LICENSEWARE

Darktrace product lines and Usage Metrics

This article is about how each Darktrace product line is delivered and measured according to the Product Specification v1.7.0, including the former product names. It is not a feature comparison and does not state prices, which are set in the Order.

On This Page

The Darktrace Offering Product Specification is incorporated into the Master Services Agreement, so what it says about how a product is delivered and measured is part of the contract.[2] Version 1.7.0, dated 15 September 2026, covers eight product families and a section of product-agnostic details. It says it should be read with the Master Services Agreement and the applicable Product Order Form, and that where a product lacks detail the documentation in the Customer Portal applies.[1]

The public documents define the licensed unit for only one product line. For the others the quantity is the “Usage Metrics” band in the Order. This article records what the documents do say, product by product, and where they stay silent.

Summary of product lines

Product Former names Measured by (public documents) 
Darktrace / NETWORK DETECT/Network, Enterprise Immune System (detection); RESPOND/Network, Antigena (response) Usage Metrics band in the Product Order Form 
Darktrace / OT DETECT/OT, DETECT & RESPOND/OT, Industrial Immune System Not stated; ingestion rules follow NETWORK 
Darktrace / IDENTITY DETECT/Apps, RESPOND/Apps, DETECT/Zero Trust, RESPOND/Zero Trust Usage Metrics band in the Product Order Form 
Darktrace / EMAIL None stated for the product; its anomaly score was formerly “Antigena Anomaly” Not stated 
Darktrace / EMAIL-DMARC None stated Not stated 
Darktrace / CLOUD Also referred to as CLOUD (Network) and CLOUD (Identities) in some deployments Identity Workload count 
Darktrace / Forensic Acquisition & Investigation Cado Not stated 
Darktrace / SECURE AI None stated Not stated 

The former names in the table are those the Product Specification gives. For EMAIL it records only the earlier name of the anomaly score, not of the product, and for CLOUD it notes that deployments in cloud-hosted environments may in exceptional circumstances be referred to as CLOUD (Network) or CLOUD (Identities).[1]

Darktrace / NETWORK

NETWORK has two elements, Real-Time Detection and Autonomous Response. Real-Time Detection analyses network activity of devices for behaviour outside a normal state, and the output appears in the Threat Visualizer. Autonomous Response takes actions against that activity.[1] The Product Specification states that “Darktrace / NETWORK Subscriptions are sold according to the Usage Metrics bands set out in the relevant Product Order Form.”[1]

Bands, capacity and Fencing Metrics

Each deployment has a capacity set by the Usage Metrics band purchased. If the customer provided incorrect or incomplete sizing information, or allows usage to exceed the band, Darktrace bears no liability for degraded service. If actual traffic exceeds the Fencing Metrics calculated for the band, the document lists possible results: overloading, inconsistent service, delayed Autonomous Response actions, a processing queue for new traffic, packet drops and unsupervised learning being turned off.[1] It also describes a “High performance mode” that disables a subset of high-load classifiers when a system is under significant load.[1] The MSA adds the commercial side: use is limited to the Usage Metrics and additional fees are payable if they are exceeded.[2] The catalog records the unit as Usage Metrics and the technical limits as Fencing Metrics.

Licence key

Autonomous Response takes actions only when a valid License Key is configured on the Threat Visualizer’s System Config page. In Unified View environments the key propagates from the Unified View master to subordinate masters, and adding it activates Autonomous Response on all connected virtual sensors.[1] An asset record should therefore note whether response is licensed and enabled.

Darktrace / OT

OT evaluates activity across IT and operational technology environments and builds a baseline of normal behaviour from network connections and other supplied data. The ingestion and analysis sections of the NETWORK specification apply, and OT adds protocols specific to operational technology, a list of which is available on request.[1] A specialised rugged hardware Probe is available for industrial environments unsuitable for standard hardware.[1]

Darktrace / IDENTITY

IDENTITY modules retrieve activity logs from third-party SaaS and enterprise platforms and analyse users and entities for unusual behaviour. Some modules can respond by changing users, entities or configuration in the third-party platform.[1] Subscriptions are “sold according to the Usage Metrics bands set out in the relevant Product Order Form”.[1]

IDENTITY is available only when a valid License Key is configured; the key gives access to all available IDENTITY modules and activates Autonomous Response for modules that support it.[1] Two licensing dependencies on third parties apply. First, some third-party platforms restrict the events and APIs available behind their own licence requirements, and Darktrace states it will outline the minimum licences where possible. Second, the modules rely on specific vendor licences for events and responses, and if the required licences are absent or revoked, “degradation or interruption of service will occur”.[1] A customer that reduces a Microsoft, Salesforce or other platform licence tier can therefore reduce what IDENTITY sees.

Darktrace / EMAIL

EMAIL does not operate as a gateway or inline in the mail path. The email provider sends copies of inbound, outbound and lateral email to Darktrace for analysis, and Darktrace instructs the provider to act through the provider’s API, for example by removing or moving a message or neutralising attachments. It also provides Account Protection that reports anomalous account usage in supported systems.[1] Deployment options cover Microsoft 365, hybrid Exchange, on-premises Exchange and Gmail.[1]

Licensing prerequisites sit with the mail provider. Hybrid Exchange needs a Microsoft 365 (formerly Office 365) Business Essentials licence or above, and Darktrace / EMAIL for Google Workspace is available only to organisations with an Enterprise or Education Plus licence or above because of Google restrictions on third-party email archiving. The customer must ensure that its email provider licences are supported by Darktrace.[1] Visibility is limited to mail the provider sends: email filtered by a gateway before it reaches Microsoft or Google is not seen, and mail-enabled public folders cannot be observed.[1] The public documents do not state whether EMAIL is measured by mailbox, user or domain; that is in the Order.

EMAIL-DMARC

EMAIL-DMARC guides deployment of the DMARC standard and evaluates SPF and DKIM measures by polling public DNS records and ingesting aggregate and forensic reports from third-party mail processors for the domains the customer manages.[1] It is a separate section of the Product Specification and has no unit stated.

Darktrace / CLOUD

CLOUD enumerates the resources in a public cloud environment, analyses them for misconfiguration and compliance, retrieves user and network activity and can take response actions through cloud provider APIs.[1] It is the one product with a public usage definition: usage is calculated by reference to Identities and Workloads, which together represent the Identity Workload count.[1]

  • Identities are users with permissions to act in the cloud environment, user-like asset types and associated assets that affect identity and access management. Each counts toward the Identity count.
  • Workloads are assets that can hold metadata, originate from a supported cloud service and are not excluded, including virtual machines, compute functions, storage, messaging services, serverless instances, firewall rules and networking resources. They are weighted by computational requirements: virtual machines and compute functions are likely to amount to one Workload each, whereas a varying number of serverless instances amounts to one.[1]

Unless Darktrace excludes an asset, all identified asset types count. Darktrace states that it “reserves the right to modify the asset types classified and modify any weighting assigned to individual asset types”, and the current list of contributing asset types is available on request.[1] The count can therefore change without a change in the customer’s environment. The catalog rows are Identity, Workload and Identity Workload count.

The Cloud Schedule of the Product Specific Terms adds that CLOUD may be deployed without agents, although installing agents may improve visibility, and that integrating it may increase the customer’s cloud hosting and transfer fees, for which the customer is solely responsible.[3]

Darktrace / Forensic Acquisition & Investigation

Forensic Acquisition & Investigation automates forensic data capture, processing and analysis of cloud resources and, through integrations with cloud-native detection providers and XDR platforms, on-premises systems. It was previously named Cado, sold by Cado Security Limited, and the Product Specification applies to customers who bought under any other naming convention and regardless of the vendor or reseller.[1] Its schedule says Support Services are not provided and that basic support is offered through a customer portal, and only for the most recent version.[3] Customer-hosted deployments have a Licensing setting in the product console.[1]

Darktrace / SECURE AI

SECURE AI gives visibility of prompts, agents, development environments and unsanctioned AI use. It ingests data from supported enterprise AI services, cloud and SaaS platforms and integrations, and separates monitored, approved and shadow AI services, the last identified through network telemetry.[1] Some platforms restrict the events they expose behind their own licences. The Secure AI Schedule limits use to enhancing the safety of information systems and protecting the customer’s property and assets, makes the customer solely responsible for lawful basis, notices and consultation duties for any monitoring, and sets an Acceptable Use Policy that forbids using the offering to monitor employees for reasons other than cybersecurity or protection of customer assets.[3]

Other offerings

Attack Surface Management, Incident Readiness & Recovery and Darktrace Labs have schedules in the Product Specific Terms but no section in the Product Specification. The Incident Readiness & Recovery schedule states that, unless the Order says otherwise, if the customer expands its NETWORK deployment it pays Darktrace’s then-current standard fees for the corresponding expansion of Incident Readiness & Recovery.[3] Labs is limited to non-production testing, training and demonstration and depends on usage credits that Darktrace may revoke.[3] These are described further in support, product-specific terms and managed services.

Where the public documents stop

The Product Specification makes the customer responsible for the sizing information it gives to Darktrace. It does not publish bands, prices, per-mailbox or per-device definitions, or minimum purchase quantities. The appliance datasheet publishes guidance for unique internal devices per appliance model, for example 6,000 for the DCIP-S and 100,000 for the DCIP-Z, and describes them as guidance numbers only.[4] A licence position for NETWORK, EMAIL, IDENTITY and OT therefore has to be built from the Order Form, not from the public documents.

Out of scope

This article does not cover the detection model content, integrations lists, cloud regions or per-module IDENTITY documentation hosted in the Customer Portal, which the Product Specification treats as the source for details it lacks.[1]

References

  1. Darktrace Offering Product Specification v1.7.0Header shows v1.7.0 2026-09-15. Catalog: Darktrace Offering Product Specification v1.7.0Effective 2026-09-15. Retrieved 2026-10-08.
  2. Darktrace Master Services Agreement v2.4.0Version 2.4.0 dated 3 August 2026.Effective 2026-08-03. Retrieved 2026-10-08.
  3. Addendum to the Master Services Agreement: Product Specific Terms v1.9.1Header shows V1.9.1 2026-09-21.Effective 2026-09-21. Retrieved 2026-10-08.
  4. Darktrace Appliance SpecificationsDatasheet with a 2023 copyright notice; no version date.Retrieved 2026-10-08.

See also

Esc