Cybermatic Endpoint Protection
Malware detected. AI explains it. You end it — in one click.
The agents you already run become AI-powered EDR across Windows, Linux, and macOS. Malware is caught on disk and suspicious behavior is caught as it happens — a shell spawned by a web server, execution from a temp path, a new privileged account. Every detection arrives triaged with a plain-English verdict, and kill, quarantine, isolation, and remote wipe are one click away.
Per-endpoint pricing · Unlimited users · Same agent you already run · Nothing charged until day 14
How it works
From suspicious process to closed case
1 · Protect
Flip a device's toggle in the portal. Protection activates on the agent's next check-in — no new install, no reboot.
2 · Detect
The protection engine and Cybermatic's own detections watch process execution, files, and behavior — in Active or Monitor mode, your call per device.
3 · Understand
AI triages every detection into a verdict in plain English: what ran, what it touched, whether it matters, and what to do.
4 · Respond
Kill the process, quarantine the file, isolate the device, launch a scan, or remote-wipe a lost or stolen device — one click, executed on-device within about a minute, fully audit-logged.
The response toolkit
Every action you need when it's real
Kill process
Terminate the malicious process by PID or name — straight from the detection page that identified it.
Quarantine file
The file moves to a local encrypted store on the endpoint. It never leaves the customer's machine — only hash, path, and verdict reach the portal.
Network isolation
Cut the device off from everything except Cybermatic — attackers lose their foothold, you keep remote control. Un-isolate is one click.
Remote wipe (Growth+)
Laptop lost or stolen? Wipe it from the portal. Encrypted disks are cryptographically erased in seconds; the device is isolated first, and every wipe is audit-logged. Servers get a second confirmation and a cancel window.
Monitor mode
Fragile server? Change-controlled fleet? Detect and alert without touching anything — per device or workspace-wide.
Policy that scales
One workspace default, per-device overrides. Flip the whole fleet to monitor-only in one click, or exempt a single machine.
Immutable audit log
Every action records who requested it, when, and how it completed — the paper trail auditors and insurers ask for.
Why teams choose Cybermatic
EDR you'll actually run — without hiring for it
AI triage, not alert soup
Enterprise EDR buries small teams in raw telemetry. Every Cybermatic detection arrives already explained — severity, meaning, recommended action.
One agent for everything
Posture, SIEM logs, and endpoint protection ride the same lightweight agent. One install, one login, three products you can add independently.
Per-endpoint, not per-person
Flat tiers priced by protected device, unlimited portal users, and unprotected enrolled devices cost nothing. No per-seat surprises at renewal.
Endpoint Protection pricing
Flat tiers, priced per endpoint. Users are free.
Every plan: AI triage, the full response toolkit, workspace + per-device policy, the audit log, and unlimited portal users. Annual billing = 2 months free.
Starter
$29 /mo
billed monthly
Real protection for the smallest teams — the laptops your whole business runs on.
- Protect up to 5 endpoints ($5.80/device)
- Windows, Linux, and macOS — same agent you already run
- AI-triaged detections with plain-English verdicts
- One-click kill, quarantine, and network isolation
- Active or monitor-only mode, per device
- Unlimited portal users
- 14-day free trial — card required, $0 today
Growth
$79 /mo
billed monthly
The right fit for growing companies: full EDR response across the whole fleet.
- Protect up to 15 endpoints ($5.27/device)
- Everything in Starter
- Workspace default policy + per-device overrides
- 90-day detection history and full response audit log
- Isolation keeps devices remotely recoverable
- Remote wipe for lost or stolen devices
- Unlimited portal users
- 14-day free trial — card required, $0 today
Pro
$179 /mo
billed monthly
Security-team scale — response actions land in under a minute, fleet-wide.
- Protect up to 35 endpoints ($5.11/device)
- Everything in Growth
- Questionnaire Copilot (100/yr) & public Trust Center
- Command channel: isolate / kill / scan in ≤60 seconds
- Detections feed straight into Cybermatic SIEM offenses
- Priority support
- Unlimited portal users
- 14-day free trial — card required, $0 today
Business
$449 /mo
billed monthly
Serious fleets with a fixed, predictable bill — no per-seat surprises at renewal.
- Protect up to 100 endpoints ($4.49/device)
- Everything in Pro
- Questionnaire Copilot (250/yr) & Trust Center with NDA vault
- Priority support
- Guided Deployment included with annual billing
- Unlimited portal users
- Billed from day one (no trial)
Enterprise — 100+ endpoints
Volume pricing sized to your fleet, dedicated success manager, written 99.9% SLA, MSA/DPA/BAA, invoicing and PO terms, custom retention, Quarterly Security Reviews and Guided Deployment included, early access to new features. Same agent, same one-minute response, at any scale.
Already a Cybermatic customer? Add Endpoint Protection from its settings page — one click on your saved card.
Professional services
Expert implementation, and a security professional on your calendar
Guided Deployment
$2,500 · included with annual Business & Enterprise
Full standard deployment in 6–8 expert hours: integrations, endpoint rollout, EPP policy profiles configured for your device classes, up to five SIEM/syslog sources, your first Insurance Readiness and board reports, and a 30-day review.
Quick Start
$750
One environment connected, agents deployed, initial configuration done — the guided first hour for smaller teams.
Quarterly Security Review
$950 · $3,000/yr · included with Enterprise
Each quarter a security professional reviews your data and delivers a written review with a 90-day action plan you can hand to leadership, your board, or your insurer.
Purchased from your workspace's Settings page, so we can schedule against your real environment. All services and details →
Common questions
- Can Cybermatic help with customer security questionnaires and a trust page?
- Yes — on Growth and above (Posture) or Pro and above (SIEM, Endpoint Protection). Questionnaire Copilot drafts answers from live evidence, your approved policies, and an Approved Answer Library, marking each as Verified, Document-supported, or Attestation required, and flags any reused answer that now conflicts with current evidence. The Trust Center publishes a public page with controls measured live by Cybermatic, published policies, and documents released under a click-through NDA with recorded acceptance.
- Do I need new agents?
- No. If you run Cybermatic Security Posture Management or SIEM, the same agents power Endpoint Protection — flip a device's toggle and protection activates on its next check-in. New customers install one agent per device; it does every job.
- What does 'Active' vs 'Monitor' mode mean?
- Active mode arms automatic engine responses (block, quarantine) and every response tool. Monitor mode detects, triages, and alerts — but touches nothing automatically. Set the workspace default in one click and override per device, so a fragile server can watch-only while the fleet stays armed.
- What is network isolation, exactly?
- Isolation blocks all traffic on the device except to Cybermatic's own endpoints — the machine is cut off from your network and the internet, but stays remotely visible and recoverable from the portal. Un-isolate is one click. Response commands land in about a minute.
- What happens to quarantined files?
- They stay on the device, in a local encrypted quarantine store. Only metadata — hash, path, verdict — reaches Cybermatic. Your files never leave your machines.
- What engine runs on each operating system?
- Windows uses managed Microsoft Defender. Linux uses managed ClamAV for malware plus auditd for behavioral detections — shells spawned by network services, execution from world-writable paths, sudoers and account changes, audit-log tampering. macOS uses the Cybermatic Endpoint Security extension for real-time process behavior. Same agent, same portal, same one-click response across all three.
- Can I wipe a lost or stolen device?
- Yes, on Growth plans and above. From the device page an owner or admin types the hostname to confirm, and Cybermatic isolates the device and erases it. Encrypted disks (BitLocker, LUKS, FileVault) are cryptographically erased in seconds and are unrecoverable; unencrypted disks get a best-effort wipe with a warning. Servers require a second confirmation and get a 60-second cancel window. macOS wipes the data and disables FileVault; a full factory erase there needs MDM. Every wipe is in the immutable response audit.
- What counts as an endpoint?
- A device with protection toggled on. Agent-enrolled devices with protection off cost nothing — enroll your whole fleet for posture visibility and protect the subset you pay for. The seat meter shows exactly where you stand.
- How many people can use the portal?
- Unlimited — admins and viewers alike. Endpoint Protection is priced per protected endpoint, never per person. Roles are per product: someone can run Endpoint Protection with no SIEM or posture access at all.
- How does the trial work?
- 14 days on Starter, Growth, or Pro — a card is required but nothing is charged until day 14, and canceling before then costs nothing. The trial runs at the full limits of the tier you pick and converts automatically. One trial per workspace; Business and Enterprise bill from day one.
- Does it work with Cybermatic SIEM?
- Beautifully. Detections carry full context — process, user, file hash — into the same platform your logs live in, and Copilot reasons across both. Run either alone, or both on one agent, one login, one bill.
- What happens if I cancel?
- Protection deactivates within one check-in, devices return to their native defaults, and your detection history is retained 30 days in case you return. Your other Cybermatic subscriptions are completely unaffected.
Not ready for a trial? Run a free security scan — your score in 10 minutes, no card.