24observe
checking… Start free
Pricing

An AI SOC analyst, logs, and uptime.
One predictable bill.

You pay for what costs us money and earns its keep — log volume and AI investigations — at a fraction of a stitched-together SIEM, SOAR, and analyst seat. No per-host metering, no per-seat tax, no "contact sales."

Plan
24Observe
Legacy equivalent
You save
Free 25 monitors · 5 endpoints · 1 GB logs · 10 investigations
Free
$15/mo
Pingdom
$180/yr
Team 100 monitors · 50 endpoints · 25 GB logs · 250 investigations
$29 /mo
$120/mo
uptime + logs SaaS
$1,092/yr
Scale 1,000+ monitors · unmetered endpoints & investigations
$299 /mo
enterprise SIEM
Fleet-scale
// competitor prices sampled 2026-04 · sources linked in /docs/pricing-comparison
Every plan includes

No "enterprise tier" to unlock encryption.

Features gated by price are 2015 thinking. Everyone gets the same feature set — uptime, logs, the full SIEM, and the AI SOC analyst. You pay for what you actually consume — log volume and AI investigations — not for unlocking what should be default.

All 7 check types (HTTP/S, TCP, SSL, ping, port, keyword, heartbeat)
1-minute minimum interval on paid plans, 30s on Pro
Email, webhook, Slack, Discord, Telegram, Microsoft Teams, PagerDuty, Opsgenie alerts (unlimited)
Event webhook subscriptions (incident.opened / acknowledged / resolved / monitor.status_changed / log_alert.fired) — unlimited on every plan
Pre-converted LLM tool definitions: /openapi/openai-tools.json, /openapi/anthropic-tools.json, /openapi/langchain-tools.json
Personal access tokens with 24 narrow scopes + per-token daily mutation and log-byte caps
Idempotency-Key on every mutating endpoint (same key + different body returns 409)
X-PAT-Mut-Limit / Remaining / Reset headers on every authenticated response
Public status pages with custom branding + custom domain
Incident timeline with public updates ("we have identified the cause")
Maintenance windows that pause alerts but keep checking
SLO targets (set 99.9%/30d, get green/red badges and breach alerts)
Audit log for every mutation, PAT-attributed, exportable as CSV
AI SOC Analyst: autonomous incident triage — multi-step investigation with evidence-cited verdicts, disposition + confidence + recommended actions (10/mo Free → 250 Team → 1,500 Business; upgrade for more)
Logs: ingest + search + live-tail + pattern grouping + error tracking + anomaly alerts (1 GB/mo Free → 25 GB Team → 150 GB Business → 1 TB Scale)
Connected endpoints — one combined count for Linux Sensor hosts, monitored AI agents, and universal-ingest sources (5 Free → 50 Team → 300 Business). A ceiling, never a per-host meter: send all the telemetry you want, we never charge per host or per agent
SIEM: 50 ATT&CK-tagged detections + multi-event correlation — on every plan, no security tier
Threat-intel matching + GeoIP / identity / asset enrichment, inline at ingest
Security cases + forward-cursor NDJSON SIEM export + signed detection webhooks
OpenAPI spec for typed clients in any language
Continuous point-in-time backups of your data
Public uptime badge (live SVG you can drop in a README)
Questions

What people actually ask on the first call.

Is the pricing this flat, really?
Yes. No "Contact Sales" tier. No per-seat multipliers. No hidden "data egress" line item. The table above is the full menu. On the inbound side: the ingest endpoint accepts gzip/deflate/brotli natively, so a customer pushing 50 GB/day of structured logs typically sees ~2.3 GB/day on the wire — your AWS egress bill is the thing that shrinks, not ours.
What's the catch?
There isn't one, but the tradeoffs are real: we don't yet offer APM, distributed tracing, or RUM — that's the Datadog lane. If you need those now, we're not the fit yet. If you need uptime/ping/cert/keyword at 1/10 the price, we are.
Is the security / SIEM included, or an add-on?
The SIEM is included on every plan — 50 ATT&CK-tagged detections, multi-event correlation, threat-intel + GeoIP / identity / asset enrichment at ingest, security cases, and forward-cursor SIEM export. No "security tier", no per-GB intelligence meter. The one metered piece is the AI SOC Analyst — the autonomous triage that actually investigates each incident — because every investigation runs a real model. You get a monthly allotment per plan; need more, move up a tier. See what it does →
What counts as an "AI investigation"?
One autonomous triage of one incident: the analyst pulls the incident's blast-radius from the context graph, searches your logs, and returns an evidence-cited verdict (disposition + confidence + recommended actions). Re-opening the same incident later can re-investigate. Your monthly allotment covers normal incident volume; if you consistently need more, the next tier raises it.
Why is self-host free forever?
Paid plans cover fully managed hosting, operations, and support. If you would rather run the platform on your own infrastructure, a fully self-hostable distribution is available — the capabilities are identical either way. You choose managed convenience or full control — the capabilities are identical either way.
Can I upgrade or downgrade anytime?
Yes. Changes prorate to the hour. No annual commits unless you want one (10% off if you do).
Do you offer volume discounts above Scale?
Yes — past 1,000 monitors we'll price based on your actual tick rate. Email billing@24observe.com.

Pick a plan. Or run it yourself.

Either way, docker compose up gets you to first tick in 60 seconds.