- Best for
- MSPs standardizing security delivery across SMB and mid-market clients
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
Your team still owns
- Selecting the Todyl package and deciding which modules, tenants and data sources are in scope
- Deploying and administering the Todyl agent, SIEM sources, SASE policies and endpoint controls
- Customer-facing communication, business recovery and follow-on remediation after incidents
- Verifying which response actions are automated, one-click, analyst-led or require MSP approval
- Managing non-Todyl security tools that are only ingested into the SIEM
Pricing
| Line | Figure |
|---|---|
| Published price | Quote-based package pricing |
| Billing model | Tiered, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Strong fit for MSPs that want one platform across SIEM, endpoint, SASE, SOAR, GRC and MXDR
- DRAM model gives partners a named response and planning resource instead of only a shared queue
- Todyl exposes cases and response context in the platform, which helps MSPs explain incidents to clients
- Official package pages are clearer about retention and SOAR differences than many MSP-channel services
Watch out for
- Public pricing is quote-only despite published package names
- Review evidence is mostly for the full Todyl platform, so buyers should ask for MXDR-specific references
- The service is platform-centered; non-Todyl tools may be ingested without the same response depth
- Reddit and review-site complaints point to setup complexity, dashboard/reporting limits, DNS or SASE friction and configuration sensitivity
What buyers say
Alert noise
Not assessed
Transparency
Not assessed
Customers like
- G2 reviewers often value the all-in-one MSP console and one deployed agent
- Several users describe the SOC or MXDR team as helpful for alert evaluation and first actions
- TrustRadius and SoftwareFinder show limited but positive review volume
- MSP community posts include users who like the SIEM, SASE and MXDR combination when configured well
Watch out for
- G2 cautions include setup complexity, reporting/dashboard limits and integration issues
- Reddit threads include serious complaints about missed token-theft behavior and support quality
- Community discussions repeatedly mention SASE, DNS, tunnel or agent friction
- Review surfaces do not cleanly isolate MXDR from the broader Todyl platform
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which response actions can Todyl take for endpoint, identity and SASE events without waiting for MSP approval?
- How are DRAM coverage, after-hours escalation and client communication handled for each tenant?
- Which package includes the retention, SOAR playbooks, static IPs, tunnels and compliance frameworks we need?
Integrations
Editorial notes
Why co-managed SOC
Todyl MXDR is more than alert notification because official material describes 24/7 analysts, investigations, proactive outreach, a dedicated DRAM, case visibility, response playbooks and threat mitigation. It is still co-managed because the service is built around partner transparency, collaboration and MSP/customer oversight rather than Todyl quietly owning every daily SOC decision.
Platform boundary
MXDR is tightly coupled to the Todyl platform. Official FAQs say MXDR runs from Todyl Managed Cloud SIEM and gains full insight when paired with Todyl SASE, Endpoint Security, SOAR and other modules. Buyers using another EDR, SIEM or SASE stack should confirm what Todyl only ingests versus what Todyl can act on.
Pricing boundary
Todyl now publishes Essentials, Advanced and Complete package structures, but each package points buyers to sales for pricing. Avoid comparing it against MDR providers on list price alone until the quote shows package tier, retention, SOAR limits, SASE ratios, tunnel needs and MSP margin.
Review boundary
Public reviews are strongest for the Todyl platform as a whole, not MXDR alone. G2 reviews praise MSP-friendly consolidation and SOC help, while Reddit discussions include serious complaints about missed identity events, configuration sensitivity, SASE or DNS friction and support variability.