Full mallcop functionality at every tier. Bring your own API key for $0, or let us handle inference for less than you'd pay Anthropic directly.
Mallcop runs on donuts. Scanning and detection are free. Investigations cost donuts.
Quick check: is this finding normal or does it need a closer look?
Triage + basic investigationMultiple guards coordinate to investigate a suspicious finding together.
Multi-agent investigationDeep dive across event history and cross-finding correlation.
Deep investigationMallcop drafts an improvement and tests it against your real history. A new rule costs ~7🍩. A prompt overhaul costs ~55🍩.
Self-improvement + validation. See breakdownConnectors and events are unlimited on every tier. Scanning and detection are always free.
Mallcop monitors for anomalies. It does not guarantee detection of all security threats.
Mallcop is not SOC 2, ISO 27001, or FedRAMP certified. See Privacy and Security for our current compliance posture.
You choose your comfort level. We route accordingly.
All models, including Chinese-origin models on the Open tier, run on AWS Bedrock in US regions. Your data does not leave AWS infrastructure.
| Tier | Multiplier | Providers |
|---|
Every plan grants access to all three operation modes. How deep you go determines how many donuts each call consumes.
A quick patrol (triage) consumes donuts at the baseline rate. A standard investigation costs 2× per call. A deep heal-mode investigation costs 5×. These multipliers apply on top of your sovereignty tier (Open / Allied / US-only).
| Mode | Multiplier | What it does |
|---|---|---|
| Patrol (triage) | 1× | Quick check — is this finding normal or does it need a closer look? |
| Investigation | 2× | Standard investigation with full context and correlation. |
| Heal | 5× | Deep investigation that can propose parser fixes for log-format drift. |
Example: a heal call on the Allied sovereignty tier costs 5× × 1.3× = 6.5× the base inference rate.
See what you'd pay on each tier vs. bringing your own Anthropic key.
Managed tiers route to optimized models at lower cost per token.
mallcop upgrade handles tier changes. Upgrade mid-cycle and your new donut
allocation starts immediately. Downgrade takes effect at the next billing cycle.