Org Guard · service boundaries, in writing

Exactly what's included —
and what isn't.

Most managed-security contracts hide their limits in a PDF you see after you've signed. We'd rather publish ours. This page states what each Org Guard tier includes — accounts, onboarding, reports, reviews, simulations, and what happens in an incident — and names the work that is scoped separately, so the price on the pricing page is the price you actually pay.

Reviewed by the founder · last updated 30 September 2026 (AI app builders added to the AI App Exposure Report; after-hours wording aligned with the incident-response section; exploited-vulnerability watch cadence stated as daily. Previously 17 September: incident response rewritten as a five-step model with a 60-minute business-hours SLA, three post-incident services and the Backup Survivability tabletop added to the published project-price menu). If we ever do less than this page says, that's a bug: security@familysentinel.org reaches a person.

Monitoring: 24/7The detection engine never sleeps. Collection, correlation, and alerting run around the clock, every day.
Analyst: business hoursHuman review and response are business hours (Mon–Fri, Central), with urgent findings handled best-effort after hours on every tier. On Guardian Complete, urgent findings are paged to our analyst after hours, and a written after-hours response commitment is agreed before you sign.
Security, not help deskWe are your security team. Printers, migrations, and password resets belong to your IT — we work alongside them, not instead of them.
The numbers

What each tier includes.

These match the plan cards on the pricing page — this is the same promise with the edges drawn in.

Essentials
$99/mo
Guardian
$249/mo
Guardian Plus
$549/mo · Insurance Ready
Guardian Complete
$999/mo
Staff accounts / inboxes coveredup to 10 inboxes (a hard cap — an 11th means Guardian)up to 15 included, then $12/account to 25up to 50 included, then $12/account to 7525 accounts & devices included, then $20/seat
Admin console (Google Workspace / Microsoft 365) monitored & hardened— (inbox-level + outside-in only)1 tenant1 tenant1 (a second tenant quoted individually)
Sending domains (DMARC protection)every domain your organization actually sends from — we don't cap this, because partial DMARC is false comfort
Onboarding & first-month hardeningremote inbox connection (each person, ~2 min); no hardeningone guided admin call (~1 hr) + up to 2 hrs hands-on hardeningguided call + up to 4 hrsguided call + up to 8 hrs incl. device rollout planning
Reportingmonthly reportweekly digest + monthly reportweekly digest + monthly reportweekly digest + monthly report
Evidence with every findingevery tier — each finding quotes the actual record we read, so you can verify it yourself (method & limits)
Fix re-verificationevery tier — we re-run the same check after you fix something and report "confirmed closed" with the date; a finding is never marked fixed on a cycle where the check could not run
Breach-catalog checkevery tier — your domain against the published breach catalog. Per-address monitoring needs domain-ownership verification with the breach provider; we set that up with you on request
Exploited-vulnerability watchevery tier — your internet-facing services cross-referenced against CISA's actively-exploited catalog, refreshed daily (inferred from public version banners, never by testing your systems)
Phone line to the Security Architect— (email + monthly report)urgent findings are a callurgent findings are a callpriority, incl. after-hours paging
Standing review calls—none standing — call us when you need usquarterly review callmonthly review call
Access reviews (who can touch what)——quarterlyquarterly
Cyber-insurance concierge— (the one-time Readiness Checkup is available to any tier)—questionnaire, gap-closing & evidence packet at every renewalsame, plus underwriter follow-ups handled with you
Phishing simulation——1 per year; date agreed at onboarding, first one within your first year1 per year (a second on request); date agreed at onboarding, first one within your first year
Threat-awareness talk—1 per year1 per year1 per year
Incident practice with leadership———twice yearly
Managed EDR / password manager / backup & restore test———included on covered devices; vendors chosen with you at onboarding

Churches and nonprofits keep their 20% discount on Essentials ($79), Guardian and Guardian Plus. Founding-client rates are locked for 24 months from your start date (added seats and third-party license costs aside), and discounts and credits don't combine: one per account, the larger applies. Why every tier has an included count and a per-account price above it: the human work in a tier — onboarding, reports, reviews, the concierge — is per organization, but monitoring is per account, so growth is always paid for and never silently absorbed. That is what lets these prices stay where they are.

The one-time checkup

Cyber-Insurance Readiness Checkup — $750, exactly what you get.

A posture assessment of your Google Workspace or Microsoft 365; a scorecard against the 12 controls insurers probe (the published standard), each line marked pass / gap with the evidence quoted; a one-page broker-ready summary; a prioritized fix list walked through on a call; and a re-check of anything you fix within 60 days, reported with the date. It includes the AI App Exposure Report (which AI tools can read your staff's mail and files). $750 up to 15 users; $1,250 for 16–50; larger, multi-site or regulated environments are quoted from $2,500. The fee is credited in full if you start a 12-month Guardian, Guardian Plus or Guardian Complete agreement within 30 days; the credit has no cash value and doesn't combine with other discounts. How cyber-insurance readiness works →

Supports eligibility, underwriting readiness and risk reduction; does not guarantee premiums, coverage, claim payment or insurer approval.

Scoped separately, at published prices

Project work — so a $99 plan can never quietly cost forty hours.

Everything below is a fixed quote you approve in writing before it starts. Declining never affects your monitoring. Guardian Plus and Complete already include guided incident containment (above); these are the hands-on projects beyond a tier's boundary.

ProjectWhat it isPrice
MFA rollout & verificationEnforce MFA on every account, admin and remote access; verify coverage; document it for the insurer$500–$1,250 by account count
Google Workspace / Microsoft 365 hardeningThe full best-practice baseline applied to your tenant, each change explained first$750–$2,500
Backup & recovery reviewWhat is backed up, where, encrypted how, and a documented restore test$350–$750
Incident-response plan & tabletopA written plan with named roles, plus a one-hour practice run with leadership$750–$1,500
Security-awareness kickoff & phishing exerciseStaff/volunteer session plus a measured phishing simulation with a plain-English result$350 setup + $2–$4 per user/mo ($50/mo minimum)
Insurance questionnaire assistanceFor Essentials and Guardian clients: we sit with the form and prepare the evidence (included in Plus and Complete)$250–$500
AI App Exposure ReportWhich AI tools (assistants, meeting notetakers, writing tools, and app builders such as Lovable, Replit or Bolt) your staff have connected to Google Workspace or Microsoft 365, and what each can read or send, built from your own access records, with what the report can and cannot see stated on it$250 (included in the Readiness Checkup and quarterly on every Guardian plan)
Broker or board presentation60 minutes, your Security Architect presents the posture and the plan$250 (included once a year in Plus and Complete)
Remediation & special projectsHands-on work outside any package above$150/hr · prepaid 5-hour block $675
After-hours incident supportManaged clients only, when you need hands on the wheel outside business hours$225/hr, 2-hour minimum
Persistence huntSame-day, short-form sweep across inbox rules, OAuth grants, delegation, MFA devices, sessions, and sign-in geography — after any verified incident$450 (included on Guardian and above)
30-day heightened watchElevated monitoring on the affected accounts and tenant for 30 days after an incident closes$150 (included on Guardian and above)
Debrief report & lessons-learned callA one-to-two page incident report your board or broker can read, plus a short call on what to change$250 (included on Guardian and above)
Backup Survivability tabletopA 60-minute exercise built around one question: if an attacker reaches domain admin, can they also destroy your backups?$350 (included annually on Guardian Plus and above)

We do not complete insurance applications on your behalf, speak to a carrier without you, or promise a premium. We prepare the evidence, help you answer accurately, and the insurer decides.

The part that matters

What incident response includes — on every tier.

We follow a five-step response model used across the security industry, in plain English: detect it, verify it's real and how serious, triage it with you, then work the response loop — scope, contain, eradicate, recover — until nothing new turns up, and debrief so it does not happen twice.

Verify and triage. Every finding is scored, investigated, and confirmed by a person before you hear about it — AI drafts the explanation from your own logs, it never decides on its own that you should hear about it. If it is real and serious, you get a phone call within 60 minutes of a person verifying it (Mon–Fri, 8am–6pm Central, excluding US federal holidays; best-effort outside those hours) on Guardian and above (Essentials: same-day email plus the written containment checklist) — after hours too on Guardian Complete: what happened, why it matters to you, and one clear recommendation.

Contain, together. You keep the keys; we bring the checklist. We walk your admin or IT provider through the exact steps for your platform — reset the credential, sign out every session and revoke tokens, remove the forwarding rule and any rogue app access, preserve the evidence — and then we check, read-only, that each step actually took. The full checklist, and what we validate afterward, is published: After we alert you →

Eradicate and recover. Included on Guardian and above (priced separately above on Essentials): a same-day persistence hunt across inbox rules, app grants, delegations, MFA devices and sign-ins, and thirty days of heightened watch on the affected tenant.

Debrief. Included on Guardian and above (priced separately above on Essentials): a one-page incident report your board and your broker can read, a short lessons-learned call, and follow-up on anything left open.

What's scoped separately: hands-on recovery work we perform ourselves beyond guided containment and the persistence hunt — rebuilding compromised environments, organization-wide credential resets executed by us, deep forensic investigation, work for insurers or attorneys. Before any of that starts, you get a written, fixed quote and you say yes or no. Nothing outside your subscription ever begins without your written approval, and declining never affects your monitoring.

Response model adapted from Dynamic Incident Response by Joshua Wright, © 2026 SANS Institute, licensed CC BY 4.0.

Plainly

Never included, at any price.

  • Help-desk IT — printers, mailbox migrations, routine password resets belong to your IT provider.
  • Holding your passwords — access is granted by you, read-only, revocable in one click.
  • Sending, deleting, or altering your mail or funds — we can't, by design.
  • Work outside the scope you authorized in writing.
  • Alert floods — urgent findings are a phone call; everything else waits for your digest.
  • Attacking your systems to prove a risk — our checks are passive and read public records. A real penetration test is a separate engagement with a signed scope (why, in detail).
  • Calling something "fixed" without re-checking it — if the check could not run, the finding stays open and the report says so.

And one promise about the boundaries themselves: if your organization consistently needs more than your tier includes, we will tell you plainly and propose the right scope — you will never discover a limit for the first time on an invoice.