Protected Workload Pricing for AWS Digital Intelligence
Aegisify Digital Intelligence for AWS IaaS is billed by Aegisify Protected Workloads measured across the active cloud estate. The model is designed to reflect modern AWS environments spanning virtual machines, serverless, containers, managed runtimes, images, and identity coverage.
What Is an Aegisify Protected Workload?
A Protected Workload is Aegisify’s normalized measure of the active AWS execution and managed-service estate that DI protects. The model is intentionally broader than a simple EC2 count so serverless, containers, databases, and managed runtimes are not hidden from capacity utilization.
= 1 Protected Workload
= 1 Protected Workload
= 1 Protected Workload
= 1 Protected Workload
= 1 Protected Workload
= 1 Protected Workload
Example mid-sized AWS environment
On a 100-workload Starter plan, this environment is shown at 140% utilization. DI does not reduce a cloud-native estate to a low utilization percentage simply because much of the workload runs in Lambda, containers, or managed services.
Count the Protected Runtime Without Counting the Same Capacity Twice
Aegisify uses workload deduplication so customers are not billed once for an application workload and then again for the infrastructure that exists only to host it.
Virtual Machines
An active standalone EC2 instance counts as one workload. If an EC2 instance is identified as an ECS or EKS worker and DI has healthy task/pod inventory, the worker node is backing infrastructure and is not added again on top of those application workloads.
Containers and Kubernetes
A running ECS/Fargate application task or active EKS application pod counts as one workload. Completed or terminated workloads, platform/system pods, and sidecars inside the same Kubernetes pod do not create separate Protected Workloads.
Serverless
Each active in-scope Lambda function counts as one workload. Dormant and deleted functions are removed according to the published activity and coverage rules instead of remaining billable indefinitely.
Managed Data and Application Runtimes
Active database, search, streaming, cache, application, and supported AI/runtime resources can count as workloads when the published billing catalog classifies them as active managed runtimes. Cluster shells and objects already represented by counted runtime nodes are not added again.
The DI Dashboard Uses the Same Meter the Contract Uses
Capacity is based on sustained protected usage, not a low month-end snapshot that can hide autoscaling, container, or serverless activity.
140%
140 measured workloads / 100 licensed workloads
DI can show 80%, 90%, 100%, and over-capacity states so customers see growth before and after the contracted ceiling is reached.
The planned billing meter samples protected workload usage regularly and uses sustained high-percentile usage for the billing period. This prevents one short autoscaling spike from creating a surprise tier change while also preventing recurring high usage from disappearing into a low monthly average.
Predictable Cloud Intelligence Pricing
DI AWS is sold as an annual subscription. Capacity is measured from Aegisify Protected Workloads across the protected AWS estate. Volume pricing is already built into each tier.
Up to 100
$18,000
per year
Up to 300
$36,000
per year
Up to 500
$54,000
per year
Up to 1,000
$90,000
per year
1,001+
Custom
volume agreement
Not Every AWS Resource Becomes Another Protected Workload
Protected Workloads measure active execution and managed-service capacity. Supporting infrastructure still participates in DI intelligence without becoming a separate workload every time DI discovers another configuration object.
These resources can participate in inventory, digital-twin relationships, drift, evidence, contextual risk, attack paths, and investigations. They remain included context unless the published Protected Workload catalog classifies the resource itself as an active runtime or managed workload.
Aegisify Pricing Does Not Replace the AWS Bill
DI integrates with AWS-native security and telemetry services instead of recreating them. The customer keeps ownership of those services and pays AWS directly for the AWS usage they enable.
Common Questions About Aegisify DI Billing
Why does Aegisify use Protected Workloads instead of charging per AWS account?
Two AWS accounts can be radically different in size. One may contain a handful of resources while another runs hundreds of functions, containers, databases, and managed services. Protected Workloads measure the protected estate instead of the number of account containers.
Is an Aegisify Protected Workload the same as an AWS Security Hub Resource Unit?
No. AWS Security Hub uses a simplified Resource Unit model for its own pricing. Aegisify Protected Workloads are a separate commercial meter. DI counts active execution and managed-service workloads more directly so a serverless- or container-heavy environment is not understated on the DI utilization dashboard.
Does every AWS resource become a workload?
No. Supporting resources such as security groups, subnets, routes, KMS keys, CloudTrail configuration, and many other control-plane objects remain included security context. Active compute, serverless, application containers, managed runtimes, monitored image coverage, and identity coverage drive the Protected Workload meter.
Will a container running on EC2 be charged twice?
No when DI has sufficient inventory to identify the relationship. Container worker infrastructure is deduplicated from the application workload layer. If task/pod visibility is temporarily unavailable, DI uses a documented fallback and marks the meter degraded instead of incorrectly reporting zero usage.
How is my utilization percentage calculated?
The dashboard uses the same versioned Protected Workload meter used for billing and true-up. A customer with 140 measured Protected Workloads on a 100-workload plan is shown at 140% utilization, not capped at 100%.
Are AWS Security Hub, GuardDuty, Inspector, Macie, or CloudWatch charges included?
No. AWS-native service charges remain on the customer’s AWS bill. Aegisify charges for DI’s Digital Intelligence service and does not hide AWS usage charges inside the Protected Workload price.
What happens if my AWS environment grows past my licensed workload tier?
DI shows capacity utilization as the protected environment grows. Sustained usage above the contracted capacity moves through the applicable billing or contract true-up process rather than silently reducing security coverage. Brief isolated bursts are not intended to create a surprise tier change.
How can Aegisify AI help?
Ask about Aegisify or WordPress: errors, plugins, security, SEO, compatibility, troubleshooting, comparisons, or launch a free website scan.
