- Best for
- Mid-market and enterprise teams that want MDR around existing EDR and SIEM investments
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
- OT/ICS
Your team still owns
- Licensing, deploying and maintaining the EDR, SIEM, identity, cloud and other tools in scope
- Making sure expected assets, log sources and telemetry are connected and reporting
- Defining rules of engagement, response authority and approval paths for high-impact actions
- Remediation, recovery and business decisions after containment or escalation
- Confirming which tier includes custom detections, reporting, advisory work and incident response access
Pricing
| Line | Figure |
|---|---|
| Published price | Quote-based tiered MDR with AWS Marketplace private-offer procurement |
| Billing model | Tiered, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Strong fit for buyers that want MDR without replacing every existing security tool
- Public materials support response actions on the buyer's behalf when rules and integrations allow them
- Gartner Peer Insights shows more public review volume than many mid-market MDR providers
- Tiering gives buyers a way to align MDR scope with maturity instead of buying a single monolithic package
Watch out for
- Public pricing is quote-based, and marketplace $0.01 dimensions are not real list prices
- Response authority depends on rules of engagement, integration depth and service tier
- Public evidence supports a U.S.-based SOC but not detailed multi-region SOC locations
- G2 review volume is thin, and Reddit practitioner comments are mixed
What buyers say
Alert noise
Not assessed
Transparency
Not assessed
Customers like
- Buyers praise 24x7 monitoring and useful analyst interaction
- Reviews often point to alert-noise reduction and faster investigation workflows
- Some practitioners value support for existing SIEM and multiple security vendors
Watch out for
- Small G2 sample limits confidence outside Gartner
- Reddit sentiment is mixed and includes concerns about service quality and scale fit
- Buyers should ask for references that match their environment size and tool stack
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which response actions can the SOC take directly in our tools, and which require our approval?
- Which assets, log sources and integrations are in scope for the quoted tier on day one?
- Are advisory SOC analysts, incident response services, custom detections and executive reporting included or tier-dependent?
Integrations
Editorial notes
Why contain threats
The MDR offer goes beyond monitor-and-notify because official sources support 24x7 investigation and response plus remote threat containment through MOBILESOC. It is still not a full SOC replacement because the buyer owns the stack, asset coverage, rules of engagement, remediation and recovery.
Rejected co-managed SOC
Critical Start can act as an extension of the buyer's team and tune MDR outcomes, but the profiled offer is primarily MDR around connected signals. The public service-tier material does not make Critical Start responsible for running every security-operations process or tool.
Response boundary
AWS Marketplace language says the SOC can take response action on the buyer's behalf based on rules of engagement and the security tool. This profile should not imply universal remediation across every product, identity workflow, cloud account or business system.
Pricing boundary
The public tiering datasheet describes Essentials, Enterprise and Signature packages, and AWS Marketplace supports private-offer contract procurement. The $0.01 marketplace dimensions are procurement placeholders, not usable MDR list prices.
Review evidence
Gartner has meaningful Critical Start MDR review volume, while G2 has only three reviews and Reddit evidence is mixed and anecdotal. Customer sentiment should be useful but cautious, especially for large-environment fit and support-quality questions.