Blackpoint Cyber

MDR · SOCaaS

Blackpoint Cyber CompassOne MDR is a managed detection and response service for MSPs and businesses that want Blackpoint's SOC to monitor endpoint, identity and cloud activity. After an alert, Blackpoint investigates and can contain threats through actions such as endpoint isolation and account disabling, while the buyer or MSP still owns connected-tool coverage, policy decisions, remediation, recovery and client communication.

What they do
Contain threats
Works with
Their platform
Built for
MSP/MSSP / SMB
Price
Quote-based MSP/channel pricing
Best for
MSPs that want a channel-friendly MDR platform for SMB and mid-market clients

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications

Your team still owns

  • Deploying and maintaining agents, cloud connectors and supported integrations
  • Setting response authority, notification preferences and tenant-specific policies
  • Handling remediation, recovery, user communication and business-owner decisions after containment
  • Managing MSP-client packaging, billing and service-level expectations
  • Validating whether LogIC and reports satisfy the buyer's audit or insurance requirements

Pricing

Line Figure
Published price Not published
Billing model Custom, Tiered
Contract Not published
Onboarding Not published

Blackpoint says it primarily sells through MSPs and does not list public rates to preserve partner pricing confidentiality. MDR Essentials material says endpoint and cloud editions can be month-to-month, with tiered volume pricing available from 50 endpoints for at least a one-year commitment.

Tradeoffs

Works well

  • Strong fit for MSPs that need multi-tenant MDR rather than an enterprise-only service model
  • Public material supports real containment action, not just notification
  • CompassOne can consolidate MDR, cloud posture, asset inventory, vulnerability context, application control and logging
  • G2 reviews show repeated positive themes around support, response speed and deployment

Watch out for

  • Public pricing is not listed, and partner-channel quotes can vary by package, volume and commitment
  • Buyers need to verify which modules and integrations are included because CompassOne capabilities vary by package
  • The service does not remove buyer or MSP ownership of remediation, recovery and tenant-specific policy decisions
  • Customer-review evidence on G2 is useful but skewed toward MSPs and small businesses

What buyers say

Alert noise

Not assessed

Transparency

Black-box

Customers like

  • G2 reviewers frequently cite fast SOC response, useful support and ease of deployment
  • MSP-oriented reviewers value multi-tenant workflow and integrations
  • Public review text supports endpoint, cloud and compliance-reporting use cases

Watch out for

  • G2 caveats mention portal usability, reporting, integration issues and cost
  • Gartner CompassOne review volume is too small to use as broad market validation
  • Reddit/community comments are mostly MSP anecdotes and older pricing discussions

Effective noise filtering, but reviewers ask for more transparency into what the SOC did and why.

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which containment actions can Blackpoint run automatically for our tenants or environment?
  2. Which endpoint, identity, cloud and PSA integrations are included in the quoted package?
  3. How do MDR Essentials, Core, Standard and add-on modules change coverage, retention and commitment terms?

Integrations

CompassOne LogICBlackpoint EDRMicrosoft Defender for EndpointSupported endpoint integrationsMicrosoft 365Google WorkspaceAzure SSOCisco DuoCompassOneConnectWise ManageUbiquiti UniFiConnectSecurePax8 Marketplace

Editorial notes

Why contain threats

Official MDR, SOC and datasheet pages support 24/7 investigation plus active containment, including endpoint isolation and account disabling. That goes beyond alert-only or advice-only MDR, but it still depends on connected systems and agreed response rules.

Why not full SOC

Blackpoint operates its own SOC and can take response actions, but the scoped offer is a managed MDR platform for partners and customers. Buyers still own tenant administration, remediation, recovery, policy choices and broader security-program decisions.

Pricing boundary

Blackpoint's pricing page says public rates are not listed because services are primarily delivered through MSPs. The profile therefore uses quote-based channel pricing and avoids legacy per-endpoint dollar ranges from indirect sources.

Compliance boundary

The profile keeps SOC 2, GDPR and HIPAA because Blackpoint's Trust Center supports those company/service commitments. It does not treat LogIC reporting for PCI, CMMC, CIS or NIST as proof that the MDR service itself certifies those frameworks.

Customer evidence

G2 has a large Blackpoint review set with themes around fast response, support and deployment ease, but reviews are heavily MSP and small-business weighted. Gartner's CompassOne page has very limited review volume, so sentiment is useful but not definitive.

Questions

Does Blackpoint Cyber only alert customers?
No. This profile classifies Blackpoint as Contain threats because official MDR and SOC pages support human-led active response, including containment actions such as endpoint isolation and account disabling when those actions are in scope.
Is Blackpoint Cyber pricing public?
No. Blackpoint says it primarily offers products and services through MSPs and does not publish rates on its website. Buyers should expect quote-based channel pricing, with package, volume and commitment terms confirmed by the partner or Blackpoint.
Does Blackpoint Cyber replace a full SOC?
Not by itself. Blackpoint provides 24/7 MDR monitoring, investigation and containment through its SOC, but the buyer or MSP still owns deployment, connected telemetry, response authority, remediation, recovery and client or business communication.