A Fortify 24x7 brand. Detection engineering and analyst response, run from a staffed security operations center.Client sign inContact
S1XDR
Managed XDR platform

Telemetry in.Verdicts out.Remediation included.

S1XDR is one package: the SentinelOne Complete agent on the endpoint, Fluency correlating five telemetry planes behind it, and a 24x7 security operations center staffed by people whose shift does not end. Fortify-XDR+ is the tier where those analysts stop forwarding findings and act on the host themselves.

SentinelOne Complete on every tier Five planes, one verdict Analysts on shift, not on call
Detection pipeline: five telemetry sources feed a three-layer detection stack, which resolves each signal into a benign, contained, or remediated verdict. ENDPOINT EMAIL CLOUD NETWORK IDENTITY BEHAVIORAL AI STATIC + RUNTIME MODELS CORRELATION FLUENCY CROSS-LAYER ANALYST TRIAGE 24x7 SOC SHIFT BENIGN, CLOSED CONTAINED REMEDIATED 01 COLLECT 02 DETECT AND TRIAGE 03 RESOLVE XDR+ CARRIES STAGE 03 ON YOUR BEHALF
Coverage5 telemetry planes correlated
Shift model24x7, every day of the year
0 Telemetry planes folded into one correlated verdict
0 Detection tiers, three of them Kubernetes agent variants
24x7 Analyst shift coverage with no rota of your own to staff
0 Add-on modules that ride the same monthly invoice
Operated by Fortify 24x7 Payments handled by Stripe Published per-endpoint rates No seat minimum 14-day refund window
What the package is

Three components. One rate per endpoint.

Most buyers already own an EDR console. What they do not own is the second half: something that reads the rest of the estate, and somebody awake at 04:00 to decide what the alert means.

01 / SENSOR

SentinelOne Complete on the endpoint

The agent runs static and behavioral models locally, so conviction does not wait on a cloud round trip and does not stop when the laptop leaves your network. It carries next-generation antivirus and full EDR telemetry, records the process lineage behind a detection, and holds the rollback capability that makes a ransomware event survivable rather than final.

Vendor: SentinelOne · Included at MDR, XDR and XDR+
02 / ANALYTICS

Fluency across the other four planes

An endpoint alert on its own is a fragment. Fluency ingests email, cloud workloads across AWS, Azure and GCP, network traffic, and Active Directory alongside the agent stream, then joins them on shared entities so one attack path appears as one case. This is the layer that separates XDR from a well-tuned EDR console, and it starts at the Fortify-XDR tier.

Vendor: Fluency · Included at XDR and XDR+
03 / ANALYSTS

A security operations center already staffed

Fortify 24x7 runs the shift rota, the hunting queue, and the escalation path. Every tier is monitored around the clock. At Fortify-XDR+ the mandate widens: our analysts perform direct remediation on identified events rather than writing them up and waiting for your morning.

Operated by Fortify 24x7 · Monitoring at every tier
Pipeline

What happens between the signal and the silence.

Five stages, in order, every time. The tier you buy decides how far along this sequence the service carries the event before it reaches a human on your side.

01

Collect

Agent telemetry, mail flow, cloud control planes, network sessions, and directory events arrive continuously and are normalized to a common schema.

02

Detect

Behavioral models score process lineage on the endpoint itself. Conviction happens locally, which is why a disconnected laptop still defends itself.

03

Correlate

Signals sharing a user, host, address, or session are joined into a single case, so a phishing click and the process it spawned stop being two unrelated alerts.

04

Triage

An analyst on shift reads the case, discards the noise, and assigns a verdict. Nothing reaches you carrying the phrase "possible activity detected".

05

Act

Isolate the host, kill the chain, revoke the session, roll the change back. At XDR+ this stage is ours to execute. Below it, the same step is yours.

Detection tiers

Six SKUs. One decision: where does the work stop being ours?

Every tier ships the same agent and the same round-the-clock watch. What changes is how much of the estate is correlated, and whether the response is performed for you. Quantity is your endpoint count, or your node count on the Kubernetes rows.

The live rate table did not load. Reload the page, and if the catalog is still unreachable write to our team for a quotation in writing.

Loading published rates

Add-on modules

Everything else is optional, and priced on its own line.

Eighteen modules across five families. None of them are bundled into the detection tiers, none of them are required, and each one bills per unit on the same monthly subscription.

Loading module catalog

Deployment

From checkout to first conviction.

Agent rollout is the only task that needs anyone on your side, and it is a package push. Everything after that is our shift, not yours.

STEP 01

Configure and subscribe

Pick the tier, enter your endpoint count, add whichever modules you want, and check out. Stripe handles the payment surface; no card data reaches this site or our systems.

STEP 02

Tenant, agent, connectors

We stand up your console tenant and issue signed agent packages for Windows, macOS, Linux, and Kubernetes as applicable. On XDR tiers we also send the connector authorizations that bring email, cloud, network, and directory telemetry into correlation.

STEP 03

The watch begins

Telemetry lands, the models learn your baseline, and the SOC picks up the queue. You receive escalations that have already been triaged, and at XDR+ you receive them with the action already taken.

FORTIFY 24X7

Heads up: card statements show FORTIFY 24X7 - S1XDR is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Configuration 0 lines configured $0.00/mo