https://www.thetechbag.com/browse/devops/observability-apm - Category: [DevOps](https://www.thetechbag.com/browse/devops) - Products compared: 14 ## What observability & apm actually is Observability is the practice of keeping enough telemetry — logs, metrics, traces — that you can answer a question you did not anticipate. Monitoring answers questions you wrote a check for in advance. That distinction sounds academic until you see the bill: keeping the detail is exactly what you pay for. The thirteen products below split by meter more usefully than by feature. Four are per-host or per-GB platform modules. Six are event-metered and materially cheaper for the same job at small volumes. Two are quote-only. And two — Mixpanel’s pair — are product analytics rather than infrastructure observability, included because the meter and the buying team overlap, and labelled so you do not buy one for the other. **The most common mis-purchase.** The **pricing meter**. This is the category’s equivalent of a firewall’s throughput figure: a per-host quote and a per-GB quote for the same estate can differ by **an order of magnitude**, and no comparison on the internet models it against your volumes. Ask every vendor to price your *actual* host count, ingest volume and event rate — then compare the totals, never the rates. ## Four terms, resolved These are not tiers. Observability is not monitoring done better — it answers questions you never wrote a check for, from telemetry you pay to keep, at a materially different cost. ### Monitoring vs observability Did you know in advance what to check? ### Observability vs APM The whole estate, or the application request? ### Logs vs metrics vs traces Which one answers your question, and what does it cost to keep? ### APM vs RUM vs error tracking Server-side performance, device experience, or exceptions? None of these is a better product than the others. They answer different questions at different meters, and the expensive mistake is buying platform-grade telemetry for a question that error tracking answers for a few hundred dollars a month. ## The decision variables Seven variables move the shortlist. The first one moves it more than the other six combined. **The pricing meter.** Per host, per GB ingested, per million events indexed, per session, per user — or quote-only. Same estate, different meters, order-of-magnitude difference. **Retention, and what keeping it costs.** The licence covers the first tranche. Shortening retention to control cost is the standard reflex, and the incident then falls outside the window. **Language and runtime coverage.** For the stack you actually run, including the older service nobody wants to touch. **Cardinality limits.** The failure mode nobody forecasts: one well-meant custom tag turns a metric into millions of time series. **Alerting and on-call integration.** Whether alerts reach the rota you already run, or need a second product. **Open-source viability.** Prometheus, Grafana and OpenTelemetry are genuinely credible here. A page pretending otherwise is not worth reading. **India region and residency.** Undocumented across every vendor on this page — logs frequently carry personal data, so confirm rather than assume. ## The 14 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Elastic Observability — Elastic - **Who it's for:** Teams already running the ELK stack for logs — this formalises what they have rather than migrating — and estates large enough that per-host pricing has become the problem. - **The honest limitation:** You run the cluster unless you buy Elastic Cloud, and operating Elasticsearch well at scale is real engineering work. The correlation UX is less polished than Datadog’s and dashboards need more assembly. - **Price:** Free → tier — engine free under AGPL plus a subscription tier; Elastic Cloud Hosted priced on PROVISIONED RESOURCES rather than per host or per GB (reported ~$99/mo Standard to ~$184/mo Enterprise at entry size), or Serverless on consumption - **Details:** https://www.thetechbag.com/elastic/elastic-observability ### Datadog APM — Datadog - **Who it's for:** Estates running microservices that need to follow one request across many services, and that already accept a platform bill rather than a per-tool one. - **The honest limitation:** The meter is per host, so the bill tracks your infrastructure rather than your traffic — and it compounds with every other Datadog module you enable. Cost management is the standing operational task, not a one-time negotiation. - **Price:** Per host, published — per host / month, published list; distributed tracing across services with the span-level detail that names the slow hop — billed on top of Infrastructure Monitoring rather than instead of it - **Details:** https://www.thetechbag.com/datadog/datadog-apm ### Datadog Infrastructure Monitoring — Datadog - **Who it's for:** Teams that want one place for infrastructure health across cloud accounts, and are choosing the platform deliberately rather than by accident. - **The honest limitation:** Metrics only: it will tell you the p99 got worse and not which span caused it. Custom metrics and high cardinality are separately metered, and cardinality is the line that multiplies a bill without traffic multiplying. - **Price:** Per host, published — per host / month, published list; the base layer of the platform — host, container and cloud-service metrics with the dashboards and alerting most estates start from - **Details:** https://www.thetechbag.com/datadog/datadog-infrastructure-monitoring ### Datadog Log Management — Datadog - **Who it's for:** Estates whose debugging happens in logs and who are prepared to decide, deliberately, which logs are worth indexing. - **The honest limitation:** Two meters on one product is where forecasts break: teams model ingest and forget indexing. Almost every runaway observability bill in this category is a log bill. - **Price:** Per GB + per million events — per GB ingested PLUS per million events indexed, published list; ingest and indexing are separate meters, so what you keep searchable costs more than what you merely collect - **Details:** https://www.thetechbag.com/datadog/datadog-log-management ### Datadog Digital Experience Monitoring — Datadog - **Who it's for:** Teams whose users report slowness that server-side metrics insist is not happening — the gap between what the server did and what the device experienced. - **The honest limitation:** Session-metered, so a traffic spike is a bill spike with no infrastructure change to explain it. Synthetics are a third meter again. - **Price:** Per session, published — per 1,000 sessions / month for RUM, with synthetic tests metered separately by run; what the browser or mobile app actually experienced, including the network and third-party scripts the backend never sees - **Details:** https://www.thetechbag.com/datadog/datadog-digital-experience ### Sentry Error Monitoring — Sentry - **Who it's for:** Teams whose actual question is “why did that crash, in which release, for how many people” — answered at a fraction of full APM pricing. - **The honest limitation:** Errors and performance for the application, not the infrastructure: no host metrics, no cloud-service integration, no log platform. It is deliberately one job done well rather than a platform. - **Price:** From ~$26/mo (≈ ₹2,158) — per month on the Team tier (about ₹2,158), Business about $80, both annual; metered on events captured rather than hosts run — exceptions grouped by fingerprint with the release, the commit and the users affected - **Details:** https://www.thetechbag.com/sentry/sentry-error-monitoring ### Sentry Performance Monitoring — Sentry - **Who it's for:** Engineering teams that want tracing tied to the commit that caused the regression, without adopting a per-host platform. - **The honest limitation:** Sampled by design and scoped to the application — it will not replace infrastructure monitoring, and deep cloud-service telemetry is outside it. - **Price:** In the Sentry tiers — metered on transactions/spans within the same published Sentry tiers; developer-first tracing joined to the errors and the release that introduced them - **Details:** https://www.thetechbag.com/sentry/sentry-performance-monitoring ### Sentry Session Replay — Sentry - **Who it's for:** Teams losing time to bugs that cannot be reproduced from a stack trace alone. - **The honest limitation:** Replays are a separate meter and privacy masking must be configured deliberately — an unmasked replay of a checkout page is a data-protection problem, not a debugging win. - **Price:** Per replay, in the tiers — metered per replay within the Sentry tiers; a recording of the session that produced the error, so the reproduction step is watching rather than guessing - **Details:** https://www.thetechbag.com/sentry/sentry-session-replay ### Splunk Observability Cloud — Splunk - **Who it's for:** Estates that want every trace kept rather than sampled, and that are already in the Cisco/Splunk relationship — a distinct SKU from Splunk Enterprise Security, which is carded on the Security category. - **The honest limitation:** No published list pricing, so it cannot be compared like-for-like on a spreadsheet and the quote is the only real number. Full-fidelity tracing is a genuine differentiator and a genuine volume commitment. - **Price:** Quote — not published — quoted; a full-fidelity platform built on OpenTelemetry with no-sample tracing. Splunk does not publish list rates for this SKU — the per-host and per-session figures circulating online are third-party, not vendor list - **Details:** https://www.thetechbag.com/splunk/splunk-observability-cloud ### Splunk ITSI — Splunk - **Who it's for:** Large estates already ingesting into Splunk whose problem is alert volume rather than missing telemetry. - **The honest limitation:** It assumes the Splunk platform underneath and its value is proportional to how much you already ingest there. Service modelling is configuration work measured in weeks, not a switch. - **Price:** Quote — not published — quoted on the Splunk platform; service-level health modelling and AIOps event correlation over data the platform already holds — the layer that turns thousands of alerts into a handful of service states - **Details:** https://www.thetechbag.com/splunk/splunk-itsi ### Quest Foglight Cloud — Quest - **Who it's for:** Estates already running Foglight for databases that want the same console over cloud infrastructure rather than a second platform. - **The honest limitation:** Narrower application-tracing depth than the observability specialists; its strength is the database line, and buying it as a general APM is buying the wrong half of the portfolio. - **Price:** Quote — quoted per monitored resource; SaaS-delivered infrastructure and application monitoring from the vendor whose depth is databases — the cloud front end to a Foglight estate - **Details:** https://www.thetechbag.com/quest/quest-foglight-cloud ### Quest Foglight Evolve — Quest - **Who it's for:** Estates with a large virtualised footprint that need capacity forecasting alongside health, particularly through a hypervisor migration. - **The honest limitation:** Infrastructure-scoped: no application tracing and no log platform. Its natural buyer is the virtualisation team, not the engineering team this page is written for. - **Price:** Quote — quoted per monitored host or VM; virtual and cloud infrastructure monitoring with capacity planning — built for VMware-shaped estates and their migrations - **Details:** https://www.thetechbag.com/quest/quest-foglight-evolve ### Mixpanel Product Analytics — Mixpanel - **Who it's for:** Product and engineering teams asking which features are used and where people drop out — a different question from whether the system is up. - **The honest limitation:** This is product analytics, not infrastructure observability: it will not tell you a service is down or a query is slow. Included here because the event meter and the buying team overlap, not because it substitutes for APM. - **Price:** ~$0.28 / 1k events — about $0.28 per 1,000 events over the free allowance, Enterprise from roughly $25–30k a year; product analytics — what users did in the product, funnels and retention, not whether the server was healthy - **Details:** https://www.thetechbag.com/mixpanel/mixpanel-product-analytics ### Mixpanel Session Replay — Mixpanel - **Who it's for:** Teams that have the funnel data and still cannot explain the drop-off at one step. - **The honest limitation:** Tied to the Mixpanel platform and to product questions rather than engineering ones. Privacy masking is a deliberate configuration, not a default. - **Price:** In the event tiers — metered within the Mixpanel event tiers; replays joined to the analytics events, so a funnel drop-off can be watched rather than inferred - **Details:** https://www.thetechbag.com/mixpanel/mixpanel-session-replay ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **published pricing.** Rules out Elastic Observability, Splunk Observability Cloud, Splunk ITSI, Quest Foglight Cloud and Quest Foglight Evolve — quote-only: no published list, so the quote is the only real number. That leaves Datadog APM, Datadog Infrastructure Monitoring, Datadog Log Management, Datadog Digital Experience Monitoring, Sentry Error Monitoring, Sentry Performance Monitoring, Sentry Session Replay, Mixpanel Product Analytics and Mixpanel Session Replay. **not per host.** Rules out Datadog APM and Datadog Infrastructure Monitoring — per host, so the bill tracks infrastructure and autoscaling moves it. That leaves Elastic Observability, Datadog Log Management, Datadog Digital Experience Monitoring, Sentry Error Monitoring, Sentry Performance Monitoring, Sentry Session Replay, Splunk Observability Cloud, Splunk ITSI, Quest Foglight Cloud, Quest Foglight Evolve, Mixpanel Product Analytics and Mixpanel Session Replay. **event metering.** Rules out Elastic Observability, Datadog APM, Datadog Infrastructure Monitoring, Datadog Log Management, Splunk Observability Cloud, Splunk ITSI, Quest Foglight Cloud and Quest Foglight Evolve — not event-metered. That leaves Datadog Digital Experience Monitoring, Sentry Error Monitoring, Sentry Performance Monitoring, Sentry Session Replay, Mixpanel Product Analytics and Mixpanel Session Replay. **distributed traces.** Rules out Datadog Infrastructure Monitoring, Datadog Log Management, Datadog Digital Experience Monitoring, Sentry Error Monitoring, Sentry Session Replay, Splunk ITSI, Quest Foglight Cloud, Quest Foglight Evolve, Mixpanel Product Analytics and Mixpanel Session Replay — no distributed tracing. That leaves Elastic Observability, Datadog APM, Sentry Performance Monitoring and Splunk Observability Cloud. **log search.** Rules out Datadog APM, Datadog Infrastructure Monitoring, Datadog Digital Experience Monitoring, Sentry Error Monitoring, Sentry Performance Monitoring, Sentry Session Replay, Quest Foglight Cloud, Quest Foglight Evolve, Mixpanel Product Analytics and Mixpanel Session Replay — not a log platform. That leaves Elastic Observability, Datadog Log Management, Splunk Observability Cloud and Splunk ITSI. **real user monitoring.** Rules out Datadog APM, Datadog Infrastructure Monitoring, Datadog Log Management, Sentry Error Monitoring, Sentry Performance Monitoring, Splunk ITSI, Quest Foglight Cloud, Quest Foglight Evolve and Mixpanel Product Analytics — server-side only: it cannot see what the device experienced. That leaves Elastic Observability, Datadog Digital Experience Monitoring, Sentry Session Replay, Splunk Observability Cloud and Mixpanel Session Replay. **error tracking.** Rules out Elastic Observability, Datadog APM, Datadog Infrastructure Monitoring, Datadog Log Management, Datadog Digital Experience Monitoring, Sentry Performance Monitoring, Sentry Session Replay, Splunk Observability Cloud, Splunk ITSI, Quest Foglight Cloud, Quest Foglight Evolve, Mixpanel Product Analytics and Mixpanel Session Replay — no dedicated error grouping with release and commit context. That leaves Sentry Error Monitoring. **OpenTelemetry-native.** Rules out Datadog APM, Datadog Infrastructure Monitoring, Datadog Log Management, Datadog Digital Experience Monitoring, Sentry Error Monitoring, Sentry Performance Monitoring and Splunk ITSI — OpenTelemetry is supported but the vendor agent is the primary path; Sentry Session Replay, Quest Foglight Cloud, Quest Foglight Evolve, Mixpanel Product Analytics and Mixpanel Session Replay — OpenTelemetry support is not documented. That leaves Elastic Observability and Splunk Observability Cloud. **one platform.** Rules out Sentry Error Monitoring, Sentry Performance Monitoring, Sentry Session Replay, Quest Foglight Cloud, Quest Foglight Evolve, Mixpanel Product Analytics and Mixpanel Session Replay — focused on one job rather than covering the estate. That leaves Elastic Observability, Datadog APM, Datadog Infrastructure Monitoring, Datadog Log Management, Datadog Digital Experience Monitoring, Splunk Observability Cloud and Splunk ITSI. **on-premises.** Rules out Elastic Observability, Datadog APM, Datadog Infrastructure Monitoring, Datadog Log Management, Datadog Digital Experience Monitoring, Sentry Session Replay, Splunk Observability Cloud, Quest Foglight Cloud, Mixpanel Product Analytics and Mixpanel Session Replay — SaaS only. That leaves Sentry Error Monitoring, Sentry Performance Monitoring, Splunk ITSI and Quest Foglight Evolve. **India region.** Rules nothing out on published terms. It flags Datadog APM — An India data region for telemetry is not documented on the vendor's pages, Datadog Infrastructure Monitoring — An India data region for telemetry is not documented on the vendor's pages, Datadog Log Management — An India data region for telemetry is not documented on the vendor's pages, Datadog Digital Experience Monitoring — An India data region for telemetry is not documented on the vendor's pages, Sentry Error Monitoring — An India data region for telemetry is not documented on the vendor's pages, Sentry Performance Monitoring — An India data region for telemetry is not documented on the vendor's pages, Sentry Session Replay — An India data region for telemetry is not documented on the vendor's pages, Splunk Observability Cloud — An India data region for telemetry is not documented on the vendor's pages, Splunk ITSI — An India data region for telemetry is not documented on the vendor's pages, Quest Foglight Cloud — An India data region for telemetry is not documented on the vendor's pages, Quest Foglight Evolve — An India data region for telemetry is not documented on the vendor's pages, Mixpanel Product Analytics — An India data region for telemetry is not documented on the vendor's pages and Mixpanel Session Replay — An India data region for telemetry is not documented on the vendor's pages — marked, not removed. **The meter decides the bill, not the rate.** A per-host quote and a per-GB quote for the same estate can differ by an order of magnitude. Datadog alone runs three meters — per host for APM and infrastructure, per GB ingested plus per million events indexed for logs, per session for RUM. Model your own volumes against each meter before comparing any two vendors. **Splunk does not publish list pricing here.** The per-host and per-session figures circulating online for Splunk Observability are third-party, not vendor list. We say so rather than repeating them. The quote is the only real number, and it is a volume commitment. **Cardinality is the line nobody forecasts.** Add a user ID or request ID as a metric tag and one metric becomes millions of time series. It is the most common cause of a bill that multiplies while traffic does not, and no vendor stops you doing it. **Open source is genuinely viable here.** Prometheus for metrics, Grafana for dashboards, OpenTelemetry for instrumentation, Loki or Elastic for logs. Unlike most categories on this site, the open-source path is credible for real production estates. It costs engineering time instead of licence — typically an owner, not a side project — and that trade is worth making explicitly rather than by default. ## Eight situations, and what each one buys If one of these is your sentence, the shortlist is short. ### We just need to know why it crashed, and in which release **Shortlist:** Sentry Error Monitoring, Sentry Session Replay **Why:** Exceptions grouped by fingerprint with the release, the commit and the affected users — event-metered, published from about $26 a month. **Trade-off:** No infrastructure monitoring and no log platform. If you also need host health, this is half the answer. ### A request crosses six services and nobody owns the latency **Shortlist:** Datadog APM, Splunk Observability Cloud, Sentry Performance Monitoring **Why:** Distributed tracing is the only signal that attributes time per hop across service boundaries. **Trade-off:** Datadog meters per host and compounds with its other modules; Splunk keeps every trace but publishes no list price. ### The bill doubled and traffic only grew 30% **Shortlist:** Sentry Error Monitoring, Mixpanel Product Analytics **Why:** Move from a host or ingest meter to an event meter, and cut what you index rather than what you collect. **Trade-off:** Event-metered tools are narrower. The real fix is usually cardinality and log indexing discipline, not a new vendor. ### Users say it is slow and our server metrics say it is not **Shortlist:** Datadog Digital Experience, Sentry Session Replay, Mixpanel Session Replay **Why:** Only real user monitoring sees the device, the network and the third-party scripts the backend never touches. **Trade-off:** Session-metered, so a traffic spike is a bill spike with no infrastructure change to explain it. ### We will not be locked into a vendor agent **Shortlist:** Splunk Observability Cloud **Why:** OpenTelemetry-native ingest keeps the instrumentation portable, so changing vendor does not mean reinstrumenting. **Trade-off:** Quote-only, and full-fidelity tracing is a real volume commitment. ### Telemetry cannot leave our infrastructure **Shortlist:** Sentry Error Monitoring, Splunk ITSI, Quest Foglight Evolve **Why:** All three offer a self-hosted path where residency or policy forbids SaaS telemetry. **Trade-off:** You own the upgrades, the storage and the scaling — the operational burden the SaaS price was covering. ### We have thousands of alerts and no idea which service is unhealthy **Shortlist:** Splunk ITSI **Why:** Service-level health modelling collapses alert volume into a handful of service states. **Trade-off:** Assumes the Splunk platform underneath, and the service modelling is weeks of configuration. ### We have engineering time and a tight licence budget **Shortlist:** Prometheus + Grafana + OpenTelemetry (open source) **Why:** Genuinely credible for real production estates in this category, unlike most others on this site. Named here because pretending otherwise would waste your time. **Trade-off:** It costs an owner rather than a licence. Budget the person, the storage and the upgrade path — and revisit when that person leaves. ## At scale Scale here means telemetry volume, not team size — which is the whole point of the category. ### 1 telemetry volume — One application, modest traffic - Event-metered tools are far cheaper - Error tracking usually answers the real question - Open source is overkill for one service **The test:** Price the event meter before looking at any platform. ### 2 telemetry volume — Several services, real traffic - Tracing starts earning its price - Log indexing discipline begins to matter - Cardinality becomes a live risk **The test:** Decide what gets indexed versus merely collected. ### 3 telemetry volume — Microservices at scale - Platform consolidation starts to pay - Sampling strategy is now a design decision - Retention windows become a cost lever **The test:** Model the bill at 2× and 10× before signing multi-year. ### 4 telemetry volume — Very high volume - Open source plus a specialist becomes competitive - Vendor commitment discounts require volume forecasts - Cardinality governance needs an owner **The test:** Name the person who owns cardinality. Nobody does until the bill arrives. Where a vendor does not publish list pricing, this page says so rather than repeating a third-party figure. ## Getting out Instrumentation is the lock-in, not the data. **Instrumentation** — Vendor agents mean reinstrumenting; OpenTelemetry means changing an endpoint *(Depends entirely on OTel)* **Dashboards** — Rebuilt in the new tool every time — no interchange format exists *(Not portable)* **Historical telemetry** — Exportable in principle, rarely worth the cost of moving *(Practically lost)* **Alert rules and on-call routing** — Re-authored, and the tuning that made them quiet is re-learned *(Rebuilt)* The practical consequence: instrument with OpenTelemetry from the start if you expect to change vendor, even if you use a vendor agent today. It is the single cheapest insurance in this category. ## What it costs By meter, in USD and INR, modelled at more than one volume. ### Do you already own one? Four checks, in the order most likely to return a yes. - **Your cloud provider — CloudWatch and Azure Monitor are already collecting.** Enough for infrastructure health and basic alerting; they **stop** at cross-service tracing and correlated debugging. - **Your SIEM — It already ingests many of the same logs.** Different question, different meter, and usually longer retention. Read the [SIEM guide](https://www.thetechbag.com/browse/security/siem-log-management) before buying a second log platform. - **Open source — Prometheus, Grafana and OpenTelemetry are genuinely credible here.** Not a licence cost but an engineering one — budget an owner, not a side project. - **Your APM's free tier — Sentry and Datadog both have real free tiers.** Enough to prove the meter against your own volumes before committing. This is the one category on the site where the open-source answer is genuinely competitive for production estates. Saying otherwise would cost you credibility with the engineer reading this. ### What the rest actually cost Three meters, and the published rates that exist. ### What isn't in the licence price - **Ingest and retention overage.** The largest hidden line. The licence covers a tranche; growth and retention are billed on top. - **Custom metrics and cardinality.** Frequently metered separately. One tag can multiply a metric into millions of series. - **Engineering time for open source.** Not a licence, but real and recurring. Budget an owner, storage and an upgrade path. - **Reinstrumentation on vendor change.** Unless you instrumented with OpenTelemetry, changing vendor means changing every service. ## What goes wrong Five ways this purchase goes wrong. Every one of them is a cost surprise rather than a capability gap. - **The second-year bill after traffic grew.** The forecast was built on today's volume against a meter that tracks usage. Model at 2× and 10× before signing a multi-year contract. - **A cardinality explosion from one well-meant tag.** Someone adds a user ID to a metric label. One metric becomes millions of time series and the bill multiplies with no traffic change. - **Retention shortened to control cost.** The reflex works until the incident that matters falls outside the window, and the post-mortem has no data. - **Instrumenting everything, alerting on nothing actionable.** Full telemetry and an on-call rota that ignores the pages. The tool is not the problem; nobody owns alert quality. - **Buying APM when the requirement was error tracking.** Ten times the price for a question that error tracking answers better. Read the boundary section above before shortlisting. ## Questions this guide answers ### What is the difference between monitoring and observability? Monitoring checks things you knew to check — you defined the dashboard and threshold in advance. Observability answers questions you did not anticipate, such as why one specific customer is slow on one build in one region, by keeping high-cardinality telemetry you can slice after the fact. Observability is not monitoring done better; it is a different cost structure, because keeping that detail is exactly what you pay for. ### How is observability priced? On volume, not headcount — which is what makes this category different from everything else on this site. Datadog publishes per host for APM and Infrastructure, per GB ingested plus per million events indexed for logs, and per thousand sessions for RUM. Sentry and Mixpanel meter events. Splunk does not publish list pricing for Observability Cloud. The meter matters far more than the rate: the same estate can differ by an order of magnitude depending on which meter you are quoted. ### Is Prometheus and Grafana a real alternative? Yes, and this is one of the few categories on this site where that is honestly true for production estates. Prometheus for metrics, Grafana for dashboards, OpenTelemetry for instrumentation, Loki or Elastic for logs. It substitutes engineering time for licence cost — you need a named owner rather than a side project, plus storage and an upgrade path. That trade is worth making deliberately; many estates make it by accident and then discover the owner has left. ### Why did our observability bill double when traffic only grew 30%? Almost always one of three things. Cardinality: a new tag such as a user or request ID turned one metric into millions of time series. Log indexing: ingest and indexing are separate meters at Datadog, and indexing everything is expensive. Or a host-count change: moving from a few large instances to many small autoscaled ones multiplies a per-host bill with no traffic change at all. ### Do I need APM if I already have error tracking? Only if the question is where time goes rather than what failed. Error tracking captures the exception, the release and the affected users at a fraction of APM pricing. APM traces a request across services and attributes latency per hop. If a single request crossing six services has no clear owner, you need tracing. If the real question is 'why did that crash', APM is typically a ten-times overpay. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/devops/observability-apm* --- # The licence you are quoted is for the database. The cost you will carry is the migration — and nobody quotes that. *Databases & Data Tools — a TechBag decision guide. Last reviewed 2026-09-07.* > Engine licensing is the visible number, and it is usually the smaller one. The application rewrite, the driver differences, the stored procedures and the testing are where the project actually spends — and none of it appears on a vendor quote. **The checkable fact:** The test: ask whoever estimated the migration whether they counted the schema or the application. Schema conversion is largely automatable. Application behaviour is not, and that is the half that overruns. - Canonical: https://www.thetechbag.com/browse/devops/databases-data-tools - Category: [DevOps](https://www.thetechbag.com/browse/devops) - Products compared: 20 ## What databases & data tools actually is Nineteen products doing four distinct jobs. Seven **are** the database — an engine you license and run. Six **monitor** one somebody else supplies. Five put schema changes **through the pipeline** the way application code already goes. One **models** the data for governance rather than operations. They are routinely conflated in a requirement, and the cost of conflating them is specific: buying monitoring when the problem was deployment friction, or buying an engine subscription when the actual gap was that nobody can see which query is slow. **The most common mis-purchase.** The **licence unit**. Per core, per instance, per developer or consumption — and **per core on virtualised infrastructure** is where estates get counted for hosts their database never used. Get the virtualisation counting policy in writing before signing anything per-core; it is the single most common surprise in this route. ## Four terms, resolved These are not tiers. A tool that monitors a database perfectly will not migrate it, and a migration path says nothing about whether the result is healthy. ### Database monitoring vs APM The query was slow, or the plan changed? ### Managed vs self-hosted vs DBaaS Where does the support boundary sit? ### Migration vs replication Different engine, or another copy of the same one? ### Compatibility vs conversion How much application code survives? The practical consequence: name the job before shortlisting. Half the products here cannot do the job the other half exists for, and the vocabulary hides it. ## The decision variables Seven variables move the shortlist. **Engine and version coverage.** Postgres, SQL Server, Oracle, MongoDB, MySQL — and what 'supported' means per tool, which varies from full diagnostics to a connection test. **The support boundary.** Self-managed, managed subscription on your infrastructure, or DBaaS. This decides the vendor list before any feature does. **Migration tooling and realistic effort.** Especially Oracle-to-Postgres, which is the live movement in Indian enterprises. Estimate from the application, not the schema. **Monitoring depth versus APM overlap.** Both name a slow query. Only one explains the plan. Decide whether you are buying both deliberately. **Licence model.** Per core, per instance, per developer; subscription or perpetual. Per core on virtualised hosts is the one to get in writing. **Compliance and audit reporting.** Whether the tool produces evidence an auditor accepts, or a screenshot somebody has to interpret. **India support presence and hours.** Undocumented across every vendor here. A support contract that does not cover Indian business hours is a real operational cost. ## The 20 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Elasticsearch — Elastic - **Who it's for:** Search, log analytics and — increasingly — vector storage and retrieval for AI applications, on an engine a great many engineering teams already run. - **The honest limitation:** Operating it well at scale (shard strategy, index lifecycle, capacity, upgrades) is genuine engineering work. And AWS’s OpenSearch fork has diverged enough that documentation and clients are not interchangeable — check which one you deployed. - **Price:** Free → tier — free and open source under AGPL since 2024; paid subscription tiers add features and support. Elastic Cloud Hosted priced on provisioned resources across 60 regions, Serverless on consumption - **Details:** https://www.thetechbag.com/elastic/elasticsearch ### EDB Postgres Advanced Server — EDB - **Who it's for:** Enterprises with a live Oracle renewal and budget released to move off it — the most-proven compatibility path, and the one that keeps the most stored procedures intact. - **The honest limitation:** Compatibility reduces the rewrite; it does not remove it. The estimate that matters is the application's, not the schema's — and per-core licensing on virtualised infrastructure counts hosts in ways that surprise people. Confirm what the vendor counts. - **Price:** Per core, quote — quoted per core, subscription; Oracle-compatible Postgres — PL/SQL, Oracle syntax and package compatibility so a migration changes far less application code than plain Postgres would - **Details:** https://www.thetechbag.com/edb/edb-postgres-advanced-server ### EDB Postgres Extended Server — EDB - **Who it's for:** Estates already standardised on Postgres that want a supported enterprise distribution rather than community builds. - **The honest limitation:** No Oracle compatibility layer, so it is the wrong SKU for a migration project — that is Advanced Server. Buying this expecting PL/SQL support is the most common mix-up in the EDB line. - **Price:** Per core, quote — quoted per core; enterprise-hardened Postgres without the Oracle compatibility layer — for estates already on Postgres that need enterprise support, security and extended capability - **Details:** https://www.thetechbag.com/edb/edb-postgres-extended-server ### EDB Distributed High Availability — EDB - **Who it's for:** Estates whose Postgres cannot take a maintenance window — multi-site, active-active, with failover measured in seconds. - **The honest limitation:** Active-active is an architecture decision, not a switch: conflict handling and application behaviour must be designed for it. It also adds licensed cores rather than replacing them. - **Price:** Per core, quote — quoted per core as an addition to the Postgres subscription; active-active distributed replication for near-continuous availability across sites - **Details:** https://www.thetechbag.com/edb/edb-distributed-ha ### EDB Postgres AI — EDB - **Who it's for:** Postgres estates that want vector and analytical workloads beside the transactional data instead of a second platform to move it to. - **The honest limitation:** Newer than the core server line and the strongest case assumes EDB Postgres underneath. If the requirement is a dedicated vector database, a purpose-built one is deeper. - **Price:** Quote — quoted; the multi-model platform bringing analytics and AI workloads onto the same Postgres estate rather than exporting to a separate system - **Details:** https://www.thetechbag.com/edb/edb-postgres-ai ### MongoDB Atlas — MongoDB - **Who it's for:** Teams that want the document model without operating it — and who would rather the scaling decisions be a slider than a project. - **The honest limitation:** Consumption pricing is honest and hard to forecast: an inefficient query pattern shows up as a bill rather than a slow dashboard. Egress and cross-region transfer are billed separately. - **Price:** Consumption — consumption-priced per cluster on compute, storage and data transfer, with Indian cloud regions available; the vendor runs the database and the support boundary is the endpoint - **Details:** https://www.thetechbag.com/mongodb/mongodb-atlas ### MongoDB Database (self-managed) — MongoDB - **Who it's for:** Estates that must keep the data on their own infrastructure, for residency, latency or policy reasons. - **The honest limitation:** You own the upgrades, the backups, the sharding decisions and the on-call. The Atlas features arrive later, and some do not arrive at all. - **Price:** Quote — quoted for the Enterprise Advanced subscription; the same document database run on your own infrastructure, with the operational burden and the residency control both yours - **Details:** https://www.thetechbag.com/mongodb/mongodb-database ### MongoDB Atlas Vector Search — MongoDB - **Who it's for:** Teams building AI retrieval features that already store the source documents in MongoDB — one database, no synchronisation job. - **The honest limitation:** Tied to Atlas: the self-managed database is not the path here. A dedicated vector database will be deeper on index tuning and scale. - **Price:** In Atlas consumption — metered within Atlas consumption; vector storage and search beside the operational documents, so retrieval-augmented applications query one database rather than syncing two - **Details:** https://www.thetechbag.com/mongodb/mongodb-vector-search ### Redgate Monitor — Redgate - **Who it's for:** DBA teams responsible for many instances who need one place to see which of them is unhealthy right now. - **The honest limitation:** Instance-metered, so a sprawling estate of small databases costs like a large one. It watches the database and does not trace the application request that caused the load. - **Price:** Per instance, quote — quoted per monitored instance; estate-wide database health — waits, blocking, disk, backups and alerting across SQL Server, Postgres and Oracle from one console - **Details:** https://www.thetechbag.com/redgate/redgate-monitor ### Redgate Flyway — Redgate - **Who it's for:** Teams whose deployments stall because the schema change is a manual step performed by one person at the weekend. - **The honest limitation:** Per developer, so it scales with the team rather than the estate. It versions the schema; it does not tell you the production database is unhealthy. - **Price:** Per developer, quote — quoted per developer; schema migrations under version control so database changes ship through the same pipeline as application code, with a documented rollback path - **Details:** https://www.thetechbag.com/redgate/redgate-flyway ### Redgate Test Data Manager — Redgate - **Who it's for:** Regulated estates where a production restore into a test environment is the quiet compliance problem nobody has raised yet. - **The honest limitation:** Masking rules are yours to define and maintain, and they drift as the schema changes. It is a discipline with a tool, not a tool that supplies the discipline. - **Price:** Per developer, quote — quoted per developer; provisioning realistic test databases with sensitive fields masked, so non-production environments stop being a copy of production data - **Details:** https://www.thetechbag.com/redgate/redgate-test-data-manager ### Redgate SQL Toolbelt — Redgate - **Who it's for:** SQL Server shops whose developers work in SSMS all day and lose time to manual comparison and deployment scripting. - **The honest limitation:** SQL Server only. On a mixed estate it covers one engine and Flyway covers the rest, which is two licences for one job. - **Price:** Per developer, quote — quoted per developer; the SQL Server developer bundle — compare, data compare, prompt, source control and unit testing in one licence - **Details:** https://www.thetechbag.com/redgate/redgate-sql-toolbelt ### Idera SQL Diagnostic Manager — Idera - **Who it's for:** SQL Server estates that want deep engine-level diagnostics on their own infrastructure without a SaaS telemetry pipeline. - **The honest limitation:** SQL Server only and on-premises oriented. It is a specialist, so a mixed-engine estate needs a second tool beside it. - **Price:** Per instance, quote — quoted per monitored instance, perpetual or subscription; SQL Server performance monitoring with query-level diagnostics, blocking analysis and predictive alerting - **Details:** https://www.thetechbag.com/idera/idera-sql-diagnostic-manager ### Idera DB PowerStudio — Idera - **Who it's for:** DBA teams running a genuinely mixed estate who would rather learn one tool than four vendor consoles. - **The honest limitation:** Breadth over depth: it is not as deep on any single engine as that engine's specialist. Interface age shows against newer tools. - **Price:** Per developer, quote — quoted per developer; cross-platform DBA and development tooling — administration, development, tuning and space management across four engines from one interface - **Details:** https://www.thetechbag.com/idera/idera-db-powerstudio ### Idera ER/Studio — Idera - **Who it's for:** Organisations that need the data model documented and governed rather than inferred from whatever is in production. - **The honest limitation:** Modelling and governance, not operations: it will not tell you the database is slow. Its value depends on someone owning the models, which is a role rather than a licence. - **Price:** Per developer, quote — quoted per named user; enterprise data modelling — logical and physical models, lineage and a business glossary over a multi-engine estate - **Details:** https://www.thetechbag.com/idera/idera-er-studio ### Idera SQL Safe Backup — Idera - **Who it's for:** SQL Server estates whose backup window has stopped fitting the night, or whose restore time is the number that fails an audit. - **The honest limitation:** SQL Server only and focused on the database layer — see the Backup & Cyber Resilience guides for the estate-wide picture including immutability. - **Price:** Per instance, quote — quoted per instance; compressed, encrypted SQL Server backups with faster restores and policy-based scheduling across the estate - **Details:** https://www.thetechbag.com/idera/idera-sql-safe-backup ### Quest Foglight for Databases — Quest - **Who it's for:** Genuinely mixed estates that need one console across every engine rather than a specialist tool per database. - **The honest limitation:** Breadth means the per-engine depth is behind the single-engine specialists, and the console is dense. It is a platform decision, not a quick install. - **Price:** Per instance, quote — quoted per monitored instance; cross-platform database observability with workload analytics across the widest engine list here — SQL Server, Oracle, Postgres, MySQL, MongoDB and more - **Details:** https://www.thetechbag.com/quest/quest-foglight-databases ### Quest Foglight for SQL Server — Quest - **Who it's for:** SQL Server estates wanting Quest depth on one engine without the cross-platform console. - **The honest limitation:** Single engine, and on a mixed estate you end up buying the cross-platform edition anyway. Compare the two before signing. - **Price:** Per instance, quote — quoted per monitored instance; SQL Server-specific performance monitoring with wait-state analysis and change tracking on the engine - **Details:** https://www.thetechbag.com/quest/quest-foglight-sql-server ### Quest Foglight for Oracle — Quest - **Who it's for:** Oracle estates — including those planning an exit, where knowing which workloads are genuinely heavy shapes the migration order. - **The honest limitation:** Oracle only. If the plan is to leave Oracle, this is a tool for the journey rather than the destination. - **Price:** Per instance, quote — quoted per monitored instance; Oracle performance monitoring with wait-event analysis, RAC awareness and storage correlation - **Details:** https://www.thetechbag.com/quest/quest-foglight-oracle ### Quest Foglight Performance Investigator — Quest - **Who it's for:** Estates whose recurring incident is 'the same query got slow overnight' and nobody can prove what changed. - **The honest limitation:** An add-on rather than a standalone product, so it assumes Foglight underneath and adds to that bill. - **Price:** Per instance, add-on — quoted per instance as an addition to Foglight; query-level diagnostics with historical plan comparison — the layer that answers why the plan changed, not merely that it did - **Details:** https://www.thetechbag.com/quest/quest-foglight-performance-investigator ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Postgres.** Rules out Elasticsearch, MongoDB Atlas, MongoDB Database (self-managed), MongoDB Atlas Vector Search, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera SQL Safe Backup, Quest Foglight for SQL Server and Quest Foglight for Oracle — Postgres is not a covered engine. That leaves EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Idera DB PowerStudio, Idera ER/Studio, Quest Foglight for Databases and Quest Foglight Performance Investigator. **SQL Server.** Rules out Elasticsearch, EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, MongoDB Atlas, MongoDB Database (self-managed), MongoDB Atlas Vector Search and Quest Foglight for Oracle — SQL Server is not covered. That leaves Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera DB PowerStudio, Idera ER/Studio, Idera SQL Safe Backup, Quest Foglight for Databases, Quest Foglight for SQL Server and Quest Foglight Performance Investigator. **Oracle.** Rules out Elasticsearch, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, MongoDB Atlas, MongoDB Database (self-managed), MongoDB Atlas Vector Search, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera SQL Safe Backup and Quest Foglight for SQL Server — Oracle is not covered. That leaves EDB Postgres Advanced Server, Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Idera DB PowerStudio, Idera ER/Studio, Quest Foglight for Databases, Quest Foglight for Oracle and Quest Foglight Performance Investigator. **MongoDB.** Rules out Elasticsearch, EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera DB PowerStudio, Idera SQL Safe Backup, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator — MongoDB is not covered. That leaves MongoDB Atlas, MongoDB Database (self-managed), MongoDB Atlas Vector Search, Idera ER/Studio and Quest Foglight for Databases. **the database itself.** Rules out Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera DB PowerStudio, Idera ER/Studio, Idera SQL Safe Backup, Quest Foglight for Databases, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator — a tool that works on a database somebody else supplies. That leaves Elasticsearch, EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, MongoDB Atlas, MongoDB Database (self-managed) and MongoDB Atlas Vector Search. **database monitoring.** Rules out Elasticsearch, EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, MongoDB Atlas, MongoDB Database (self-managed), MongoDB Atlas Vector Search, Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera DB PowerStudio, Idera ER/Studio and Idera SQL Safe Backup — not a monitoring product. That leaves Redgate Monitor, Idera SQL Diagnostic Manager, Quest Foglight for Databases, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator. **database DevOps.** Rules out Elasticsearch, EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, MongoDB Atlas, MongoDB Database (self-managed), MongoDB Atlas Vector Search, Redgate Monitor, Idera SQL Diagnostic Manager, Idera ER/Studio, Quest Foglight for Databases, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator — not database DevOps tooling. That leaves Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera DB PowerStudio and Idera SQL Safe Backup. **migration tooling.** Rules out Elasticsearch, EDB Postgres Extended Server, EDB Postgres AI, MongoDB Atlas, MongoDB Database (self-managed), Redgate Flyway, Idera DB PowerStudio and Idera ER/Studio — some import tooling, but no documented engine-migration path; EDB Distributed High Availability, MongoDB Atlas Vector Search, Redgate Monitor, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera SQL Safe Backup, Quest Foglight for Databases, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator — no migration tooling. That leaves EDB Postgres Advanced Server. **a managed service.** Rules out EDB Distributed High Availability, MongoDB Database (self-managed), Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera DB PowerStudio, Idera ER/Studio, Idera SQL Safe Backup, Quest Foglight for Databases, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator — no managed service: the operational burden is yours. That leaves Elasticsearch, EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Postgres AI, MongoDB Atlas and MongoDB Atlas Vector Search. **on-premises.** Rules out Elasticsearch, MongoDB Atlas and MongoDB Atlas Vector Search — managed service only. That leaves EDB Postgres Advanced Server, EDB Postgres Extended Server, EDB Distributed High Availability, EDB Postgres AI, MongoDB Database (self-managed), Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera DB PowerStudio, Idera ER/Studio, Idera SQL Safe Backup, Quest Foglight for Databases, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator. **not per-core.** Rules out EDB Postgres Advanced Server, EDB Postgres Extended Server and EDB Distributed High Availability — per-core licensing, which on virtualised infrastructure counts hosts in ways that surprise people. That leaves Elasticsearch, EDB Postgres AI, MongoDB Atlas, MongoDB Database (self-managed), MongoDB Atlas Vector Search, Redgate Monitor, Redgate Flyway, Redgate Test Data Manager, Redgate SQL Toolbelt, Idera SQL Diagnostic Manager, Idera DB PowerStudio, Idera ER/Studio, Idera SQL Safe Backup, Quest Foglight for Databases, Quest Foglight for SQL Server, Quest Foglight for Oracle and Quest Foglight Performance Investigator. **an Indian region.** Rules nothing out on published terms. It flags EDB Postgres Advanced Server — An Indian region or in-country support hours are not documented on the vendor's pages, EDB Postgres Extended Server — An Indian region or in-country support hours are not documented on the vendor's pages, EDB Distributed High Availability — An Indian region or in-country support hours are not documented on the vendor's pages, EDB Postgres AI — An Indian region or in-country support hours are not documented on the vendor's pages, MongoDB Database (self-managed) — An Indian region or in-country support hours are not documented on the vendor's pages, Redgate Monitor — An Indian region or in-country support hours are not documented on the vendor's pages, Redgate Flyway — An Indian region or in-country support hours are not documented on the vendor's pages, Redgate Test Data Manager — An Indian region or in-country support hours are not documented on the vendor's pages, Redgate SQL Toolbelt — An Indian region or in-country support hours are not documented on the vendor's pages, Idera SQL Diagnostic Manager — An Indian region or in-country support hours are not documented on the vendor's pages, Idera DB PowerStudio — An Indian region or in-country support hours are not documented on the vendor's pages, Idera ER/Studio — An Indian region or in-country support hours are not documented on the vendor's pages, Idera SQL Safe Backup — An Indian region or in-country support hours are not documented on the vendor's pages, Quest Foglight for Databases — An Indian region or in-country support hours are not documented on the vendor's pages, Quest Foglight for SQL Server — An Indian region or in-country support hours are not documented on the vendor's pages, Quest Foglight for Oracle — An Indian region or in-country support hours are not documented on the vendor's pages and Quest Foglight Performance Investigator — An Indian region or in-country support hours are not documented on the vendor's pages — marked, not removed. **Per core is the licensing trap.** On virtualised infrastructure, per-core counting frequently includes cores your database never uses — the host's, not the VM's. Confirm in writing what the vendor counts before signing anything per-core, and get the virtualisation policy in the contract. **Migration is estimated from the wrong artefact.** Teams estimate an Oracle-to-Postgres move from the schema, because the schema is easy to count. The cost lives in the application: stored procedures, driver behaviour, SQL dialect, transaction assumptions. EDB's compatibility layer reduces that work materially; it does not remove it. **Monitoring gets bought twice.** APM names the slow query from the outside; database monitoring explains it from inside the engine. Estates commonly own both without deciding to. That is defensible — but decide it, rather than discovering it at renewal. **Open source is not free at the support boundary.** Postgres, MySQL and MongoDB community editions cost nothing to download. The number that appears later is the support contract, and it appears at the worst possible moment. Budget it at the start. ## Eight situations, and what each one buys If one of these is your sentence, the shortlist is short. ### An Oracle renewal arrived and somebody said Postgres **Shortlist:** EDB Postgres Advanced Server, Quest Foglight for Oracle **Why:** Advanced Server is the most-proven compatibility path; Foglight for Oracle tells you which workloads are heavy, which decides the migration order. **Trade-off:** Compatibility reduces the rewrite rather than removing it — read the depth section below before committing to a date. ### We run four different engines and four different consoles **Shortlist:** Quest Foglight for Databases, Idera DB PowerStudio **Why:** Both cover a genuinely mixed estate from one place — Foglight for monitoring, PowerStudio for administration. **Trade-off:** Breadth trades against per-engine depth; the specialists see more on any single engine. ### Schema changes are a manual step someone does at the weekend **Shortlist:** Redgate Flyway, Redgate SQL Toolbelt **Why:** Migrations under version control, shipping through the same pipeline as application code, with a documented rollback. **Trade-off:** Per developer, so it scales with team size. Toolbelt is SQL Server only; Flyway spans engines. ### We do not want to run a database at all **Shortlist:** MongoDB Atlas, EDB Postgres AI **Why:** The vendor owns upgrades, backups and scaling; you get an endpoint and a support boundary. **Trade-off:** Consumption pricing is honest and hard to forecast — an inefficient query becomes a bill rather than a slow dashboard. ### The data cannot leave our infrastructure **Shortlist:** MongoDB Database (self-managed), EDB Postgres Advanced Server, Idera SQL Diagnostic Manager **Why:** All three run entirely on your own infrastructure with a commercial support contract behind them. **Trade-off:** You own the upgrades and the on-call — the operational burden the managed price was covering. ### The same query got slow overnight and nothing changed **Shortlist:** Quest Foglight Performance Investigator, Idera SQL Diagnostic Manager, Redgate Monitor **Why:** Historical plan comparison is the only thing that proves what changed — usually statistics or an index, not the code. **Trade-off:** Performance Investigator is an add-on and assumes Foglight underneath. ### Our test environment is a copy of production, including the personal data **Shortlist:** Redgate Test Data Manager **Why:** Provisioning realistic test databases with sensitive fields masked, which is the quiet compliance problem in most estates. **Trade-off:** Masking rules are yours to define and they drift as the schema changes. ### We are building retrieval features on our own documents **Shortlist:** MongoDB Atlas Vector Search, EDB Postgres AI **Why:** Vectors beside the operational data means one database and no synchronisation job between two systems. **Trade-off:** Both assume their platform underneath, and a dedicated vector database will be deeper on index tuning at scale. ## At scale Database tooling scales by instance count and engine variety, not by user count. ### 1 database instances — A handful of instances, one engine - Native tooling plus a specialist is enough - Per-instance pricing is affordable at this size - Schema changes can still be manual, just about **The test:** Version the schema before the team grows, not after. ### 2 database instances — Dozens of instances, one or two engines - Estate-wide monitoring starts to pay - Per-instance costs become visible - Test data and masking become a real question **The test:** Count instances honestly — sprawl is what moves this bill. ### 3 database instances — Mixed engines at scale - Cross-platform consoles beat four specialists - Licence models differ per engine and complicate renewal - Modelling and lineage start to matter **The test:** Compare the cross-platform edition against the specialists you already own. ### 4 database instances — Enterprise, with a migration in flight - Per-core counting on virtualised hosts becomes material - Monitoring both old and new engines through the transition - Support hours and escalation paths become contractual **The test:** Get the virtualisation counting policy in the contract, in writing. Where a vendor does not publish list pricing, this page says so rather than implying a figure. ## Getting out The database is the hardest thing on this site to leave, and the tooling around it is not. **The data** — Every engine exports; the format and the downtime are the negotiation *(Portable, with a window)* **Stored procedures and dialect SQL** — Rewritten unless the target offers a compatibility layer *(The real cost)* **Monitoring configuration** — Thresholds, baselines and alert routing are re-authored per tool *(Rebuilt)* **Schema version history** — Flyway and similar keep migrations in your repository, not the vendor's *(Portable if versioned)* The practical consequence: version your schema migrations in your own repository from day one. It is the one artefact here that stays yours whatever you buy next. ## What it costs By licence unit, in USD and INR, with the counting policy named. ### Do you already own one? Four checks, in the order most likely to return a yes. - **Your cloud provider — RDS, Azure SQL and Cloud SQL include basic monitoring.** Enough for health and simple alerting; they **stop** at wait-state and plan-level diagnosis. - **Native engine tooling — Query Store, pg_stat_statements and AWR are already there.** Genuinely useful and free, and they need somebody who knows how to read them. - **Your APM — It already names the slow query.** Different depth, same symptom. See the boundary section before buying database monitoring as well. - **Community editions — Postgres, MySQL and MongoDB cost nothing to download.** The support contract is the number that appears later. Budget it at the start, not at the incident. Native tooling is stronger in this category than most buyers assume. The case for a commercial tool is usually estate-wide visibility, not depth on one instance. ### What the rest actually cost Four licence units, and where each one surprises people. ### What isn't in the licence price - **Migration effort.** The largest line in any engine change, and it never appears on the vendor quote. Estimate from the application. - **Support contracts on open source.** Community editions are free to download. Production support is not, and it is needed at the worst moment. - **Per-core counting on virtual hosts.** Cores your database never used, counted because the hypervisor could have scheduled them there. - **The DBA who reads the output.** Every monitoring tool here produces more signal than an unowned console will ever action. ## What goes wrong Five ways this purchase goes wrong. - **Per-core licensing counted against the host, not the VM.** The estate is billed for cores the database never used. Get the virtualisation counting policy in the contract before signing. - **Migration estimated from the schema.** Tables convert; PL/SQL, driver behaviour and application assumptions do not. The schema is the easy half and the cheap half. - **Monitoring bought twice.** Once inside APM and once at the database layer. Defensible if deliberate — expensive when discovered at renewal. - **Support hours that miss Indian business hours.** A severity-one at 10am IST answered at 9am Pacific is a working day lost. Confirm coverage, not just the SLA number. - **Open source assumed free, then the support contract arrives.** Usually mid-incident, at a price nobody budgeted. Decide the support position before production, not during it. ## Questions this guide answers ### What does an Oracle-to-Postgres migration actually cost? The licence saving is real and survives scrutiny; the migration cost is where estimates fail. Schema conversion — tables, indexes, constraints — is largely automatable. What is not: PL/SQL packages, Oracle-specific SQL, driver behaviour, sequence and transaction semantics, and every application that assumed Oracle. EDB Postgres Advanced Server accepts PL/SQL and Oracle syntax, which materially reduces that second half; it does not remove it. Estimate from the application, not the schema, and run an assessment before committing to a date. ### What is the difference between database monitoring and APM? APM traces the request from outside and names the slow query. Database monitoring sits inside the engine: wait states, execution plans, index health, blocking chains. APM rarely tells you the statistics went stale or the plan flipped under a parameter sniff; database monitoring cannot follow a request across six services. Many estates own both, which is defensible — the question is whether they chose to or discovered it. ### How are database tools licensed? Four different units on this page. EDB quotes per core by subscription. Redgate quotes per developer for Flyway, Test Data Manager and SQL Toolbelt, and per instance for Monitor. Idera and Quest quote per monitored instance. MongoDB Atlas is consumption-priced. Per core is the one that surprises people: on virtualised infrastructure the vendor may count the host's cores rather than the VM's, so get the counting policy in writing. ### Is community Postgres good enough without a commercial subscription? For many workloads, yes — Postgres is genuinely production-grade. What you are buying with a commercial subscription is a support boundary and, in EDB Advanced Server's case, Oracle compatibility. The mistake is assuming free means free: the support contract is needed at the worst possible moment, and negotiating it during an incident costs more than budgeting it at the start. ### Do these tools support Indian business hours? It is not documented on the vendor pages for any product on this page, which is why we mark it unknown rather than assume either way. It is a real operational cost — a severity-one raised at 10am IST and answered at 9am Pacific is a working day lost. Ask for coverage hours and the escalation path in the contract, not just the SLA number, and TechBag will confirm it as part of the quote. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/devops/databases-data-tools* --- # This is the one route here that meters per seat — and the seat count you are quoted is rarely the seat count you end up paying for. *Developer Tools — a TechBag decision guide. Last reviewed 2026-09-07.* > Seats drift because access is easy to grant and nobody audits it. Then the second meter arrives: CI minutes, build runners, monitor runs and AI assistants are all billed apart from the licence they sit beside. **The checkable fact:** GitHub, GitLab and Bitbucket all meter build minutes separately from seats. A busy pipeline can exceed the seat bill entirely — and nothing in the platform warns you before the invoice does. - Canonical: https://www.thetechbag.com/browse/devops/developer-tools - Category: [DevOps](https://www.thetechbag.com/browse/devops) - Products compared: 14 ## What developer tools actually is Thirteen products across four jobs. Four are **platforms or source control** — where the code lives and how it ships. Four are **API lifecycle** tooling. Three are **infrastructure and secrets**, adjacent to the pipeline rather than inside it. And two are **AI assistants**, licensed separately from the platforms they run in. Application security appears here as a *section*, not a route: SAST, dependency and secrets scanning ship inside the SCM platforms and are compared below. Runtime and cloud posture — CNAPP, WAF — are a different purchase entirely and live on the Security and Network Security categories, cross-linked and not repeated here. **The most common mis-purchase.** The **licence unit**, and the **second meter** beside it. GitHub, GitLab, Atlassian and Postman price per user; Terraform meters managed resources; Vault meters clients; JetBrains licenses per named user or a floating pool. Then CI minutes, runners, monitor runs and AI seats are billed *apart*. Model the total, never the per-seat rate. ## Four terms, resolved These are not tiers. A DevOps platform is not source control done better — it is four purchases bundled, and whether that is cheaper depends entirely on how many of the four you would otherwise buy. ### SCM vs CI/CD Where the code lives, or what happens when it changes? ### SCM vs DevOps platform One vendor, or best-of-breed? ### IDE licensing vs seat licensing Who is the licence attached to? ### Secrets management vs configuration A credential, or a setting? The practical consequence: price the whole toolchain, not the seat. Every product here has a second meter, and the second meter is where the forecast breaks. ## The decision variables Seven variables move the shortlist. **One platform or best-of-breed.** GitLab's case is strongest when you use most of it. Using SCM and CI alone means paying for planning and scanning you do not touch. **CI/CD minutes and runner costs.** Metered separately everywhere, and frequently larger than the seat bill. Self-hosted runners trade the meter for machines you operate. **Self-hosted or SaaS.** The documented route to India residency for GitHub Enterprise Server and GitLab self-managed. It moves upgrades onto your team. **The licence unit.** Named user, concurrent, floating or per-organisation. JetBrains and Atlassian differ sharply from GitHub and GitLab here. **AI assistant bundling.** The fastest-moving variable in this category. Generous in the trial, itemised at renewal — model the tier plus the assistant. **Pipeline security scanning.** SAST, dependency and secrets scanning are in the platform tiers. Runtime and cloud posture are a different purchase entirely. **Contractors and occasional committers.** Every model treats them differently, and this is where seat counts drift furthest from headcount. ## The 14 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Elastic Enterprise Search — Elastic - **Who it's for:** Teams building search into their own product, website or ecommerce, or across internal content — with relevance tuning, semantic search and vector retrieval rather than a bolted-on search box. - **The honest limitation:** Relevance tuning is a skill rather than a setting: the platform gives you the levers and someone has to learn them. Same cluster, same operational burden as the rest of the Elastic platform. - **Price:** Free → tier — built on Elasticsearch — free engine under AGPL plus a subscription tier; Elastic Cloud Hosted on provisioned resources or Serverless on consumption - **Details:** https://www.thetechbag.com/elastic/elastic-enterprise-search ### GitHub Enterprise — GitHub - **Who it's for:** Teams that want the largest ecosystem, the deepest third-party integration and the hiring advantage of the tool most developers already know. - **The honest limitation:** Three meters on one platform: seats, Actions minutes and Advanced Security. The minutes line is the one that surprises — a busy monorepo pipeline can exceed the seat bill without anybody noticing until the invoice. - **Price:** Per seat + minutes — per user / month for the platform, with GitHub Actions CI metered separately in minutes and Advanced Security licensed as an addition; Enterprise Cloud or Enterprise Server for self-hosting - **Details:** https://www.thetechbag.com/github/github-enterprise ### GitHub Copilot — GitHub - **Who it's for:** Teams where the measurable win is time-to-first-draft on routine code, and where the editors in use are supported. - **The honest limitation:** A separate line at renewal, however generous the trial was. Seat counts drift upward faster than developer headcount because access is easy to grant and nobody audits it. - **Price:** Per seat, published — per user / month, published tiers, licensed separately from GitHub Enterprise; code completion, chat and agentic assistance inside the editor and the pull request - **Details:** https://www.thetechbag.com/github/github-copilot ### GitLab DevSecOps Platform — GitLab - **Who it's for:** Estates that want one vendor and one bill across the whole toolchain rather than integrating four products — and self-managed installation where India residency requires it. - **The honest limitation:** The single-platform case is strongest when you use most of it; teams using SCM and CI alone pay for planning and scanning they do not touch. Self-managed means you own the upgrades, which is a standing job. - **Price:** Per seat + minutes — per user / month across Free, Premium and Ultimate, with CI minutes metered separately; SCM, CI/CD, security scanning, packages and planning under one licence — Ultimate carries the full scanning set - **Details:** https://www.thetechbag.com/gitlab/gitlab-devsecops-platform ### GitLab Duo — GitLab - **Who it's for:** GitLab estates that want AI assistance without introducing a second vendor's tooling and a second data-handling conversation. - **The honest limitation:** An add-on rather than an inclusion — the same renewal surprise as Copilot. Capability depends on the underlying GitLab tier, so the comparison is tier-plus-Duo against a rival's equivalent. - **Price:** Per seat add-on — per user / month as an addition to a GitLab tier; AI code suggestions, chat, vulnerability explanation and merge-request summaries inside the platform - **Details:** https://www.thetechbag.com/gitlab/gitlab-duo ### Atlassian Bitbucket — Atlassian - **Who it's for:** Organisations already standardised on Jira that want source, branches and pull requests linked to the work item without an integration to maintain. - **The honest limitation:** A smaller ecosystem than GitHub or GitLab, and the strongest case assumes Jira. Atlassian pricing steps at user-count thresholds, so crossing one costs more than the extra seats suggest. - **Price:** Per user + minutes — per user / month with Pipelines build minutes metered separately; source control that shares identity, permissions and issue linking with Jira - **Details:** https://www.thetechbag.com/atlassian/atlassian-bitbucket ### Atlassian Jira — Atlassian - **Who it's for:** Engineering organisations that need the work item, the branch and the release connected — the planning half of the toolchain rather than the code half. - **The honest limitation:** Planning, not source control or CI. Pricing steps at user-count thresholds and the jump is the thing to model — crossing 100 users is not a linear increase. - **Price:** Per user, published — per user / month across Free, Standard, Premium and Enterprise, published; issue tracking and planning for software teams, linked to the branch and the deployment - **Details:** https://www.thetechbag.com/atlassian/atlassian-jira ### Postman API Client — Postman - **Who it's for:** Any team building or consuming APIs, which is nearly all of them — this is usually already in use before it is ever purchased. - **The honest limitation:** The free tier is genuinely capable, so the paid case is collaboration and governance rather than the client itself. Shadow usage on free accounts is common and worth auditing. - **Price:** Per user, published — per user / month with a free tier; the client most API developers already have open — requests, environments, collections and history - **Details:** https://www.thetechbag.com/postman/postman-api-client ### Postman API Design — Postman - **Who it's for:** Teams where the API contract needs agreeing before implementation — typically where a separate team consumes it. - **The honest limitation:** Design-first is a working practice more than a product: without the discipline, the tool produces schemas nobody updates. Value depends on adoption, not licences. - **Price:** In the Postman tiers — within the per-user Postman tiers; schema-first API design with OpenAPI, mocking and documentation generated from the contract rather than written after it - **Details:** https://www.thetechbag.com/postman/postman-api-design ### Postman API Testing — Postman - **Who it's for:** Teams whose integration failures are found by customers rather than by the pipeline. - **The honest limitation:** Scheduled monitor runs are a separate meter from seats — small, but a second meter nonetheless. It tests the API, not the user journey through the interface. - **Price:** In the Postman tiers — within the per-user tiers, with monitor runs metered separately; automated API tests that run in CI and on a schedule against live environments - **Details:** https://www.thetechbag.com/postman/postman-api-testing ### Postman Governance — Postman - **Who it's for:** Organisations with more APIs than anyone can list, and no consistent standard across teams. - **The honest limitation:** Governance is only as real as the enforcement: rules that warn rather than block are ignored within a quarter. Enterprise-tier only. - **Price:** Enterprise tiers — in the Enterprise per-user tiers; API standards enforcement, secret detection in collections, and visibility of every API the organisation has published - **Details:** https://www.thetechbag.com/postman/postman-governance ### HashiCorp Terraform — HashiCorp - **Who it's for:** Teams whose infrastructure changes should be reviewed, versioned and repeatable rather than clicked in a console. - **The honest limitation:** The per-managed-resource meter means the bill tracks infrastructure sprawl, not team size — a resource nobody uses still counts. IBM-owned since 2025, which some estates weigh in a multi-year commitment. - **Price:** Per managed resource — HCP Terraform priced per managed resource per month with a free tier; Terraform Enterprise self-hosted on quote — infrastructure as code with state management, policy and a run history - **Details:** https://www.thetechbag.com/hashicorp/hashicorp-terraform ### HashiCorp Vault — HashiCorp - **Who it's for:** Estates where credentials currently live in CI variables and configuration files, and somebody has finally asked who can read them. - **The honest limitation:** Client-based metering is hard to forecast, because a client is any application or workload that authenticates. Vault is also an operational commitment: it becomes a critical dependency the day you adopt it. - **Price:** Quote (per client) — quoted on active clients for HCP Vault or Vault Enterprise; centralised secrets with dynamic credentials, rotation and an audit trail — the machine-identity half of the toolchain - **Details:** https://www.thetechbag.com/hashicorp/hashicorp-vault ### HashiCorp Consul — HashiCorp - **Who it's for:** Estates running many services across environments where discovery and service-to-service encryption are the operational gap. - **The honest limitation:** A service mesh is a serious architectural commitment with its own failure modes, and many estates adopt one before they need it. If service count is modest, native platform networking is usually enough. - **Price:** Quote (per service) — quoted per service instance; service discovery, health checking and service-mesh networking with mutual TLS between services - **Details:** https://www.thetechbag.com/hashicorp/hashicorp-consul ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **one platform.** Rules out Elastic Enterprise Search, Atlassian Bitbucket, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — one layer of the toolchain, not the whole platform. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo and Atlassian Jira. **pipeline scanning.** Rules out Elastic Enterprise Search, GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, HashiCorp Terraform and HashiCorp Consul — no pipeline security scanning; Atlassian Bitbucket, Postman Governance and HashiCorp Vault — one scanning type only, not the SAST + dependency + secrets set. That leaves GitHub Enterprise and GitLab DevSecOps Platform. **API tooling.** Rules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — not API-lifecycle tooling. That leaves Elastic Enterprise Search, Postman API Client, Postman API Design, Postman API Testing and Postman Governance. **infrastructure and secrets.** Rules out Elastic Enterprise Search, GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance — not infrastructure or secrets tooling. That leaves HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul. **per-seat pricing.** Rules out Elastic Enterprise Search and HashiCorp Terraform — consumption-metered: the bill tracks resources, not people; HashiCorp Vault and HashiCorp Consul — quote-only, and metered on clients or services rather than seats. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance. **no metered minutes.** Rules out GitHub Enterprise, GitLab DevSecOps Platform and Atlassian Bitbucket — CI minutes are metered separately and routinely exceed the seat bill. That leaves Elastic Enterprise Search, GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul. **published pricing.** Rules out HashiCorp Vault and HashiCorp Consul — quote-only. That leaves Elastic Enterprise Search, GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance and HashiCorp Terraform. **self-hosting.** Rules out GitHub Copilot, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance — SaaS only, so India residency cannot be met by deployment choice. That leaves Elastic Enterprise Search, GitHub Enterprise, GitLab DevSecOps Platform, GitLab Duo, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul. **AI assistance.** Rules out Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — no AI assistant documented for this product. That leaves Elastic Enterprise Search, GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform and GitLab Duo. **an Indian region.** Rules nothing out on published terms. It flags GitHub Enterprise — No Indian SaaS region is documented, GitHub Copilot — No Indian region is documented and there is no self-hosted option, GitLab DevSecOps Platform — No Indian SaaS region is documented, GitLab Duo — No Indian SaaS region is documented, Atlassian Bitbucket — No Indian region is documented and there is no self-hosted option, Atlassian Jira — No Indian region is documented and there is no self-hosted option, Postman API Client — No Indian region is documented and there is no self-hosted option, Postman API Design — No Indian region is documented and there is no self-hosted option, Postman API Testing — No Indian region is documented and there is no self-hosted option, Postman Governance — No Indian region is documented and there is no self-hosted option, HashiCorp Terraform — No Indian SaaS region is documented, HashiCorp Vault — No Indian SaaS region is documented and HashiCorp Consul — No Indian SaaS region is documented — marked, not removed. **The minutes are the surprise, not the seats.** GitHub Actions, GitLab CI and Bitbucket Pipelines all meter build minutes separately from the seat licence. A busy monorepo with a matrix build can exceed its seat bill without anybody noticing until the invoice — and the fix is pipeline discipline, not a different vendor. **Seat counts drift upward, quietly.** Access is easy to grant and nobody audits it. Contractors, occasional committers and people who left the team last quarter all count. Audit against actual commit activity before every renewal; it is the cheapest saving in this route. **AI assistants are bundled in the trial, itemised at renewal.** Copilot and GitLab Duo are both separate licences however the pilot was framed. Model the platform tier PLUS the assistant when comparing vendors, because that is the number you will pay in year two. **JetBrains is carried but not ranked here.** TechBag sells JetBrains licences and it belongs in this route. There are no intel pages yet, so it is named and not ranked rather than silently omitted. Its licence unit differs materially from everything carded here — per named user or a floating pool, which changes the maths for teams with part-time or shift-based developers. ## Eight situations, and what each one buys If one of these is your sentence, the shortlist is short. ### We want one vendor for the whole toolchain **Shortlist:** GitLab DevSecOps Platform, GitHub Enterprise **Why:** SCM, CI, packages, scanning and planning under one licence and one renewal conversation. **Trade-off:** You pay for the whole platform whether or not you use the whole platform. Price it against what you would otherwise buy. ### Repository data cannot leave India **Shortlist:** GitLab DevSecOps Platform (self-managed), GitHub Enterprise Server, HashiCorp Vault (self-hosted) **Why:** Self-hosting is the documented residency route — no vendor here publishes an Indian SaaS region. **Trade-off:** Somebody owns upgrades, backups and availability. That role is the real cost, and it is usually unassigned at signature. ### CI cost more than the seat licences last month **Shortlist:** GitLab DevSecOps Platform, GitHub Enterprise **Why:** Both support self-hosted runners, which trades the per-minute meter for machines you already pay for. **Trade-off:** Self-hosted runners are infrastructure you now maintain and secure — and a compromised runner is a supply-chain problem. ### Everything already runs through Jira **Shortlist:** Atlassian Bitbucket, Atlassian Jira **Why:** Shared identity, permissions and issue linking with no integration to build or maintain. **Trade-off:** Smaller ecosystem than GitHub or GitLab, and Atlassian pricing steps hard at user-count thresholds. ### Nobody can list the APIs we have published **Shortlist:** Postman Governance, Postman API Design **Why:** An inventory of every published API plus enforceable standards across teams. **Trade-off:** Enterprise tier, and governance that warns rather than blocks is ignored within a quarter. ### Credentials live in CI variables and config files **Shortlist:** HashiCorp Vault **Why:** Centralised secrets with dynamic credentials, rotation and an audit trail of who read what. **Trade-off:** Client-based metering is hard to forecast, and Vault becomes critical infrastructure the day you adopt it. ### Infrastructure changes are clicked in a console **Shortlist:** HashiCorp Terraform **Why:** Infrastructure as code with state, policy and a reviewable run history. **Trade-off:** Per managed resource, so the bill tracks infrastructure sprawl rather than team size — unused resources still count. ### We are deciding whether to licence an AI assistant **Shortlist:** GitHub Copilot, GitLab Duo **Why:** Both are per-seat add-ons to their platform; the honest comparison is platform tier plus assistant, not assistant alone. **Trade-off:** A separate line at renewal however the trial was framed, and seat counts drift upward faster than headcount. ## At scale This route scales by developers — and by pipeline volume, which is not the same number. ### 1 developers — Under 20 developers - Free tiers are genuinely capable here - CI minutes rarely exceed the allowance - One platform is simpler than a toolchain **The test:** Prove the minutes against your real pipeline before paying. ### 2 developers — 20–100 developers - Seat drift starts — audit against commit activity - CI minutes become a visible line - Scanning tiers start to matter **The test:** Audit seats before every renewal. It is the cheapest saving here. ### 3 developers — 100–500 developers - Self-hosted runners usually pay for themselves - Atlassian threshold jumps become material - AI assistant seats need a policy **The test:** Model the tier jump, not the per-seat rate. ### 4 developers — 500+ developers - Self-hosting for residency and control becomes credible - Platform-versus-toolchain is a strategic decision - Secrets and IaC become critical infrastructure **The test:** Name the owner for the self-hosted upgrade path before choosing it. Where a vendor does not publish list pricing, this page says so rather than implying a figure. ## Getting out Git is portable. Everything built around it is not. **Repositories and history** — Git is distributed by design — a clone is a complete copy *(Fully portable)* **Pipeline definitions** — Vendor-specific YAML, rewritten for the new platform *(Rebuilt)* **Issues, boards and pull-request history** — Exportable via API; the discussion context rarely survives intact *(Partly portable)* **Secrets and IaC state** — Vault and Terraform state are portable with planning, catastrophic without it *(Plan it first)* The practical consequence: the code is never the lock-in. The pipelines, the scanning configuration and the accumulated review history are, and none of them appear in a switching-cost estimate. ## What it costs Per seat, plus the meters beside it, in USD and INR. ### Do you already own one? Four checks, in the order most likely to return a yes. - **GitHub or GitLab free tiers — Both are genuinely capable for small teams.** They **stop** at required reviewers, advanced permissions, scanning and support — the compliance features, not the coding ones. - **Your Atlassian licence — Bitbucket may already be in the bundle.** Worth checking before buying a second SCM — particularly where Jira is already the system of record. - **Postman free accounts — Almost certainly already in use across your teams.** Shadow usage on personal accounts is the norm. Audit it, then decide the tier. - **Open-source CI — Jenkins, Drone and Woodpecker are real options.** Costs infrastructure and an owner instead of a per-minute meter — the same trade as observability. The free tiers here are unusually strong. The paid case is compliance, support and scale rather than capability. ### What the rest actually cost One meter you expect, and several you do not. ### What isn't in the licence price - **CI/CD minutes and runners.** Metered separately everywhere, and routinely larger than the seat bill on a busy pipeline. - **AI assistant seats.** Copilot and Duo are separate licences however generous the trial was. - **Self-hosted operational burden.** Upgrades, backups, availability and runner security. A role, not a line item. - **Seats for people who have left.** Access is easy to grant and nobody audits it. Check against commit activity, not the directory. ## What goes wrong Five ways this purchase goes wrong. Four of them are meters nobody modelled. - **CI/CD minutes exceeding the seat bill.** A matrix build on every push, on a busy monorepo. The fix is pipeline discipline and self-hosted runners, not a different vendor. - **Seats counted per repository access rather than per active developer.** Contractors, occasional committers and people who left all count. Audit against commit activity before every renewal. - **Self-hosted chosen for residency, then nobody owns the upgrades.** The residency requirement is met on day one and the platform is three versions behind by year two. Name the owner at signature. - **The AI assistant licensed separately at renewal.** Bundled generously in the trial, itemised afterwards. Compare platform tier plus assistant, not the tier alone. - **Atlassian tier jumps at user-count thresholds.** Crossing a threshold is not a linear increase. Model the jump before hiring past it. ## Questions this guide answers ### GitHub or GitLab — which is right? GitHub has the larger ecosystem, the deepest third-party integration and the hiring advantage of being the tool most developers already know. GitLab's pitch is one platform and one licence across SCM, CI, scanning, packages and planning, with self-managed installation as a first-class option where residency requires it. The honest test is how much of the platform you would otherwise buy separately: if the answer is most of it, GitLab's economics are strong; if you want best-of-breed at each layer, GitHub plus a toolchain is the more common shape. ### Why did our CI bill exceed our licence cost? Because they are different meters. GitHub Actions, GitLab CI and Bitbucket Pipelines all bill build minutes separately from seats, and a busy monorepo running a matrix build on every push consumes minutes at a rate nothing in the platform warns you about. The fixes are pipeline discipline — caching, path filters, fewer matrix legs — and self-hosted runners, which trade the per-minute meter for machines you already operate and must now secure. ### Can we keep repository data in India? No vendor on this page documents an Indian SaaS region. The documented route is self-hosting: GitLab self-managed and GitHub Enterprise Server both run entirely on your own infrastructure, as does HashiCorp Vault. That meets the residency requirement and moves upgrades, backups and availability onto your team — which is a named role rather than a line item, and the thing most estates leave unassigned at signature. ### Is an AI coding assistant worth licensing? The measurable win is time-to-first-draft on routine code, and it is real for teams working in supported editors and languages. The commercial trap is the renewal: GitHub Copilot and GitLab Duo are both separate per-seat licences however the pilot was framed, so compare platform tier plus assistant rather than the tier alone. And audit the seats — assistant access is easy to grant and drifts upward faster than developer headcount. ### Do you sell JetBrains? Yes. TechBag carries JetBrains licences and they belong in this route; there are no intel pages for them yet, so JetBrains is named here and not ranked rather than omitted. The commercially important point is that its licence unit differs from everything carded on this page: per named user, or a floating pool shared across a team. For estates with contractors, shift work or part-time developers, a floating pool can be materially cheaper than per-seat SCM licensing — and the two cannot be compared line-for-line. Ask us to quote it alongside any shortlist here. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/devops/developer-tools* --- # DevOps — observability, databases and developer tooling — where the bill scales with usage, not headcount *A TechBag category guide. Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/devops - Routes: 3 ## The routes ### Observability & APM The licence is not the bill. Ingest is the bill — and it grows with your traffic, not your headcount. - 14 products compared - Guide: https://www.thetechbag.com/browse/devops/observability-apm - Boundary terms resolved: Monitoring vs observability · Observability vs APM · Logs vs metrics vs traces · APM vs RUM vs error tracking ### Databases & Data Tools The licence you are quoted is for the database. The cost you will carry is the migration — and nobody quotes that. - 20 products compared - Guide: https://www.thetechbag.com/browse/devops/databases-data-tools - Boundary terms resolved: Database monitoring vs APM · Managed vs self-hosted vs DBaaS · Migration vs replication · Compatibility vs conversion ### Developer Tools This is the one route here that meters per seat — and the seat count you are quoted is rarely the seat count you end up paying for. - 14 products compared - Guide: https://www.thetechbag.com/browse/devops/developer-tools - Boundary terms resolved: SCM vs CI/CD · SCM vs DevOps platform · IDE licensing vs seat licensing · Secrets management vs configuration --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/devops* --- # Every DLP deployment starts by discovering that nobody agrees what “sensitive” means here. The policy work is the project; the licence is the small number. *DLP & Insider Risk — a TechBag decision guide. Last reviewed 2026-09-07.* > A DLP product inspects content at an exit point and enforces a rule on it. That requires a rule — and writing one means the organisation has decided, in writing, which documents matter and what may happen to them. Most have not, which is why the first six months are policy work rather than product work. **The checkable fact:** The test before you shortlist: ask three people in the business to define a confidential document. If the answers differ, the tuning effort is the project and the licence is a rounding error against it. - Canonical: https://www.thetechbag.com/browse/data-security-privacy/dlp-insider-risk - Category: [Data Security & Privacy](https://www.thetechbag.com/browse/data-security-privacy) - Products compared: 18 ## What dlp & insider risk actually is Data loss prevention inspects content — in a file, an email, an upload or a clipboard — and decides whether the action may proceed. Insider risk asks a different question: not what this file contains, but whether this person’s behaviour has changed. Most estates need both, and most buy one while describing the other. The eighteen products below split by where they inspect and what they can act on. Twelve are standalone products. Six are modules of platforms carded in other categories — Zscaler and Netskope in SASE, CrowdStrike in endpoint, Proofpoint and Mimecast in email, Coro in the SMB platform. Those six are frequently already licensed. **The most common mis-purchase.** Whether the thing you are buying is a **product or a module**. Six of these eighteen ship inside a subscription you may already hold, and estates routinely buy a standalone DLP while paying for an unused data-protection module in their SASE contract. Check the entitlement first; it is the cheapest finding on this page. ## Four terms, resolved These are adjacent controls at different points in the data’s life, not tiers. A product that classifies perfectly may block nothing; a product that blocks at the endpoint may never see the cloud copy. ### DLP vs insider risk Is the question what left, or who is behaving differently? ### Insider risk vs UEBA Are you buying the product, or the technique inside it? ### Endpoint vs network DLP Where does your data actually leave from? ### Cloud DLP vs the rest Sanctioned applications, or all of them? None of these four is a better product than the others. They watch different exits, and an estate that buys one and describes another gets a working product answering a question nobody asked. ## The decision variables Six variables move the shortlist. Everything else is preference. **Channel coverage.** Endpoint, email, web, cloud, USB, print, screenshot — and AI prompt, the newest and least covered. Ask for the list, not the category. **Classification approach.** Regex and keyword needs manual upkeep. Machine learning needs training and tuning. Fingerprinting works only on documents you already have. Each has a different first-year effort. **Block, monitor or coach.** Blocking demands a false-positive rate low enough that the business tolerates it. Coaching changes behaviour without stopping work, and is why several mid-market products lead with it. **Behavioural depth.** Rule-based DLP and behavioural insider risk answer different questions. Confirm which engine is actually present rather than which words are in the datasheet. **Agent coexistence.** Another endpoint agent alongside your EDR, UEM and SASE agents is a real operational cost and a real conflict risk. Two products here need no agent at all. **Product or module.** Six of eighteen are modules. If you run the platform, the control may already be licensed. ## The 18 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Forcepoint DLP — Forcepoint - **Who it's for:** Estates that want one DLP policy enforced everywhere rather than four products with four consoles — and the broadest single-vendor channel coverage on this page. - **The honest limitation:** Breadth costs tuning: the classifier library is large and the first months are spent cutting false positives before blocking mode is credible. An India data region is not documented — confirm before assuming residency for classified content. - **Price:** From ~$52 (≈ ₹4,316) — per user / year entry list (about ₹4,316), rising materially for the full channel stack; one policy engine across endpoint, network, email, web and cloud with a large pre-built classifier library - **Details:** https://www.thetechbag.com/forcepoint/forcepoint-dlp ### Forcepoint Risk-Adaptive Protection — Forcepoint - **Who it's for:** Organisations whose false-positive problem is really a policy-granularity problem — the same action is fine from one person and not from another, and a single rule cannot express that. - **The honest limitation:** An add-on, not a standalone purchase: it needs Forcepoint DLP underneath. Behavioural scoring also needs a baseline period before it is useful, so value arrives months after signature. - **Price:** Quote (add-on) — quoted as an add-on to Forcepoint DLP; behavioural risk scoring that raises or relaxes enforcement per user as their risk changes, rather than one static policy for everyone - **Details:** https://www.thetechbag.com/forcepoint/forcepoint-risk-adaptive-protection ### Varonis DLP — Varonis - **Who it's for:** Estates that already run Varonis for discovery and want enforcement driven by what the platform found, rather than a second product with a second definition of sensitive. - **The honest limitation:** The case is much weaker without the Varonis platform underneath — it is the enforcement arm of a discovery investment, not a first DLP purchase. Quote-only. - **Price:** Quote — quoted per user or per data store within the Varonis platform; DLP that acts on the same classification and access-path map the DSPM half already built - **Details:** https://www.thetechbag.com/varonis/varonis-dlp ### Trellix DLP Endpoint — Trellix - **Who it's for:** Estates whose exfiltration path is physical and local — removable media, printing, the laptop that leaves the network — and who already run Trellix ePO for management. - **The honest limitation:** Endpoint-scoped: it does not see the cloud copy or the webmail upload unless the network and discovery products are bought alongside. Rule-based classification needs manual maintenance as data changes. - **Price:** Quote — quoted per endpoint, perpetual or subscription; device-level control of USB, print, clipboard, screenshot and local file operations, managed from the Trellix ePO console - **Details:** https://www.thetechbag.com/trellix/trellix-dlp-endpoint ### Trellix DLP Network — Trellix - **Who it's for:** Estates that need inspection without deploying another agent, particularly where unmanaged devices sit on the corporate network. - **The honest limitation:** Blind to anything encrypted it cannot terminate, which today is most traffic — and entirely blind once the laptop leaves the network. Network DLP alone routinely misses the USB stick. - **Price:** Quote — quoted per appliance or throughput; inspects traffic in flight for policy violations at the network boundary, with no endpoint agent required - **Details:** https://www.thetechbag.com/trellix/trellix-dlp-network ### Safetica Platform — Safetica - **Who it's for:** Mid-market estates that want published pricing and a working deployment in weeks rather than an enterprise programme — and the user-coaching model, which changes behaviour without blocking work. - **The honest limitation:** Less depth than the enterprise suites on classification sophistication and very large estates; documented deployments are mid-market. India data residency is not documented. - **Price:** $72–144 (≈ ₹5,976) — per user / year published list across Discovery, Protection and Enterprise (about ₹5,976–₹11,952); DLP with insider-risk analytics and user coaching, sized and priced for the mid-market - **Details:** https://www.thetechbag.com/safetica/safetica-platform ### Safetica On-Prem — Safetica - **Who it's for:** Regulated and localisation-sensitive estates that cannot send classified content or incident evidence to a vendor cloud. - **The honest limitation:** You own the server, the database and the upgrade cycle; the cloud edition gets features first. Narrower channel coverage than the SaaS platform. - **Price:** Quote — quoted per user, self-hosted; the same DLP and insider-risk engine kept entirely inside your own infrastructure - **Details:** https://www.thetechbag.com/safetica/safetica-on-prem ### Data Resolve inDefend DLP — Data Resolve - **Who it's for:** Indian estates that want the vendor, the support engineer and the data in the same country, with an on-premises option and a price in rupees. - **The honest limitation:** Narrower cloud-application coverage than the global suites, and documented deployments are Indian mid-market rather than global enterprise. Indian data-type classification is not documented — prove it against your own records. - **Price:** Quote (INR) — quoted per user in INR, on-premises or cloud; endpoint-centric DLP with user-activity monitoring, built and supported from India - **Details:** https://www.thetechbag.com/dataresolve/dataresolve-dlp ### Data Resolve UBA — Data Resolve - **Who it's for:** Estates whose question is who is behaving differently rather than which file contained a card number — the resignation-shaped pattern that content rules never see. - **The honest limitation:** Analytics, not enforcement: it produces signal and names no policy. Without a DLP alongside it you can see the behaviour and cannot stop the file. - **Price:** Quote (INR) — quoted per user in INR; user behaviour analytics over endpoint activity — baselines normal and flags deviation rather than matching file content to a rule - **Details:** https://www.thetechbag.com/dataresolve/dataresolve-uba ### Seqrite DLP — Seqrite - **Who it's for:** Indian estates already running Seqrite endpoint protection that want data controls on the agent they have deployed rather than a second one. - **The honest limitation:** A module on an endpoint suite rather than a full DLP platform: no network or cloud inspection, and no behavioural analytics. Right answer when the requirement is device control; wrong one when it is cloud egress. - **Price:** Quote (INR) — quoted per endpoint in INR, frequently bundled with Seqrite endpoint protection; device control, application control and content rules on the same agent - **Details:** https://www.thetechbag.com/seqrite/seqrite-dlp ### Cyera Omni DLP — Cyera - **Who it's for:** Cloud-first estates that want enforcement to inherit a classification they trust, and one of the few products here documenting AI-prompt as a channel. - **The honest limitation:** Newer than the incumbent suites, and the strongest case assumes the Cyera platform underneath. Quote-only, and India residency is not documented. - **Price:** Quote — quoted within the Cyera platform; DLP driven by the AI-native classification the DSPM half produces, including controls on data pasted into AI assistants - **Details:** https://www.thetechbag.com/cyera/cyera-omni-dlp ### Seclore AI-DLP — Seclore - **Who it's for:** Estates where files legitimately have to go outside and blocking is not an acceptable answer — the DLP decision becomes protect-and-send rather than allow-or-deny. - **The honest limitation:** The distinctive capability assumes you also adopt Seclore's rights management; as a pure DLP it is narrower than Forcepoint or Trellix. Indian data-type classification is not documented despite the India-built positioning. - **Price:** Quote (INR) — quoted per user in INR from the Mumbai-built vendor; DLP that hands off to Seclore's rights management rather than only blocking — the file leaves protected instead of not leaving - **Details:** https://www.thetechbag.com/seclore/seclore-ai-dlp ### Proofpoint DLP & Insider Risk — Proofpoint - **Who it's for:** Estates already running Proofpoint for email security whose data-loss path is overwhelmingly outbound mail — the control sits where the traffic already is. - **The honest limitation:** A module of a platform, not a standalone purchase: buying it without Proofpoint email security is unusual and priced accordingly. Weaker on USB, print and local device control than the endpoint-first suites. - **Price:** Quote (in the suite) — quoted inside the Proofpoint suite, commonly alongside email security; people-centric DLP with insider-risk telemetry, strongest where the exit is email - **Details:** https://www.thetechbag.com/proofpoint/proofpoint-dlp-insider ### Mimecast Incydr — Mimecast - **Who it's for:** Estates whose real question is departing-employee data theft, where the file's journey matters more than its contents and rule-writing has already failed. - **The honest limitation:** Telemetry-first by design: it is deliberately not a rule-based blocking DLP, so estates that need to stop the transfer in the moment will find it monitors rather than prevents. - **Price:** Quote (in the suite) — quoted within Mimecast; insider risk built on file-movement telemetry — what moved, where it went and who moved it — rather than content-matching rules - **Details:** https://www.thetechbag.com/mimecast/mimecast-incydr ### Zscaler Data Protection — Zscaler - **Who it's for:** Estates already routing traffic through Zscaler — the inspection point exists, so data controls are a licence change rather than a deployment. - **The honest limitation:** Inline coverage only: it sees what traverses the platform and nothing local — USB, print and offline file operations are outside its view entirely. Check whether your subscription already includes it before buying anything on this page. - **Price:** In the platform — a module inside the Zero Trust Exchange subscription, not a separate purchase; inline inspection of web and cloud traffic that already passes the platform, plus CASB and SaaS posture - **Details:** https://www.thetechbag.com/zscaler/zscaler-data-protection ### Netskope Data Protection — Netskope - **Who it's for:** Estates whose data problem is SaaS sprawl — including unsanctioned applications — and who want the inspection and the residency documented in the same platform. - **The honest limitation:** Like every inline platform it is blind to local device activity. The strongest case assumes Netskope is already the SASE choice; bought alone it is an expensive DLP. - **Price:** In the platform — a module of the Netskope platform where CASB and DLP are core rather than bolted on; eight Indian data centres with a Mumbai management plane supporting DPDP-aligned residency - **Details:** https://www.thetechbag.com/netskope/netskope-data-protection ### CrowdStrike Falcon Data Protection — CrowdStrike - **Who it's for:** Falcon estates that want basic data controls without adding an agent — the single most common source of endpoint conflict on this page. - **The honest limitation:** Narrower than a dedicated DLP suite: no email or deep cloud inspection, and classification is rule-based. It is the pragmatic answer for estates that will not tolerate another agent, not the complete one. - **Price:** In the platform — a Falcon module licensed per endpoint on the agent you already run; data controls with no second agent to deploy or reconcile - **Details:** https://www.thetechbag.com/crowdstrike/crowdstrike-falcon-data-protection ### Coro Cloud & Data Governance — Coro - **Who it's for:** Small estates with no security team that want a data control switched on rather than a project scoped — the honest floor of this category. - **The honest limitation:** Deliberately simple: shallow classification, no behavioural analytics and no local device control. It is a starting position, not a compliance answer for a regulated estate. - **Price:** In the platform — a module of the Coro modular platform, priced per user alongside the other modules an SMB turns on; cloud application and email data governance with deliberately few settings - **Details:** https://www.thetechbag.com/coro/coro-cloud-data-governance ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **removable media and print.** Rules out Forcepoint Risk-Adaptive Protection, Varonis DLP, Trellix DLP Network, Data Resolve UBA, Cyera Omni DLP, Seclore AI-DLP, Proofpoint DLP & Insider Risk, Mimecast Incydr, Zscaler Data Protection, Netskope Data Protection and Coro Cloud & Data Governance — no local device control: USB and print are outside what it sees. That leaves Forcepoint DLP, Trellix DLP Endpoint, Safetica Platform, Safetica On-Prem, Data Resolve inDefend DLP, Seqrite DLP and CrowdStrike Falcon Data Protection. **cloud applications.** Rules out Trellix DLP Endpoint, Trellix DLP Network, Safetica On-Prem, Data Resolve inDefend DLP, Data Resolve UBA, Seqrite DLP and CrowdStrike Falcon Data Protection — no cloud application inspection. That leaves Forcepoint DLP, Forcepoint Risk-Adaptive Protection, Varonis DLP, Safetica Platform, Cyera Omni DLP, Seclore AI-DLP, Proofpoint DLP & Insider Risk, Mimecast Incydr, Zscaler Data Protection, Netskope Data Protection and Coro Cloud & Data Governance. **outbound email.** Rules out Forcepoint Risk-Adaptive Protection, Trellix DLP Endpoint, Data Resolve UBA, Seqrite DLP and CrowdStrike Falcon Data Protection — email is not an inspected channel. That leaves Forcepoint DLP, Varonis DLP, Trellix DLP Network, Safetica Platform, Safetica On-Prem, Data Resolve inDefend DLP, Cyera Omni DLP, Seclore AI-DLP, Proofpoint DLP & Insider Risk, Mimecast Incydr, Zscaler Data Protection, Netskope Data Protection and Coro Cloud & Data Governance. **AI assistants.** Rules out Forcepoint DLP, Forcepoint Risk-Adaptive Protection, Varonis DLP, Trellix DLP Endpoint, Trellix DLP Network, Safetica Platform, Safetica On-Prem, Data Resolve inDefend DLP, Data Resolve UBA, Seqrite DLP, Proofpoint DLP & Insider Risk, Mimecast Incydr, Zscaler Data Protection, Netskope Data Protection, CrowdStrike Falcon Data Protection and Coro Cloud & Data Governance — AI-prompt exfiltration is not documented as a covered channel. That leaves Cyera Omni DLP and Seclore AI-DLP. **no new agent.** Rules out Forcepoint DLP, Forcepoint Risk-Adaptive Protection, Varonis DLP, Trellix DLP Endpoint, Safetica Platform, Safetica On-Prem, Data Resolve inDefend DLP, Data Resolve UBA, Seqrite DLP, Cyera Omni DLP, Seclore AI-DLP, Proofpoint DLP & Insider Risk, Mimecast Incydr and CrowdStrike Falcon Data Protection — requires its own agent alongside your endpoint, UEM and SASE agents. That leaves Trellix DLP Network, Zscaler Data Protection, Netskope Data Protection and Coro Cloud & Data Governance. **on-premises.** Rules out Varonis DLP, Safetica Platform, Cyera Omni DLP, Proofpoint DLP & Insider Risk, Mimecast Incydr, Zscaler Data Protection, Netskope Data Protection, CrowdStrike Falcon Data Protection and Coro Cloud & Data Governance — SaaS only. That leaves Forcepoint DLP, Forcepoint Risk-Adaptive Protection, Trellix DLP Endpoint, Trellix DLP Network, Safetica On-Prem, Data Resolve inDefend DLP, Data Resolve UBA, Seqrite DLP and Seclore AI-DLP. **a standalone product.** Rules out Proofpoint DLP & Insider Risk, Mimecast Incydr, Zscaler Data Protection, Netskope Data Protection, CrowdStrike Falcon Data Protection and Coro Cloud & Data Governance — a module of a platform, priced and sold inside that subscription. That leaves Forcepoint DLP, Forcepoint Risk-Adaptive Protection, Varonis DLP, Trellix DLP Endpoint, Trellix DLP Network, Safetica Platform, Safetica On-Prem, Data Resolve inDefend DLP, Data Resolve UBA, Seqrite DLP, Cyera Omni DLP and Seclore AI-DLP. **behavioural insider risk.** Rules out Forcepoint DLP, Safetica Platform, Safetica On-Prem, Data Resolve inDefend DLP, Cyera Omni DLP, Seclore AI-DLP, Zscaler Data Protection, Netskope Data Protection and CrowdStrike Falcon Data Protection — some behavioural signal, but not a insider-risk engine; Trellix DLP Endpoint, Trellix DLP Network, Seqrite DLP and Coro Cloud & Data Governance — content rules only, no behavioural analytics. That leaves Forcepoint Risk-Adaptive Protection, Varonis DLP, Data Resolve UBA, Proofpoint DLP & Insider Risk and Mimecast Incydr. **machine-learning classification.** Rules out Trellix DLP Endpoint, Trellix DLP Network, Safetica Platform, Safetica On-Prem, Data Resolve inDefend DLP, Data Resolve UBA, Seqrite DLP, CrowdStrike Falcon Data Protection and Coro Cloud & Data Governance — rule and keyword based, which needs manual upkeep as data changes; Mimecast Incydr — fingerprints known documents rather than classifying new ones. That leaves Forcepoint DLP, Forcepoint Risk-Adaptive Protection, Varonis DLP, Cyera Omni DLP, Seclore AI-DLP, Proofpoint DLP & Insider Risk, Zscaler Data Protection and Netskope Data Protection. **user coaching.** Rules out Forcepoint DLP, Varonis DLP, Trellix DLP Endpoint, Trellix DLP Network, Safetica On-Prem, Data Resolve inDefend DLP, Data Resolve UBA, Seqrite DLP, Cyera Omni DLP, Proofpoint DLP & Insider Risk, Mimecast Incydr, Zscaler Data Protection, Netskope Data Protection, CrowdStrike Falcon Data Protection and Coro Cloud & Data Governance — blocks or monitors; no in-the-moment user coaching documented. That leaves Forcepoint Risk-Adaptive Protection, Safetica Platform and Seclore AI-DLP. **India residency.** Rules nothing out on published terms. It flags Forcepoint DLP — India residency for classified content is not documented, Forcepoint Risk-Adaptive Protection — India residency for classified content is not documented, Varonis DLP — India residency for classified content is not documented, Trellix DLP Endpoint — India residency for classified content is not documented, Trellix DLP Network — India residency for classified content is not documented, Safetica Platform — India residency for classified content is not documented, Safetica On-Prem — India residency for classified content is not documented, Cyera Omni DLP — India residency for classified content is not documented, Proofpoint DLP & Insider Risk — India residency for classified content is not documented, Mimecast Incydr — India residency for classified content is not documented, Zscaler Data Protection — Data region documented, Netskope Data Protection — Data region documented, CrowdStrike Falcon Data Protection — India residency for classified content is not documented and Coro Cloud & Data Governance — India residency for classified content is not documented — marked, not removed. **Indian data types.** Rules nothing out on published terms. It flags Forcepoint DLP — Indian data-type classification is not documented by the vendor, Forcepoint Risk-Adaptive Protection — Indian data-type classification is not documented by the vendor, Varonis DLP — Indian data-type classification is not documented by the vendor, Trellix DLP Endpoint — Indian data-type classification is not documented by the vendor, Trellix DLP Network — Indian data-type classification is not documented by the vendor, Safetica Platform — Indian data-type classification is not documented by the vendor, Safetica On-Prem — Indian data-type classification is not documented by the vendor, Data Resolve inDefend DLP — Indian data-type classification is not documented by the vendor, Data Resolve UBA — Indian data-type classification is not documented by the vendor, Seqrite DLP — Indian data-type classification is not documented by the vendor, Cyera Omni DLP — Indian data-type classification is not documented by the vendor, Seclore AI-DLP — Indian data-type classification is not documented by the vendor, Proofpoint DLP & Insider Risk — Indian data-type classification is not documented by the vendor, Mimecast Incydr — Indian data-type classification is not documented by the vendor, Zscaler Data Protection — Indian data-type classification is not documented by the vendor, Netskope Data Protection — Indian data-type classification is not documented by the vendor, CrowdStrike Falcon Data Protection — Indian data-type classification is not documented by the vendor and Coro Cloud & Data Governance — Indian data-type classification is not documented by the vendor — marked, not removed. **Six of these eighteen are modules, not products.** Zscaler, Netskope, CrowdStrike, Coro, Proofpoint and Mimecast sell data protection inside a platform subscription. If you already run the platform, check your entitlement before buying anything on this page — the control may already be paid for. **Indian data types are undocumented everywhere.** No vendor on this page documents PAN, Aadhaar or GSTIN classification support. That is marked per product and never used to eliminate one. Prove it in a proof of concept with your own records; a classifier tuned for US social security numbers finds nothing useful in an Indian estate. **The licence is the small number.** Classification and policy tuning commonly exceed the licence in year one. Someone has to decide what sensitive means in your organisation, document it, and cut the false positives until blocking is credible. No vendor does that for you. **Blocking mode is a decision, not a setting.** The common failure is enabling block too early, stopping legitimate business, and reverting to monitor permanently. Estates that succeed run monitor first, tune against real traffic, then block one narrow high-confidence policy at a time. ## Eight situations, and what each one buys If one of these is your sentence, the shortlist is short. ### A departing employee copied files to a personal drive **Shortlist:** Mimecast Incydr, Forcepoint Risk-Adaptive Protection, Varonis DLP, Data Resolve UBA **Why:** This is a behavioural question, not a content one — the pattern precedes the transfer by weeks and no content rule describes it. **Trade-off:** Incydr monitors rather than blocks by design; if you need the transfer stopped in the moment, pair it with an enforcing DLP. ### Someone pasted customer data into a public AI assistant **Shortlist:** Cyera Omni DLP, Seclore AI-DLP **Why:** AI prompt is the newest exfiltration channel and only these two document it as covered. **Trade-off:** Both are newer than the incumbent suites and both are strongest with their own platform underneath. ### The exfiltration path is USB sticks and printing **Shortlist:** Trellix DLP Endpoint, Seqrite DLP, Data Resolve inDefend, Safetica Platform **Why:** Local device control needs an agent on the device; no inline platform sees any of this. **Trade-off:** The endpoint-first products are correspondingly thinner on cloud application coverage. ### We already route everything through Zscaler or Netskope **Shortlist:** Zscaler Data Protection, Netskope Data Protection **Why:** The inspection point already exists — this is a licence change rather than a deployment. **Trade-off:** Neither sees local device activity. If USB and print matter, you still need an endpoint product. ### We will not deploy another endpoint agent **Shortlist:** CrowdStrike Falcon Data Protection, Zscaler Data Protection, Netskope Data Protection, Trellix DLP Network **Why:** Either the control rides an agent you already run, or it needs no agent at all. **Trade-off:** All four are narrower than a dedicated endpoint DLP suite; this is the pragmatic answer, not the complete one. ### Classified content cannot leave our infrastructure **Shortlist:** Safetica On-Prem, Data Resolve inDefend, Seqrite DLP, Trellix DLP Network, Forcepoint DLP **Why:** All five deploy on-premises, and three are India-built with INR pricing and local support. **Trade-off:** You own the server, the database and the upgrade cycle; cloud editions get features first. ### We want published pricing and a deployment in weeks **Shortlist:** Safetica Platform, Forcepoint DLP **Why:** These are the two products on this page with a published per-user list you can budget against before a sales conversation. **Trade-off:** Safetica is mid-market in depth; Forcepoint's entry price rises materially for the full channel stack. ### No security team, and something has to be switched on **Shortlist:** Coro Cloud & Data Governance **Why:** Deliberately few settings, priced per user inside a modular platform an SMB can run without specialists. **Trade-off:** Shallow classification, no behavioural analytics, no local device control. A starting position, not a compliance answer. ## At scale DLP scales by users and by the number of exits you have to watch, not by data volume. ### 1 users — Under 200 users - Coro or a platform module is usually enough - One channel — normally email or USB — carries most of the risk - Nobody will tune a complex policy set **The test:** Ask which single exit accounts for most of your exposure, and cover that. ### 2 users — 200–2,000 users - Safetica and Forcepoint's published pricing fits here - Monitor first, then one narrow blocking policy - The incident queue needs a named owner **The test:** Name the person who reviews alerts before you sign. ### 3 users — 2,000–10,000 users - Multi-channel coverage becomes the requirement - Behavioural insider risk starts earning its licence - Agent coexistence with EDR and UEM is a real constraint **The test:** Test agent conflict in a pilot ring, not in production. ### 4 users — 10,000+ users - One policy engine across all channels avoids four consoles - Risk-adaptive enforcement replaces one static rule set - Tuning is a standing role, not a project **The test:** Budget the tuning role permanently — it does not end at go-live. Documented deployment scale is stated per product where the vendor publishes it, and marked as mid-market where the evidence is mid-market. ## Getting out DLP policy is the asset, and almost none of it is portable. **Policy rules** — Every vendor expresses them differently; there is no interchange format *(Rebuilt from scratch)* **Classification labels** — Microsoft Information Protection labels are the nearest thing to a standard and are read by several products here *(Partly portable)* **Incident history** — Exports to CSV or via API almost everywhere; the evidentiary value depends on your retention obligation *(Portable)* **The tuning effort** — The months spent cutting false positives do not transfer — the new engine classifies differently *(Not portable)* The practical consequence: switching DLP means re-running the tuning project. That is the real switching cost, and it is why the first choice deserves a proof of concept with your own documents. ## What it costs Per user or per endpoint, in USD and INR where the vendor publishes a list. ### Do you already own one? Four checks, in the order most likely to return a yes. - **Microsoft Purview — The dominant already-own answer in this category.** E3 carries manual and basic labelling. **E5 adds automatic classification, endpoint DLP and insider risk management** — which is the tier most comparisons on this page are really against. Standalone Purview SKUs sit between the two. - **Your SASE or SSE subscription — DLP is a base module at Zscaler and Netskope.** Not an add-on in most plans. Check the entitlement before buying a standalone product for the same job. - **Your email security platform — Proofpoint and Mimecast both sell DLP beside the filter.** If email is your dominant exit, the control may be one line item away in a contract you already hold. - **Your endpoint platform — CrowdStrike sells Falcon Data Protection on the agent you run.** Narrower than a suite, but it adds no agent — which is the constraint that usually decides this row. None of these is automatically right. Each is a real option that a shortlist built from vendor comparisons will miss entirely. ### What the rest actually cost Two vendors publish a list. The rest quote, and the India-built options quote in rupees. ### What isn't in the licence price - **Classification and policy tuning.** The largest hidden line. Commonly exceeds the licence in year one and does not end at go-live. - **The incident review queue.** Alerts need a named reviewer. Without one the console fills and the deployment quietly becomes shelfware. - **Proof of concept on Indian data types.** No vendor documents PAN, Aadhaar or GSTIN support. Budget the time to prove it against your own records. - **Agent coexistence testing.** Where the product needs its own agent, conflicts with EDR and UEM are found in a pilot ring or in production. ## What goes wrong Six ways this purchase goes wrong. Each is recoverable if caught before signature. - **Blocking mode enabled too early.** Legitimate business stops, the policy reverts to monitor within days, and it is never re-enabled. Monitor first, tune, then block one narrow policy. - **Classification rules that flag every invoice.** A rule matching any nine-digit number flags the entire finance function. Precision is tuning work, and it is the work that decides whether anyone trusts the console. - **Agent conflicts with the existing EDR.** Two agents hooking the same file operations degrade the endpoint or break each other. Test in a pilot ring; two products here need no agent at all. - **Cloud DLP that only sees sanctioned applications.** The personal drive a user signs into is invisible unless traffic also passes an inline proxy. Ask for the connected-application list. - **No owner for the incident queue.** Alerts accumulate unreviewed and the deployment becomes shelfware with a renewal attached. Name the reviewer before signing. - **AI prompt exfiltration uncovered.** Most policies do not cover it at all. Two products on this page document it as a channel; if that is your exposure, it is a shortlist of two. ## Questions this guide answers ### What is the difference between DLP and insider risk management? DLP inspects content and enforces a policy on it — this file contains a card number, so it may not leave. Insider risk scores a person's behaviour over time: unusual volume, unusual hours, movement to personal storage in the weeks before a resignation. Rule-based DLP misses the behavioural pattern entirely, and behavioural tooling frequently cannot name the specific file that went. Most estates need both, and most buy one while describing the other in the requirement. ### Do I already own DLP? Very possibly. Microsoft Purview inside Microsoft 365 E5 includes automatic classification, endpoint DLP and insider risk management; E3 carries only manual and basic labelling. Zscaler and Netskope include data protection as a base module of their SASE platforms. Proofpoint and Mimecast sell DLP beside email security, and CrowdStrike sells Falcon Data Protection on the Falcon agent. Six of the eighteen products on this page are modules of platforms you may already pay for — check the entitlement before buying anything standalone. ### How much does DLP cost in India? Safetica publishes about $72–144 per user per year across its tiers, and Forcepoint DLP starts near $52 per user per year, rising for the full channel stack. Seclore, Data Resolve and Seqrite are India-built and quote per user or per endpoint in INR, on-premises or cloud. Varonis and Trellix are quote-only. The licence is rarely the largest number: classification and policy tuning commonly exceed it in year one. ### Do DLP products classify Indian data types like PAN and Aadhaar? No vendor on this page documents PAN, Aadhaar or GSTIN classification support. We mark that as unknown per product rather than assuming it either way, and we never use it to eliminate a product. It should be proven in a proof of concept against your own records — a classifier tuned for US social security numbers finds nothing useful in an Indian estate, and this is the single most common reason a deployment produces an empty console. ### Can DLP stop data being pasted into ChatGPT? Only if AI prompt is a documented channel, and most products do not cover it. Cyera Omni DLP and Seclore AI-DLP document it on this page. Inline platforms like Zscaler and Netskope can see traffic to AI services where it passes the platform, but coverage of the prompt content itself varies — ask specifically rather than accepting 'we cover web traffic' as an answer. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/data-security-privacy/dlp-insider-risk* --- # DSPM will find data you did not know existed, in places you did not know it was stored. The finding is fast. The remediation is not. *DSPM & Data Discovery — a TechBag decision guide. Last reviewed 2026-09-07.* > A DSPM product connects to your stores, scans what is in them, classifies it and maps who can reach it. The first scan typically returns thousands of findings within days — and every one of them needs an owner, a decision and a change made by someone who has other work. **The checkable fact:** The check before you shortlist: ask where your sensitive data is. If the answer is a guess, the first deliverable of any product here is the map — and the second, larger project is doing something about what the map shows. - Canonical: https://www.thetechbag.com/browse/data-security-privacy/dspm - Category: [Data Security & Privacy](https://www.thetechbag.com/browse/data-security-privacy) - Products compared: 16 ## What dspm & data discovery actually is Data security posture management finds data at rest, decides what it is, and maps who can reach it. It is the answer to the question almost no organisation can answer unaided — where is our sensitive data — and it is the prerequisite for writing any credible DLP policy or rights-management rule. The fifteen products below differ most in what they can physically scan. Cloud-native tools are agentless and fast and stop at the cloud boundary. Hybrid platforms reach on-premises file shares and cost more to deploy. Two are modules of platforms carded elsewhere — Wiz in cloud security, Rubrik in backup, where the scan runs over a copy production never notices. **The most common mis-purchase.** What it can **actually scan**. Cloud object storage is universal; managed databases are common; SaaS varies; **on-premises file shares are the usual gap**. Estates whose sensitive data lives on shares and whose business case assumed coverage discover the mismatch after signature. Ask for the specific store list, not the category. ## Four terms, resolved These are adjacent controls at different points in the data’s life, not tiers. A product that classifies perfectly may block nothing, and a product that secures the cloud account may know nothing about what is inside it. ### DSPM vs CSPM Are you securing the cloud account, or what is inside it? ### DSPM vs DLP Do you need to find data at rest, or stop it moving? ### Discovery vs classification Finding the file, or deciding what it is? ### Classification vs cataloguing Is the audience security, or the data team? The practical consequence: these four sit in sequence rather than in competition. Discover, classify, then decide whether the control you need watches the exit, governs the access, or travels with the file. ## The decision variables Six variables move the shortlist. Everything else is preference. **What it can scan.** Cloud object storage, managed databases, SaaS applications, on-premises file shares, large unstructured estates. Coverage varies enormously and on-premises is where business cases break. **Agentless or connector-based.** Agentless is fastest to first finding. Connector catalogues decide coverage — confirm your specific stores are on the list before signature. **Access-path depth.** Reporting permissions is not the same as computing effective access through nested groups, inherited rights and share links. This is Varonis's differentiator and where several cloud-first tools are visibly thinner. **Remediation or reporting.** Acting on a finding, raising a workflow, or producing a report. The further right you sit, the more headcount the programme needs. **Indian data-type accuracy.** PAN, Aadhaar, GSTIN. Undocumented across every vendor here — prove it in a proof of concept, because a US-tuned classifier returns nothing useful in an Indian estate. **Scanning cost.** Metered on stores or scanned volume rather than headcount, so a small team with large object stores can cost more than a large workforce. ## The 16 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Varonis DSPM — Varonis - **Who it's for:** Estates whose real question is who can actually reach this — through every nested group, inherited permission and share link — and whose data lives partly on file shares that cloud-first tools do not scan. - **The honest limitation:** The most complete answer here and priced accordingly; quote-only, and deployment is a programme rather than a connector. The breadth that makes it strong on file shares also makes it heavier than an agentless cloud scan. - **Price:** Quote — quoted per user or per data store; discovery and classification across Microsoft 365, cloud stores, databases and on-premises file shares, with effective-permission mapping and automated remediation - **Details:** https://www.thetechbag.com/varonis/varonis-dspm ### Varonis Data Access Governance — Varonis - **Who it's for:** Estates that already know roughly where the data is and whose finding is that far too many people can reach it — the remediation half rather than the discovery half. - **The honest limitation:** Governance over unstructured data specifically: it is not a cloud posture tool and not a DLP. Assumes the Varonis platform underneath. - **Price:** Quote — quoted within the Varonis platform; least-privilege enforcement over unstructured data — finding and removing excessive access rather than only reporting it - **Details:** https://www.thetechbag.com/varonis/varonis-data-access-governance ### Varonis DDR — Varonis - **Who it's for:** Estates that have the map and now need a motion sensor on it — detecting the account that suddenly reads ten thousand files it has never touched. - **The honest limitation:** Detection over data Varonis already classifies: it is the response half of a posture investment, not a standalone monitoring product. - **Price:** Quote — quoted within the Varonis platform; alerting and automated response on abnormal access to data at rest, rather than on a cloud configuration - **Details:** https://www.thetechbag.com/varonis/varonis-ddr ### Cyera DSPM — Cyera - **Who it's for:** Cloud-first estates that want an accurate map quickly without deploying anything — the fastest time-to-first-finding on this page. - **The honest limitation:** Cloud-scoped: on-premises file shares are the usual gap, and buyers whose business case assumed them discover it after signature. Access-path analysis is present but shallower than Varonis. - **Price:** Quote — quoted per environment or scanned volume; agentless AI-native discovery and classification across cloud object storage, managed databases and SaaS applications - **Details:** https://www.thetechbag.com/cyera/cyera-dspm ### Cyera Data Access Governance — Cyera - **Who it's for:** Cyera estates whose next question after discovery is access — and who want that answered inside the platform that did the classification. - **The honest limitation:** Cloud and SaaS scope, following the platform's coverage; on-premises shares are outside it. Assumes Cyera DSPM underneath. - **Price:** Quote — quoted within the Cyera platform; who can reach which classified data across cloud stores and SaaS, with entitlement analysis over the discovered map - **Details:** https://www.thetechbag.com/cyera/cyera-data-access-governance ### Securiti DSPM — Securiti - **Who it's for:** Estates whose driver is privacy operations as much as security — where the same map has to serve a DPDP or GDPR obligation and a security finding. - **The honest limitation:** Connector-based, so coverage is a function of the catalogue: confirm your specific stores are supported before signature. Acquired by Veeam (about $1.725B, closed December 2025) and continuing under its own brand. - **Price:** Quote — quoted within the Data Command Center; discovery, classification and posture across cloud, database, SaaS and on-premises sources through a connector catalogue - **Details:** https://www.thetechbag.com/securiti/securiti-dspm ### Securiti Data Discovery — Securiti - **Who it's for:** Organisations at the very start of a privacy programme whose first deliverable is a defensible data map rather than an enforcement control. - **The honest limitation:** Discovery and cataloguing rather than posture: it produces the inventory and does not analyse access paths or remediate. The right first step, not the whole answer. - **Price:** Quote — quoted within the Data Command Center; the discovery and cataloguing layer — what personal and sensitive data exists, where, and whose it is - **Details:** https://www.thetechbag.com/securiti/securiti-data-discovery ### Securiti Data Privacy Automation — Securiti - **Who it's for:** Estates whose obligation is operational privacy — honouring data-principal requests and evidencing consent — rather than a security posture finding. - **The honest limitation:** Privacy operations, not a security control: it does not block, encrypt or detect. It answers a regulator's question, not an attacker's. - **Price:** Quote — quoted within the Data Command Center; consent records, data-principal request handling and privacy reporting built on the discovered map - **Details:** https://www.thetechbag.com/securiti/securiti-data-privacy ### Securiti Data Governance — Securiti - **Who it's for:** Organisations where the data map has to serve analytics governance as well as security — one inventory, two audiences. - **The honest limitation:** Governance tooling rather than a security control, and its audience is the data team rather than the security team. Buying it to satisfy a security finding answers a different question. - **Price:** Quote — quoted within the Data Command Center; policy, quality and lineage over the catalogued data estate for governance and analytics teams - **Details:** https://www.thetechbag.com/securiti/securiti-data-governance ### Forcepoint DSPM — Forcepoint - **Who it's for:** Estates buying discovery and enforcement together, where the classification that finds the data should be the one the DLP acts on. - **The honest limitation:** The strongest case assumes Forcepoint DLP alongside it; as a standalone DSPM it is less specialised than the cloud-native tools. India residency is not documented. - **Price:** Quote — quoted within the Forcepoint data-security portfolio; discovery and classification that feed the same policy engine driving Forcepoint DLP - **Details:** https://www.thetechbag.com/forcepoint/forcepoint-dspm ### Forcepoint DDR — Forcepoint - **Who it's for:** Forcepoint estates that want the posture map to raise alerts when someone actually touches what it found. - **The honest limitation:** Detection over data Forcepoint classifies — it is the response half of a portfolio purchase rather than a standalone product. - **Price:** Quote — quoted within the Forcepoint portfolio; detection and response on access to classified data at rest, rather than on cloud configuration drift - **Details:** https://www.thetechbag.com/forcepoint/forcepoint-ddr ### Seclore DSPM — Seclore - **Who it's for:** Indian estates that want the discovery and the protection from one India-built vendor, with the remediation being protect-the-file rather than only report-the-finding. - **The honest limitation:** Narrower connector coverage than the global platforms and documented deployments are Indian mid-market and BFSI. Indian data-type classification is not documented despite the India-built positioning — prove it. - **Price:** Quote (INR) — quoted per environment in INR from the Mumbai-built vendor; discovery and classification that can hand off directly to Seclore's rights management for protection - **Details:** https://www.thetechbag.com/seclore/seclore-dspm ### Wiz DSPM — Wiz - **Who it's for:** Wiz estates that want to know whether the public bucket the CSPM found actually holds sensitive data — the finding and the consequence in one view. - **The honest limitation:** Cloud-native only and a module, not a standalone product: no on-premises coverage at all, and the case assumes Wiz is already the cloud security platform. - **Price:** In the platform — a module of the Wiz platform, licensed with the cloud security graph; data findings joined to the same graph that carries the misconfiguration and vulnerability context - **Details:** https://www.thetechbag.com/wiz/wiz-dspm ### Rubrik DSPM — Rubrik - **Who it's for:** Rubrik estates that want a data map without a second scan of production — the backup copy is already a complete, quiescent snapshot of everything. - **The honest limitation:** Scope is whatever Rubrik backs up, which is a real constraint if some stores are not protected. Reporting-oriented: it finds and classifies rather than remediating. - **Price:** In the platform — a module of the Rubrik platform; classification run over data the backup already holds, so discovery does not touch production systems - **Details:** https://www.thetechbag.com/rubrik/rubrik-dspm ### Seqrite Data Privacy — Seqrite - **Who it's for:** Indian mid-market estates whose driver is DPDP readiness and whose data sits mostly on endpoints and file shares rather than cloud object storage. - **The honest limitation:** Endpoint and share oriented: cloud object storage and managed database coverage is thin, and there is no access-path analysis. Reports rather than remediates. - **Price:** Quote (INR) — quoted per endpoint or per user in INR; personal-data discovery across endpoints and shares with DPDP-shaped reporting, from the India-built vendor - **Details:** https://www.thetechbag.com/seqrite/seqrite-data-privacy ### LinkShadow DSPM — LinkShadow - **Who it's for:** Estates ALREADY deploying LinkShadow NDR that want data-exposure context in the same console — the consolidation argument is the real one here, not standalone DSPM depth. - **The honest limitation:** The newest and least-proven of LinkShadow’s three products, in a crowded field: Varonis, Cyera, Securiti and Wiz all have far deeper track records, more India presence and named references. LinkShadow’s 2026 Gartner Visionaries placement is for its NDR, NOT for DSPM — there is no independent analyst recognition of this module at all. No India data residency (their privacy policy allows storage anywhere in the world) and no DPDP reporting. Buying it standalone is a materially weaker case than buying it to extend an existing LinkShadow deployment. - **Price:** Quote — quoted as a module on the CyberMeshX platform; discovery, classification, exposure analysis and least-privilege recommendations, correlated with the vendor’s NDR and ITDR signal rather than sold as a standalone data-security programme - **Details:** https://www.thetechbag.com/linkshadow/linkshadow-dspm ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **on-premises shares.** Rules out Cyera DSPM, Cyera Data Access Governance, Securiti Data Governance, Wiz DSPM and LinkShadow DSPM — cloud-scoped: on-premises shares are not covered. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Rubrik DSPM and Seqrite Data Privacy. **managed databases.** Rules out Varonis Data Access Governance, Varonis DDR, Forcepoint DDR, Seclore DSPM, Rubrik DSPM and Seqrite Data Privacy — database contents are not a documented scan target. That leaves Varonis DSPM, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Wiz DSPM and LinkShadow DSPM. **SaaS applications.** Rules out Wiz DSPM — SaaS application data is not covered. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Rubrik DSPM, Seqrite Data Privacy and LinkShadow DSPM. **unstructured shares.** Rules out Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Wiz DSPM, Rubrik DSPM and LinkShadow DSPM — not documented for large unstructured share estates. That leaves Varonis DSPM, Varonis Data Access Governance, Securiti Data Discovery and Seqrite Data Privacy. **effective access paths.** Rules out Cyera DSPM, Securiti DSPM, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Wiz DSPM, Rubrik DSPM and LinkShadow DSPM — reports permissions, but not effective access through nested groups and inherited rights; Securiti Data Discovery, Securiti Data Privacy Automation and Seqrite Data Privacy — no access analysis at all. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR and Cyera Data Access Governance. **acting on findings.** Rules out Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM and Wiz DSPM — raises a workflow or ticket; the change is made elsewhere; Securiti Data Discovery, Rubrik DSPM, Seqrite Data Privacy and LinkShadow DSPM — reporting only. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Forcepoint DDR and Seclore DSPM. **data detection and response.** Rules out Varonis Data Access Governance, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Seclore DSPM, Wiz DSPM, Rubrik DSPM, Seqrite Data Privacy and LinkShadow DSPM — posture only, no data detection and response. That leaves Varonis DSPM, Varonis DDR and Forcepoint DDR. **agentless deployment.** Rules out Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Forcepoint DSPM and Forcepoint DDR — hybrid deployment with components to install; Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Seclore DSPM, Rubrik DSPM, Seqrite Data Privacy and LinkShadow DSPM — connector-based: coverage depends on the connector catalogue. That leaves Cyera DSPM, Cyera Data Access Governance and Wiz DSPM. **a standalone product.** Rules out Wiz DSPM, Rubrik DSPM and LinkShadow DSPM — sold inside a cloud-security or backup platform licence, not as a discovery product on its own. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM and Seqrite Data Privacy. **DPDP reporting.** Rules out Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Forcepoint DSPM, Forcepoint DDR, Wiz DSPM, Rubrik DSPM and LinkShadow DSPM — no DPDP-specific reporting documented (the underlying discovery may still serve the obligation). That leaves Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Seclore DSPM and Seqrite Data Privacy. **Indian data types.** Rules nothing out on published terms. It flags Varonis DSPM — Indian data-type classification is not documented by the vendor, Varonis Data Access Governance — Indian data-type classification is not documented by the vendor, Varonis DDR — Indian data-type classification is not documented by the vendor, Cyera DSPM — Indian data-type classification is not documented by the vendor, Cyera Data Access Governance — Indian data-type classification is not documented by the vendor, Securiti DSPM — Indian data-type classification is not documented by the vendor, Securiti Data Discovery — Indian data-type classification is not documented by the vendor, Securiti Data Privacy Automation — Indian data-type classification is not documented by the vendor, Securiti Data Governance — Indian data-type classification is not documented by the vendor, Forcepoint DSPM — Indian data-type classification is not documented by the vendor, Forcepoint DDR — Indian data-type classification is not documented by the vendor, Seclore DSPM — Indian data-type classification is not documented by the vendor, Wiz DSPM — Indian data-type classification is not documented by the vendor, Rubrik DSPM — Indian data-type classification is not documented by the vendor, Seqrite Data Privacy — Indian data-type classification is not documented by the vendor and LinkShadow DSPM — Indian data-type classification is not documented by the vendor — marked, not removed. **India residency.** Rules nothing out on published terms. It flags Varonis DSPM — India residency for the classification index is not documented, Varonis Data Access Governance — India residency for the classification index is not documented, Varonis DDR — India residency for the classification index is not documented, Cyera DSPM — India residency for the classification index is not documented, Cyera Data Access Governance — India residency for the classification index is not documented, Securiti DSPM — India residency for the classification index is not documented, Securiti Data Discovery — India residency for the classification index is not documented, Securiti Data Privacy Automation — India residency for the classification index is not documented, Securiti Data Governance — India residency for the classification index is not documented, Forcepoint DSPM — India residency for the classification index is not documented, Forcepoint DDR — India residency for the classification index is not documented, Wiz DSPM — India residency for the classification index is not documented, Rubrik DSPM — India residency for the classification index is not documented and LinkShadow DSPM — India residency for the classification index is not documented — marked, not removed. **On-premises is the usual gap.** Cloud-native DSPM is fast and agentless because it scans cloud APIs. Estates whose sensitive data sits on file shares discover this after signature. Confirm on-premises coverage explicitly if the business case assumed it. **Two of these fifteen are modules.** Wiz and Rubrik sell DSPM inside their platforms. If you already run either, the discovery may be a licence change rather than a purchase — and Rubrik's runs over the backup copy, so production carries no scan load. **Classification accuracy on Indian records is unproven.** No DSPM vendor here documents PAN, Aadhaar or GSTIN support. We mark it per product rather than assume it, and never eliminate on it. Scan a representative sample of your own records during the proof of concept — an empty finding list is the usual symptom of a US-tuned classifier. **Finding is fast; remediation is not.** A scan returns thousands of findings in days. Every one needs an owner and a decision. Estates that treat the scan as the deliverable end up with a report nobody actions and a renewal nobody can justify. ## Eight situations, and what each one buys If one of these is your sentence, the shortlist is short. ### Most of our sensitive data is on file shares **Shortlist:** Varonis DSPM, Securiti Data Discovery, Seclore DSPM, Seqrite Data Privacy **Why:** On-premises unstructured coverage is the dividing line here, and the cloud-native tools do not cross it. **Trade-off:** Deployment is heavier than an agentless cloud scan — a programme rather than a connector. ### Cloud-first, and we need a map this quarter **Shortlist:** Cyera DSPM, Wiz DSPM **Why:** Agentless discovery across cloud object storage, databases and SaaS with nothing to install. **Trade-off:** On-premises shares are outside scope entirely; confirm that matches your estate before signature. ### Too many people can reach the data we found **Shortlist:** Varonis Data Access Governance, Cyera Data Access Governance, Varonis DSPM **Why:** Effective access-path analysis through nested groups and inherited permissions, plus least-privilege enforcement. **Trade-off:** Both assume their platform underneath; this is the remediation half of a discovery investment. ### The CSPM found a public bucket and nobody knows if it matters **Shortlist:** Wiz DSPM, Cyera DSPM **Why:** This is exactly the CSPM-to-DSPM handoff: configuration finding, data consequence. **Trade-off:** Wiz DSPM is a module — the case assumes Wiz is already your cloud security platform. ### We cannot put scan load on production **Shortlist:** Rubrik DSPM **Why:** Classification runs over the backup copy, which is a complete quiescent snapshot production never notices. **Trade-off:** Scope is whatever Rubrik backs up. Stores outside the backup are outside the map. ### DPDP readiness started and the data map does not exist **Shortlist:** Securiti Data Discovery, Securiti Data Privacy Automation, Seqrite Data Privacy, Seclore DSPM **Why:** All four document DPDP-shaped reporting, and personal-data discovery is the first practical step of any readiness programme. **Trade-off:** Privacy automation is not a security control — read the DPDP section below before assuming one product covers both. ### We have the map and want alerts when someone touches it **Shortlist:** Varonis DDR, Forcepoint DDR, Varonis DSPM **Why:** Data detection and response alerts on access to classified data at rest, not on configuration drift. **Trade-off:** Both are the response half of a posture investment and assume the classification is already there. ### We are buying discovery and enforcement together **Shortlist:** Forcepoint DSPM, Varonis DSPM, Seclore DSPM **Why:** The classification that finds the data is the one the enforcement acts on — one definition of sensitive, not two. **Trade-off:** Ties you to one vendor across two routes; the specialists are deeper at each individual job. ## At scale DSPM is metered on stores and scanned volume, so scale here means data, not headcount. ### 1 data stores — A handful of cloud stores - Agentless scanning is fast and cheap at this size - One person can action the findings - Wiz or Rubrik may already cover it **The test:** Check whether an existing platform already includes DSPM. ### 2 data stores — Cloud plus SaaS, tens of stores - Connector coverage becomes the deciding variable - Findings need a triage process, not one person - Classification accuracy starts to matter commercially **The test:** Confirm your specific stores appear on the connector list. ### 3 data stores — Hybrid, with on-premises shares - The cloud-native tools stop being candidates - Deployment becomes a programme - Access-path analysis earns its price **The test:** Prove on-premises coverage in the proof of concept, not in the datasheet. ### 4 data stores — Petabyte-scale unstructured - Scanning cost becomes a material line item - Incremental and targeted scanning matters more than raw speed - Remediation needs automation, not tickets **The test:** Model the scanning bill on your actual volume before signature. Where a vendor does not publish deployment scale evidence, this page says so rather than implying it. ## Getting out The map is easier to leave than the tuning behind it. **The inventory** — Findings and classifications export to CSV or API almost everywhere *(Portable)* **Classification tuning** — Custom classifiers and thresholds are vendor-specific and are rebuilt *(Not portable)* **Connector configuration** — Each platform models stores differently; the connections are re-made *(Rebuilt)* **Remediation history** — Who decided what about which finding — exportable, but rarely in a form the next tool ingests *(Partly portable)* The practical consequence: a second DSPM re-scans and re-classifies from scratch. Switching is cheaper than switching DLP, and still not free. ## What it costs Metered on stores, environments or scanned volume — not per user, which changes the budgeting shape entirely. ### Do you already own one? Four checks, in the order most likely to return a yes. - **Microsoft Purview — Already scanning, if your data is in Microsoft 365.** E5 includes data classification and scanning across Microsoft 365. **Its scope is the Microsoft estate** — strong there, and not a map of your cloud object storage or file shares. - **Your cloud security platform — Wiz sells DSPM on the same graph as its CSPM findings.** If Wiz is already deployed, the data half is a licence change rather than a new tool to run. - **Your backup platform — Rubrik sells DSPM over the copy it already holds.** Discovery with no production scan load — scope is whatever is backed up. - **Your DLP vendor — Forcepoint, Varonis and Seclore sell both halves.** Buying discovery from the vendor that will enforce means one definition of sensitive rather than two. None of these is automatically right, and each covers a different slice. The Microsoft answer in particular is strong inside its own estate and silent outside it. ### What the rest actually cost Quote-led across the board, and the meter is the thing to negotiate. ### What isn't in the licence price - **Remediation headcount.** Thousands of findings need owners and decisions. This is the line that decides whether the map becomes a fix. - **Scanning costs on large stores.** Cloud egress and compute for scanning petabyte-scale object storage is a real and separate bill. - **Indian data-type proof of concept.** Undocumented across every vendor. Budget the time to prove it against your own records. - **Connector gaps.** Stores outside the catalogue need custom work or stay unscanned — and unscanned stores are exactly where surprises live. ## What goes wrong Five ways this purchase goes wrong. Each is recoverable if caught before signature. - **Findings nobody owns.** The scan returns thousands of results in days and stops there. Without a named owner and a triage process, the map is a report and the renewal has no case behind it. - **On-premises shares out of scope.** The business case assumed them; the agentless tool cannot see them. This is the single most common mismatch in this category — confirm it explicitly. - **Classification tuned for US data types.** A classifier looking for social security numbers finds nothing useful in an Indian estate. Undocumented across every vendor here, so prove it with your own records. - **Scanning costs nobody modelled.** Volume-metered scanning on large object stores produces a bill that has nothing to do with headcount. Model it before signature. - **Buying DSPM when the requirement was DLP.** Or the reverse. One finds data at rest; the other stops it moving. The boundary section above resolves it in one question. ## Questions this guide answers ### What is the difference between DSPM and CSPM? CSPM reads cloud configuration and tells you the bucket is public. DSPM reads contents and tells you the public bucket holds customer records. One finds misconfigurations, the other finds consequences — and a CSPM report of 400 public buckets cannot tell you which three actually matter. They are complementary, and CSPM is covered on the Cloud & Workload Security guide rather than repeated here. ### Does DPDP require DSPM? No. Rule 6 of the DPDP Rules, 2025 (notified 13 November 2025) requires reasonable security safeguards to prevent personal data breaches, and lists measures including encryption, obfuscation, masking, access control and log retention. It does not name DSPM, DLP or any product category. The practical inference — that you cannot apply access control to personal data you cannot locate — is an implication we label as one. Any vendor claiming DPDP mandates their product category is overstating the instrument. Confirm the schedule applicable to your class of fiduciary with counsel. ### Can DSPM scan on-premises file shares? Some can and many cannot, and this is the most common mismatch in the category. Varonis, Securiti, Seclore and Seqrite document on-premises coverage; the cloud-native agentless tools including Cyera and Wiz are scoped to cloud stores, databases and SaaS. If your business case assumed on-premises shares, confirm coverage explicitly before signature — it is discovered after the fact more often than any other constraint here. ### Do DSPM tools recognise PAN, Aadhaar and GSTIN? No vendor on this page documents support for Indian data types. We mark that as unknown per product rather than assuming it either way, and we never eliminate a product on it. It must be proven in a proof of concept against your own records: a classifier trained on US formats returns nothing useful on Indian identifiers, and this is the most common reason an expensive scan produces an empty finding list. ### How is DSPM priced? Per environment, per data store or on scanned volume — not per user. That means an organisation with a small team and large object stores can pay more than one with a large workforce and little data. Varonis, Cyera and Securiti are quote-led. Seclore and Seqrite quote in INR and are the two India-built options. Wiz and Rubrik include DSPM inside their platform licences. Ask each vendor to model the bill against your actual store inventory, because the meter matters more than the rate. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/data-security-privacy/dspm* --- # Every other control protects data while it is inside your boundary. This is the only one that still works after the file has left. *Encryption & Rights Management — a TechBag decision guide. Last reviewed 2026-09-07.* > Rights management puts the policy inside the document rather than around it. The file carries its own rules — who may open it, whether they may print or copy, when it expires — and those rules are enforced on a recipient’s laptop in an organisation you do not control. **The checkable fact:** The test that separates this from everything else on the site: a confidential file was legitimately sent to an external auditor last month and the engagement has ended. Can you stop them opening it today? Only one product on this page can. - Canonical: https://www.thetechbag.com/browse/data-security-privacy/encryption-rights - Category: [Data Security & Privacy](https://www.thetechbag.com/browse/data-security-privacy) - Products compared: 18 ## What encryption & rights management actually is Six products, three distinct jobs. **Rights management** wraps policy inside the file so it stays enforced anywhere. **Encryption** protects storage — a disk, a removable drive, a database — so a stolen device or a raw dump is unreadable. **Classification** labels documents so one of the other two knows what to act on. They are routinely conflated, and the cost of conflating them is specific: buyers who ask for encryption usually already have it from their storage layer or device management, and buyers who need protection to survive the file leaving find that disk encryption does nothing at all for that scenario. **The most common mis-purchase.** What the **external recipient** has to do. If opening a protected file requires them to install your software, register an account or contact your helpdesk, the process is abandoned within weeks and people revert to unprotected email. This decides adoption more than any capability on the datasheet, and it is the question to put in writing before signature. ## Four terms, resolved These are adjacent controls at different points in the data’s life, not tiers. A product that encrypts a disk perfectly protects nothing once a legitimate user copies a file off it. ### Encryption at rest vs in transit Which gap are you actually closing? ### Encryption at rest vs in use Is the data protected while it is being processed? ### EDRM/IRM vs encryption Does the protection travel, or stop at your boundary? ### EDRM/IRM vs DLP Stop the file, or protect it after it goes? The practical consequence: confirm which of the three jobs you are buying before you compare products, because all six vendors here will use the word encryption and only one of them makes protection survive the file leaving. ## The decision variables Six variables move the shortlist. Everything else is preference. **What travels with the file.** Whether the policy is inside the document or around its container. This is the dividing line of the whole page. **Revocation after distribution.** Withdrawing access to a file already delivered is the reason to buy rights management. Confirm in writing whether it reaches a copy already downloaded and held offline. **The external-recipient experience.** Can they open it with no software from you? This decides adoption, and adoption decides whether the investment returns anything. **Format and application coverage.** Office and PDF are universal here. CAD, engineering drawings and arbitrary formats are not — and manufacturing estates usually need them. **Integration with DLP and DSPM.** Rights management is normally the enforcement arm of a classification decision made elsewhere. Applied manually, it is applied rarely. **Key management.** Who holds the keys, where they are held, and what happens to protected files if the vendor relationship ends. Nobody owns this until it matters. ## The 18 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Thales CipherTrust Secrets Management — Thales - **Who it's for:** Estates where the real exposure is not encrypted-at-rest data but the long-lived credential sitting in a repository. Leaked credentials in source control are one of the most reliably exploited initial-access routes there is, and the credential is usually shared widely and rotated never. This replaces that with centrally issued, scoped, rotatable secrets — and it roots into the same CipherTrust key custody as the rest of the platform. - **The honest limitation:** This is infrastructure credential hygiene, NOT document protection — it will not follow a file anywhere, and if that is your problem you want EDRM. It also competes directly with HashiCorp Vault, which has a free self-hostable edition and a far larger engineering community; the case for buying it from Thales is that you already run CipherTrust and want one key-custody story rather than two. - **Price:** Quote — Quote-only, licensed by the applications and workloads that authenticate to it rather than by data volume; centralises API keys, database passwords, certificates and tokens so they stop living in config files, environment variables and CI/CD settings - **Details:** https://www.thetechbag.com/thales/thales-ciphertrust-secrets-management ### HashiCorp Vault — HashiCorp (IBM) - **Who it's for:** Engineering-led estates that need encryption-as-a-service and key custody under their own control rather than a document-protection product. Vault issues and rotates keys, encrypts data on behalf of applications without ever handing them the key material, and can run entirely on your own infrastructure in India — which is the cleanest answer to a DPDP or RBI question about who holds the keys. - **The honest limitation:** This is NOT rights management and will not protect a document that leaves your estate — different problem, different product. It is also operationally heavy: Vault is a distributed system with unseal, replication and upgrade responsibilities, and teams underestimate that consistently. HashiCorp is now an IBM company, so weigh roadmap direction accordingly. - **Price:** Free → Quote — Community edition is free and self-hostable; HCP Vault is managed and quoted, Enterprise is quoted per cluster. Metering is on clients rather than data volume — an application or workload that authenticates to Vault - **Details:** https://www.thetechbag.com/hashicorp/hashicorp-vault ### ESET PROTECT Advanced — ESET - **Who it's for:** Organisations whose actual encryption requirement is the laptop that gets left in a taxi, not inter-company document control. Full-disk encryption is what turns a lost device from a reportable breach into an inventory problem under DPDP — and buying it inside the endpoint suite you were purchasing anyway is materially cheaper than a standalone encryption product. - **The honest limitation:** Full-disk encryption protects data AT REST ON THE DEVICE and nothing else. The moment a file is copied off, emailed or uploaded it is plaintext again — there is no travelling policy, no post-distribution revocation, and no control over the recipient. If your problem is documents leaving the organisation, this is the wrong category entirely; look at EDRM. - **Price:** ~$55 (≈ ₹4,565) — per device per year on PUBLIC list pricing — the only published price in this guide. Full-disk encryption is bundled into the endpoint-protection tier rather than sold as a separate SKU, alongside cloud sandboxing - **Details:** https://www.thetechbag.com/eset/eset-protect-advanced ### Thales CipherTrust Data Discovery and Classification — Thales - **Who it's for:** The estate that has bought encryption and cannot confidently say what it is pointed at. Every other control on this page — encryption, access policy, key management — has to be aimed at something, and aiming it at an asset inventory nobody trusts is how encryption programmes quietly miss the data that mattered. Under the DPDP Act the first practical question is what personal data you hold and where, which is this product’s output rather than a by-product. - **The honest limitation:** Classification is not protection — it labels and hands off, and bought alone it produces an inventory nothing acts on. It is also the least glamorous line in a proposal and the first one cut, which is usually the decision that undermines everything bought alongside it. - **Price:** Quote — Quote-only, scoped by the data stores scanned; scans structured and unstructured stores to find sensitive data and label what it finds, feeding the rest of the CipherTrust platform - **Details:** https://www.thetechbag.com/thales/thales-data-discovery-classification ### Seqrite Data Privacy — Seqrite - **Who it's for:** Indian organisations working out what the DPDP Act actually requires of them. Before you can protect personal data you have to find it and know what it is, and this is the discovery-and-classification half of that problem from a vendor headquartered in Pune with Indian support and INR invoicing. - **The honest limitation:** Classification is not protection. It tells you where personal data lives and labels it — it does not encrypt the file, does not travel with it, and cannot revoke access after distribution. It is the input to a protection decision, so pair it with EDRM or DLP or the labels achieve nothing on their own. - **Price:** Quote (INR) — Quoted in INR by an India-built vendor (Quick Heal), SaaS or on-premises; scoped around discovering and classifying personal data rather than encrypting documents - **Details:** https://www.thetechbag.com/seqrite/seqrite-data-privacy ### Thales CipherTrust Manager — Thales - **Who it's for:** The buyer whose regulator has stopped asking whether data is encrypted and started asking who can decrypt it. Cloud providers encrypt at rest by default and it protects against exactly one thing, a stolen disk — it does nothing about the provider, who holds the key. CipherTrust Manager makes the keys yours, under your policy, on infrastructure you operate, so the answer to an auditor is a demonstration rather than a contract clause. - **The honest limitation:** This protects infrastructure, not documents — it will not follow a file that leaves your estate, and if that is your problem you want EDRM instead. CipherTrust as-a-Service is EU/NA only with NO India region, so residency-bound buyers deploy on-premises. And be precise about a fact this market blurs: Thales has 2,200+ staff in India with Noida as its Cyber & Digital centre, but people in India and data in India are different things. - **Price:** Quote — Quote-only. Deploys as a virtual appliance or physical hardware, and can be rooted in a Luna HSM so master keys never exist in software. Licensed by scope — the hosts, databases or applications protected — rather than by data volume - **Details:** https://www.thetechbag.com/thales/thales-ciphertrust-manager ### Thales Luna HSM — Thales - **Who it's for:** Indian BFSI, government and defence-adjacent buyers whose regulator asks specifically about hardware key protection, and payments or PKI use cases with an explicit HSM mandate. Keys are generated inside tamper-resistant hardware and never leave in usable form, so compromising the server that calls the HSM does not yield the key. It is also the strongest possible answer to an Indian residency question — the key is in a physical box in your data centre. - **The honest limitation:** This is an appliance, not software, and budgets go wrong in a predictable way: the purchase price gets captured and firmware maintenance, security-domain backup, separation of duties between administrators and approvers, and a second unit for resilience do not. Also worth raising early — Entrust’s nShield holds Bureau of Indian Standards certification. If BIS is a procurement requirement for you, that is a deciding fact rather than a preference. - **Price:** Quote — Quote-only, and it is a capital purchase rather than a subscription — an appliance price plus a support contract, and more than one unit if you want to survive a site failure - **Details:** https://www.thetechbag.com/thales/thales-luna-hsm ### Thales CipherTrust Transparent Encryption — Thales - **Who it's for:** Estates whose most sensitive systems are the ones nobody will modify. Encryption programmes stall because protecting data appears to require changing every application that touches it, and a fifteen-year-old line-of-business system is not getting refactored whatever the policy says. An agent leaves it untouched. The second capability matters as much: privileged-user access control lets a DBA administer a system without reading the data inside it — exactly the control an RBI or SEBI reviewer probes. - **The honest limitation:** There is a performance overhead, and the only number that means anything is the one you measure on your own least-modern system rather than a clean test host. It also protects data at rest on infrastructure you control and nothing beyond that — a file exported by an authorised process is plaintext the moment it lands elsewhere. - **Price:** Quote — Quote-only, typically licensed per protected host. An agent sits between the application and storage, so no application changes are required - **Details:** https://www.thetechbag.com/thales/thales-ciphertrust-transparent-encryption ### Entrust nShield HSM — Entrust - **Who it's for:** Indian buyers where BUREAU OF INDIAN STANDARDS certification is in the tender. nShield Connect XC holds BIS and its closest competitor does not — and for Indian government and several BFSI procurement processes BIS is a GATE rather than a scoring criterion, meaning a product without it is not permitted regardless of merit or price. If BIS is in your requirements, this single fact settles the comparison before any feature is discussed. - **The honest limitation:** An appliance, not software: budget firmware maintenance, Security World backup, separation-of-duties roles that did not previously exist, and a second unit for resilience. nShield as a Service has NO India region (UK/US/DE/AU), so India means on-premises. And on analyst standing we are being conservative — Gartner publishes no MQ for HSM or key management at all, and we could not verify an HSM Leader placement for Entrust with any analyst. Thales has the stronger verified position. - **Price:** Quote — Quote-only, and a capital purchase rather than a subscription — appliance price plus support, and more than one unit if you want to survive a site failure. Security World manages keys across a group of HSMs as one logical unit - **Details:** https://www.thetechbag.com/entrust/entrust-nshield-hsm ### Entrust PKI — Entrust - **Who it's for:** Estates where machine identities are multiplying faster than anyone can issue certificates by hand. Private certificate authority for the machine identities, device certificates, internal TLS and code signing your own systems trust — with the trust model, issuance policy and validity periods defined by you rather than inherited from a commercial CA’s compliance record. - **The honest limitation:** READ THE SCOPE: this is PRIVATE PKI. Entrust sold its entire public TLS certificate business to Sectigo in September 2025 after Chrome, Apple and Mozilla distrusted its roots — so publicly trusted SSL for an internet-facing site is no longer an Entrust product, whatever older search results say. Private PKI was not part of that sale, and the two share vocabulary and little else. - **Price:** Quote — Quote-only. Available on-premises or as PKI as a Service — check the managed option’s region list if Indian residency binds you - **Details:** https://www.thetechbag.com/entrust/entrust-pki ### Entrust Certificate Lifecycle Management — Entrust - **Who it's for:** Anyone who cannot confidently list their certificates — which is usually discovered through an outage rather than through planning. Expired certificates cause a disproportionate share of unplanned downtime, and the cause is never the cryptography: it is that nobody knew the certificate existed until it stopped working. The DISCOVERY half matters more than the renewal half, because a renewal process only covers certificates you already know about. - **The honest limitation:** It manages certificates; it does not issue trust — a CA still sits behind it, public or private. And if your estate is genuinely small and stable, a maintained spreadsheet with calendar reminders is not a ridiculous answer and we would say so rather than sell you a platform you do not need yet. - **Price:** Quote — Quote-only. Discovery, inventory, automated renewal and revocation across the certificates scattered through a real estate - **Details:** https://www.thetechbag.com/entrust/entrust-certificate-lifecycle ### Microsoft Purview Information Protection — Microsoft - **Who it's for:** Microsoft estates sharing documents outside the organisation. The integration advantage is real and no third party can match it inside Microsoft 365 — and India is an eligible Local Region Geography under Advanced Data Residency, with Information Protection in scope as of February 2026, which most of this category cannot offer at all. Message Encryption also lets external recipients open protected email with a one-time passcode and no software installed. - **The honest limitation:** REVOCATION IS PARTIAL, not absolute: a revoked document stays readable until the recipient’s offline policy period expires, and files uploaded to SharePoint or OneDrive lose the content identifier and cannot be tracked or revoked AT ALL — which in a Microsoft estate is where documents routinely end up. Double Key Encryption gives you one of the two keys but disables co-authoring, SharePoint/OneDrive processing, search, eDiscovery and Copilot, and is Windows Office only. Format coverage is strong on Office and PDF and narrower beyond — for CAD, see Seclore. And the ADR conditions are strict: all users in the tenant, and tenant default geography India. - **Price:** $12 (≈ ₹11,952) — per user / MONTH published for the Microsoft 365 E5 Compliance add-on over E3 (~$144/user/year); full E5 is $60/user/month after the July 2026 increase. But check your entitlement FIRST — manual sensitivity labels and RMS encryption are already included in E3, and in most estates they are sitting unconfigured. The add-on buys automatic labelling, trainable classifiers, exact data match and Double Key Encryption - **Details:** https://www.thetechbag.com/microsoft/microsoft-purview ### Seclore ARMOR EDRM — Seclore - **Who it's for:** Indian BFSI and manufacturing estates that share confidential documents outside the organisation routinely and need the protection to survive the file leaving — with the vendor, the keys and the support in the same country. - **The honest limitation:** Rights management is only as good as its adoption: protection applied manually is applied rarely, so it needs to be driven by a classification or DLP decision rather than by users remembering. Narrower than a global suite on adjacent capabilities — this is a specialist, not a platform. - **Price:** Quote (INR) — quoted per protected user in INR from the Mumbai-built vendor, SaaS or self-hosted; policy travels inside the file with usage controls, expiry and post-distribution revocation across Office, PDF, CAD and arbitrary formats - **Details:** https://www.thetechbag.com/seclore/seclore-edrm ### Seclore ARMOR Data Classification — Seclore - **Who it's for:** Estates deploying Seclore EDRM that need the protection triggered by a rule rather than a person — the piece that turns rights management from optional into automatic. - **The honest limitation:** Classification is not a protection control by itself: it labels and hands off. Bought alone it produces labels nothing acts on. - **Price:** Quote (INR) — quoted per user in INR; labelling at creation and at rest that decides which documents get protected, feeding the rights-management engine automatically rather than relying on the author - **Details:** https://www.thetechbag.com/seclore/seclore-data-classification ### Trellix Data Encryption — Trellix - **Who it's for:** Estates whose requirement is the lost-laptop and stolen-USB scenario — device-level encryption with a central place to recover keys when someone leaves or forgets a passphrase. - **The honest limitation:** Encryption at rest on devices you manage: it protects the disk, not the file once a legitimate user copies it elsewhere. It does not answer the after-it-leaves question at all — that is the row above. - **Price:** Quote — quoted per endpoint, managed from the Trellix ePO console; full-disk, file and removable-media encryption with central key escrow and recovery - **Details:** https://www.thetechbag.com/trellix/trellix-data-encryption ### Trellix Database Security — Trellix - **Who it's for:** Estates whose sensitive data is structured and sitting in databases, where the control needs to sit at the data layer rather than on the endpoint. - **The honest limitation:** Database-scoped, on-premises oriented, and it is monitoring and protection rather than rights management — the file exported from the database is outside its control entirely. - **Price:** Quote — quoted per database instance; activity monitoring, vulnerability assessment and protection for database contents at rest, without changing the application - **Details:** https://www.thetechbag.com/trellix/trellix-database-security ### Seqrite Encryption — Seqrite - **Who it's for:** Indian mid-market estates that need documented device encryption for an audit, at a price and on an agent they may already be running. - **The honest limitation:** Device encryption only, on the Seqrite agent: no file-level rights, no revocation, and no protection once a file is legitimately copied off the device. It answers the compliance question about lost devices and nothing beyond it. - **Price:** Quote (INR) — quoted per endpoint in INR, frequently bundled with Seqrite endpoint protection; full-disk and removable-media encryption with central policy and key recovery from the India-built vendor - **Details:** https://www.thetechbag.com/seqrite/seqrite-encryption ### Forcepoint Data Classification — Forcepoint - **Who it's for:** Forcepoint estates that want one classification decision made once and honoured by every control in the portfolio, rather than each product deciding separately. - **The honest limitation:** A labelling layer, not a protection control: it decides what a document is and hands the enforcement to DLP. Bought alone it produces metadata with nothing acting on it. India residency is not documented. - **Price:** Quote — quoted within the Forcepoint data-security portfolio; user-driven and automated labelling that drives Forcepoint DLP policy and downstream protection decisions - **Details:** https://www.thetechbag.com/forcepoint/forcepoint-data-classification ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **protection that travels.** Rules out Thales CipherTrust Secrets Management, HashiCorp Vault, ESET PROTECT Advanced, Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Entrust PKI, Entrust Certificate Lifecycle Management, Seclore ARMOR Data Classification, Trellix Data Encryption, Trellix Database Security, Seqrite Encryption and Forcepoint Data Classification — protects data inside your boundary; a legitimate copy taken elsewhere is unprotected. That leaves Microsoft Purview Information Protection and Seclore ARMOR EDRM. **revocation after delivery.** Rules out ESET PROTECT Advanced, Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Seclore ARMOR Data Classification, Trellix Data Encryption, Trellix Database Security, Seqrite Encryption and Forcepoint Data Classification — no revocation after distribution; Microsoft Purview Information Protection — revocation documented, but not for copies already downloaded. That leaves Thales CipherTrust Secrets Management, HashiCorp Vault, Entrust PKI, Entrust Certificate Lifecycle Management and Seclore ARMOR EDRM. **no software for recipients.** Rules out Thales CipherTrust Secrets Management, HashiCorp Vault, ESET PROTECT Advanced, Seqrite Data Privacy, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Entrust PKI, Trellix Data Encryption and Seqrite Encryption — the recipient needs an agent or client installed. That leaves Thales CipherTrust Data Discovery and Classification, Entrust Certificate Lifecycle Management, Microsoft Purview Information Protection, Seclore ARMOR EDRM, Seclore ARMOR Data Classification, Trellix Database Security and Forcepoint Data Classification. **any file format.** Rules out Microsoft Purview Information Protection, Seclore ARMOR Data Classification and Forcepoint Data Classification — documented for Office and PDF; other formats are not covered. That leaves Thales CipherTrust Secrets Management, HashiCorp Vault, ESET PROTECT Advanced, Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Entrust PKI, Entrust Certificate Lifecycle Management, Seclore ARMOR EDRM, Trellix Data Encryption, Trellix Database Security and Seqrite Encryption. **CAD formats.** Rules out Thales CipherTrust Secrets Management, HashiCorp Vault, ESET PROTECT Advanced, Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Entrust PKI, Entrust Certificate Lifecycle Management, Microsoft Purview Information Protection, Seclore ARMOR Data Classification, Trellix Data Encryption, Trellix Database Security, Seqrite Encryption and Forcepoint Data Classification — CAD formats are not documented. That leaves Seclore ARMOR EDRM. **a protection control.** Rules out Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy, Entrust Certificate Lifecycle Management, Seclore ARMOR Data Classification and Forcepoint Data Classification — classification labels the file and hands enforcement elsewhere. That leaves Thales CipherTrust Secrets Management, HashiCorp Vault, ESET PROTECT Advanced, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Entrust PKI, Microsoft Purview Information Protection, Seclore ARMOR EDRM, Trellix Data Encryption, Trellix Database Security and Seqrite Encryption. **SaaS — nothing of ours to host.** Rules out Thales Luna HSM, Entrust nShield HSM and Trellix Database Security — on-premises deployment only. That leaves Thales CipherTrust Secrets Management, HashiCorp Vault, ESET PROTECT Advanced, Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy, Thales CipherTrust Manager, Thales CipherTrust Transparent Encryption, Entrust PKI, Entrust Certificate Lifecycle Management, Microsoft Purview Information Protection, Seclore ARMOR EDRM, Seclore ARMOR Data Classification, Trellix Data Encryption, Seqrite Encryption and Forcepoint Data Classification. **Keys held only by us, never the vendor.** Rules out Microsoft Purview Information Protection, Seclore ARMOR EDRM, Seclore ARMOR Data Classification and Forcepoint Data Classification — the vendor can hold the keys in the default deployment; customer-held is available on request. That leaves Thales CipherTrust Secrets Management, HashiCorp Vault, ESET PROTECT Advanced, Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Entrust PKI, Entrust Certificate Lifecycle Management, Trellix Data Encryption, Trellix Database Security and Seqrite Encryption. **India.** Rules nothing out on published terms. It flags Thales CipherTrust Secrets Management — Data region documented, HashiCorp Vault — Data region documented, ESET PROTECT Advanced — India residency for the policy server and key material is not documented, Thales CipherTrust Data Discovery and Classification — Data region documented, Thales CipherTrust Manager — Data region documented, Thales Luna HSM — Data region documented, Thales CipherTrust Transparent Encryption — Data region documented, Entrust nShield HSM — Data region documented, Entrust PKI — Data region documented, Entrust Certificate Lifecycle Management — Data region documented, Microsoft Purview Information Protection — Data region documented, Trellix Data Encryption — India residency for the policy server and key material is not documented, Trellix Database Security — India residency for the policy server and key material is not documented and Forcepoint Data Classification — India residency for the policy server and key material is not documented — marked, not removed. **documented offline behaviour.** Rules out Thales CipherTrust Secrets Management, HashiCorp Vault, Thales CipherTrust Data Discovery and Classification, Seqrite Data Privacy and Entrust Certificate Lifecycle Management — offline behaviour is not documented; confirm before relying on it; Trellix Database Security — not applicable: this control does not travel with files. That leaves ESET PROTECT Advanced, Thales CipherTrust Manager, Thales Luna HSM, Thales CipherTrust Transparent Encryption, Entrust nShield HSM, Entrust PKI, Microsoft Purview Information Protection, Seclore ARMOR EDRM, Seclore ARMOR Data Classification, Trellix Data Encryption, Seqrite Encryption and Forcepoint Data Classification. **Only one product here survives the file leaving.** Seclore ARMOR EDRM is the only product on this page whose protection travels inside the file. The others encrypt storage, encrypt devices or label documents — all valuable, none of them answering the after-it-leaves question. **The external recipient decides adoption.** If the person you send a protected file to cannot open it easily, the process is abandoned within weeks and people revert to unprotected email. This is the variable that decides deployments, and it is under-weighted in almost every evaluation. **Classification is the trigger, not the control.** Two of these six are labelling layers. They decide which documents get protected and hand the enforcement elsewhere. Bought alone they produce metadata that nothing acts on. **Every product here runs on-premises, and every one allows customer-held keys.** That is unusual and worth stating: it is not a variable that narrows this shortlist. What does narrow it is whether protection survives the file leaving, and what the external recipient has to do. **Encryption at rest is usually already on.** Your storage layer, your cloud provider and your device management probably already encrypt at rest. If that is the requirement, check before buying — and note that it stops none of the scenarios that bring people to this page. ## Eight situations, and what each one buys If one of these is your sentence, the shortlist is short — frequently one product. ### A confidential file went outside and we need it back **Shortlist:** Seclore ARMOR EDRM **Why:** Revocation after distribution is documented, and it is the only product here whose protection persists outside your estate. **Trade-off:** Confirm in writing whether revocation reaches a copy already downloaded and held offline — that is the scenario people picture when they buy this. ### Files legitimately go to external auditors and consultants **Shortlist:** Seclore ARMOR EDRM, Seclore ARMOR Data Classification **Why:** Protect-and-send rather than block-or-allow, with expiry when the engagement ends and no software for the recipient to install. **Trade-off:** Needs the classification half to trigger protection automatically; applied by hand, it is applied rarely. ### A laptop was lost and we need to prove the data was safe **Shortlist:** Trellix Data Encryption, Seqrite Encryption **Why:** Full-disk encryption with central key escrow — the documented answer to the lost-device audit question. **Trade-off:** Protects the device, not the file. A legitimate copy taken elsewhere is unprotected, which is a different problem entirely. ### Removable media leaves the building routinely **Shortlist:** Trellix Data Encryption, Seqrite Encryption **Why:** Media encryption with central policy means the stick is unreadable off your estate without the key. **Trade-off:** The recipient needs the agent or the recovery process; this is not a way to share files with outsiders. ### Our confidential documents are engineering drawings **Shortlist:** Seclore ARMOR EDRM **Why:** CAD and arbitrary formats are documented, where the classification layers here cover Office and PDF only. **Trade-off:** Prove your specific CAD applications in a proof of concept — format support is version-specific in practice. ### The sensitive data is structured, in databases **Shortlist:** Trellix Database Security **Why:** Protection and activity monitoring at the data layer, without changing the application. **Trade-off:** On-premises oriented, and the file exported from the database is outside its control entirely. ### The keys and the vendor must be in India **Shortlist:** Seclore ARMOR EDRM, Seclore ARMOR Data Classification, Seqrite Encryption **Why:** All three are India-built, quote in INR, and offer self-hosted deployment with customer-held keys. **Trade-off:** Both vendors are narrower than a global suite on adjacent capabilities — specialists rather than platforms. ### Protection is applied by hand, so it is barely applied **Shortlist:** Seclore ARMOR Data Classification, Forcepoint Data Classification **Why:** Labelling at creation and at rest triggers protection by rule rather than relying on the author to remember. **Trade-off:** Neither is a control on its own — each hands enforcement to something else, and produces only metadata if bought alone. ## At scale Rights management scales by protected users and by how automatic the protection is. ### 1 protected users — One team, one document type - Manual protection is workable at this size - Legal or finance is the usual first team - The external-recipient test still decides everything **The test:** Run the recipient test with a real outside party before widening. ### 2 protected users — Several departments - Manual application starts failing — people forget - Classification becomes the trigger, not a nice-to-have - Format coverage beyond Office starts to matter **The test:** Automate the trigger before adding the second department. ### 3 protected users — Estate-wide, externally facing - Protection must be driven by DLP or DSPM decisions - Key management needs a named owner - Revocation gets used in anger, so test it properly **The test:** Name the key-management owner. Nobody does until it matters. ### 4 protected users — Regulated, with retention obligations - Self-hosted and customer-held keys become the requirement - Audit evidence of access and revocation is the deliverable - Exit planning matters — what happens to protected files later **The test:** Ask what happens to protected files if you stop paying. Where a vendor does not publish deployment-scale evidence, this page says so rather than implying it. ## Getting out This is the one category on the site where leaving badly can make your own data unreadable. **Protected files** — Every protected document depends on a policy server and keys that must keep answering *(Bulk-decrypt before leaving)* **Encryption keys** — Customer-held keys are portable; vendor-held keys are the whole risk of this row *(Depends who holds them)* **Classification labels** — Microsoft Information Protection labels are the nearest thing to a standard and travel reasonably *(Partly portable)* **Policy definitions** — Vendor-specific and rebuilt in the next product *(Not portable)* Ask this question before signature, not at renewal: what happens to files already protected if the contract ends? The answer should be a documented bulk-decryption process, and you should hold the keys. ## What it costs Per protected user for rights management, per endpoint for encryption. ### Do you already own one? Four checks, in the order most likely to return a yes. - **Microsoft Purview — Already encrypting Office files, if you hold E5.** E5 includes sensitivity labels with **Information Protection encryption** that travels with Office files. **Its limits are format and ecosystem** — strong for Office and PDF inside the Microsoft world, thin for CAD and arbitrary formats. - **Your storage or cloud provider — Encryption at rest is on by default nearly everywhere.** If the requirement is the lost-drive scenario at the storage layer, it is already covered and needs no purchase. - **Your device management — BitLocker and FileVault are managed by most UEM platforms.** Full-disk encryption with key escrow is frequently a policy switch in a tool you already run. - **Your endpoint suite — Seqrite and Trellix both sell encryption on their existing agents.** If either is already deployed, device encryption is a module rather than a new agent. The pattern here is unusual: for encryption the answer is very often yes, and for rights management it is very often no. Separate the two before shortlisting. ### What the rest actually cost Quote-led, and the India-built options quote in rupees. ### What isn't in the licence price - **Key-management ownership.** Somebody has to own keys, escrow and recovery. Unowned until a laptop is wiped or an employee leaves, and then urgent. - **The external-recipient trial.** Testing with real outside parties on machines you do not manage. Skipped almost universally, and the reason deployments fail. - **Classification to trigger protection.** Manual protection is rarely applied. The trigger is usually a second purchase. - **Format proof of concept.** CAD and specialist formats are version-specific in practice. Prove your actual applications. ## What goes wrong Five ways this purchase goes wrong. The first is the one that ends deployments. - **External recipients cannot open protected files.** They ask what this is, someone sends an unprotected copy to unblock the meeting, and the informal rule becomes not to protect anything anyone outside needs to read. - **Protection applied manually, so applied rarely.** If a person has to remember, they will not. Protection has to be triggered by a classification or DLP decision to reach meaningful coverage. - **Revocation that does not reach a downloaded copy.** The scenario people picture when buying is a file already on someone's laptop. Confirm that specific case in writing — it is where implementations differ most. - **Key management nobody owns.** Escrow and recovery are unassigned until an employee leaves or a device is wiped, and then it is an incident rather than a process. - **Buying rights management when the requirement was encryption at rest.** Which the storage layer, the cloud provider and the device management already do. Separate the three jobs before shortlisting anything. ## Questions this guide answers ### What is the difference between encryption and rights management? Encryption protects a container — a disk, a volume, a removable drive, a database — so a stolen device or a raw storage dump is unreadable. Rights management puts the policy inside the document itself, so the rules are enforced on a recipient's machine in an organisation you do not control. Disk encryption does nothing at all once a legitimate user copies a file elsewhere; that is exactly the gap rights management exists to close. ### Can I revoke access to a file someone has already downloaded? That is the reason to buy rights management, and it is the capability to confirm in writing rather than assume. Seclore ARMOR EDRM documents post-distribution revocation. The specific case to put to any vendor is a copy already downloaded to an external recipient's laptop and held offline — implementations differ most precisely there, and it is the scenario buyers picture when they sign. ### Do recipients need to install software to open protected files? It depends on the product, and it is the variable that decides whether the deployment survives. If opening a protected file requires an external party to install a viewer or create an account, people revert to unprotected email within weeks. Test this with a real outside party on a machine you do not manage during the proof of concept — a demonstration on your own network with your own software installed answers a different question. ### Isn't encryption at rest enough? For the lost-laptop and stolen-drive scenario, usually yes — and you almost certainly already have it from your storage layer, cloud provider or device management, at no additional cost. It stops none of the scenarios that bring people to this page: a legitimate user copying a file to a personal drive, a document forwarded to a competitor, an auditor keeping records after the engagement ended. Anyone with a valid session reads plaintext. ### What happens to protected files if we stop paying? Ask before signature, not at renewal. Protected documents depend on a policy server and keys that must keep answering — if they stop, the files may become unreadable to you as well. The answer you want is a documented bulk-decryption process and customer-held keys. Seclore offers self-hosted deployment with customer-held keys, which is the configuration that makes this question answerable on your terms. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/data-security-privacy/encryption-rights* --- # Data Security & Privacy — where is your sensitive data, what leaves, and what still protects it after it has gone *A TechBag category guide. Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/data-security-privacy - Routes: 3 ## The routes ### DLP & Insider Risk Every DLP deployment starts by discovering that nobody agrees what “sensitive” means here. The policy work is the project; the licence is the small number. - 18 products compared - Guide: https://www.thetechbag.com/browse/data-security-privacy/dlp-insider-risk - Boundary terms resolved: DLP vs insider risk · Insider risk vs UEBA · Endpoint vs network DLP · Cloud DLP vs the rest ### DSPM & Data Discovery DSPM will find data you did not know existed, in places you did not know it was stored. The finding is fast. The remediation is not. - 16 products compared - Guide: https://www.thetechbag.com/browse/data-security-privacy/dspm - Boundary terms resolved: DSPM vs CSPM · DSPM vs DLP · Discovery vs classification · Classification vs cataloguing ### Encryption & Rights Management Every other control protects data while it is inside your boundary. This is the only one that still works after the file has left. - 18 products compared - Guide: https://www.thetechbag.com/browse/data-security-privacy/encryption-rights - Boundary terms resolved: Encryption at rest vs in transit · Encryption at rest vs in use · EDRM/IRM vs encryption · EDRM/IRM vs DLP --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/data-security-privacy* --- # The throughput number on the datasheet is measured with every inspection feature switched off. Turn them on and you are buying a different box. *Firewall & Network Security — a TechBag decision guide. Last reviewed 2026-09-07.* > A next-generation firewall inspects traffic at your edge: it identifies the application, decrypts what it is allowed to decrypt, matches it against threat signatures, logs it, and decides. Every one of those steps costs throughput, and the headline figure on the front page of the datasheet includes none of them. **The checkable fact:** Palo Alto publishes 7.5–20 Gbps threat prevention across the PA-3400 series and states exactly what was enabled — App-ID, IPS, antivirus, anti-spyware, WildFire, DNS Security, file blocking and logging. Most vendors lead with a raw firewall figure several times higher. - Canonical: https://www.thetechbag.com/browse/network-security-sase/firewall-network-security - Category: [Network Security & SASE](https://www.thetechbag.com/browse/network-security-sase) - Products compared: 13 ## What firewall & network security actually is A device — physical, virtual or cloud — that sits where your network meets everything else and decides what may pass. The “next-generation” part means it identifies the **application** rather than just the port, can decrypt and inspect TLS, matches traffic against threat intelligence, and enforces policy per user rather than per IP address. Around that core, vendors add SD-WAN for connecting sites, sandboxing, DNS security and web filtering — usually as subscriptions. Two numbers decide the purchase and only one is printed large. **Inspected throughput** — what the box does with threat prevention and logging enabled — and **TLS inspection throughput**, which is lower again and matters because most traffic is encrypted. Everything else is the commercial shape: what is in the subscription bundle, what management costs, and what happens at renewal. When enforcement should follow users off your network instead, that is the [SASE & SSE guide](https://www.thetechbag.com/browse/network-security-sase/sase-sse). **The most common mis-purchase.** Sizing on the datasheet’s headline figure and hitting a wall at a fraction of it once TLS inspection is on. **Ask for the threat-prevention-enabled number, then ask for the TLS-inspection number, then add headroom for three years of traffic growth.** ## NGFW vs UTM vs firewall · SD-WAN vs MPLS vs SASE Two pairs this buyer confuses. Neither is a maturity ladder — each term describes a different scope or a different enforcement location, with different failure modes and different cost behaviour. ### Firewall vs NGFW A classic firewall allows or blocks by port, protocol and address — it knows nothing about what the traffic is. An NGFW identifies the application regardless of port, ties policy to user identity, decrypts TLS and matches against threat intelligence. The name is a generation, not a tier: nobody sells the classic kind for a perimeter any more, but plenty of internal segmentation still runs on it. ### UTM vs NGFW Unified threat management bundles many functions — firewall, antivirus, web filtering, mail filtering, VPN — into one box for a small estate that cannot run five. NGFW is about deep application inspection at scale. The engineering overlaps almost entirely today; the difference is where the vendor points the product. A UTM box asked to do enterprise inspection is where sizing disasters happen. ### SD-WAN vs MPLS MPLS is a carrier circuit with guaranteed behaviour and a long contract. SD-WAN is software that steers traffic across whatever links you have — broadband, 4G, MPLS — choosing per application and healing around problems. SD-WAN replaces the expensive circuit, not the inspection; you still decide where inspection happens, which is the next card. ### SD-WAN vs SASE SD-WAN connects sites and steers traffic; SASE moves the security enforcement itself into a provider's cloud so it applies wherever the user is. SASE is not 'firewall, evolved' — it is a different enforcement location with different failure modes (PoP latency instead of appliance capacity), different cost behaviour (subscription instead of refresh), and a different renewal trap. Many buyers need SD-WAN and no SASE; many need SASE and no SD-WAN. **These are not a maturity ladder.** An estate with heavy site-to-site traffic and regulated inspection requirements may be correct to buy appliances for another decade; an estate whose people and applications have all left the building may be correct to buy no appliance at all. The expensive middle is owning both without reconciling what overlaps — which the [category page](https://www.thetechbag.com/browse/network-security-sase) opens with. ## The decision variables Seven variables decide this purchase. The instrument tests what documentation establishes (published inspected and TLS figures, form factor, SD-WAN, management, the vendor’s own SASE, India presence); real-world sizing, renewal behaviour and RMA turnaround are prose because the honest answers come from a proof of concept and a delivery team. **Real throughput with threat prevention, TLS inspection and logging enabled.** The single most misleading spec in enterprise networking. Use the vendor's own inspected figure, note what was enabled when it was measured, and never accept the headline number. **TLS / SSL inspection performance.** Most traffic is encrypted and decryption is the expensive part. A box sized on threat-prevention throughput can still fall over here — and the certificate rollout is a project of its own. **Form factor and HA model.** Appliance, virtual, scale-out or cloud; active-passive or active-active. Scale-out (Maestro) changes how you grow — you add members rather than replace the box. **SD-WAN integrated or separate.** In the licence (Fortinet, Versa), a separate product from the same vendor (Check Point, Cisco), or absent. It decides whether branch connectivity is one purchase or two. **Centralised management across sites.** Included (Check Point, Versa, Sophos Central) or a separate product to licence and run (Panorama, FortiManager, Firewall Management Center). At ten sites it is a convenience; at a hundred it is the product. **Subscription bundling and renewal.** Which features are in the bundle, which are add-ons, and what the same bundle costs in year four. Over five years the subscription usually exceeds the hardware. **Refresh cycle and the SASE question.** A five-year appliance bought eighteen months before a SASE decision strands most of its value. Every vendor here except Sophos NDR sells its own SASE — negotiate the migration path before you sign, not after. ## The 13 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Fortinet FortiGate (FortiOS) — Fortinet - **Who it's for:** Estates that want the best inspected throughput per rupee, SD-WAN in the same box, and a single vendor from branch to data centre to SASE. - **The honest limitation:** The value comes from buying into the Fabric — FortiManager and FortiAnalyzer are separate purchases, and the subscription bundle you need (UTP vs Enterprise) changes the five-year cost more than the appliance does. Feature depth in the console lags the marketing. - **Price:** Appliance + bundle — appliance capex plus a UTP or Enterprise subscription bundle per year; the ASIC design is why the inspected figure holds up better than software-only rivals at the same price - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortigate ### Fortinet Secure SD-WAN — Fortinet - **Who it's for:** Multi-site estates that want application-steering, link remediation and security in one box rather than an overlay bought from someone else. - **The honest limitation:** SD-WAN throughput with inspection enabled is not published as a separate figure — size from the FortiGate model's threat-protection number, not from an SD-WAN claim. Orchestration at scale needs FortiManager. - **Price:** In the FortiGate licence — no separate SD-WAN licence — it runs on the FortiGate you already bought, which is the commercial argument; FortiManager for orchestration is separate - **Details:** https://www.thetechbag.com/fortinet/fortinet-secure-sd-wan ### Palo Alto Strata NGFW (PA-Series) — Palo Alto Networks - **Who it's for:** Enterprises that want the deepest application identification and the most honest datasheet — Palo Alto states exactly which engines were enabled when the throughput was measured. - **The honest limitation:** The premium option on both licence and subscription: CDSS bundles are where the five-year cost sits, and Panorama is another line. The full value assumes you adopt the platform rather than one appliance. - **Price:** Appliance + CDSS — appliance capex plus Cloud-Delivered Security Services subscriptions per year; Panorama for central management is separate; Mumbai cloud location documented since 2021 - **Details:** https://www.thetechbag.com/palo-alto/strata-ngfw ### Check Point Quantum Force — Check Point - **Who it's for:** Security-first estates that want the strongest prevention posture and a management console included in the price rather than sold beside it. - **The honest limitation:** SD-WAN is a separate product (Quantum SD-WAN), not a mode of the firewall; the appliance range is wide and model selection is unforgiving — the 9100's inspected figure is a fraction of the 29200's at a fraction of the price. - **Price:** Appliance + subscription — appliance capex plus a threat-prevention subscription; SmartConsole management is included rather than a separate product, which changes the comparison against Palo Alto and Fortinet - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-quantum-force ### Check Point Quantum Maestro — Check Point - **Who it's for:** Data centres that would otherwise buy a chassis: scale by adding gateways instead of replacing the box, with one policy across all of them. - **The honest limitation:** No single inspected throughput figure exists for a scale-out cluster — it depends entirely on the member appliances, so size the members, not the orchestrator. It solves scaling, not the per-appliance inspection cost. - **Price:** Orchestrator + gateways — a hyperscale orchestrator that binds many gateways into one logical firewall — you buy the orchestrator plus the appliances it scales; throughput is the sum of the members, not a published single figure - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-quantum-maestro ### Check Point Quantum SD-WAN — Check Point - **Who it's for:** Check Point estates adding branch connectivity without introducing a second vendor's overlay. - **The honest limitation:** Newer than Fortinet's or Versa's SD-WAN and documented at smaller scale; no separate inspected throughput figure is published, so size from the underlying gateway. - **Price:** Subscription — a software blade on Quantum gateways rather than a separate appliance; application steering and link selection with Check Point inspection in path - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-quantum-sd-wan ### Cisco Secure Firewall (Firepower) — Cisco - **Who it's for:** Cisco-centric networks that want the firewall, the switching and the routing under one support contract and one account team. - **The honest limitation:** Model-by-model inspected throughput figures vary widely across the 1000, 3100 and 4200 series and are not summarised here — pull the figure for your exact model from the datasheet and confirm which engines were enabled. Management is a separate deployment to run. - **Price:** Appliance + subscription — appliance capex plus threat-defence subscriptions; Firewall Management Center is a separate deployment; the natural choice where Cisco already owns the network layer - **Details:** https://www.thetechbag.com/cisco/cisco-secure-firewall ### Sophos Firewall (XGS) — Sophos - **Who it's for:** Mid-market estates — especially those already running Intercept X — that want firewall and endpoint sharing telemetry from one cloud console. - **The honest limitation:** XGS models publish their inspection figures per model rather than as a headline series number; pull yours from the datasheet. Documented deployments are mid-market rather than large-enterprise, and the security heartbeat's value depends on running Sophos endpoints too. - **Price:** Appliance + protection bundle — appliance capex plus a Standard or Xstream Protection bundle; Sophos Central management is cloud-hosted and included, and the firewall shares signal with the Sophos endpoint agent - **Details:** https://www.thetechbag.com/sophos/sophos-firewall ### Sophos NDR — Sophos - **Who it's for:** Estates that need to see lateral movement inside the network, where a perimeter firewall has no visibility at all. - **The honest limitation:** Detection only: no inspection throughput figure applies because it blocks nothing. It is an addition to a firewall, never a replacement, and its value is realised through Sophos XDR or MDR. - **Price:** Per sensor — per deployed sensor, on quote; watches east-west traffic for anomalies and feeds Sophos XDR — it detects, it does not enforce - **Details:** https://www.thetechbag.com/sophos/sophos-ndr ### LinkShadow Intelligent NDR — LinkShadow - **Who it's for:** Estates that need to see lateral movement and anomalous behaviour INSIDE the network, where a perimeter firewall has no visibility — and that want the option of keeping the whole deployment on-premises rather than shipping traffic metadata to a vendor cloud. - **The honest limitation:** Detection only — no inspected-throughput figure applies because it blocks nothing, and it is an addition to a firewall, never a replacement. Gartner placed LinkShadow in VISIONARIES on the 2026 Magic Quadrant for NDR, NOT as a Leader: Vectra AI, Darktrace and ExtraHop sit above it on Ability to Execute, and a buyer who needs the most-proven NDR should shortlist those first. It also needs SPAN or traffic mirroring plus a Master appliance — real network engineering, not an agent rollout. The vendor names no customers publicly and publishes no price. - **Price:** Quote — quoted per sensor and Master appliance; the Master may run on-premises or in the cloud, which is the point for estates that need traffic and metadata to stay in country. Deep packet inspection plus behavioural analytics on mirrored traffic — it detects, it does not enforce - **Details:** https://www.thetechbag.com/linkshadow/linkshadow-ndr ### Barracuda Network Protection (SecureEdge) — Barracuda - **Who it's for:** Distributed mid-market estates — retail, manufacturing, many small sites — that want one platform for branch firewalls and remote access without an enterprise project. - **The honest limitation:** Inspected throughput figures are published per appliance model rather than as a series headline; documented deployments are mid-market. The per-site plus per-user split makes quotes hard to compare against per-appliance rivals. - **Price:** Per site / per user — SecureEdge is licensed per site for the firewall and per user for the access side, with bundled bandwidth; the same platform spans appliance, virtual and cloud-delivered enforcement - **Details:** https://www.thetechbag.com/barracuda/barracuda-network-protection ### Versa NGFW — Versa Networks - **Who it's for:** Estates that want one software stack for SD-WAN, firewall and SASE rather than an appliance vendor's cloud service bolted on later. - **The honest limitation:** Software-defined throughput depends on the hardware you run it on, so no single inspected figure applies — benchmark on your own platform. Smaller channel and support footprint in India than Fortinet or Palo Alto. - **Price:** Subscription — software-first, licensed by subscription on your hardware or Versa's; the same code runs the branch, the data centre and the SASE PoP, which is the architectural argument - **Details:** https://www.thetechbag.com/versa/versa-ngfw ### Versa Secure SD-WAN — Versa Networks - **Who it's for:** Multi-site networks replacing MPLS that want routing, steering and inspection converged in software they can also run in the cloud later. - **The honest limitation:** Often reached through a carrier's managed service rather than bought directly, which changes who holds the support relationship. No standalone inspected throughput figure — it is a function of your platform. - **Price:** Per site subscription — per branch site per year, with security services layered on the same instance; frequently sold through carriers as a managed service in India - **Details:** https://www.thetechbag.com/versa/versa-sd-wan ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **A published inspected figure.** Rules nothing out on published terms. It flags Fortinet Secure SD-WAN — No headline inspected figure published for this product, Check Point Quantum Maestro — No headline inspected figure published for this product, Check Point Quantum SD-WAN — No headline inspected figure published for this product, Cisco Secure Firewall (Firepower) — No headline inspected figure published for this product, Sophos Firewall (XGS) — No headline inspected figure published for this product, Sophos NDR — No headline inspected figure published for this product, LinkShadow Intelligent NDR — No headline inspected figure published for this product, Barracuda Network Protection (SecureEdge) — No headline inspected figure published for this product, Versa NGFW — No headline inspected figure published for this product and Versa Secure SD-WAN — No headline inspected figure published for this product — marked, not removed. **A published TLS figure.** Rules out Fortinet Secure SD-WAN, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos NDR, LinkShadow Intelligent NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN — no TLS inspection throughput figure published; encrypted traffic performance is unproven on paper. That leaves Fortinet FortiGate (FortiOS), Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force and Sophos Firewall (XGS). **Physical appliance.** Rules out Check Point Quantum Maestro — software or scale-out only, no physical appliance form. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, LinkShadow Intelligent NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN. **Virtual form.** Rules out Check Point Quantum Maestro — no virtual form documented. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, LinkShadow Intelligent NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN. **Scale-out capacity.** Rules out Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, LinkShadow Intelligent NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN — capacity is bounded by the appliance model; growing means a bigger box. That leaves Check Point Quantum Maestro. **SD-WAN integrated.** Rules out Check Point Quantum Force and Cisco Secure Firewall (Firepower) — SD-WAN is a separate product from the same vendor; Check Point Quantum Maestro, Sophos NDR and LinkShadow Intelligent NDR — no SD-WAN capability. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum SD-WAN, Sophos Firewall (XGS), Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN. **Management included.** Rules out Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series) and Cisco Secure Firewall (Firepower) — central management is a separate product to licence and deploy. That leaves Check Point Quantum Force, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Sophos Firewall (XGS), Sophos NDR, LinkShadow Intelligent NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN. **The vendor's own SASE.** Rules out Sophos NDR and LinkShadow Intelligent NDR — no SASE platform from this vendor; a move means a second vendor and a parallel estate. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN. **India support presence.** Rules nothing out on published terms. It flags Fortinet FortiGate (FortiOS) — India support reaches you through the channel rather than a documented in-country vendor operation, Fortinet Secure SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum Force — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum Maestro — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation, Sophos Firewall (XGS) — India support reaches you through the channel rather than a documented in-country vendor operation, Sophos NDR — India support reaches you through the channel rather than a documented in-country vendor operation, LinkShadow Intelligent NDR — India support reaches you through the channel rather than a documented in-country vendor operation, Barracuda Network Protection (SecureEdge) — India support reaches you through the channel rather than a documented in-country vendor operation, Versa NGFW — India support reaches you through the channel rather than a documented in-country vendor operation and Versa Secure SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation — marked, not removed. **Data-centre scale.** Rules nothing out on published terms. It flags Check Point Quantum SD-WAN — Unverified at data-centre scale, Sophos Firewall (XGS) — Unverified at data-centre scale, Sophos NDR — Unverified at data-centre scale, LinkShadow Intelligent NDR — Unverified at data-centre scale and Barracuda Network Protection (SecureEdge) — Unverified at data-centre scale — marked, not removed. **The only throughput number worth reading.** Every firewall datasheet leads with a raw firewall figure measured with inspection switched off. It tells you nothing about the box you will actually run. The figures on this page are the vendors' own threat-prevention-enabled numbers, and where a vendor publishes one it is stated with what was enabled: Palo Alto's PA-3400 series at 7.5–20 Gbps is measured with App-ID, IPS, antivirus, anti-spyware, WildFire, DNS Security, file blocking and logging on; Fortinet's 100F at 1.6 Gbps threat protection; Check Point's Force 9100 at 6.5 Gbps rising to 75 Gbps on the 29200. Where no headline inspected figure is published — Cisco, Sophos and Barracuda publish per model, Versa is software, Maestro is scale-out, Sophos NDR blocks nothing — it is marked and not derived. Never size from a raw figure, and never let a reseller do it either. **TLS inspection is where appliances actually fall over.** Most traffic is encrypted, and decryption is far more expensive than inspection. A box sized on threat-prevention throughput can still collapse when TLS inspection is switched on for real traffic. Palo Alto, Fortinet, Check Point and Sophos publish TLS or SSL inspection figures; the rest on this page do not — flagged, not ruled out. Ask for the figure with your own cipher mix, and plan the certificate deployment before the purchase order. **The subscription is the bigger number.** Over five years the security subscription usually exceeds the appliance it runs on, and the renewal is where the surprise lives. Read which features are in the bundle you are quoted (Fortinet UTP vs Enterprise, Palo Alto's CDSS set, Check Point's threat-prevention package, Sophos Standard vs Xstream) and what the same bundle costs in year four. Central management — Panorama, FortiManager, Firewall Management Center — is a separate line at three of these vendors and included at two. **Refresh cycles and the SASE decision.** An appliance bought today is a five-year commitment; a SASE decision taken eighteen months from now strands most of it. Every vendor here except Sophos NDR sells its own SASE, which makes a phased move commercially easier — but it does not make the appliance's remaining book value disappear. If a SASE evaluation is plausible within the refresh window, size shorter or negotiate a migration path into the contract now. **India support and RMA.** Palo Alto and Cisco document in-country operations; the rest reach you through the channel, which is not worse but is different — the RMA clock, the spares depot and the escalation path belong to your partner, not the vendor. Real RMA turnaround by vendor and city is delivery-team knowledge: [TechBag to confirm]. ## Eight situations, eight shortlists — with the sizing named Each shortlist states how you would size it and what the subscription does to the five-year number. If a SASE decision is plausible in your refresh window, start from the fourth row. ### Branch and mid-size sites, best inspected throughput per rupee **Shortlist:** Fortinet FortiGate (FortiOS), Sophos Firewall (XGS), Barracuda Network Protection (SecureEdge) **Why:** FortiGate's ASIC design keeps the threat-protection figure high relative to price and includes SD-WAN; Sophos and Barracuda target the same band with cloud management included. **Trade-off:** Fortinet's value assumes buying into the Fabric (FortiManager, FortiAnalyzer); Sophos and Barracuda are documented at mid-market rather than data-centre scale. ### Data centre, above 10 Gbps with inspection on **Shortlist:** Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum Maestro **Why:** Palo Alto's PA-3400 series publishes 7.5–20 Gbps threat prevention with every engine named; Check Point's Force line reaches 35–75 Gbps inspected on the 19100 and 29200; Maestro scales by adding gateways instead of replacing the chassis. **Trade-off:** Maestro has no single inspected figure — it is the sum of its members, so the sizing work moves to the member appliances rather than disappearing. ### Replacing MPLS across many sites **Shortlist:** Versa Secure SD-WAN, Fortinet Secure SD-WAN, Check Point Quantum SD-WAN **Why:** Versa is software-first and often delivered as a carrier-managed service in India; Fortinet includes SD-WAN in the FortiGate licence with no separate SKU; Check Point runs it as a blade on Quantum gateways. **Trade-off:** None of the three publishes a separate inspected SD-WAN throughput figure — size from the underlying platform. Carrier-managed delivery changes who owns your support relationship. ### A SASE decision is likely within the refresh window **Shortlist:** Fortinet FortiGate (FortiOS), Palo Alto Strata NGFW (PA-Series), Versa NGFW **Why:** All three vendors sell their own SASE, so the appliance and the future cloud enforcement come from one contract and one policy model — Versa most literally, since the same software runs both. **Trade-off:** Same-vendor continuity does not recover the appliance's book value. Negotiate the migration terms into the appliance contract now, while you still have leverage. ### Cisco already owns the network layer **Shortlist:** Cisco Secure Firewall (Firepower), Palo Alto Strata NGFW (PA-Series), Fortinet FortiGate (FortiOS) **Why:** One support contract and one account team across switching, routing and firewall is a real operational argument; the alternatives win on published inspection transparency. **Trade-off:** Cisco's inspected figures must be pulled per model rather than read off a series headline, and Firewall Management Center is a separate deployment to run. ### The firewall should share signal with the endpoint **Shortlist:** Sophos Firewall (XGS), Fortinet FortiGate (FortiOS), Sophos NDR **Why:** Sophos Firewall and Intercept X exchange a security heartbeat from one cloud console; Fortinet does the equivalent through the Fabric; Sophos NDR adds east-west visibility a perimeter firewall cannot have. **Trade-off:** The heartbeat's value depends on running that vendor's endpoint too — a second lock-in. NDR detects and enforces nothing. ### Management console included, not another product to buy and run **Shortlist:** Check Point Quantum Force, Versa NGFW, Sophos Firewall (XGS) **Why:** Check Point includes SmartConsole management, Versa includes its director, and Sophos Central is cloud-hosted and included — against Panorama, FortiManager and Firewall Management Center as separate lines. **Trade-off:** Included management is not always equivalent management: compare multi-site policy, role separation and reporting depth, not just the licence line. ### Many small sites, one platform, no enterprise project **Shortlist:** Barracuda Network Protection (SecureEdge), Sophos Firewall (XGS), Fortinet FortiGate (FortiOS) **Why:** Barracuda SecureEdge licenses per site for the firewall and per user for access on one platform; Sophos and Fortinet cover the same estate from cloud consoles. **Trade-off:** Barracuda's split meter is hard to compare against per-appliance quotes — normalise to a per-site annual cost including the subscription before choosing. ## At scale Firewalls scale by inspected throughput and by site count, and the two need different answers. The bill follows the appliance tier; the operational load follows the number of policies and consoles. ### 1 Gbps inspected throughput — Sizing honesty is the constraint - A single branch or a small office: FortiGate, Sophos XGS and Barracuda all cover it, and the temptation is to size on the headline figure and buy one model too small. - TLS inspection may be the deciding factor even here — a 1.6 Gbps threat-protection box does not do 1.6 Gbps of decrypted traffic. - Cloud-managed consoles (Sophos Central, Barracuda) save an appliance's worth of operational effort. **The test:** Run the proof of concept with TLS inspection on and your own traffic. If the vendor resists, that is the finding. ### 10 Gbps inspected throughput — TLS and management are the constraint - Now the inspected figure is the whole conversation: Palo Alto's PA-3400 series and Check Point's Force line publish theirs; pull the exact model's number and add three years of growth. - Central management stops being optional — Panorama, FortiManager or Firewall Management Center is a separate product to licence, deploy and staff at three of these vendors. - The subscription bundle now dominates the five-year cost, and renewal terms deserve as much attention as the discount. **The test:** Ask three vendors for their inspected and TLS figures on the exact models quoted, in writing, with the datasheet date. The spread will decide the shortlist. ### Above 10 Gbps inspected throughput — Architecture and the refresh horizon are the constraint - Scale-out (Check Point Maestro) versus a bigger chassis becomes a real architectural choice — Maestro has no single inspected figure because it is the sum of its members. - At this size a SASE evaluation is almost certainly already running somewhere in the organisation; buying a five-year appliance without reconciling the two is how the double-spend starts. - Sophos, Barracuda, Check Point SD-WAN and Versa's smaller deployments are flagged unverified at data-centre scale — not ruled out; ask for the reference. **The test:** Model the five-year cost of appliances plus subscriptions against the same estate on SASE. If nobody has done that comparison, the refresh decision is being made blind. Fortinet, Palo Alto, Check Point, Cisco and Versa document data-centre-scale deployments; Sophos Firewall, Sophos NDR, Barracuda Network Protection and Check Point Quantum SD-WAN are flagged unverified above 10 Gbps inspected. Where a specific product strains for your traffic profile: [TechBag to confirm]. ## Leaving a firewall estate is a policy migration, not a swap The appliance is the easy part. The rule base — grown over years, full of exceptions nobody remembers — is what actually moves, and it rarely moves cleanly. **The rule base** — Thousands of rules, many redundant, some load-bearing for an application nobody can name. Automated converters get most of the way; the last 10% is manual and is where outages come from. *(Convert, then audit)* **Certificates and TLS** — The decryption trust chain is per platform: new certificates deployed to every endpoint before the cut-over, or inspection silently stops working for someone. *(Re-deploy before cut-over)* **The parallel run** — Both estates live while sites cut over one at a time, which means two support contracts and two subscription bills for a quarter or more. *(Overlap, site by site)* **The remaining book value** — The appliance you are leaving is on a depreciation schedule that does not care about your architecture decision. Finance will ask; have the number before they do. *(Write-down or run-out)* **Rule-base conversion effort, certificate rollout and parallel-run cost for your estate:** [TechBag to confirm] — TechBag scopes it from your rule count, site count and refresh dates. ## Three lines, and the subscription is usually the largest What you may already hold, the appliance and subscription shape at three estate sizes, and what the licence line leaves out — which, for firewalls, starts with the box you are still paying for. ### Do you already own one? Four things that may already inspect part of this. Two of them genuinely do. - **Your existing NGFW subscription — Often.** Web filtering, DNS security, application control and sometimes SD-WAN are frequently already in the bundle you renew each year — unused because nobody switched them on. Audit the bundle before buying the same capability again. - **Your ISP or carrier's managed service — Partly.** Many Indian carriers deliver SD-WAN and basic security as a managed service, often on Versa or Fortinet. Real capability; ask who holds the policy and how fast a change request moves. - **Cloud-native firewalls — Partly.** AWS Network Firewall, Azure Firewall and their equivalents protect traffic inside that cloud, on consumption. They do not reach your data centre or your branches. - **Your endpoint vendor's network module — No.** Host firewalls and endpoint web filtering protect the device, not the segment. Useful, and not a substitute for inspection between networks. If the capability you need is already inside a subscription you renew every year, we say so. It costs us a sale and saves you one. ### What the rest actually cost Firewall pricing is quoted, not listed — the honest thing to publish is the **shape** of the bill rather than invented per-unit numbers. Three lines at three estate sizes, with the vendors that publish per-user or per-site meters named explicitly, and the India-built and mid-market options covered because no global comparison does. ### What isn't in the licence price - **The appliance you are still paying for.** If SASE arrives mid-refresh, the remaining book value does not disappear — and the parallel run is a real line for a quarter or more. This is the double-spend the category opens with, and it belongs in the business case before the purchase order. - **Circuits, bandwidth and the certificate project.** The links the firewall sits on, the bandwidth upgrade the inspection makes necessary, and the TLS certificate rollout to every endpoint — none of it is in the quote, all of it is in the timeline. - **Rule-base and operational time.** Policy migration, exception review, and the people to run the console day to day. A firewall with an unaudited rule base is an expensive router. Your hours: [TechBag to confirm]. ## What goes wrong Documented behaviour and sizing outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover at the traffic peak. - **Sizing on datasheet throughput and hitting a wall with TLS on.** The headline figure was raw; the box met a fraction of it once decryption was enabled for real traffic. Size on the threat-prevention figure, then check the TLS figure. - **Subscription renewals costing more than the hardware.** The appliance was negotiated hard and the year-four renewal was not. Over five years the subscription is usually the larger number — get year four in writing at signature. - **HA pairs that fail over but drop sessions.** The cluster worked in the test and dropped long-lived sessions in production. Test failover with real application sessions, not pings. - **RMA times that don't match the SLA in India.** The contract said four hours; the spare was in another country. Confirm the depot, the city and the escalation path with your partner, in the contract. - **Buying a five-year appliance eighteen months before a SASE decision.** Two enforcement estates, overlapping capability, and a depreciation schedule that does not care. Reconcile the roadmap before the refresh, not after. - **The bundle that didn't include the feature demonstrated.** Sandboxing or DNS security was in the demo and not in the quoted tier. Compare enabled features, not model numbers. - **Certificate deployment stalling the inspection rollout.** TLS inspection was licensed, configured and never switched on because the certificates never reached the endpoints. It is a device-management project, and it belongs in the plan. - **A rule base nobody audited.** Years of accumulated exceptions, some load-bearing, most redundant. Migration exposed it, and the outage came from the 10% no converter could translate. ## Questions this guide answers ### What throughput figure should I size a firewall on? The threat-prevention-enabled figure from the vendor's own datasheet, with the enabled engines named — never the headline raw firewall number, which is measured with inspection off. Palo Alto publishes 7.5–20 Gbps across the PA-3400 series measured with App-ID, IPS, antivirus, anti-spyware, WildFire, DNS Security, file blocking and logging enabled; Fortinet publishes 1.6 Gbps threat protection for the 100F; Check Point publishes 6.5 Gbps for the Force 9100 rising to 75 Gbps on the 29200. Then ask separately for the TLS/SSL inspection figure, because most traffic is encrypted and decryption costs more than inspection. Where a vendor publishes no headline inspected figure, this guide marks it unknown rather than deriving one. ### What is the difference between SD-WAN, MPLS and SASE? MPLS is a carrier circuit with guaranteed behaviour and a long contract. SD-WAN is software that steers traffic across whatever links you have, choosing per application — it replaces the expensive circuit, not the inspection. SASE moves the security enforcement itself into a provider's cloud so it applies wherever the user is, whether or not traffic ever touches your network. They are not a maturity ladder: SASE is not 'firewall, evolved', it is a different enforcement location with different failure modes (PoP latency rather than appliance capacity) and different cost behaviour (subscription rather than refresh cycle). ### Is the firewall subscription really bigger than the appliance? Over a five-year life, usually yes. The appliance is a one-time capex negotiated hard at purchase; the security subscription — threat prevention, sandboxing, web filtering, DNS security — renews every year and reprices at renewal. Central management is a further separate line at Palo Alto (Panorama), Fortinet (FortiManager) and Cisco (Firewall Management Center), and included at Check Point, Versa and Sophos. Model five years with year four's subscription quoted in writing before signing; a one-year comparison flatters the hardware and hides the renewal. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/network-security-sase/firewall-network-security* --- # Most organisations buying SASE only need SSE — and are quoted for both. *SASE & SSE — a TechBag decision guide. Last reviewed 2026-09-07.* > SASE moves enforcement out of your rack and into a provider’s cloud, so policy applies wherever the user is. It has two halves: the security half (SSE — web gateway, CASB, ZTNA, DLP) and the network half (SD-WAN). Buying the second when your WAN is already fine is the most common overspend in this category. **The checkable fact:** Netskope documents eight data centres in India and a NewEdge management plane in Mumbai; Cloudflare’s Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur. Several major vendors publish no named Indian city list at all — and PoP distance decides user experience more than any feature. - Canonical: https://www.thetechbag.com/browse/network-security-sase/sase-sse - Category: [Network Security & SASE](https://www.thetechbag.com/browse/network-security-sase) - Products compared: 20 ## What sase & sse actually is A set of security controls delivered from a provider’s global network instead of a box in your building. The user’s device connects to the nearest point of presence, the provider inspects and enforces there — web filtering, malware inspection, data-loss rules, application access — and the traffic goes on to the internet or the private application without ever transiting your network. **SSE** is that security bundle. **SASE** is SSE plus SD-WAN, the network half that connects your sites. Three things decide the purchase and only one is a feature comparison. **Which half you need** — most estates need SSE. **PoP presence** where your people actually are, because latency is the experience. **What is genuinely bundled** versus licensed separately, which is where quotes diverge from expectations. The appliance estate this replaces — and the overlap you will pay for twice during the transition — is the [firewall guide](https://www.thetechbag.com/browse/network-security-sase/firewall-network-security). **The most common mis-purchase.** Signing for SASE and discovering that DLP, CASB or browser isolation are separate SKUs — then running the new subscription alongside an unamortised firewall estate for three years. **Ask which modules are in the base tier, and put the parallel-run cost in the business case before the purchase order.** ## SASE vs SSE · single-vendor vs dual-vendor · what SSE excludes One split that decides the price, one architectural choice, and one boundary buyers discover after signing. None of these is a maturity ladder. ### SASE vs SSE SSE is the security half: secure web gateway, CASB, ZTNA, DLP, and often firewall-as-a-service, delivered from the provider's cloud. SASE is SSE plus the network half — SD-WAN connecting your sites. If your WAN works and your problem is people and applications outside the building, SSE is the whole purchase. The quote will usually be for SASE. ### Single-vendor vs dual-vendor SASE Single-vendor means one policy model, one console, one negotiation — and one vendor's weakest module. Dual-vendor means best-of-breed SSE from one provider and SD-WAN from another, with two policy models to keep in step. Neither is more mature; the honest question is whether your team would rather run one console badly or two consoles well. ### What SSE excludes SSE inspects traffic to and from users and applications. It does not secure the workload itself — container runtime, cloud posture, identity entitlements in your cloud accounts are CNAPP and identity products, on other guides. It also does not replace east-west inspection inside a data centre. Buying SSE and assuming those cloud workloads are covered is a scope error, not a product failure — that ground is the Cloud & Workload Security guide under Security. ### SASE is not 'firewall, evolved' It is a different enforcement location with different failure modes. An appliance fails by running out of capacity; a SASE platform fails by PoP distance, an outage in someone else's cloud, or a module you did not license. Cost behaves differently too — subscription rather than refresh cycle — and the renewal trap is module creep rather than a hardware end-of-life. **These are not a maturity ladder.** An estate with heavy site-to-site traffic and on-premises applications may be right to keep appliances; an estate whose people work from anywhere may be right to buy no appliance at all. The expensive middle — owning both, reconciling neither — is what the [category page](https://www.thetechbag.com/browse/network-security-sase) opens with, because no vendor will write it down. ## The decision variables Eight variables decide this purchase. The instrument tests what documentation establishes (scope, modules, bundling, India PoPs and logs, experience monitoring, firewall lineage); real latency, contractor counting and the migration path are prose because they need measurement and a contract, not a datasheet. **SASE or SSE — do you need the network half.** SD-WAN included, or the security half alone. The single largest difference between what buyers need and what they are quoted. **PoP presence and performance in India.** The nearest point of presence decides user experience more than any feature on the datasheet. Documented by city for Netskope, Cloudflare and Palo Alto; not established for several major vendors — flagged, never assumed. **Single-vendor versus best-of-breed.** One policy model and one weakest module, or two consoles and two contracts. An operating-model question, not a maturity one. **What is genuinely included versus licensed separately.** SWG, CASB, ZTNA, DLP, browser isolation and firewall-as-a-service are bundled differently by every vendor. Zscaler's ZPA is a separate subscription from ZIA; Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base. **Digital experience monitoring.** The capability that tells you whether the platform is working, and where it is not. Documented at Zscaler (as its own subscription), Netskope, Palo Alto, Cisco and Versa; absent at the others here. **Migration path from an existing firewall estate.** Same vendor (Palo Alto, Fortinet, Check Point, Versa, Cisco, Trend) or a second vendor in parallel (Zscaler, Netskope, Cloudflare, Coro). It decides whether the transition is one policy model or two. **Data residency for inspected traffic and logs.** Where traffic is decrypted and where the logs are stored are two separate questions. Only Netskope documents the second in India here. **Bandwidth-based versus user-based pricing.** Per user is the norm and it meets contractors, seasonal staff and service accounts awkwardly; Versa's network half is per site. Ask how a user is counted and what happens when the count moves. ## The 20 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Zscaler Internet Access (ZIA) — Zscaler - **Who it's for:** Estates whose internet traffic should never touch their own network again — the reference proxy-based SSE, with the largest deployed footprint and the deepest inspection. - **The honest limitation:** The base edition is the web gateway; DLP, CASB and browser isolation arrive as higher editions or add-ons, which is where quotes diverge from expectations. Zscaler sells no firewall, so a migration from an appliance estate means two vendors in parallel. Named Indian PoP cities are not established from the vendor's own documentation here — flagged. - **Price:** ~$6–12 (≈ ₹498) — per user / month reported (roughly $72–325 per user / year by edition); the secure web gateway is the base and CASB, DLP, browser isolation and firewall-as-a-service are edition or add-on SKUs - **Details:** https://www.thetechbag.com/zscaler/zscaler-internet-access ### Zscaler Private Access (ZPA) — Zscaler - **Who it's for:** Estates replacing remote-access VPN with per-application access — the most widely deployed ZTNA, and the reason many buyers arrive at Zscaler at all. - **The honest limitation:** A separate subscription from ZIA: the combined bill is what most buyers actually pay, and it is rarely what they were first quoted. Server-initiated protocols need the Network Connector, an extra component to deploy. - **Price:** ~$6–11 (≈ ₹498) — per user / month reported (ZPA Business roughly $4–7, Transformation roughly $7–11); the private-application half, sold alongside ZIA rather than inside it - **Details:** https://www.thetechbag.com/zscaler/zscaler-private-access ### Zscaler Digital Experience (ZDX) — Zscaler - **Who it's for:** Estates that have deployed SSE and now need to answer “is it the network, the PoP, or the application?” when a user complains. - **The honest limitation:** Monitoring, not enforcement — it protects nothing. It is a third Zscaler subscription on top of ZIA and ZPA, and the case for it only becomes obvious after the first month of unexplained complaints. - **Price:** Add-on — per user / month add-on; hop-by-hop visibility from the device through the PoP to the application — the product that tells you whether the SASE is actually working - **Details:** https://www.thetechbag.com/zscaler/zscaler-digital-experience ### Zscaler Zero Trust Exchange (platform) — Zscaler - **Who it's for:** Enterprises consolidating internet access, private access and experience monitoring under one platform and one negotiation. - **The honest limitation:** Platform pricing is quoted, not listed, and the edition ladder decides what is included — the reported enterprise figures are large enough that a per-user comparison against point products is misleading. Still no firewall: the appliance estate remains someone else's. - **Price:** Bundle quote — the platform bundle that combines ZIA, ZPA, ZDX and data protection — reported around $312,000 a year for 500 users on the Transformation edition, which is the number to reason from rather than any per-module list - **Details:** https://www.thetechbag.com/zscaler/zscaler-zero-trust-exchange ### Netskope One SSE Platform — Netskope - **Who it's for:** Estates where data protection is the reason for the project — CASB and DLP are in the platform's DNA rather than bolted on — and where Indian data residency must be documented, not assumed. - **The honest limitation:** Module creep is the pattern to watch: entry bundles look competitive and the fully-loaded per-user figure converges with Zscaler's. No firewall estate of its own, so an appliance migration runs in parallel with another vendor. - **Price:** ~$15+ (≈ ₹1,245) — per user / month for a fully-bundled configuration (entry bundles list lower and rise through add-on modules); NewEdge carries eight data centres in India, and a NewEdge management plane in Mumbai supports DPDP-aligned data residency - **Details:** https://www.thetechbag.com/netskope/netskope-sse-platform ### Netskope Next Gen SWG — Netskope - **Who it's for:** Estates whose control requirement is by application instance — allow the corporate tenant, block the personal one — which domain-level filtering cannot express. - **The honest limitation:** Instance awareness is the differentiator and the reason it is priced as a platform module rather than a cheap filter. DNS-layer-only estates will find this more product than they need — the secure web guide covers that end. - **Price:** Per user — per user / month within the Netskope One platform; inline inspection of web and cloud application traffic with application-instance awareness rather than domain-level allow or block - **Details:** https://www.thetechbag.com/netskope/netskope-swg ### Palo Alto Prisma SASE — Palo Alto Networks - **Who it's for:** Palo Alto firewall estates moving enforcement to the cloud without changing vendor, policy model or account team — the cleanest migration path on this page. - **The honest limitation:** The full SASE bundle includes the network half you may not need; buying Prisma Access alone is the SSE-shaped purchase, and the quote will not default to it. Premium-priced, and the value assumes you adopt the platform. - **Price:** Per user bundle — per user / year bundles combining Prisma Access with Prisma SD-WAN; a Mumbai cloud location has been documented since 2021, and Prisma Access falls back to India West for users who cannot connect in-country - **Details:** https://www.thetechbag.com/palo-alto/prisma-sase ### Palo Alto Prisma Access — Palo Alto Networks - **Who it's for:** Estates that want the firewall's inspection model applied to users who never come back to the office, without buying the network half. - **The honest limitation:** Still enterprise-priced, and the migration only feels seamless if you already run Palo Alto policy. In-country log storage for Indian buyers is not established from documentation — confirm in writing. - **Price:** Per user — per user / year, quoted; the security half without SD-WAN — the same App-ID policy model as the firewall estate, delivered from Palo Alto's cloud - **Details:** https://www.thetechbag.com/palo-alto/prisma-access ### Fortinet FortiSASE — Fortinet - **Who it's for:** FortiGate estates extending the same policy and console to remote users at the lowest published entry price on this page. - **The honest limitation:** Digital experience monitoring is not a documented capability here, and named Indian PoP cities are not established from vendor documentation — both flagged rather than ruled out. The Fabric discount is real and it deepens the single-vendor commitment. - **Price:** $8–18 (≈ ₹664) — per user / month list depending on bundle tier (roughly $90–350 per user / year in the 50–499 band); FortiGate customers receive Security Fabric pricing that reportedly saves 20–25% - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortisase ### Check Point Harmony SASE — Check Point - **Who it's for:** Mid-market and distributed estates that want network-level access and web security quickly, with a Check Point firewall estate alongside. - **The honest limitation:** Narrower module set than the SSE leaders — CASB and DLP depth are not its ground — and no documented digital experience monitoring. Indian PoP cities are not established from this vendor's own documentation. - **Price:** From ~$10 (≈ ₹830) — per user / month from published plans (roughly $15–40 per user / year at some tiers depending on feature set and protected applications); the former Perimeter 81, now integrated with Check Point's estate - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-harmony-sase ### Cisco Secure Access — Cisco - **Who it's for:** Cisco estates consolidating Umbrella, VPN and firewall policy into one cloud service under an existing enterprise agreement. - **The honest limitation:** Newer than Zscaler's and Netskope's platforms and carrying the Umbrella lineage; module depth varies by tier. Named Indian PoP cities are not established from vendor documentation — flagged, and worth asking for in writing given the latency stakes. - **Price:** Per user — per user / year, quoted; the successor to Umbrella's SIG tiers with ZTNA, and the natural extension for estates already running Cisco networking and Duo - **Details:** https://www.thetechbag.com/cisco/cisco-secure-access ### Cloudflare One (Zero Trust) — Cloudflare - **Who it's for:** Estates that want real SSE capability at a published price they can start on today, on the largest Indian PoP footprint here. - **The honest limitation:** The $7 tier is genuinely capable and genuinely not the enterprise product: DLP depth, CASB breadth and log retention move to Enterprise, which is quoted. No firewall estate, and no documented digital experience monitoring. - **Price:** Free → $7 (≈ ₹581) — free for up to 50 users, then $7 per user / month pay-as-you-go with no user cap; Enterprise adds expanded CASB, custom DLP, browser isolation, dedicated egress IPs and longer log retention — India PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur - **Details:** https://www.thetechbag.com/cloudflare/cloudflare-one-zero-trust ### Versa SASE — Versa Networks - **Who it's for:** Estates that want one software stack from branch to cloud, and are willing to buy it through a carrier-managed service. - **The honest limitation:** Frequently reached through a carrier rather than directly, which changes who owns support and how fast policy changes move. Named Indian PoP cities are not established from Versa's own documentation. - **Price:** Per site / per user — subscription per site for the network half and per user for the security half; the same software runs the branch appliance, the data centre and the cloud PoP — often delivered in India through a carrier - **Details:** https://www.thetechbag.com/versa/versa-sase ### Versa SSE — Versa Networks - **Who it's for:** Estates that want Versa's inspection and access controls without replacing the WAN they already run. - **The honest limitation:** Smaller deployed footprint than Zscaler or Netskope in the SSE market specifically, and PoP presence in India is not documented by city. Support often sits with a partner. - **Price:** Per user — per user / year for the security half alone, without committing to Versa's SD-WAN — the honest answer for estates that keep their existing network - **Details:** https://www.thetechbag.com/versa/versa-sse ### Coro Network & SASE — Coro - **Who it's for:** SMB and mid-market estates that want network access, web security and endpoint protection on one modular per-user bill with no appliance. - **The honest limitation:** Built for the mid-market and documented there: inspection depth, module breadth and enterprise controls are well behind the SSE leaders, and it is unverified above 2,000 users. No documented India PoP presence. - **Price:** $10.50 (≈ ₹872) — per user / month published for the SASE module (Coro Essentials $10.50, Complete $15 unmanaged / $20 managed); individual modules from $4 per user / month on a modular platform built for the mid-market - **Details:** https://www.thetechbag.com/coro/coro-network-sase ### Cato SASE Platform — Cato Networks - **Who it's for:** Estates where the network is the problem as much as the security — Cato owns and operates the backbone, so latency and local breakout are testable from your own branches before you sign. - **The honest limitation:** You commit to one vendor's backbone: the traffic path becomes their architecture decision, and where their PoPs are thin no feature compensates. In-country log storage is not established — their site sits behind bot protection, so it could not be verified and should be asked for in writing. - **Price:** Quote-only — quoted by sites, bandwidth and which of the four modules you license; the whole platform runs on Cato's own private backbone of 85+ PoPs rather than public cloud, with Chennai and Mumbai among them and a stated 99.999% uptime SLA on the SD-WAN half - **Details:** https://www.thetechbag.com/cato ### Cato SSE — Cato Networks - **Who it's for:** Estates that want the security half without the network half, and value inspection happening on the path rather than beside it — particularly where TLS decryption has been quietly scoped down on branch appliances. - **The honest limitation:** The no-hairpin advantage largely disappears if your network is not also on Cato, at which point you are comparing it to the SSE specialists on features alone. Private application access overlaps with their ZTNA module — confirm which one the quote covers. - **Price:** Quote-only — per user, quoted; the security half alone, with inspection running inside the PoP the traffic already crosses rather than as a separate cloud service you hairpin to - **Details:** https://www.thetechbag.com/cato/cato-sse ### Cato Universal ZTNA — Cato Networks - **Who it's for:** Estates that secured remote users and left the office on implicit network trust — the universal half is the seam most ZTNA projects postpone into a phase that never gets funded. - **The honest limitation:** Application-level segmentation needs an inventory of your applications and who legitimately needs each. That is the real project and no vendor supplies it. Private app access also appears in their SSE module. - **Price:** Quote-only — per user, quoted; one policy across user types and locations with continuous verification through the session and entitlement granted per application rather than admission to a network - **Details:** https://www.thetechbag.com/cato/cato-ztna ### Cato AI Security — Cato Networks - **Who it's for:** Estates that cannot list the AI services their staff actually use, and where an endpoint agent rollout is the objection blocking every other option — this rides inspection that already exists. - **The honest limitation:** The newest of the four modules, so ask what is generally available today versus roadmap, especially around AI agents. Network-based, so AI use that never crosses the network is outside its view. - **Price:** Quote-only — quoted; packaging against the other three modules is worth confirming rather than assuming, since this one was added in March 2026 and recently introduced modules tend to be repackaged - **Details:** https://www.thetechbag.com/cato/cato-ai-security ### Trend Micro Zero Trust Secure Access — Trend Micro - **Who it's for:** Trend Vision One estates that want access decisions informed by the same risk score their endpoint and email products already produce. - **The honest limitation:** Credit-based billing is opaque until you run it, and the SSE module set is narrower than the platform leaders'. Its value depends on running Trend elsewhere; India PoP presence is not documented. - **Price:** Credits / quote — consumed as Vision One credits alongside Trend's other modules rather than as a standalone per-user list; risk signals from the endpoint and email products feed the access decision - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-zero-trust-secure-access ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **The security half only.** Rules out Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE, Coro Network & SASE and Cato SASE Platform — sold as full SASE including the network half; the SSE-shaped purchase is a different SKU from this vendor. That leaves Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE, Cato SSE, Cato Universal ZTNA, Cato AI Security and Trend Micro Zero Trust Secure Access. **SD-WAN included.** Rules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE, Cato SSE, Cato Universal ZTNA, Cato AI Security and Trend Micro Zero Trust Secure Access — security-only; SD-WAN comes from another product or another vendor. That leaves Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE, Coro Network & SASE and Cato SASE Platform. **CASB.** Rules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Palo Alto Prisma Access, Check Point Harmony SASE, Coro Network & SASE and Cato Universal ZTNA — CASB is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Cato SASE Platform, Cato SSE, Cato AI Security and Trend Micro Zero Trust Secure Access. **DLP.** Rules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Check Point Harmony SASE, Coro Network & SASE, Cato Universal ZTNA and Trend Micro Zero Trust Secure Access — DLP is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Cato SASE Platform, Cato SSE and Cato AI Security. **Browser isolation.** Rules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE, Coro Network & SASE, Cato SASE Platform, Cato SSE, Cato Universal ZTNA, Cato AI Security and Trend Micro Zero Trust Secure Access — remote browser isolation is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access and Cloudflare One (Zero Trust). **Firewall-as-a-service.** Rules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust), Versa SSE, Cato SSE, Cato Universal ZTNA, Cato AI Security and Trend Micro Zero Trust Secure Access — firewall-as-a-service is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Coro Network & SASE and Cato SASE Platform. **ZTNA in the base tier.** Rules out Zscaler Internet Access (ZIA), Zscaler Digital Experience (ZDX), Netskope Next Gen SWG and Cato AI Security — no ZTNA capability in this product; Netskope One SSE Platform — ZTNA exists but is a separate subscription or higher edition. That leaves Zscaler Private Access (ZPA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Coro Network & SASE, Cato SASE Platform, Cato SSE, Cato Universal ZTNA and Trend Micro Zero Trust Secure Access. **Named India PoPs.** Rules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Private Access (ZPA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Digital Experience (ZDX) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Zero Trust Exchange (platform) — An India region is served but named PoP cities are not established from the vendor's own documentation, Fortinet FortiSASE — India PoP presence not established from vendor documentation, Check Point Harmony SASE — India PoP presence not established from vendor documentation, Cisco Secure Access — India PoP presence not established from vendor documentation, Versa SASE — India PoP presence not established from vendor documentation, Versa SSE — India PoP presence not established from vendor documentation, Coro Network & SASE — India PoP presence not established from vendor documentation and Trend Micro Zero Trust Secure Access — India PoP presence not established from vendor documentation — marked, not removed. **In-country logs.** Rules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — In-country log storage not established from documentation, Zscaler Private Access (ZPA) — In-country log storage not established from documentation, Zscaler Digital Experience (ZDX) — In-country log storage not established from documentation, Zscaler Zero Trust Exchange (platform) — In-country log storage not established from documentation, Palo Alto Prisma SASE — In-country log storage not established from documentation, Palo Alto Prisma Access — In-country log storage not established from documentation, Fortinet FortiSASE — In-country log storage not established from documentation, Check Point Harmony SASE — In-country log storage not established from documentation, Cisco Secure Access — In-country log storage not established from documentation, Cloudflare One (Zero Trust) — In-country log storage not established from documentation, Versa SASE — In-country log storage not established from documentation, Versa SSE — In-country log storage not established from documentation, Coro Network & SASE — In-country log storage not established from documentation, Cato SASE Platform — In-country log storage not established from documentation, Cato SSE — In-country log storage not established from documentation, Cato Universal ZTNA — In-country log storage not established from documentation, Cato AI Security — In-country log storage not established from documentation and Trend Micro Zero Trust Secure Access — In-country log storage not established from documentation — marked, not removed. **Experience monitoring.** Rules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cloudflare One (Zero Trust), Coro Network & SASE, Cato Universal ZTNA, Cato AI Security and Trend Micro Zero Trust Secure Access — no documented digital experience monitoring; a slow user is a support ticket without evidence. That leaves Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access, Cisco Secure Access, Versa SASE, Versa SSE, Cato SASE Platform and Cato SSE. **Same vendor as the firewall.** Rules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust), Coro Network & SASE, Cato SASE Platform, Cato SSE, Cato Universal ZTNA and Cato AI Security — this vendor sells no firewall estate, so the migration runs two vendors in parallel. That leaves Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE and Trend Micro Zero Trust Secure Access. **Above 5,000 users on the platform.** Rules nothing out on published terms. It flags Coro Network & SASE — Not documented at this platform size and Cato AI Security — Not documented at this platform size — marked, not removed. **Most buyers who say SASE mean SSE.** SASE is the security half plus the network half (SD-WAN). SSE is the security half alone. If your WAN is fine and your problem is users and applications that left the building, you need SSE — and you will be quoted for SASE, because the bundle is larger. Zscaler, Netskope, Cloudflare and Cisco are SSE-shaped; Palo Alto, Fortinet, Check Point, Versa and Coro sell the fuller SASE, and Palo Alto and Versa also sell the SSE-shaped half separately. Ask which half you are being quoted, per line. **India PoP presence decides user experience more than any feature.** The nearest PoP is the difference between a platform users forget about and one they route around. Documented here from vendor sources: Netskope carries eight data centres in India with a NewEdge management plane in Mumbai supporting DPDP-aligned residency; Cloudflare's Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur; Palo Alto has documented a Mumbai cloud location since 2021, with Prisma Access falling back to India West where in-country connection is unavailable. Zscaler serves the region but named Indian PoP cities are not established from its own documentation here; Fortinet, Check Point, Cisco, Versa, Coro and Trend Micro are not established either — all flagged, none ruled out. Ask for the city list and a latency test from your own offices before signing; real measured latency from Indian cities is delivery-team knowledge: [TechBag to confirm]. **What is bundled, and what arrives as a separate SKU.** This is where quotes diverge from expectations. Zscaler's base is the web gateway with CASB, DLP and browser isolation as editions or add-ons, and ZPA is a separate subscription from ZIA — the combined bill is what estates actually pay. Netskope bundles CASB with the gateway and adds modules upward. Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base tier. Coro is modular from $4 per user per month. Read the line items, not the platform name. **User-based pricing meets contractors and service accounts.** Per-user meters are simple until you count the people who are not employees: contractors, seasonal staff, partners, and the service accounts that also traverse the proxy. Ask how each vendor counts a user, whether inactive users are billed, and what happens when the number moves seasonally. Bandwidth-based and site-based meters (Versa's network half) behave differently again. **Under 500 users.** No published term excludes an estate this size: Cloudflare is free to 50 users and $7 per user per month beyond, Coro publishes $10.50 for its SASE module, and Fortinet's $8–18 band starts at 50 users. The platform leaders publish no floor but carry minimums through the channel — current minimums by vendor: [TechBag to confirm]. ## Eight situations, eight shortlists — with the half named Each shortlist states whether the answer is SSE or full SASE, and what the India question does to it. If your WAN is already fine, start from the first row. ### The WAN is fine — it is the users and applications that left **Shortlist:** Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Cloudflare One (Zero Trust) **Why:** All three are SSE-shaped: security enforcement in the cloud without buying SD-WAN you do not need. Cloudflare publishes a price you can start on today; Netskope and Zscaler are the depth options. **Trade-off:** You will be quoted SASE. Ask for the SSE-shaped configuration explicitly, line by line, and check whether ZTNA is inside the base tier or a second subscription. ### Migrating off a firewall estate without changing vendor **Shortlist:** Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE **Why:** Same policy model, same console, same account team — Palo Alto's App-ID policy carries across, Fortinet gives FortiGate customers Security Fabric pricing worth a reported 20–25%, and Check Point extends the Quantum estate. **Trade-off:** Single-vendor continuity makes the migration easier and the lock-in deeper. It also does not recover the appliance's book value — the parallel run is still real. ### Indian data residency has to be documented, not assumed **Shortlist:** Netskope One SSE Platform, Cloudflare One (Zero Trust), Palo Alto Prisma SASE **Why:** Netskope documents eight Indian data centres plus a Mumbai management plane for DPDP-aligned residency; Cloudflare documents six Indian PoP cities; Palo Alto documents a Mumbai cloud location. **Trade-off:** PoP presence and log residency are different questions — only Netskope documents the second here. Get both in the contract, by name. ### Data protection is the reason for the project **Shortlist:** Netskope One SSE Platform, Zscaler Internet Access (ZIA), Cloudflare One (Zero Trust) **Why:** Netskope's CASB and DLP are the platform's origin rather than an add-on; Zscaler's are higher editions; Cloudflare's arrive at Enterprise. **Trade-off:** The cheapest quote in this row is rarely the one with the DLP depth demonstrated — confirm which edition the demo was on. ### Users complain it is slow and nobody can prove where **Shortlist:** Zscaler Digital Experience (ZDX), Netskope One SSE Platform, Cisco Secure Access **Why:** Digital experience monitoring answers whether it is the device, the link, the PoP or the application. Zscaler sells ZDX as its own subscription; Netskope, Cisco, Palo Alto and Versa document it inside the platform. **Trade-off:** Zscaler's is a third subscription on top of ZIA and ZPA. Fortinet, Check Point, Cloudflare and Coro document none — a slow user stays a support ticket without evidence. ### Mid-market, no appliance, one bill **Shortlist:** Coro Network & SASE, Cloudflare One (Zero Trust), Check Point Harmony SASE **Why:** Coro publishes $10.50 per user per month for SASE on a modular platform; Cloudflare starts free to 50 users and $7 beyond; Harmony SASE deploys quickly for distributed teams. **Trade-off:** Coro is unverified above 2,000 users and its inspection depth is well behind the leaders. Cheap and adequate is a legitimate answer — cheap and assumed-equivalent is not. ### Branch connectivity and security together, one stack **Shortlist:** Versa SASE, Palo Alto Prisma SASE, Fortinet FortiSASE **Why:** Versa runs the same software in the branch, the data centre and the PoP; Palo Alto pairs Prisma Access with Prisma SD-WAN; Fortinet extends the FortiGate estate. **Trade-off:** Versa is frequently delivered through a carrier in India, which changes who owns support and how fast a policy change moves. Confirm the operating model, not just the technology. ### Already inside a Cisco or Trend platform agreement **Shortlist:** Cisco Secure Access, Trend Micro Zero Trust Secure Access, Cloudflare One (Zero Trust) **Why:** Cisco Secure Access consolidates Umbrella, VPN and firewall policy under an existing enterprise agreement; Trend feeds endpoint and email risk into the access decision through Vision One credits. **Trade-off:** Both carry narrower SSE module sets than the leaders, and neither documents Indian PoP cities. Credit-based billing at Trend is opaque until you run it. ## At scale SASE scales by users and by PoP distance, and the second is invisible until it is not. The bill follows the per-user meter; the satisfaction follows the map. ### 500 users — Published pricing is the constraint - Cloudflare ($7 per user per month beyond 50 free), Coro ($10.50 published for SASE) and Fortinet ($8–18 by tier) let you start without an enterprise negotiation. - One or two Indian offices means PoP distance is testable in an afternoon — do it before signing. - The module question is simpler here: most estates this size need the web gateway and ZTNA, not the full data-protection stack. **The test:** Run a two-week pilot from your actual offices and measure page-load times against the current path. If it is slower, no feature list fixes it. ### 5,000 users — Modules and the parallel run are the constraint - Module creep is now the pattern: entry bundles that looked competitive converge upward as CASB, DLP and browser isolation are added. - The firewall estate is still on the books — the parallel-run quarters belong in the business case, not in a surprise. - Digital experience monitoring stops being optional: at this size, unexplained slowness becomes a weekly meeting. **The test:** Price the same estate three ways — SSE only, full SASE, and staying on appliances — over five years. If nobody has, the decision is being made blind. ### 20,000 users — Residency and the operating model are the constraint - Traffic decryption location and log residency become regulator-visible; only Netskope documents in-country log storage here. - User counting matters commercially: contractors, seasonal staff and service accounts on a per-user meter add up to a negotiation of their own. - Coro is flagged unverified above 2,000 users; everything else here documents large estates. **The test:** Get the Indian PoP city list, the log-residency commitment and the user-counting definition into the contract — all three in writing, before the discount conversation. Zscaler, Netskope, Palo Alto, Fortinet, Check Point, Cisco, Cloudflare, Versa and Trend Micro document large estates; Coro Network & SASE is flagged unverified above 2,000 users. Where a specific platform strains for your user population: [TechBag to confirm]. ## Leaving a SASE platform means re-pointing every user and every application The platform sits in the traffic path for everyone. Switching means new agents on every device, new tunnels from every site, and every private application re-published — while the old platform still carries production. **The agent on every device** — A new agent pushed to every laptop and phone, with the old one removed in the right order. It is a device-management project before it is a security one. *(Re-deploy, device by device)* **The private applications** — Every published application, connector and access policy is rebuilt on the new platform and tested — including the awkward ones that needed a workaround the first time. *(Re-publish and re-test)* **Certificates and inspection** — The decryption trust chain is per platform: new certificates to every endpoint before inspection can work, or it silently stops working for someone. *(New trust chain first)* **The overlap** — Both platforms run while users and sites cut over. Two per-user bills for a quarter is the honest cost of not breaking access for everyone at once. *(Two bills, one quarter)* **Agent rollout, application re-publishing and overlap cost for your estate:** [TechBag to confirm] — TechBag scopes it from your device count, application inventory and contract dates. ## Per user per month — times the modules you actually need What you may already hold, the platforms priced per user at three estate sizes in USD and INR, and what the subscription leaves out — which, during a transition, is the estate you are still paying for. ### Do you already own one? Four subscriptions that may already carry part of this. Two of them genuinely do. - **Your existing NGFW subscription — Often.** Web filtering, DNS security and application control are frequently already in the bundle you renew — for traffic that comes back to your network. It does not follow the user, which is the whole point of SSE. - **Microsoft Entra ID P1 / P2 — Partly.** Conditional access decides whether a sign-in proceeds, based on device and risk. Real access control; no traffic inspection, no DLP on the wire, no web filtering. - **Cloudflare's free tier — Partly.** Genuinely free for up to 50 users on Zero Trust, and real DNS ground beyond that. A legitimate starting point for a small estate, not an enterprise SSE. - **Your endpoint vendor's web filtering — Partly.** Many endpoint agents filter web traffic on the device. It travels with the user, and it is thinner than a cloud gateway on inspection, CASB and DLP. If what you already renew covers the traffic you were worried about, we say so. It costs us a sale and saves you one. ### What the rest actually cost Published and reported per-user meters (INR for scale), worked at three estate sizes per year. The mid-market and published-price options are covered explicitly — they are absent from every global comparison, and at 500 users they are the honest answer more often than the leaders are. ### What isn't in the licence price - **The estate you are still paying for.** The unamortised appliances, their renewing subscriptions, and the quarters during which both bills arrive. This is the double-spend the category opens with, and it belongs in the business case as a line rather than a surprise. - **Circuits, bandwidth and the certificate rollout.** Breakout bandwidth at each site, the links themselves, and the TLS trust chain deployed to every endpoint before inspection works. None of it is in the per-user price; all of it is in the timeline. - **The users who are not employees.** Contractors, seasonal staff, partners and service accounts on a per-user meter. Ask how a user is counted and whether inactive users are billed, before the count moves. Your number: [TechBag to confirm]. ## What goes wrong Documented platform behaviour and migration outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover after the cut-over. - **PoP latency from Indian cities to the nearest node.** Users in a city with no nearby point of presence route through another country and notice every day. Test from your actual offices before signing — and get the city list in the contract. - **Discovering DLP and CASB are separate SKUs after signing.** The demo showed data protection; the quoted tier was the web gateway. Read the module line items, not the platform name. - **Running SASE and an unamortised firewall estate in parallel for three years.** Two enforcement estates, overlapping capability, two bills, and a saving that never materialised because nobody switched the duplicates off. - **User-based pricing that ignored contractors and service accounts.** The employee count was the budget; the billable count included everyone who traversed the proxy. Define a user in the contract. - **Logs stored outside India when the regulator asked otherwise.** Traffic residency and log residency are different commitments — only one vendor here documents the second. Ask for both by name. - **No way to prove where the slowness is.** Without digital experience monitoring, every complaint is an argument between the network team and the platform vendor. Four products here document none. - **Assuming SSE covers cloud workloads.** It inspects user and application traffic; container runtime and cloud posture are CNAPP, on another guide. A scope error, not a product failure. - **Buying the network half nobody needed.** SD-WAN arrived in the bundle for an estate whose WAN was fine. Ask for the SSE-shaped configuration, explicitly, and compare it against the SASE quote. ## Questions this guide answers ### What is the difference between SASE and SSE? SSE — security service edge — is the security half: secure web gateway, CASB, ZTNA, DLP and often firewall-as-a-service, delivered from a provider's cloud so policy follows the user. SASE is SSE plus the network half, SD-WAN, connecting your sites. Most organisations buying SASE only need SSE, because their WAN is already adequate and the problem is people and applications outside the building — but the quote will usually be for the fuller bundle. Ask which half each line covers. Zscaler, Netskope, Cloudflare and Cisco are SSE-shaped; Palo Alto, Fortinet, Check Point, Versa and Coro sell full SASE, and Palo Alto and Versa also sell the SSE half separately. ### Which SASE and SSE vendors have points of presence in India? From vendor documentation: Netskope operates eight data centres in India and has introduced a NewEdge management plane in Mumbai supporting DPDP-aligned data residency; Cloudflare's Indian points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur; Palo Alto Networks has documented a Mumbai cloud location since 2021, with Prisma Access falling back to India West where an in-country connection is unavailable. Zscaler serves the region but named Indian PoP cities are not established from its own documentation on this guide, and Fortinet, Check Point, Cisco, Versa, Coro and Trend Micro are not established either — all flagged rather than ruled out. Ask for the city list and a latency test from your own offices; PoP distance decides user experience more than any feature. ### Why do SASE quotes come in so much higher than the per-user list price? Three reasons, all avoidable. First, the network half: SD-WAN arrives in a SASE bundle even when the WAN is fine. Second, module separation — Zscaler's ZPA is a separate subscription from ZIA and ZDX is a third, while CASB, DLP and browser isolation move up editions at several vendors, so the demo and the quoted tier differ. Third, user counting: contractors, seasonal staff and service accounts traverse the proxy and appear on a per-user meter nobody budgeted for. Ask for the module line items, the definition of a billable user, and the SSE-shaped configuration alongside the SASE one. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/network-security-sase/sase-sse* --- # ZTNA replaces the VPN for applications. It does not replace it for everything — and the gap is where projects stall. *Zero Trust Access — a TechBag decision guide. Last reviewed 2026-09-07.* > A VPN puts a device on your network and trusts what it does there. ZTNA authenticates the user and the device, then connects them to **one application** through a broker — never to the network, so nothing else is even visible. The connector sits beside the application and dials out, which is why no inbound firewall rule is needed. **The checkable fact:** Netskope documents SSH, RDP and server-initiated traffic including VoIP and SCCM. Zscaler handles server-initiated protocols through a separate Network Connector appliance. For most products on this page it is not documented at all — and that one gap is what keeps a VPN concentrator alive for years. - Canonical: https://www.thetechbag.com/browse/network-security-sase/zero-trust-access - Category: [Network Security & SASE](https://www.thetechbag.com/browse/network-security-sase) - Products compared: 14 ## What zero trust access actually is A broker that stands between a user and a private application. The user authenticates against your identity provider, the device is checked for posture, and the broker then stitches together **one connection to one application** — not a route onto your network. A lightweight connector sits next to the application and makes an outbound connection to the broker, so there is no inbound rule, no exposed VPN concentrator, and nothing for an attacker to scan. The variable that decides everything is **reach**: what the broker can actually carry. Internal web applications are universal; SSH and RDP are common; desktop applications are harder; and server-initiated protocols — where the server opens the connection to the agent, as on-premises VoIP and SCCM do — are the ones that keep a VPN running for years. This page records reach from vendor documentation only. The wider platform this often sits inside is the [SASE & SSE guide](https://www.thetechbag.com/browse/network-security-sase/sase-sse); the identity behind it is the [IAM guide](https://www.thetechbag.com/browse/identity-access/iam-sso-mfa). **The most common mis-purchase.** Buying on the web-application demo and discovering the desktop application, the VoIP system or SCCM cannot traverse it. **The VPN stays up for one application, the project is declared complete, and the attack surface it was meant to remove is still there.** ## ZTNA vs VPN · agent-based vs agentless · ZTNA vs zero trust One replacement that is only partial, one choice that decides who is in scope, and one word used for both a product and an architecture. None of these is a maturity ladder. ### ZTNA vs VPN A VPN authenticates once and puts the device on the network — everything routable is now reachable, and lateral movement is the attacker's reward. ZTNA authenticates the user and device, then connects them to one named application through a broker, with nothing else visible. The catch: a VPN carries any protocol, and ZTNA carries what its broker supports. That difference is the whole project plan. ### Agent-based vs agentless An agent gives deep device posture — disk encryption, patch level, endpoint agent present — and can carry desktop applications and arbitrary protocols. Agentless access runs in the browser, reaches web applications (and sometimes browser-rendered SSH and RDP), cannot run desktop applications or map local drives, and can only see what a browser reports about the device. Not a cheaper agent: a different reach, for a different population. ### ZTNA vs zero trust as an architecture ZTNA is a product category — a broker for private application access. Zero trust is an architecture: verify explicitly, least privilege, assume breach, applied across identity, devices, networks, applications and data. Buying ZTNA does not make an estate zero trust, and every vendor's marketing blurs this deliberately. ZTNA is one control inside a much larger programme. ### Network-level access inside a ZTNA product Several products offer a network-level mode alongside per-application access, for the things per-application access cannot reach. It is useful and it is a VPN by another name for those applications. Treat it as a shrinking exception list with a review date — if it is still the same size in year two, the project did not happen. **These are not a maturity ladder.** ZTNA is not “VPN, evolved” — it is a narrower, safer path that covers most applications and not all of them. An estate that replaces 90% of VPN use and keeps a documented, shrinking exception list has succeeded; one that declares victory while a concentrator quietly serves the whole network has not. ## The decision variables Seven variables decide this purchase. The instrument tests what documentation establishes (protocol reach, access mode, posture, identity depth, standalone availability, India origin); latency, the exception list and the fallback trap are prose because they come from a pilot and a plan. **Agent-based versus agentless access.** Decides whether contractors, BYOD and third parties are in scope at all. Agentless reaches web applications and stops; agents reach further and require a device you manage. **What it can actually reach.** Web applications, SSH and RDP, desktop applications, legacy TCP, and server-initiated protocols like VoIP and SCCM. Documented reach only — this page marks unknown rather than assuming, because this is the variable that keeps VPNs alive. **Connector architecture and where it sits.** A lightweight connector beside each application, dialling out to the broker — which is why no inbound rule is needed. How many connectors, where they run and who patches them is real operational work. **Identity provider integration depth.** SAML federation is universal; SCIM provisioning and conditional-access signal consumption are not. ZTNA is only as good as the identity behind it, and inherits its blind spots. **Device posture checking.** What it can verify, and on whose devices. Agent-based posture reads disk encryption, patch level and endpoint agents; browser-based posture reads little more than the source address and user-agent. **India PoP presence.** Where the broker terminates decides latency, and latency decides adoption. Documented by city for Cloudflare, Netskope and Palo Alto; India-built and India-hosted for InstaSafe and Seqrite; not established for the rest. **Standalone or only inside a SASE bundle.** Zscaler, Netskope, Cloudflare, Check Point, Sophos, Versa, InstaSafe and Seqrite sell it as a product; Palo Alto, Cisco and Trend Micro sell it inside a wider platform. It changes the size of the commitment, not just the price. ## The 14 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Zscaler Private Access (ZPA) — Zscaler - **Who it's for:** Large estates replacing remote-access VPN outright — the most widely deployed ZTNA, with the protocol reach to actually retire the concentrator. - **The honest limitation:** Server-initiated traffic requires the Network Connector rather than working natively, which is an extra component and an extra design conversation. Named Indian PoP cities are not established from vendor documentation, and the standalone purchase still sits inside Zscaler's commercial model. - **Price:** ~$6–11 (≈ ₹498) — per user / month reported (ZPA Business roughly $4–7, Transformation roughly $7–11); server-initiated protocols such as VoIP and active FTP need the Zscaler Network Connector, a separate virtual appliance to deploy - **Details:** https://www.thetechbag.com/zscaler/zscaler-private-access ### Netskope One Private Access — Netskope - **Who it's for:** Estates whose application list includes the awkward protocols — VoIP, SCCM, desktop applications — and that need Indian data-centre presence documented rather than assumed. - **The honest limitation:** Priced and sold as part of the Netskope One platform, so the standalone comparison against a point ZTNA product is not like-for-like. Module creep applies here as elsewhere in the platform. - **Price:** Per user — per user / month inside Netskope One; documented support for SSH and RDP alongside server-initiated traffic including VoIP and SCCM — the broadest documented protocol reach here; eight Indian data centres on NewEdge - **Details:** https://www.thetechbag.com/netskope/netskope-private-access ### Palo Alto Prisma Access (ZTNA) — Palo Alto Networks - **Who it's for:** Palo Alto estates that want private-application access under the policy model their firewalls already enforce, with in-country cloud presence documented. - **The honest limitation:** Not sold as a standalone ZTNA — it arrives inside Prisma Access, which is a larger commitment than a point product. Server-initiated protocol support is not established from documentation here; confirm against your VoIP and management traffic. - **Price:** Per user — per user / year within Prisma Access rather than as a standalone ZTNA licence; the same App-ID policy model as the firewall estate, with a documented Mumbai cloud location since 2021 - **Details:** https://www.thetechbag.com/palo-alto/prisma-access ### Palo Alto Prisma Access Browser — Palo Alto Networks - **Who it's for:** Contractor, BYOD and third-party access to web applications where installing an agent is impossible and a browser is the only control point you have. - **The honest limitation:** Web applications only: desktop applications, SSH, RDP and server-initiated protocols are outside a browser's reach entirely. Device posture is limited to what a browser can observe, and it does not replace agent-based access for employees. - **Price:** Per user — per user / year; a managed enterprise browser that enforces policy inside the browsing session itself — the emerging fifth enforcement model, for unmanaged devices and contractors - **Details:** https://www.thetechbag.com/palo-alto/prisma-access-browser ### Cloudflare Access (Cloudflare One) — Cloudflare - **Who it's for:** Estates that want per-application access on the largest documented Indian PoP footprint here, at a price they can start on without a negotiation. - **The honest limitation:** Documented reach covers web applications plus SSH and RDP; desktop applications and server-initiated protocols are not established from documentation — confirm before assuming the VPN can be retired. Enterprise features move to the quoted tier. - **Price:** Free → $7 (≈ ₹581) — free for up to 50 users, then $7 per user / month with no user cap; Indian points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur - **Details:** https://www.thetechbag.com/cloudflare/cloudflare-one-zero-trust ### Cisco Secure Access (ZTNA) — Cisco - **Who it's for:** Cisco estates already running Duo that want ZTNA decisions informed by the device-trust signals Duo already collects. - **The honest limitation:** Bought as part of Secure Access, not as a point product, and the Umbrella lineage means module depth varies by tier. Named Indian PoP cities are not documented by this vendor. - **Price:** Per user — per user / year inside Cisco Secure Access rather than standalone; integrates with Duo for device trust and posture, which is the deepest identity pairing here for a Cisco estate - **Details:** https://www.thetechbag.com/cisco/cisco-secure-access ### Check Point Harmony SASE (ZTNA) — Check Point - **Who it's for:** Mid-market and distributed estates that need working private access in days rather than a quarter, with a Check Point estate alongside. - **The honest limitation:** Network-level access is available as well as per-application, which is convenient and quietly reintroduces the thing ZTNA exists to remove. Desktop-application and server-initiated reach are not established from documentation. - **Price:** From ~$10 (≈ ₹830) — per user / month from published plans; the former Perimeter 81, which is why it deploys faster than most enterprise ZTNA and reaches network-level access as well as per-application - **Details:** https://www.thetechbag.com/checkpoint/checkpoint-harmony-sase ### Sophos ZTNA — Sophos - **Who it's for:** Sophos estates — firewall and endpoint — that want private access with device health from the agent already deployed, on one console. - **The honest limitation:** Posture depends on the Sophos agent, so unmanaged and contractor devices are outside the model; desktop-application and server-initiated reach are not established from documentation. Sophos has been transitioning this into its Workspace Protection packaging — confirm the current SKU when quoting. - **Price:** Per user — per user / year on annual subscription through the channel, with user-band pricing; shares device health signal with Intercept X, so posture comes from the endpoint agent you already run - **Details:** https://www.thetechbag.com/sophos/sophos-ztna ### Sophos Network Access — Sophos - **Who it's for:** Sophos estates that need a network-level path for the legacy systems ZTNA will not cover, managed from the same console rather than a separate VPN. - **The honest limitation:** Network-level access is a VPN by another name for those applications — it is the honest fallback, not zero trust. It exists precisely because per-application access has gaps, and it should shrink over time rather than become permanent. - **Price:** Per user — per user / year; the network-level remote access companion to ZTNA for the applications and protocols per-application access cannot reach - **Details:** https://www.thetechbag.com/sophos/sophos-network-access ### Versa SSE (ZTNA) — Versa Networks - **Who it's for:** Estates that want one vendor's software from branch to cloud, including the private-access half, without replacing the WAN. - **The honest limitation:** Smaller deployed SSE footprint than Zscaler or Netskope, often reached through a carrier-managed service in India which changes who owns support. Indian PoP cities are not documented by this vendor. - **Price:** Per user — per user / year within Versa SSE, buyable without committing to Versa's SD-WAN; the same software stack that runs the branch appliance also enforces the access policy - **Details:** https://www.thetechbag.com/versa/versa-sse ### InstaSafe ZTNA — InstaSafe - **Who it's for:** Indian estates — including government buyers who need GeM availability — that want zero-trust access with local data handling, local support and INR contracting. - **The honest limitation:** Documented deployments are smaller than the global platforms' and the ecosystem is narrower: identity integration covers SAML and OIDC rather than the deeper conditional-access pairings, and there is no SSE platform around it. Flagged unverified above 5,000 users. - **Price:** ~$8 (≈ ₹664) — per user / month published for the secure access solution with managed service; India-built and India-hosted, available on GeM for government procurement - **Details:** https://www.thetechbag.com/instasafe/instasafe-ztna ### InstaSafe Zero Trust Application Access — InstaSafe - **Who it's for:** Indian estates giving third parties access to internal web applications without shipping them an agent or a laptop. - **The honest limitation:** Web applications only — desktop applications, SSH, RDP and server-initiated protocols are outside its reach. Posture is limited to what the browser reports. Smaller documented scale. - **Price:** Quote (INR) — per user, quoted in INR; browser-delivered access to internal web applications for contractors and unmanaged devices, from an India-hosted platform - **Details:** https://www.thetechbag.com/instasafe/instasafe-ztaa ### Seqrite ZTNA — Seqrite - **Who it's for:** Indian mid-market estates — often already running Seqrite endpoints — that want private access with data handled in country and support in the same time zone. - **The honest limitation:** Identity integration is documented for SAML rather than the deeper conditional-access pairings; desktop-application and server-initiated reach are not established from documentation; documented scale is mid-market. It is thinner than Zscaler or Palo Alto and priced accordingly. - **Price:** Quote (INR) — per user, quoted in INR through the channel; India-built by Quick Heal with local data handling, and commonly bought alongside Seqrite endpoint protection - **Details:** https://www.thetechbag.com/seqrite/seqrite-ztna ### Trend Micro Zero Trust Secure Access (Private Access) — Trend Micro - **Who it's for:** Trend Vision One estates that want continuous risk — not just identity and posture at connection time — feeding the access decision. - **The honest limitation:** Not standalone: it arrives inside Vision One and is billed in credits, which is opaque until you run it. Desktop-application and server-initiated reach are not established from documentation, and Indian PoP presence is not documented. - **Price:** Credits / quote — consumed as Vision One credits rather than a standalone per-user list; the access decision is informed by the same risk score Trend's endpoint and email products produce - **Details:** https://www.thetechbag.com/trendmicro/trendmicro-zero-trust-secure-access ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **Web apps with no agent.** Rules out Sophos Network Access — internal web applications need the agent installed; there is no browser-only path. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access). **SSH and RDP.** Rules out Palo Alto Prisma Access Browser and InstaSafe Zero Trust Application Access — SSH and RDP access not documented. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access). **Desktop applications.** Rules nothing out on published terms. It flags Palo Alto Prisma Access Browser — Desktop-application support not established from vendor documentation, Cloudflare Access (Cloudflare One) — Desktop-application support not established from vendor documentation, Check Point Harmony SASE (ZTNA) — Desktop-application support not established from vendor documentation, Sophos ZTNA — Desktop-application support not established from vendor documentation, InstaSafe Zero Trust Application Access — Desktop-application support not established from vendor documentation, Seqrite ZTNA — Desktop-application support not established from vendor documentation and Trend Micro Zero Trust Secure Access (Private Access) — Desktop-application support not established from vendor documentation — marked, not removed. **Server-initiated protocols.** Rules nothing out on published terms. It flags Palo Alto Prisma Access (ZTNA) — Server-initiated traffic not documented, Palo Alto Prisma Access Browser — Server-initiated traffic not documented, Cloudflare Access (Cloudflare One) — Server-initiated traffic not documented, Cisco Secure Access (ZTNA) — Server-initiated traffic not documented, Check Point Harmony SASE (ZTNA) — Server-initiated traffic not documented, Sophos ZTNA — Server-initiated traffic not documented, Sophos Network Access — Server-initiated traffic not documented, Versa SSE (ZTNA) — Server-initiated traffic not documented, InstaSafe ZTNA — Server-initiated traffic not documented, InstaSafe Zero Trust Application Access — Server-initiated traffic not documented, Seqrite ZTNA — Server-initiated traffic not documented and Trend Micro Zero Trust Secure Access (Private Access) — Server-initiated traffic not documented — marked, not removed. **Agentless access.** Rules out Sophos Network Access — requires an agent on the device, so unmanaged and contractor devices are outside the model. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access). **Agent-based access.** Rules out Palo Alto Prisma Access Browser — browser-delivered only; no agent, and therefore no deep device posture. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access). **Deep device posture.** Rules out Palo Alto Prisma Access Browser and InstaSafe Zero Trust Application Access — posture limited to what a browser reports (source address and user-agent), not device health. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access). **SCIM provisioning.** Rules out Palo Alto Prisma Access Browser, Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access) — SCIM provisioning not documented; group membership is synchronised by other means or by hand. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA) and Versa SSE (ZTNA). **Conditional-access signals.** Rules out Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access) — SAML or OIDC federation without documented conditional-access signal integration. That leaves Palo Alto Prisma Access (ZTNA) and Cisco Secure Access (ZTNA). **Buyable standalone.** Rules out Palo Alto Prisma Access (ZTNA), Cisco Secure Access (ZTNA) and Trend Micro Zero Trust Secure Access (Private Access) — sold inside the vendor's wider platform rather than as a point ZTNA product. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access and Seqrite ZTNA. **India-built and hosted.** Rules out Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA) and Trend Micro Zero Trust Secure Access (Private Access) — a global platform; India presence is a PoP question rather than local hosting and contracting. That leaves InstaSafe ZTNA, InstaSafe Zero Trust Application Access and Seqrite ZTNA. **Above 5,000 brokered users.** Rules nothing out on published terms. It flags Sophos ZTNA — No documented deployment at this user count, Sophos Network Access — No documented deployment at this user count, InstaSafe ZTNA — No documented deployment at this user count, InstaSafe Zero Trust Application Access — No documented deployment at this user count and Seqrite ZTNA — No documented deployment at this user count — marked, not removed. **The application that keeps the VPN alive.** Almost every stalled ZTNA project has the same shape: 90% of applications moved, and one did not. The usual culprits are server-initiated protocols — on-premises VoIP, SCCM, active FTP — where the server opens the connection to the agent, which most cloud ZTNA cannot express. Netskope documents SSH, RDP and server-initiated traffic including VoIP and SCCM; Zscaler handles it through the Network Connector, a separate virtual appliance. For everyone else on this page it is not established from documentation — flagged, never ruled out, and the first thing to test. Write your awkward application list before the demo, not after the pilot. **Agentless is not a cheaper agent — it is a different reach.** Browser-delivered access works for web applications and, in some products, browser-rendered SSH and RDP. It cannot run desktop applications, cannot map local drives, usually cannot drive multiple monitors, and can only see what a browser reports about the device — effectively the source address and the user-agent string. That makes it right for contractors and unmanaged devices and wrong as the only model for employees. Palo Alto's Prisma Access Browser and InstaSafe ZTAA are the browser-first products here; most others document both modes. **ZTNA is only as good as the identity behind it.** Every product here federates with SAML, and most with OIDC. Fewer document SCIM provisioning, which is how group membership stays correct without a human, and fewer still document consuming conditional-access signals from the identity provider — Palo Alto and Cisco do. If your access policy depends on conditional access you already run, confirm the integration depth rather than assuming SAML covers it. The identity side is the IAM guide. **Network-level access is the honest fallback, and it should shrink.** Two products here document network-level access alongside per-application access: Check Point Harmony SASE and Sophos Network Access. It is genuinely useful for the applications ZTNA cannot reach — and it is a VPN by another name for those applications. Treat it as a shrinking exception list with a review date, not as a feature that makes the project complete. **Under 200 users.** No vendor publishes a floor that excludes you: Cloudflare is free to 50 users and $7 per user per month beyond, InstaSafe publishes around $8 with a managed service, and Check Point Harmony SASE starts around $10. The platform-bundled options (Palo Alto, Cisco, Trend) publish no standalone floor at all. Current vendor minimums: [TechBag to confirm]. ## Eight situations, eight shortlists — with the reach named Each shortlist states what the product can carry and what would keep a VPN alive. If retiring the concentrator is the actual goal, start from the first row. ### Retire the VPN concentrator entirely **Shortlist:** Zscaler Private Access (ZPA), Netskope One Private Access, Versa SSE (ZTNA) **Why:** Only products with documented desktop-application and server-initiated reach can actually finish the job — Netskope documents SSH, RDP, VoIP and SCCM; Zscaler covers server-initiated traffic through the Network Connector. **Trade-off:** Zscaler's Network Connector is an extra component to design and deploy. Anything without documented server-initiated support will leave a VPN running for one application, indefinitely. ### Contractors and unmanaged devices need access **Shortlist:** Palo Alto Prisma Access Browser, InstaSafe Zero Trust Application Access, Cloudflare Access (Cloudflare One) **Why:** Browser-delivered access needs nothing installed on a device you do not own — Prisma Access Browser and InstaSafe ZTAA are built for exactly this, and Cloudflare documents agentless access alongside its agent. **Trade-off:** Browser access reaches web applications and stops there, and posture is limited to what a browser can observe. It complements agent-based access for employees; it does not replace it. ### India-built, India-hosted, INR contracting **Shortlist:** InstaSafe ZTNA, Seqrite ZTNA, InstaSafe Zero Trust Application Access **Why:** InstaSafe (published around $8 per user per month, available on GeM for government procurement) and Seqrite from Quick Heal are India-built with local data handling and support in the same time zone. **Trade-off:** Both are documented at mid-market scale with narrower identity integration — Seqrite at SAML level — and neither has an SSE platform around it. Thinner than Zscaler or Palo Alto, and priced accordingly. ### Already running the vendor's firewall or endpoint **Shortlist:** Palo Alto Prisma Access (ZTNA), Sophos ZTNA, Check Point Harmony SASE (ZTNA) **Why:** One policy model and one console: Palo Alto carries App-ID policy into private access, Sophos takes device health from the Intercept X agent already deployed, Check Point extends the Quantum estate. **Trade-off:** Palo Alto and Cisco do not sell ZTNA standalone — it arrives inside the wider platform. Sophos posture depends on the Sophos agent, so contractors fall outside it. ### Administrators need SSH and RDP, not just web apps **Shortlist:** Zscaler Private Access (ZPA), Netskope One Private Access, Cloudflare Access (Cloudflare One) **Why:** All three document SSH and RDP reach; Cloudflare does it at a published price with six Indian PoP cities. **Trade-off:** Administrative access to infrastructure is also a privileged-access question — the vault, the session recording and the approval workflow live on the PAM guide, and ZTNA does not replace them. ### Device trust must come from the identity system we already run **Shortlist:** Cisco Secure Access (ZTNA), Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One) **Why:** Cisco pairs with Duo for device trust; Palo Alto documents conditional-access signal integration; Cloudflare federates broadly with SCIM provisioning. **Trade-off:** Deeper identity integration means the ZTNA inherits your identity provider's blind spots too. If conditional access is central to your policy, confirm the specific signals, not just SAML federation. ### Mid-market, working access in days **Shortlist:** Check Point Harmony SASE (ZTNA), Cloudflare Access (Cloudflare One), InstaSafe ZTNA **Why:** Harmony SASE's Perimeter 81 lineage deploys fast; Cloudflare starts free to 50 users; InstaSafe ships with a managed service. **Trade-off:** Harmony's network-level access option quietly reintroduces what ZTNA exists to remove — use it as an exception, not a default. Speed and per-application discipline pull against each other here. ### Access decisions should follow continuous risk, not just connection-time posture **Shortlist:** Trend Micro Zero Trust Secure Access (Private Access), Netskope One Private Access, Cisco Secure Access (ZTNA) **Why:** Trend feeds endpoint and email risk into the access decision through Vision One; Netskope and Cisco re-evaluate context during the session rather than only at connection. **Trade-off:** Trend is not standalone and bills in credits that are opaque until you run it. Continuous risk is only as good as the telemetry feeding it — which usually means running that vendor elsewhere too. ## At scale ZTNA scales by applications published and by exceptions unresolved, not by user count alone. The bill follows the per-user meter; the completion date follows the awkward list. ### 200 users — Published pricing and speed are the constraints - Cloudflare (free to 50 users, then $7 per user per month), InstaSafe (around $8 with a managed service) and Check Point Harmony SASE (from about $10) get working access quickly without a negotiation. - The application list is short enough to enumerate in an afternoon — do it, and check rung three and four before the pilot. - One or two offices means latency is testable directly; do not accept a global map as an answer. **The test:** Publish the five applications people actually use remotely, and try to break them from a home connection. What fails is the shortlist criterion. ### 2,000 users — The exception list is the constraint - The awkward applications now have owners and objections: the VoIP system, SCCM, the ERP desktop application. Products without documented server-initiated reach will leave the VPN running. - Contractors and third parties appear as a distinct population needing agentless access — a different product mode, sometimes a different product. - Posture policy becomes real: what you require of a managed laptop cannot be required of a contractor's, and the policy must say so explicitly. **The test:** Count the applications still on the VPN after the first wave. If the number is not falling quarterly, the exception list has become permanent. ### 10,000 users — Identity depth and residency are the constraints - Conditional-access signal integration matters at this size — Palo Alto and Cisco document it; SAML-only products inherit less of your policy. - Broker location and data handling become regulator-visible; India-built options and documented Indian PoPs answer different halves of that question. - InstaSafe, Seqrite, Sophos ZTNA and Sophos Network Access are flagged unverified above 5,000 users — not ruled out; ask for the reference. **The test:** Audit what the VPN still carries and who authorised each exception. That list, with dates, is the honest project status. Zscaler, Netskope, Palo Alto, Cloudflare, Cisco, Check Point, Versa and Trend Micro document large estates; InstaSafe ZTNA, InstaSafe ZTAA, Seqrite ZTNA, Sophos ZTNA and Sophos Network Access are flagged unverified above 5,000 users. Where a specific product strains for your application mix: [TechBag to confirm]. ## Leaving a ZTNA platform means re-publishing every application The value sits in published applications, connectors, access policies and the exception list. None of it moves, and the VPN you kept for the awkward applications is the only thing that does. **Re-publishing applications** — Every application is defined, connected and tested again on the new broker — including the awkward ones that needed a workaround the first time, which will need a different workaround now. *(Application by application)* **Connectors everywhere** — New connectors deployed beside every application estate — data centre, each cloud, each site — and the old ones removed in the right order. *(Deploy, then decommission)* **The agent on every device** — A new agent on every managed laptop and phone, and new instructions for every contractor using the browser path. *(Re-deploy and re-communicate)* **The overlap** — Both brokers run while applications cut over. Two per-user bills for a quarter is the cost of not locking everyone out of something. *(Two bills, one quarter)* **Application re-publishing, connector rollout and overlap cost for your estate:** [TechBag to confirm] — TechBag scopes it from your application inventory and user population. ## Per user per month — and the VPN you did not retire What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the subscription leaves out — which, for ZTNA, is usually the concentrator still running for one application. ### Do you already own one? Four products that may already broker some of this access. Two of them genuinely do. - **Your firewall vendor's VPN — Partly.** Every NGFW on the neighbouring guide terminates remote access. It works, it puts devices on the network, and that network exposure is the reason this category exists. - **Microsoft Entra ID P1 / P2 — Partly.** Entra application proxy publishes internal web applications, and conditional access decides whether a sign-in proceeds. Real coverage for web applications; no desktop applications, no SSH or RDP, no server-initiated protocols. - **Your SASE or SSE subscription — Often.** ZTNA is bundled into the base tier at Palo Alto, Fortinet, Check Point, Cisco and Versa — and is a separate subscription at Zscaler. If you already pay for SSE, check before buying access twice. - **Cloudflare's free tier — Partly.** Free for up to 50 users on Zero Trust, with real per-application access. A legitimate starting point for a small estate rather than an enterprise deployment. If the access you need is already inside a platform you pay for, we say so. It costs us a sale and saves you one. ### What the rest actually cost Published and reported per-user meters (INR for scale), worked at 200 / 2,000 / 10,000 users per year. The India-built options are priced explicitly — they are absent from every global ZTNA comparison and are frequently a fraction of the platform leaders. ### What isn't in the licence price - **The VPN that stayed up.** One unreachable application keeps the concentrator, its licence, its exposure and a second access path to operate. This is the number the business case assumed away — put a retirement date against every exception. Your list: [TechBag to confirm]. - **Connectors and the people who run them.** A connector beside every application estate, patched and monitored, in each data centre and cloud. Small individually, real in aggregate, and in no per-user price. - **The contractor population.** Third parties on agentless access are usually still billable users, and they arrive in waves nobody forecast. Define how a user is counted before the seasonal peak, not after. ## What goes wrong Documented behaviour and project outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the pilot’s last week. - **The legacy application that doesn't work over ZTNA.** Ninety per cent of applications moved and one did not, so the VPN stayed — with all the network exposure it always had. Test the awkward list before the purchase order. - **Desktop applications and server-initiated protocols discovered late.** VoIP, SCCM and the ERP desktop application surfaced in week three of the pilot. Only Netskope documents server-initiated reach outright; Zscaler needs the Network Connector; most others do not document it. - **Posture checks that require an agent on devices you don't manage.** The policy demanded disk-encryption status from contractor laptops nobody could install software on. Browser posture sees the source address and the user-agent, and little else. - **Contractor access that needed agentless and wasn't scoped.** The project was designed for employees; third parties arrived afterwards and needed a different access mode, sometimes a different product. - **IdP integration that supports SAML but not your conditional access.** Federation worked; the conditional-access policy that actually governs risk did not carry across. Confirm the specific signals, not the protocol. - **Network-level access used as the default.** The product offered a network mode for the hard cases and it quietly became the normal path. That is a VPN with a new invoice. - **Latency nobody tested from the offices that matter.** The broker terminated in another country and users noticed daily. PoP presence by city, tested from your own network, before signing. - **Declaring zero trust because ZTNA shipped.** ZTNA is one control. Zero trust is an architecture across identity, devices, networks, applications and data — and the marketing blurs this on purpose. ## Questions this guide answers ### What is the difference between ZTNA and a VPN? A VPN authenticates once and places the device on your network, so everything routable becomes reachable — which is what makes lateral movement easy for an attacker. ZTNA authenticates the user and checks the device, then brokers a connection to one named application, with nothing else visible; a connector beside the application dials outward, so no inbound firewall rule or exposed concentrator is needed. The trade-off is reach: a VPN carries any protocol, while ZTNA carries what its broker supports. Web applications are universal, SSH and RDP are common, desktop applications need an agent, and server-initiated protocols like on-premises VoIP and SCCM are documented at very few vendors — which is why VPNs survive ZTNA projects. ### What can agentless (browser-based) ZTNA actually do? It reaches internal web applications, and in some products browser-rendered SSH and RDP. It cannot run desktop applications, cannot map local drives, usually cannot drive multiple monitors, and can only assess the device through what a browser exposes — effectively the source address and user-agent string. That makes it the right model for contractors, third parties and unmanaged devices, and the wrong model as the only option for employees who need deep posture checking or non-web protocols. Palo Alto's Prisma Access Browser and InstaSafe ZTAA are browser-first here; most other products document both agent and agentless modes. ### Which ZTNA products are India-built or have Indian points of presence? India-built and India-hosted: InstaSafe (published at around $8 per user per month with a managed service, and listed on GeM for government procurement) and Seqrite ZTNA from Quick Heal — both with local data handling, local support and INR contracting, and both documented at mid-market rather than large-enterprise scale with narrower identity integration. Documented Indian points of presence: Cloudflare (Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur), Netskope (eight Indian data centres on NewEdge) and Palo Alto Networks (a documented Mumbai cloud location since 2021). For Zscaler, Cisco, Check Point, Sophos, Versa and Trend Micro, named Indian PoP cities are not established from vendor documentation on this guide — flagged rather than ruled out. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/network-security-sase/zero-trust-access* --- # DNS filtering is the cheapest security control you can deploy and the easiest to bypass. Both facts matter. *Secure Web & DNS — a TechBag decision guide. Last reviewed 2026-09-07.* > At the DNS layer, a resolver refuses to translate a bad domain into an address — no agent, no latency, nothing in the traffic path. A proxy goes further: it terminates the connection, decrypts it, inspects the content and decides. The first costs almost nothing and sees only destinations; the second sees everything and costs a certificate on every device. **The checkable fact:** Cisco’s DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare’s resolver is free. A browser with DNS-over-HTTPS enabled routes around both, without asking anyone. - Canonical: https://www.thetechbag.com/browse/network-security-sase/secure-web-dns - Category: [Network Security & SASE](https://www.thetechbag.com/browse/network-security-sase) - Products compared: 11 ## What secure web & dns actually is Two controls at two different depths. **DNS filtering** intercepts the name lookup that starts almost every connection: point your resolvers at the provider, and requests for known-bad or policy-blocked domains never resolve. Nothing sits in the traffic path, there is no agent to deploy on the network, and it costs very little. **A secure web gateway** is a proxy: traffic is terminated, decrypted, inspected for malware and data, and allowed or blocked by content rather than by destination. Alongside them sits **CASB**, which controls how cloud applications are used — and which is genuinely two products under one name. *Inline* CASB sits in the traffic path and can stop an upload as it happens; *API* CASB connects to the application out of band and scans what is already there. Most estates need both and are quoted one. When these controls are bought as part of a platform rather than on their own, that is the [SASE & SSE guide](https://www.thetechbag.com/browse/network-security-sase/sase-sse). **The most common mis-purchase.** Buying DNS filtering when the requirement was full web inspection. DNS blocks a domain; it cannot tell you what a user uploaded to an allowed one, scan a download, or distinguish your corporate cloud tenant from a personal one. **If the requirement mentions content, data or files, the answer is a proxy.** ## SWG vs DNS filtering vs proxy · CASB inline vs API Three enforcement depths often sold as one product, and one acronym that is genuinely two different things. Not a maturity ladder — each sees something the others cannot. ### DNS filtering Blocks at name resolution: the domain never turns into an address. No traffic path, no latency, no certificates, and it covers every device and protocol using your resolver — including things a proxy never sees. It cannot inspect content, cannot tell one page of a site from another, and is bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN. The cheapest real control there is. ### Proxy / secure web gateway Terminates the connection, decrypts TLS, inspects content, and decides on what the traffic actually contains. Sees files, uploads, form data and malware; enforces data-loss rules. Costs a certificate on every device, an exception list for applications that pin certificates, and latency in the path. Everything DNS filtering cannot do, at the price of a project. ### CASB inline In the traffic path, on the way to the cloud application. Can block an upload as it happens, coach a user in real time, and distinguish the corporate tenant of an application from a personal one. Sees only what traverses it, and only while it does — data already sitting in the application is invisible. ### CASB API Connected to the cloud application out of band, scanning what is already there: historical files, sharing permissions, external collaborators, dormant sensitive data. Finds the exposure inline inspection never saw — and can block nothing in real time. The two modes answer different questions and most estates need both. **These are not a maturity ladder.** DNS filtering is not a weak proxy — it covers protocols and devices a proxy never touches, at almost no cost. A proxy is not a better DNS filter — it sees content and carries a certificate burden. Inline and API CASB are not tiers of each other. The honest estate deploys DNS filtering everywhere as a floor and adds proxy depth where the data actually lives. ## The decision variables Seven variables decide this purchase. The instrument tests what documentation establishes (enforcement layer, TLS depth, roaming coverage, CASB mode, standalone availability, India presence); bypass behaviour, false positives and the certificate project are prose because they come from a pilot and an operations plan. **DNS-layer versus full proxy inspection.** Destinations or content. The single question that decides whether this is a cheap control deployed everywhere or a project with a certificate rollout. **Roaming agent versus network-level deployment.** Enforcement for devices that leave the office. Sophos and Palo Alto CDSS are network- or platform-bound here; the rest document roaming coverage. **TLS inspection depth and the certificate burden.** Full, selective, or none — and then the real work: an inspection certificate trusted by every device, plus an exception list for applications that pin their own. **Category coverage and false-positive rate.** A block on a business-critical site erodes trust in the control faster than any threat justifies it. Pilot against your own top destinations and check the exception workflow. **CASB — inline versus API.** Two different products under one acronym: blocking in flight versus finding what is at rest. Documented per product here; most estates need both. **Standalone or only inside a SASE platform.** Cisco Umbrella, Cloudflare, Zscaler, FortiSASE and Barracuda sell standalone; Cisco Secure Access, Netskope, Palo Alto CDSS and Sophos require the platform or appliance underneath. **India resolver presence and latency.** DNS resolution happens on every request, so resolver distance is felt constantly. Documented for Cloudflare (six cities) and Netskope (eight data centres); not established for the rest here. ## The 11 products Every product carries one stated limitation. Prices are USD with an indicative INR conversion, tier- and term-matched where the vendor publishes one. ### Cisco Umbrella — Cisco - **Who it's for:** Estates that want DNS-layer filtering deployed across every site in an afternoon, with an upgrade path to full proxy inspection in the same console. - **The honest limitation:** The DNS tiers filter by domain and cannot inspect content — the selective proxy arrives at the SIG tiers, which is where the price roughly triples. Add-on SKUs and premium support push enterprise deployments well above the list. An Indian resolver location is not established from vendor documentation. - **Price:** $2.25–6.50 (≈ ₹187) — per user / month across the tiers (DNS Security Essentials roughly $30–40 per user / year, DNS Advantage $40–55, SIG Essentials $60–90, SIG Advantage $95–135); the DNS tiers are the cheapest real control on this page - **Details:** https://www.thetechbag.com/cisco/cisco-umbrella ### Cisco Secure Access (web) — Cisco - **Who it's for:** Cisco estates consolidating Umbrella, VPN and web security into one cloud service under an existing enterprise agreement. - **The honest limitation:** Not a standalone web filter — it arrives as a platform, which is a larger commitment than the Umbrella DNS tiers it supersedes. Indian PoP cities are not established from documentation. - **Price:** Per user — per user / year inside the Secure Access platform rather than standalone; the successor to Umbrella's SIG tiers with full proxy inspection, CASB and ZTNA in one subscription - **Details:** https://www.thetechbag.com/cisco/cisco-secure-access ### Cloudflare DNS (1.1.1.1 for Families · Gateway DNS) — Cloudflare - **Who it's for:** Estates that want DNS filtering on the largest documented Indian resolver footprint here, starting at no cost. - **The honest limitation:** DNS layer only in this SKU — no content inspection, no TLS decryption, no CASB. It blocks a destination or it does not; what happens inside an allowed site is invisible. - **Price:** Free → in Zero Trust — the public resolver is free; policy-based DNS filtering sits inside Cloudflare Zero Trust (free to 50 users, then $7 per user / month); Indian points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur - **Details:** https://www.thetechbag.com/cloudflare/cloudflare-dns ### Cloudflare One — Gateway (web) — Cloudflare - **Who it's for:** Estates that want full web inspection at a published price, on documented Indian infrastructure, without an enterprise negotiation. - **The honest limitation:** The $7 tier is capable and is not the Enterprise product: CASB breadth, DLP depth, browser isolation and longer log retention move up to the quoted tier. TLS inspection still means deploying a certificate to every device. - **Price:** Free → $7 (≈ ₹581) — free for up to 50 users, then $7 per user / month with no user cap; DNS, HTTP and network filtering with TLS inspection, on the same Indian PoP footprint as the resolver - **Details:** https://www.thetechbag.com/cloudflare/cloudflare-one-zero-trust ### Zscaler Internet Access (ZIA) — Zscaler - **Who it's for:** Estates that want every session inspected in depth rather than destinations filtered — the reference proxy, and the deepest inspection here. - **The honest limitation:** A proxy, not a DNS filter: there is no cheap DNS-only tier to start on, and the base edition is the gateway with data protection arriving as editions or add-ons. Named Indian PoP cities are not established from vendor documentation. - **Price:** ~$6–12 (≈ ₹498) — per user / month reported (roughly $72–325 per user / year by edition); a full inline proxy inspecting every session, with CASB, DLP and browser isolation as higher editions or add-ons - **Details:** https://www.thetechbag.com/zscaler/zscaler-internet-access ### Netskope Next Gen SWG — Netskope - **Who it's for:** Estates whose control requirement is per application instance rather than per domain, which domain-level filtering cannot express at all. - **The honest limitation:** Sold as part of the Netskope One platform rather than as a standalone filter, so a like-for-like comparison against Umbrella's DNS tiers is not meaningful. It is more product than a DNS-only requirement needs. - **Price:** Per user — per user / month within Netskope One; inspects by application instance — allowing the corporate tenant of a cloud application while blocking the personal one — with eight Indian data centres on NewEdge - **Details:** https://www.thetechbag.com/netskope/netskope-swg ### Netskope CASB — Netskope - **Who it's for:** Estates that need both to control cloud application use: inline to stop an upload as it happens, API to find what was uploaded last year. - **The honest limitation:** Inline and API modes solve different problems and are frequently confused — API alone cannot block anything in real time, inline alone cannot see historical data at rest. Platform-priced, not standalone. - **Price:** Per user — per user / month within Netskope One; both inline (in the traffic path, able to block in real time) and API-based (out of band, scanning what is already in the cloud application) — the two modes are different products in practice - **Details:** https://www.thetechbag.com/netskope/netskope-casb ### Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) — Palo Alto Networks - **Who it's for:** Palo Alto estates that want web and DNS controls inside the policy engine already running, rather than a second console. - **The honest limitation:** Not a standalone product: it requires the firewall or Prisma Access underneath, and roaming coverage comes from Prisma Access rather than a lightweight DNS agent. Each service is its own subscription line. - **Price:** Subscription — per-firewall subscriptions layered on a Strata NGFW or Prisma Access — Advanced URL Filtering and DNS Security are separate CDSS SKUs, enforced wherever that platform enforces - **Details:** https://www.thetechbag.com/palo-alto/cloud-delivered-security-services ### Fortinet FortiSASE (web filtering) — Fortinet - **Who it's for:** FortiGate estates extending the web filtering they already run on-premises to users who never come back to the office. - **The honest limitation:** The categories and console are familiar, which is the point; as a standalone web filter for a non-Fortinet estate it is a less obvious purchase. Indian PoP cities are not established from vendor documentation. - **Price:** $8–18 (≈ ₹664) — per user / month list by bundle tier; web filtering and DNS filtering for off-network users using the same FortiGuard categories as the FortiGate estate, with Security Fabric pricing for existing customers - **Details:** https://www.thetechbag.com/fortinet/fortinet-fortisase ### Barracuda Network Protection (web security) — Barracuda - **Who it's for:** Distributed mid-market estates — many small sites — that want web filtering and firewalling from one platform and one bill. - **The honest limitation:** No CASB capability documented, so cloud application control is outside its scope; documented deployments are mid-market and an Indian resolver location is not established. The split per-site and per-user meter makes comparison awkward. - **Price:** Per site / per user — web security inside SecureEdge, licensed per site for the network side and per user for the access side; content filtering and TLS inspection for distributed sites without an enterprise project - **Details:** https://www.thetechbag.com/barracuda/barracuda-network-protection ### Sophos Firewall (web protection) — Sophos - **Who it's for:** Estates whose users are mostly in the office and who want web filtering enforced by the firewall already inspecting their traffic. - **The honest limitation:** On-network enforcement only — there is no roaming agent here, so devices off the network are unprotected unless you also run a cloud service. It is the appliance answer to a question the rest of this page answers from the cloud. - **Price:** In the protection bundle — web protection inside the Standard or Xstream Protection bundle on an XGS appliance; TLS inspection is an Xstream capability, and enforcement happens at your edge rather than in a cloud PoP - **Details:** https://www.thetechbag.com/sophos/sophos-firewall ## Why each constraint rules out what it does The full narrowing logic, as prose. Nothing here is hidden behind an interaction. **A DNS-layer tier.** Rules out Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB and Sophos Firewall (web protection) — a full proxy with no DNS-layer tier to start on. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security). **Full proxy inspection.** Rules out Cloudflare DNS (1.1.1.1 for Families · Gateway DNS) — DNS layer only; it blocks a destination and cannot see inside an allowed one. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security) and Sophos Firewall (web protection). **Full TLS inspection.** Rules out Cisco Umbrella — selective TLS inspection at the higher tiers rather than full inspection throughout; Cloudflare DNS (1.1.1.1 for Families · Gateway DNS) — no TLS inspection; encrypted content is not visible at all. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security) and Sophos Firewall (web protection). **Off-network coverage.** Rules out Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Sophos Firewall (web protection) — enforcement happens on your network only; devices elsewhere are uncovered without a second product. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security). **Inline CASB.** Rules out Cisco Umbrella — API-based CASB only; it scans what is already in the cloud application and cannot block in real time; Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Barracuda Network Protection (web security) and Sophos Firewall (web protection) — no CASB capability documented. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Fortinet FortiSASE (web filtering). **API CASB.** Rules out Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Barracuda Network Protection (web security) and Sophos Firewall (web protection) — no CASB capability documented; Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Fortinet FortiSASE (web filtering) — inline CASB only; it controls traffic in flight and cannot scan data already at rest. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG and Netskope CASB. **Buyable standalone.** Rules out Cisco Secure Access (web), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Sophos Firewall (web protection) — sold inside the vendor's wider platform or on its firewall, not as a standalone web filter. That leaves Cisco Umbrella, Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security). **Indian resolver presence.** Rules nothing out on published terms. It flags Cisco Umbrella — Indian resolver or PoP location not established from vendor documentation, Cisco Secure Access (web) — Indian resolver or PoP location not established from vendor documentation, Zscaler Internet Access (ZIA) — Indian resolver or PoP location not established from vendor documentation, Fortinet FortiSASE (web filtering) — Indian resolver or PoP location not established from vendor documentation, Barracuda Network Protection (web security) — Indian resolver or PoP location not established from vendor documentation and Sophos Firewall (web protection) — Indian resolver or PoP location not established from vendor documentation — marked, not removed. **Above 5,000 filtered users.** Rules nothing out on published terms. It flags Barracuda Network Protection (web security) — Documented deployments stop short of this size and Sophos Firewall (web protection) — Documented deployments stop short of this size — marked, not removed. **Both facts about DNS filtering are true at once.** It is the cheapest security control you can deploy — Cisco's DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare's resolver is free — and it is the easiest to bypass. DNS-over-HTTPS in a browser, a hardcoded public resolver, a personal VPN, or an application that ignores the system resolver all route around it. That does not make it worthless: it stops a large share of commodity threats at almost no cost and no latency. It makes it a floor rather than a ceiling, and anyone selling it as complete web security is selling you the floor. **TLS inspection is a certificate project before it is a security control.** Most traffic is encrypted, so inspecting content means decrypting it, which means your inspection certificate must be trusted by every device — managed laptops, phones, contractors' machines, and the applications that pin their own certificates and will simply break. Full TLS inspection is documented at Cloudflare One, Zscaler, Netskope, Palo Alto CDSS, FortiSASE, Barracuda and Sophos; Cisco Umbrella's DNS tiers are selective at the proxy tiers, and Cloudflare's DNS-only SKU does none. Plan the certificate rollout and the exception list before the licence, not after. **Inline CASB and API CASB are different products wearing one name.** Inline sits in the traffic path and can stop an upload as it happens; it sees only what traverses it, and only while it traverses. API-based CASB connects to the cloud application out of band and scans what is already there — historical files, sharing permissions, dormant data — and cannot block anything in real time. Netskope and Cloudflare document both; Cisco Umbrella is API-based; Palo Alto CDSS and FortiSASE are inline; Barracuda and Sophos document none. Estates usually need both, and are usually quoted one. **False positives are how the control dies.** A category engine that blocks a business application erodes trust fast: the exception list grows, then someone disables the policy for a group, then for everyone. Ask for the exception workflow and who can approve one, and pilot against your own top fifty destinations rather than a vendor's test list. Measured false-positive behaviour on Indian business sites is delivery-team knowledge: [TechBag to confirm]. **Under 200 users.** Published pricing excludes nobody at this size: Cloudflare is free to 50 users and $7 beyond, Cisco Umbrella's DNS tiers start around $2.25 per user per month, and Fortinet's band starts at 50 users. The platform-bundled options (Cisco Secure Access, Netskope, Palo Alto CDSS) publish no standalone floor. Current published minimums, by vendor: [TechBag to confirm]. ## Eight situations, eight shortlists — with the depth named Each shortlist states whether the answer is the DNS floor or proxy depth, and what it costs to deploy. If the requirement mentions content or data, start from the second row. ### Something cheap, deployed everywhere, this week **Shortlist:** Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cisco Umbrella, Fortinet FortiSASE (web filtering) **Why:** DNS filtering needs a resolver change and nothing else — Cloudflare's is free to start and documents six Indian cities; Cisco's DNS tiers run roughly $30–40 per user per year. **Trade-off:** It blocks destinations and cannot see inside an allowed one, and DNS-over-HTTPS or a personal VPN routes around it. A floor, deliberately chosen, is a legitimate answer — an assumed ceiling is not. ### The requirement is actually full web inspection **Shortlist:** Zscaler Internet Access (ZIA), Cloudflare One — Gateway (web), Netskope Next Gen SWG **Why:** Content inspection, malware scanning and data controls need a proxy in the path with TLS decryption — Zscaler is the depth reference, Cloudflare publishes a price, Netskope adds application-instance awareness. **Trade-off:** All three mean a certificate on every device and an exception list for applications that pin certificates. Budget the rollout as a project, not a setting. ### Control the corporate cloud tenant, block the personal one **Shortlist:** Netskope Next Gen SWG, Netskope CASB, Cloudflare One — Gateway (web) **Why:** Instance awareness is the capability domain-level filtering cannot express at all: same domain, different tenant, different verdict. **Trade-off:** It requires inline inspection and a platform-priced product — this is more capability than a DNS-only requirement needs, and the quote reflects that. ### Find what is already sitting in the cloud applications **Shortlist:** Netskope CASB, Cisco Umbrella, Cloudflare One — Gateway (web) **Why:** API-based CASB connects out of band and scans historical data, sharing permissions and dormant files — the half inline inspection cannot see. **Trade-off:** API CASB blocks nothing in real time. Estates usually need both modes; Netskope and Cloudflare document both, Cisco Umbrella is API-based. ### Users are mostly in the office and there is already a firewall **Shortlist:** Sophos Firewall (web protection), Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Barracuda Network Protection (web security) **Why:** Web filtering enforced by the appliance already inspecting the traffic avoids a second console and a second subscription entirely. **Trade-off:** Sophos and Palo Alto CDSS have no lightweight roaming agent here — devices off the network are uncovered without a cloud service, which is the whole reason the rest of this page exists. ### Already running FortiGate or Palo Alto **Shortlist:** Fortinet FortiSASE (web filtering), Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Cisco Secure Access (web) **Why:** The same categories, the same policy engine and the same console extended to roaming users — Fortinet gives existing FortiGate customers Security Fabric pricing. **Trade-off:** Familiarity is worth real money in operations and deepens single-vendor commitment. Neither Fortinet nor Cisco documents Indian PoP cities here. ### Indian resolver presence must be documented **Shortlist:** Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Netskope Next Gen SWG **Why:** Cloudflare documents six Indian cities and Netskope eight Indian data centres — resolution and inspection latency is felt on every request, not just at connection time. **Trade-off:** Cisco, Zscaler, Fortinet, Barracuda and Sophos do not document Indian resolver locations on this guide — flagged, not ruled out. Ask for the location and test it. ### Many small sites, one platform, no enterprise project **Shortlist:** Barracuda Network Protection (web security), Cisco Umbrella, Cloudflare One — Gateway (web) **Why:** Barracuda licenses web security inside SecureEdge per site and per user; Umbrella deploys per site by resolver change; Cloudflare covers roaming users at a published price. **Trade-off:** Barracuda documents no CASB, so cloud application control needs another product. Normalise the split per-site and per-user meter before comparing. ## At scale Web and DNS controls scale by devices covered and by exceptions accumulated. The bill follows the per-user tier; the credibility follows the false-positive rate. ### 200 users — Deployment speed is the constraint - A resolver change covers every device on the network in an afternoon: Cloudflare free to 50 users, Cisco's DNS tiers from about $2.25 per user per month. - TLS inspection is probably not worth the certificate project yet unless a specific requirement demands content inspection. - Roaming coverage matters as soon as anyone works from home — a DNS agent on the laptop is the cheap answer. **The test:** Turn on DNS filtering, then check how many devices actually use your resolver. The gap is the real coverage number. ### 2,000 users — TLS and false positives are the constraints - Content inspection now has a business case, and with it a certificate rollout to every managed device and an exception list for pinned applications. - The exception workflow becomes a real process: who approves an unblock, how fast, and where it is recorded. - Cloud application control appears as a requirement — and the inline versus API question arrives with it. **The test:** Run the proxy in monitor mode for two weeks and count what it would have blocked. The false positives in that list are your rollout risk. ### 20,000 users — Coverage gaps and residency are the constraints - Bypass becomes systematic rather than incidental: DoH, unmanaged devices, personal VPNs. The control needs measurement, not just deployment. - Resolver and inspection location become regulator-visible questions alongside latency ones. - Barracuda and Sophos web protection are flagged unverified above 5,000 users; the platform products document large estates. **The test:** Measure what fraction of egress actually traverses the control. If nobody knows, the coverage number is aspirational. Cisco, Cloudflare, Zscaler, Netskope, Palo Alto and Fortinet document large estates; Barracuda Network Protection and Sophos Firewall web protection are flagged unverified above 5,000 users. Where a specific filter strains for your traffic mix: [TechBag to confirm]. ## Leaving a web gateway is a certificate and policy migration The category lists, the exception list and the trust chain are all per platform. Moving means rebuilding the policy and re-trusting every device, while the old control still carries production traffic. **The category policy** — Years of accumulated allow and block decisions, many with no recorded reason. Category names differ between vendors, so it is a translation rather than an export. *(Translate, then audit)* **The certificate** — A new inspection certificate trusted by every device before the switch, and the old one removed afterwards — or inspection silently fails for someone. *(New trust chain first)* **The exception list** — Applications that pin certificates, sites that break under inspection, and the business tools someone got unblocked in 2023. All of it re-tested. *(Re-test every exception)* **The overlap** — Both controls run while users and sites cut over. Two subscriptions for a quarter is cheaper than one week of blocked business traffic. *(Two bills, one quarter)* **Policy translation, certificate rollout and exception re-testing for your estate:** [TechBag to confirm] — TechBag scopes it from your policy size and device inventory. ## Per user per month — and the depth decides the multiple What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the licence leaves out — which, for web security, is the certificate project and the exceptions. ### Do you already own one? Four places this filtering may already exist. Three of them genuinely do. - **Your existing NGFW subscription — Often.** Web filtering and DNS security are frequently already in the bundle you renew — for traffic on your network. Audit it before buying the same categories twice. - **Cloudflare's free tier — Partly.** The public resolver is free and Zero Trust is free to 50 users, with real policy-based DNS filtering. A legitimate control, not an enterprise gateway. - **Your endpoint vendor's web filtering — Partly.** Many endpoint agents filter web traffic on the device, and it travels with the user. Thinner on inspection, CASB and reporting than a cloud gateway. - **Your SASE or SSE subscription — Often.** Secure web gateway is the base module of every platform on the neighbouring guide. If you already pay for SSE, you already own this — check the tier before buying it again. If the filtering you need is already inside something you renew, we say so. It costs us a sale and saves you one. ### What the rest actually cost Published and reported per-user meters (INR for scale), worked at 200 / 2,000 / 20,000 users per year. The DNS tiers and the proxy tiers are deliberately shown together, because the gap between them — roughly threefold at Cisco — is the real decision on this page. ### What isn't in the licence price - **The certificate rollout.** An inspection certificate trusted by every device, plus the bypass list for applications that pin their own. It is a device-management project with a security deadline, and it is in no licence. Your device count: [TechBag to confirm]. - **The exceptions and who owns them.** Every unblock request, every pinned application, every business tool that broke. Small individually; the list is what the control actually is after two years. - **The coverage you do not have.** Devices not using your resolver, browsers with DNS-over-HTTPS, personal VPNs and unmanaged machines. Measure the fraction of egress that actually traverses the control before reporting coverage. ## What goes wrong Documented filtering behaviour and deployment outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the first audit. - **DNS filtering bypassed by DoH, hardcoded resolvers or a VPN.** The policy was deployed and a browser setting routed around it. Ask how the product detects DNS-over-HTTPS, and measure what fraction of egress actually uses your resolver. - **Certificate deployment stalling the TLS rollout.** Inspection was licensed, configured and never enabled because the certificate never reached the devices. It is a device-management project — plan it before the licence. - **False positives blocking business apps and eroding trust.** One blocked business-critical site produced an exception, then a group exemption, then a disabled policy. Pilot in monitor mode against your own top destinations. - **Buying DNS filtering when the requirement was web inspection.** The requirement mentioned files and data; the purchase blocked domains. DNS cannot see inside an allowed destination — that is a proxy, at roughly triple the price. - **Assuming CASB means both modes.** The quote was API-based and the requirement was to block uploads in real time. Inline and API are different products under one acronym. - **Roaming devices left uncovered.** Enforcement was network-level and half the workforce stopped coming to the office. Two products here have no roaming agent at all. - **Resolver latency mistaken for a slow internet connection.** Resolution ran through another continent and every page felt slower. Ask for the Indian resolver location and measure it from your own offices. - **Coverage reported from licences, not from traffic.** The report counted seats; the control saw a fraction of egress. Measure what actually traverses it, not what was purchased. ## Questions this guide answers ### What is the difference between DNS filtering and a secure web gateway? DNS filtering blocks at name resolution — the domain never becomes an address. It needs no agent, adds no latency, covers every device and protocol using your resolver, and costs very little (Cisco's DNS Security Essentials runs roughly $30–40 per user per year; Cloudflare's resolver is free). It cannot inspect content, cannot distinguish pages within an allowed site, and is bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN. A secure web gateway is a proxy: it terminates and decrypts the connection, inspects files, uploads and malware, and enforces data rules — everything DNS cannot do, at the cost of deploying an inspection certificate to every device and maintaining an exception list. They are not tiers of each other; the honest estate uses DNS filtering as a floor everywhere and proxy depth where the data lives. ### What is the difference between inline CASB and API CASB? Inline CASB sits in the traffic path on the way to the cloud application: it can block an upload as it happens, coach a user in real time, and distinguish your corporate tenant of an application from a personal one. It only sees what traverses it, while it traverses. API CASB connects to the cloud application out of band and scans what is already there — historical files, sharing permissions, external collaborators, dormant sensitive data — and cannot block anything in real time. They answer different questions and most estates need both. On this guide Netskope and Cloudflare document both modes, Cisco Umbrella is API-based, Palo Alto CDSS and FortiSASE are inline, and Barracuda and Sophos document neither. ### Which web and DNS products have documented Indian infrastructure? Cloudflare documents Indian points of presence including Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur — the largest documented footprint on this guide — and Netskope operates eight data centres in India on its NewEdge network. Indian resolver or point-of-presence locations for Cisco Umbrella, Cisco Secure Access, Zscaler, FortiSASE, Barracuda and Sophos are not established from vendor documentation here and are flagged rather than ruled out. This matters more in this category than most: DNS resolution happens before every connection, so a distant resolver adds delay to everything a user does — and they will report it as a slow internet connection, not as a security control. --- *Vendor-neutral. Nothing gated. Figures marked [TechBag to confirm] are team-owned and deliberately not guessed.* *TechBag — India-based software reseller and advisory. https://www.thetechbag.com/browse/network-security-sase/secure-web-dns* --- # Network Security & SASE — where enforcement happens — your edge, a provider's cloud, the application, or DNS *A TechBag category guide. Last reviewed 2026-09-07.* - Canonical: https://www.thetechbag.com/browse/network-security-sase - Routes: 4 ## The routes ### Firewall & Network Security The throughput number on the datasheet is measured with every inspection feature switched off. Turn them on and you are buying a different box. - 13 products compared - Guide: https://www.thetechbag.com/browse/network-security-sase/firewall-network-security - Boundary terms resolved: Firewall vs NGFW · UTM vs NGFW · SD-WAN vs MPLS · SD-WAN vs SASE ### SASE & SSE Most organisations buying SASE only need SSE — and are quoted for both. - 20 products compared - Guide: https://www.thetechbag.com/browse/network-security-sase/sase-sse - Boundary terms resolved: SASE vs SSE · Single-vendor vs dual-vendor SASE · What SSE excludes · SASE is not 'firewall, evolved' ### Zero Trust Access ZTNA replaces the VPN for applications. It does not replace it for everything — and the gap is where projects stall. - 14 products compared - Guide: https://www.thetechbag.com/browse/network-security-sase/zero-trust-access - Boundary terms resolved: ZTNA vs VPN · Agent-based vs agentless · ZTNA vs zero trust as an architecture · Network-level access inside a ZTNA product ### Secure Web & DNS DNS filtering is the cheapest security control you can deploy and the easiest to bypass. Both facts matter. - 11 products compared - Guide: https://www.thetechbag.com/browse/network-security-sase/secure-web-dns - Boundary terms resolved: DNS filtering · Proxy / secure web gateway · CASB inline · CASB API --- *Vendor-neutral. Nothing gated. https://www.thetechbag.com/browse/network-security-sase*