- Best for
- Teams that already run a major EDR and need 24/7 MDR coverage
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
Your team still owns
- Approving which response playbooks can run automatically
- Remediation work outside supported EDR remote actions or Active Remediation scope
- Maintaining the endpoint, identity, cloud and email controls that feed Red Canary
- Confirming whether each data source is investigated, used for context or stored only
Pricing
| Line | Figure |
|---|---|
| Published price | Quote-based. Public reviews mention roughly $100/device/year |
| Billing model | Per-endpoint, Per-user, Per-asset, Tiered, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Lets buyers keep supported EDR tools while adding analyst investigation and response playbooks
- Reviewers often mention reduced alert noise and clearer investigation detail
- Public threat reports show detection research across real customer telemetry
Watch out for
- Active Remediation is an add-on, not included in every MDR quote
- Integration depth depends on the selected plan and the connected source
- Custom detection control and SIEM-style visibility may be less flexible than an internal SOC
- Zscaler acquisition adds a roadmap and commercial question for buyers to verify
What buyers say
Alert noise
Low
Transparency
Mixed
Customers like
- Less time spent sorting noisy EDR alerts before a human investigates
- Investigations include context that teams can act on without jumping across every console
- Smaller teams value after-hours coverage and configured response playbooks
Watch out for
- Reviewers mention price as high for smaller companies
- Some buyers report gaps when a needed integration or data source is not fully covered by the selected plan
- Several reviews ask for more custom detection control or faster alert handling
Reviewers report roughly 99% true-positive rate. Log searchability is a noted weakness.
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which data sources are included in the quoted plan, and which are storage-only or context-only?
- Which response actions can run without approval, and which require customer confirmation?
- Is Active Remediation, Managed Phishing Response or Security Data Lake included, or priced as a separate add-on?
Integrations
Editorial notes
Market position
Red Canary functions as tool-flexible MDR, not a replacement for the buyer's whole security operations program. It fits buyers that already run security tools and want Red Canary to investigate alerts, tune detection logic and orchestrate response without forcing a new endpoint platform.
Scope boundary
Red Canary's pricing page separates Core, Complete and Enterprise plans. Core is single-domain MDR, Complete adds multi-domain MDR, API access and data export, while Enterprise adds strategic support and unlimited integrations. Add-ons include Active Remediation, Managed Phishing Response and Security Data Lake.
Response boundary
Red Canary supports automated and manual endpoint isolation through supported EDRs. Hands-on remediation is documented as Active Remediation, an annual add-on for MDR for Endpoint subscriptions, so it should be verified in the quote.
Ownership change
Zscaler completed its acquisition of Red Canary on August 1, 2025, and Red Canary is now branded as a Zscaler company. Buyers should confirm roadmap, commercial ownership and renewal terms, especially if they already use or are evaluating Zscaler security operations products.
Channel buying
Red Canary is available direct, through MSP and solution-provider partners, through AWS Marketplace and through Carahsoft for public-sector buyers. Buyers should confirm whether the seller of record changes support escalation, procurement terms or included services.