Aegisify company logo
Cloud Digital Intelligence Pricing2026-09-23T22:39:30+00:00
Aegisify Digital Intelligence — AWS IaaS Billing

Protected Workload Pricing for AWS Digital Intelligence

Aegisify Digital Intelligence for AWS IaaS is billed by Aegisify Protected Workloads measured across the active cloud estate. The model is designed to reflect modern AWS environments spanning virtual machines, serverless, containers, managed runtimes, images, and identity coverage.

Clear scope. Clear meter. Visible utilization. See what counts toward AWS DI capacity, how close the environment is to its licensed tier, and which supporting AWS resources remain included as security context.

AWS IaaS Digital Intelligence

What Is an Aegisify Protected Workload?

A Protected Workload is Aegisify’s normalized measure of the active AWS execution and managed-service estate that DI protects. The model is intentionally broader than a simple EC2 count so serverless, containers, databases, and managed runtimes are not hidden from capacity utilization.

1 standalone EC2 instance
= 1 Protected Workload
1 active Lambda function
= 1 Protected Workload
1 active application ECS/Fargate task or EKS pod
= 1 Protected Workload
1 managed database / data-runtime unit
= 1 Protected Workload
18 monitored ECR images
= 1 Protected Workload
125 IAM users / roles
= 1 Protected Workload
Why the broader model? Modern AWS environments can run significant application and data workloads without large EC2 fleets. A Lambda function, application container, managed database, search cluster, streaming service, or supported managed application runtime can still carry identity, vulnerability, exposure, drift, data, and investigation context. DI measures those active workloads directly instead of using AWS Security Hub’s simplified Resource Unit formula as the customer utilization meter.

Example mid-sized AWS environment

30 standalone EC230 workloads
40 active Lambda40 workloads
35 application containers35 workloads
12 managed database runtimes12 workloads
8 managed data/search/streaming runtimes8 workloads
4 application/AI managed runtimes4 workloads
90 monitored ECR images5 workloads
750 IAM users/roles6 workloads
Protected Workload total140 Protected Workloads

On a 100-workload Starter plan, this environment is shown at 140% utilization. DI does not reduce a cloud-native estate to a low utilization percentage simply because much of the workload runs in Lambda, containers, or managed services.

Fair Counting

Count the Protected Runtime Without Counting the Same Capacity Twice

Aegisify uses workload deduplication so customers are not billed once for an application workload and then again for the infrastructure that exists only to host it.

01

Virtual Machines

An active standalone EC2 instance counts as one workload. If an EC2 instance is identified as an ECS or EKS worker and DI has healthy task/pod inventory, the worker node is backing infrastructure and is not added again on top of those application workloads.

02

Containers and Kubernetes

A running ECS/Fargate application task or active EKS application pod counts as one workload. Completed or terminated workloads, platform/system pods, and sidecars inside the same Kubernetes pod do not create separate Protected Workloads.

03

Serverless

Each active in-scope Lambda function counts as one workload. Dormant and deleted functions are removed according to the published activity and coverage rules instead of remaining billable indefinitely.

04

Managed Data and Application Runtimes

Active database, search, streaming, cache, application, and supported AI/runtime resources can count as workloads when the published billing catalog classifies them as active managed runtimes. Cluster shells and objects already represented by counted runtime nodes are not added again.

Capacity Utilization

The DI Dashboard Uses the Same Meter the Contract Uses

Capacity is based on sustained protected usage, not a low month-end snapshot that can hide autoscaling, container, or serverless activity.

Example: Starter Capacity
140%
140 measured workloads / 100 licensed workloads
Usage remains visible above 100%
DI can show 80%, 90%, 100%, and over-capacity states so customers see growth before and after the contracted ceiling is reached.

The planned billing meter samples protected workload usage regularly and uses sustained high-percentile usage for the billing period. This prevents one short autoscaling spike from creating a surprise tier change while also preventing recurring high usage from disappearing into a low monthly average.

One source of truth: the utilization dashboard, capacity alerts, true-up workflow, quote calculation, and invoice calculation must use the same versioned Protected Workload formula.
DI AWS Pricing

Predictable Cloud Intelligence Pricing

DI AWS is sold as an annual subscription. Capacity is measured from Aegisify Protected Workloads across the protected AWS estate. Volume pricing is already built into each tier.

Starter

Up to 100

$18,000
per year

Business

Up to 500

$54,000
per year

Enterprise

Up to 1,000

$90,000
per year

Enterprise Plus

1,001+

Custom
volume agreement

No Aegisify per-user fee
No Aegisify per-account fee
No Aegisify per-Region fee
No Edge Agent license fee
No Aegisify raw-log ingestion fee
AWS-native services remain customer-owned
Included Security Context

Not Every AWS Resource Becomes Another Protected Workload

Protected Workloads measure active execution and managed-service capacity. Supporting infrastructure still participates in DI intelligence without becoming a separate workload every time DI discovers another configuration object.

S3 bucketsVPCsSubnetsSecurity GroupsNACLsRoute TablesLoad Balancer configurationKMS keysSecretsCloudTrailCloudWatchWAFNetwork Firewall policiesBackup configurationAWS ConfigSecurity Hub findings

These resources can participate in inventory, digital-twin relationships, drift, evidence, contextual risk, attack paths, and investigations. They remain included context unless the published Protected Workload catalog classifies the resource itself as an active runtime or managed workload.

AWS Service Charges

Aegisify Pricing Does Not Replace the AWS Bill

DI integrates with AWS-native security and telemetry services instead of recreating them. The customer keeps ownership of those services and pays AWS directly for the AWS usage they enable.

01AWSSecurity Hub, Inspector, GuardDuty, Macie, CloudWatch and related services
02DI EdgeCollects, normalizes and correlates customer-side evidence
03DI SaaSDigital Intelligence, evidence, investigations, reports and workflow
Separate charges: AWS usage fees, log processing, storage, queries, GuardDuty/Macie features, and other AWS services are not included in the Aegisify subscription unless a written order specifically says otherwise. Review current AWS pricing before enabling paid AWS capabilities.
Billing FAQ

Common Questions About Aegisify DI Billing

Why does Aegisify use Protected Workloads instead of charging per AWS account?

Two AWS accounts can be radically different in size. One may contain a handful of resources while another runs hundreds of functions, containers, databases, and managed services. Protected Workloads measure the protected estate instead of the number of account containers.

Is an Aegisify Protected Workload the same as an AWS Security Hub Resource Unit?

No. AWS Security Hub uses a simplified Resource Unit model for its own pricing. Aegisify Protected Workloads are a separate commercial meter. DI counts active execution and managed-service workloads more directly so a serverless- or container-heavy environment is not understated on the DI utilization dashboard.

Does every AWS resource become a workload?

No. Supporting resources such as security groups, subnets, routes, KMS keys, CloudTrail configuration, and many other control-plane objects remain included security context. Active compute, serverless, application containers, managed runtimes, monitored image coverage, and identity coverage drive the Protected Workload meter.

Will a container running on EC2 be charged twice?

No when DI has sufficient inventory to identify the relationship. Container worker infrastructure is deduplicated from the application workload layer. If task/pod visibility is temporarily unavailable, DI uses a documented fallback and marks the meter degraded instead of incorrectly reporting zero usage.

How is my utilization percentage calculated?

The dashboard uses the same versioned Protected Workload meter used for billing and true-up. A customer with 140 measured Protected Workloads on a 100-workload plan is shown at 140% utilization, not capped at 100%.

Are AWS Security Hub, GuardDuty, Inspector, Macie, or CloudWatch charges included?

No. AWS-native service charges remain on the customer’s AWS bill. Aegisify charges for DI’s Digital Intelligence service and does not hide AWS usage charges inside the Protected Workload price.

What happens if my AWS environment grows past my licensed workload tier?

DI shows capacity utilization as the protected environment grows. Sustained usage above the contracted capacity moves through the applicable billing or contract true-up process rather than silently reducing security coverage. Brief isolated bursts are not intended to create a surprise tier change.

Plan AWS Digital Intelligence Capacity

Match AWS Digital Intelligence Capacity to the Estate You Protect

Use versioned Protected Workload capacity for AWS IaaS with visible utilization, transparent workload definitions, and capacity alerts as the protected estate grows.