Pricing
Simple, honest pricing.
Pricing scales with monitored assets, not seats. The same dark-web corpus the €100,000+ vendors ship — priced an order of magnitude lower. Cancel any time below Enterprise.
Observer
Anyone, no account
The public observatory. Read-only.
- Full dossier access (470+ operators · 38k+ victims)
- Daily Pulse, Atlas and Research articles
- Universal lookup (domain, wallet, email, CVE)
- Free API key: 50 requests / day
Pro
Researchers · journalists · solo analysts
Asset monitoring + alerts for one person.
- Everything in Observer
- API: 300 requests / day
- 10 Monitored Assets
- Real-time alerts · email + webhook · Slack / Discord / Teams
- CSV / JSON export of any page
- Saved searches with email digest
Team
Security teams · MSSPs · small security functions
Shared watchlists across the team.
- Everything in Pro
- API: 1,000 requests / day
- 50 Monitored Assets
- Up to 10 team seats
- Shared watchlists across the team
- Quarterly AI-written sector briefing
Enterprise
CISOs · threat intel teams · large security organisations
Production-scale corpus, SLA, custom integrations.
- Everything in Team
- API: 7,000 requests / day
- 200 Monitored Assets
- Up to 100 team seats (custom above)
- SLA + dedicated support
- Custom integrations on request
All paid plans are billed through Orizon SSO. VAT charged where applicable. Annual = 2 months free (~17% off). Switch plans anytime; upgrades are prorated.
Comparison
How we compare.
Published or commonly reported annual list prices for dark-web intelligence and credential-monitoring vendors. Darkfield ships the same corpus categories at €228–€5,988/year vs €20k–€250k+ for the legacy stack.
| Vendor | ~ Annual list | Primary coverage | Notes |
|---|---|---|---|
| Darkfield Observer | €0 | Read-only public corpus | No card required |
| Darkfield Pro | €228 | 10 monitored assets | this page |
| Darkfield Team | €948 | 50 monitored assets | this page |
| Darkfield Enterprise | €5,988 | 200 monitored assets | this page |
| Have I Been Pwned Pro | $3,288~$2.3k saved vs Team | Stealer logs + bulk domain | Credentials only |
| Snusbase / DeHashed | $60–$200 | Lookup only | No monitoring |
| IntelX | $3,000+~$2.1k saved vs Team | Phonebook + breaches | Lookup-centric |
| SOCRadar Pro | $94,800~$94k saved vs Team | Dark web + brand | $7,900/mo published |
| Flare | $20,000+~$19k saved vs Team | Dark web + leak sites | Custom quote, starting |
| ZeroFox | €70,000+~$69k saved vs Team | EASM + dark web | EASM via Orizon RECON |
| SpyCloud | $50,000+~$49k saved vs Team | Credentials + identity | Enterprise estimated |
| KELA / Group-IB / Intel 471 | $75,000–$250,000+~$149k+ saved vs Team | Full TI suite | Enterprise quote |
| Recorded Future / Flashpoint | $100,000+~$99k saved vs Team | Full TI + analyst access | Enterprise quote |
Read-only public corpus
No card required
10 monitored assets
this page
50 monitored assets
this page
200 monitored assets
this page
Stealer logs + bulk domain
Credentials only
~$2.3k saved vs Team
Lookup only
No monitoring
Phonebook + breaches
Lookup-centric
~$2.1k saved vs Team
Dark web + brand
$7,900/mo published
~$94k saved vs Team
Dark web + leak sites
Custom quote, starting
~$19k saved vs Team
EASM + dark web
EASM via Orizon RECON
~$69k saved vs Team
Credentials + identity
Enterprise estimated
~$49k saved vs Team
Full TI suite
Enterprise quote
~$149k+ saved vs Team
Full TI + analyst access
Enterprise quote
~$99k saved vs Team
Source: vendor public pricing pages where published; otherwise commonly reported list prices in analyst summaries (Gartner, Forrester) and security-team RFPs from 2024–2026. Savings calculated vs Darkfield Team (€948/yr). Coverage column reflects what each tool is marketed for, not feature parity.
Need EASM + IASM too?
Darkfield is dark-web only on purpose. External + internal attack- surface management lives in RECON — same Orizon family, same SSO. Pair the two for ZeroFox-grade coverage at a fraction of the price.
Frequently asked
Common questions.
What's an Asset?
Anything Darkfield monitors continuously for new mentions — a company domain, a corporate email pattern, a crypto wallet, a brand name. Each Asset on your plan is checked against every new leak-site post, Telegram message, breach drop and blacklist update we ingest.
How does the API quota work?
A daily cap, resets at 00:00 UTC. Soft cap by default — we never auto-bill overage. If you hit your quota we email you and you can upgrade. Pro = 2,000/day, Team = 10,000/day, Enterprise = 50,000/day (custom volumes on request).
Can I switch plans mid-cycle?
Yes. Upgrades take effect immediately and are prorated; downgrades take effect at the start of your next billing period. All managed through your Orizon SSO Billing tab.
How does annual billing work?
Toggle Annual above and pay for 10 months — 2 months free, roughly 17% off the monthly rate. Billed once a year via Orizon SSO. Same plan benefits, no other changes.
Is there a free trial of Pro?
Observer is free forever and covers the public corpus. Pro adds asset monitoring and alerts — if you need a 14-day trial of those features for evaluation, email .
How does this compare to SpyCloud / Flare / KELA?
We cover the same source categories (ransomware leak sites, credential dumps, Telegram, Tor) at €228–€5,988/year vs €20k–€250k+. We do not yet ship the analyst-services layer those vendors bundle — if you need human-written briefings on demand, Enterprise includes a quarterly one.
Ready when you are
Start watching the dark web in 30 seconds.
Sign in with Orizon SSO and pick a plan. Free Observer access, no card required.
Get started
