N-able sells three groups of security add-ons alongside its RMM and backup products. N-able Endpoint Detection and Response (EDR) and Managed EDR are powered by SentinelOne. Adlumin MDR is a managed detection and response service built on N-able’s Adlumin platform. Mail Assure is an email security and archiving service. They are ordered on N-able Sales Orders under the same Quantity Commitment model as N-able’s other products. The Software Services Agreement (SSA) and EULA contain a product addendum for each of them.[1][2] The most important licensing fact about EDR is which contract governs it. N-able’s own agreements expressly do not.
Editions
| Offering | What N-able documents | Governing terms |
|---|---|---|
| N-able EDR | SentinelOne-based EDR with AI detection, remediation and rollback; Singularity Control and Complete packages[6] | SentinelOne Services Addendum[2] |
| Managed EDR | EDR delivered as a managed service; named alongside EDR in the product addendum[2] | SentinelOne Services Addendum[2] |
| Adlumin Managed ITDR | Identity-focused package; SIEM “Limited to Microsoft data”; Microsoft 365 API integration only[3] | SSA with MDR addendum[1] |
| Adlumin MDR Standard | MDR package with 30 days data retention[3] | SSA with MDR addendum |
| Adlumin MDR Advanced | MDR package with 90 days data retention[3]; Clients eligible for the cyberwarranty[1] | SSA with MDR and warranty addenda |
| Mail Assure | Inbound and outbound filtering and archiving[8] | SSA and EULA Mail Services addendum[2] |
The Adlumin package table lists data sources: the Adlumin Endpoint Agent, API integrations, and a VM Collector for non-API data such as Syslog.[3] The page does not say whether packages are priced per endpoint, per user or per organisation. Catalog proof: Adlumin MDR packages differ in data retention.
Metrics
EDR. EDR is deployed as an agent on each protected device. In N-central, EDR agents are deployed and profiled from the console.[4] In N-sight RMM, integrated EDR is offered for Windows.[5] N-able’s Billing API returns invoice-based, device-level usage for EDR as it does for N-central and Cove. This indicates that EDR is billed on devices.[7] The public licensing documentation for EDR sits behind the N-ableMe login.[4] The catalog therefore links the EDR SKUs only to the contractual Device.
Mail Assure. Billing counts the Mail Assure mailbox: “the invoice is for the number of filtered or archived mailboxes”.[8] “Mail Assure’s billing is based on usage over the previous calendar month.” The Usage Report shows protected and archived mailbox counts by day, admin or domain, and a list of detected active mailboxes.[9] Catalog proof: Mail Assure bills filtered or archived mailboxes from the previous month.
Counting / floors
EDR carve-out (EULA §16.3 and SSA addendum, 2026-07-31). “N-able Endpoint Detection and Response and Managed Endpoint Detection and Response are powered by SentinelOne® and SentinelOne’s Services Addendum applies to these Services. N-able’s Software Services Agreement and End User License Agreements do not apply.”[2] The N-able clauses on licence grant, audit, renewal and overage therefore do not by their terms reach EDR. A customer’s EDR position is governed by SentinelOne’s addendum[10] and by the N-able Sales Order that sets quantity and price. The related SentinelOne terms are covered in SentinelOne licensing. Catalog proof: EDR and Managed EDR are governed by the SentinelOne Services Addendum.
Remote Script Orchestration. A customer that buys SentinelOne Remote Script Orchestration takes “sole responsibility for any harm” from its use. It may not use it on third parties’ devices without explicit consent, or to handle sensitive data such as payment card data or PHI. Breach allows immediate suspension and termination.[1]
Mail Assure over-counting. By default Mail Assure filters every email received, inbound and outbound. N-able notes this “can result in inaccurate invoicing”. The recommended fix is to list all valid mailboxes and aliases, or sync them through LDAP or Microsoft 365, and to reject mail to unlisted mailboxes. Catch-all behaviour on the receiving mail server otherwise causes mail for any address to be accepted and counted. “Mailboxes that have filtering disabled, are configured as an alias, or are marked as a distribution list or shared mailbox, will be excluded from billing.”[8] For a licence manager, the mailbox list and catch-all settings determine the count. Catalog proof: Mail Assure bills filtered or archived mailboxes from the previous month.
Virtualization & partitioning
The retrieved documents contain no virtualization rule for EDR, MDR or Mail Assure. Under the N-able agreements a Device includes virtual machines,[1] but for EDR the SentinelOne addendum governs instead.
Cloud / BYOL
All three offerings are N-able-hosted or SentinelOne-hosted services, so bring-your-own-licence does not apply. On exit from Mail Assure, the customer must change MX records and mail server settings so that email no longer passes through N-able. It must also export archived, quarantined and logged email before the service ends, or the data may be lost.[2] Among the security services, only N-able Managed Detection and Response may be used to process HIPAA protected health information.[1] Catalog proof: PHI only in MDR, Cove, N-central and N-sight.
Programs
Adlumin MDR Advanced Cyberwarranty. If an MSP buys Adlumin MDR Advanced, its Clients are “eligible to receive the Adlumin MDR Advanced Cyberwarranty”, also called the N-able Certification Warranty. Cysurance supports and administers the warranty. The MSP must make sure each Client completes the Warranty Enrollment Form and accepts the Participant Agreement. “The Warranty is only available to eligible MSPs and their Clients”, and N-able “shall have no liability whatsoever” for it.[1] Separately, N-able’s product page describes an Adlumin Protect Warranty of up to USD 500,000 reimbursement. It is included with the “Adlumin Protection Plus suite”.[3] Catalog proof: Adlumin MDR Advanced Cyberwarranty requires Client enrolment.
MDR service levels. N-able MDR “will use commercially reasonable efforts to meet the Service Level Objectives (SLOs) listed in the SLO Addendum”.[2] The SLO Addendum was not among the published legal documents retrieved.
Out of scope
- The full text of the SentinelOne Services Addendum and SentinelOne’s own licensing units.
- Prices and licensing units for Adlumin packages, XDR, SIEM support, penetration testing and incident response services, which are not published.
- DNS Filtering and Passportal, for which no licensing document was retrieved.