LICENSEWARE

Arctic Wolf MDR, bundles and Security Operations Warranty

This article is about how Arctic Wolf packages and licenses Aurora Managed Detection and Response, Aurora Vulnerability Management, Data Explorer, the Core, Plus and Total Security Operations Bundles, Concierge Security Tiers, the Security Operations Warranty and Incident360 Retainers. For endpoint products and security awareness training, see the separate articles.

On This Page

Aurora Managed Detection and Response (MDR) is Arctic Wolf’s core security operations service. Arctic Wolf’s Security Services monitor customer logs and telemetry collected through sensors, the Arctic Wolf Agent and third-party integrations. MDR can be licensed on its own or as part of a Security Operations Bundle.[1] Aurora Vulnerability Management (AVM), formerly Managed Risk (MR), is the companion vulnerability scanning service and follows the same pattern.[2] Arctic Wolf publishes no price list for either service. What is published is the list of included components, the add-ons that can be licensed separately, the Bundle definitions and the warranty program tied to them. Incident response readiness is sold separately as Incident360 Retainers. For the contract framework, see Arctic Wolf General Terms and partner terms.

Editions

MDR components. The MDR Supplemental Product Terms list four components. Software covers the object code of the software, including software on Equipment. Equipment means virtual network appliances (vSensor) or physical sensors (Sensor). Services covers support, onboarding, Security Services and the Cyber Resilience Assessment. The Platform covers one vSensor 100 series, unlimited data ingestion, Unified Portal access, the Arctic Wolf Agent, optional ITSM ticketing integrations, and 90-day log retention unless another retention period is bought on the Order Form.[1] Catalog: MDR includes unlimited data ingestion, one vSensor 100 and 90-day log retention; vSensor 100 series.

AVM components. AVM has the same structure. Its Equipment is virtual network appliances (vScanner) or physical scanners (Scanner), and its Platform also includes unlimited data ingestion.[2] The MDR Product Description adds that Scanners are included with a subscription as set out on the Order Form.[4] The Product List classes MDR, AVM, ASAT and Aurora MDR Connect (for MSPs only) as Security Operations Products. All their add-on features fall in the same class.[12]

Separately licensed MDR features. The MDR Product Description names several features that appear on the Order Form only if bought:

  • Cloud Detection and Response (CDR) for AWS, Microsoft Azure and other supported IaaS and SaaS environments.[4]
  • Data Explorer, which gives access to historical event and observation data and Raw Log Search. Raw Log Search is now offered only within Data Explorer.[4]
  • Threat Intelligence, in a base and a “Plus” version.[4]

Metrics

The MDR and AVM terms do not name a per-unit metric. The quantity comes from the Order Form metric under the General Terms. In the Unified Portal’s licence details, MDR and AVM entitlements appear as counts such as protected users, sensors, scanners or log collectors.[11] Catalog rows: Order Form licensing metric, Sensor (vSensor), Scanner (vScanner) and Data ingestion.

Data Explorer licences are measured in days of searchable data. Data Explorer Lite searches analyzed data from the last three days. A full licence offers 14, 30 or 90 days and adds custom alerts and Raw Log Search.[5] The licence also sets the time ranges shown in Unified Portal widgets and dashboards.[5] Legacy Data Explorer customers moved from a 10-day window to the DE-14 tier.[4] Catalog: Data Explorer Lite, Data Explorer (14-, 30- or 90-day license); rule Data Explorer licence sets the searchable data window.

Counting / floors

Log volume. Because MDR and AVM include unlimited data ingestion, adding log sources does not change the licence quantity.[1][2] What can change cost is retention beyond 90 days, which is bought on the Order Form, and the Data Explorer window.[1][5]

Coverage. The MDR Product Description recommends at least 85% endpoint coverage within the environments included in the subscription.[4] This is a service recommendation, not a licence floor. Coverage does matter for the warranty and for retainers (see Programs).

AVM assets. Assets discovered by AVM scans can be marked inactive. If no scan source rediscovers an inactive asset, it is removed after 120 days. An Arctic Wolf Agent, an internal scanner or another source can bring it back.[10] Catalog: Inactive AVM assets drop out after 120 days unless rediscovered.

Equipment. If sensors or scanners are not returned within 90 days after use ends or the agreement ends, the customer owes their replacement cost. Arctic Wolf deletes customer Confidential Information when the Equipment is returned or 120 days after expiry, whichever comes first.[1][2] Catalog: Equipment must be returned within 90 days or paid for.

Virtualization & partitioning

There are no processor, core or partitioning rules. Virtual sensors (vSensor) and virtual scanners (vScanner) are Equipment, just like physical devices.[1][2]

Cloud / BYOL

Customer data is stored in the third-party data centres for the Platform location on the Order Form.[1] Cloud workloads are covered by the separately licensed CDR feature.[4] For Microsoft US Government Community (GCC) environments, the MDR terms state that Arctic Wolf is not FedRAMP compliant. They also state that only supported, integrated applications are monitored there.[1]

Programs

Security Operations Bundles

Bundle Elements[3] Security Operations Warranty[3] 
Core MDR; Data Explorer Lite for MDR USD 100K with a three-year Committed Term 
Plus MDR; Data Explorer Lite; AVM USD 500K (one-year term) or USD 1M (three-year Committed Term) 
Total MDR; Data Explorer Lite; AVM; ASAT tier; JumpStart Retainer USD 750K (one-year term) or USD 1.5M (three-year Committed Term) 

For Plus and Total, a two-year Committed Term may qualify for the one-year warranty level in each annual period, at Arctic Wolf’s discretion. In the Total Bundle, ASAT+ or ASAT CCP can be licensed for an additional fee.[3] Catalog: Warranty level depends on the Bundle and the committed term.

Concierge Security Tiers

Every Bundle includes a Concierge Security Tier, and the customer buys the tier it chooses. All three tiers include a Concierge Security Team and 24x7x365 SOC availability.[3] Silver includes four Security Touchpoints a year, Gold twelve and Platinum eighteen. In each case four of them are delivered with the quarterly business review. Each higher tier also adds more Security Posture In-Depth Reviews (SPiDRs).[3]

Security Operations Warranty

An Order Form can include the Security Operations Warranty, but signing the Order Form does not enroll the customer. The customer must enroll through the warranty provider’s link, receive a confirmation and accept the Subscriber Terms.[7] Catalog: Warranty requires separate enrollment. The warranty covers Participants with MDR, Managed Risk, Managed Security Awareness or Aurora Managed Endpoint Defense (AMED).[6] Benefits are paid for qualifying events such as ransomware, business email compromise, compliance, business income and cyber legal liability events. These events must occur in an Environment where the Solutions are deployed.[6] For AMED-level benefits, AMED must be fully deployed within 45 days of the Order Form.[6] Catalog: AMED warranty benefits need full deployment within 45 days. If product subscriptions change during the term, the warranty amount may change and the customer may need to re-enroll.[3]

Incident360 Retainers

The Incident360 Retainer terms cover three subscriptions: JumpStart Retainer, Incident360 Retainer and Incident360 Plus Retainer.[8] The Product Description compares them:[9]

Feature JumpStart Incident360 Incident360 Plus 
Scoping-call response SLA 4 hours 3 hours 3 hours 
Covered Incident engagements 0 1 1 
Threat Intelligence reports No Yes Yes 
Readiness Touchpoints 0 0 3 

Hourly IR engagements are charged at USD 325 per hour. Any hourly engagement, including Business Email Compromise, must be for at least 25 hours. The Rapid Response add-on shortens the SLA to one hour and lowers the rate to USD 295.[9] Catalog: IR Services hour; Hourly IR engagements have a 25-hour minimum.

The endpoint count on the Order Form matters for retainers. A Covered Incident cannot be used if Arctic Wolf finds that the customer’s actual endpoint count is materially greater than ordered; the engagement is then billed hourly. For a standalone retainer, a Covered Incident does not apply to incidents before, or within 10 days of, accepting the Order Form in the initial term. It also does not apply where the event starts in an environment or on an endpoint without Arctic Wolf solutions or another up-to-date prevention tool. Ransom payments are never included.[8] Catalog: Covered Incident is lost if actual endpoints materially exceed the Order Form.

Trial Access

AVM may be offered as Trial Access for 30 days from activation, for evaluation only, as is and without support.[2] Catalog: Trial Access.

Out of scope

This article does not cover the Scope of Service, response-time objectives, supported log sources, Aurora Attack Surface Management, IR Services statements of work, or MSP pricing for Aurora MDR Connect. Security awareness training and Aurora Managed Endpoint Defense are covered in Arctic Wolf security awareness and training licensing and Arctic Wolf Aurora Endpoint Security licensing.

References

  1. Aurora Managed Detection and Response Supplemental Product Termss.1.1 Components; s.2.2 data storage; s.3 Termination; s.4 GCC monitoring. Last Updated 2026.08.Retrieved 2026-10-02.
  2. Aurora Vulnerability Management Supplemental Product Termss.1.1 Components; s.3 Termination; s.4 Trial Access. Last Updated 2026.08.Retrieved 2026-10-02.
  3. Security Operations Bundle & Tier DescriptionsBundle elements, warranty levels and Concierge Security Tiers. Last Updated 2026.05.Retrieved 2026-10-02.
  4. Arctic Wolf product descriptions (Managed Detection and Response Product Description)MDR-PD PDF linked from the product descriptions page. Cover shows Last Updated 2025.05; change history lists v1.4 as 2025.10.Retrieved 2026-10-02.
  5. Data Explorer license optionsLast updated October 1, 2026.Effective 2026-10-01. Retrieved 2026-10-02.
  6. Subscriber Terms for Arctic Wolf Security Operations WarrantyDefinitions; eligibility; Schedule 1 Recovery Benefit levels. Last Updated 2025.05.Retrieved 2026-10-02.
  7. Arctic Wolf Networks General Terms and Conditionss.1.7 Security Operations Warranty. Last Updated 2026.08.Retrieved 2026-10-02.
  8. Aurora Incident360 Retainer Supplemental Product Termss.2.2 Covered Incident; s.3 engagement. Last Updated 2026.08.Retrieved 2026-10-02.
  9. Arctic Wolf product descriptions (Incident360 Retainer Product Description)I360-PD v1.5 PDF linked from the product descriptions page. Last Updated 2025.11.Retrieved 2026-10-02.
  10. Mark assets as inactive (Arctic Wolf Unified Portal)Last updated September 2, 2026.Effective 2026-09-02. Retrieved 2026-10-02.
  11. View subscriptions (Arctic Wolf Unified Portal)Last updated April 21, 2026.Effective 2026-04-21. Retrieved 2026-10-02.
  12. Arctic Wolf Product ListLast Updated August 13, 2026.Effective 2026-08-13. Retrieved 2026-10-02.

See also

Catalog Rows Cited

9Rules4SKUs6Metrics7Programs

Esc