Typical range: varies; some vendors bundle with first-year fees, others charge separately
Licensing & subscription (recurring)
Based on monthly/annual traffic volumes (e.g., requests per second, or total requests), protected domains, and features
Per-endpoint or per-app pricing can apply for larger deployments
Setup & customization fees (if heavy customization is requested)
Policy design, integration development, and pilot testing
Could be a one-time or phased over milestones
Maintenance & support
Standard support (business hours) vs. premium/24x7 support.
Software updates, security patches, and access to new featuresm.
Typical ranges: ongoing percentage of license or monthly fee; some plans include support in the base subscription.
Professional services & implementation
Optional advisory, architecture review, performance tuning, and dedicated onboarding
Time-and-materials or fixed-price engagements
Training & enablement
End-user training for security teams, runbooks, and best practices
Additional costs to consider
Data egress charges (if applicable)
Logs/monitoring data storage outside CHEQ
Custom integrations or development work with third-party systems
Training
Structured onboarding program
Guided setup for discovery, design, and initial policy configuration.
Access to a recommended rollout plan with milestones and owners.
Training formats
Self-paced resources: product docs, best-practice playbooks, and quick-start guides.
Instructor-led sessions: live onboarding workshops or webinars covering deployment, policy tuning, and integrations.
Hands-on labs: sandbox environments to validate rules and traffic flows without impacting production.
Role-based training
Separate tracks for security engineers, network/infrastructure teams, and SOC analysts.
Content on alert triage, incident response playbooks, and integration with SIEM/SOAR.
Documentation and enablement
Comprehensive user manuals, API references, and integration guides.
Runbooks for common scenarios (new bot surge, API abuse, false positives handling).
Ongoing support options
Standard support: business hours, with access to knowledge base and community resources.
Premium/24x7 support: around-the-clock access, faster response SLAs, and crisis-management assistance.
Dedicated technical account management (TAM) or success manager: for larger deployments or strategic programs.
Proactive health checks: periodic reviews of configuration, performance, and coverage.
Security Measures
Data-in-transit and data-at-rest protections
Strong encryption in transit (e.g., TLS with modern cipher suites).
Encryption options for data at rest, depending on deployment (cloud-native or on-prem equivalents).
Access control and identity
Role-based access control (RBAC) with least-privilege permissions.
Single Sign-On (SAML/OIDC) and centralized identity management.
Audit trails of user activity and configuration changes.
Data minimization and retention
Logs and events retention policies aligned with compliance needs.
Support for data localization by region and data retention controls.
Anonymization/pseudonymization options for sensitive fields in logs where applicable.
Network and deployment security
Secure API endpoints and authenticated management interfaces.
Regular vulnerability management and patching practices.
Isolation and segmentation in multi-tenant or large-scale environments.
Compliance alignmen
Support for industry standards relevant to CHEQ use cases (e.g., PCI-DSS considerations for payment endpoints, if applicable).
Documentation of control mappings and compliance artifacts for audits.
Monitoring and incident response
Real-time monitoring dashboards for security posture and system health.
Alerting with integrated ticketing/SOAR workflows to accelerate incident response.
Post-incident reviews and improvement recommendations.
Data export and portability
Options to export logs and events for external storage or analysis.
Clear data deletion and destruction procedures when a contract ends.
Updates
Release cadence
Regular update cycles, including bug fixes and feature releases.
Major releases on a defined schedule (e.g., quarterly or semi-annual) depending on product strategy.
Backward-compatible patches and hotfixes as needed between major releases.
Update process
Preview/development environment: often available for early testing before production.
Change management: release notes detailing new features, improvements, security fixes, and any deprecated functionality.
Compatibility checks: guidance on impacted configurations and how to mitigate risks.
Deployment of updates
Updates typically rolled out across protected surfaces (endpoints, edge nodes, or CDN integrations) with minimal downtime.
Optional maintenance windows for larger changes or migrations.
Rollback options if a release introduces issues.
Communication and governance
Early access notices for upcoming features and security advisories.
Access to a product roadmap and release calendars (subject to internal policy).
Customer-specific change advisories for high-impact updates.
Data Ownership and Portability
Data ownership
Your organization retains ownership of the data you provide to CHEQ Essentials (e.g., configuration data, policy definitions, and traffic logs that you generate).
CHEQ typically acts as a data processor for logs and telemetry generated by its service; you remain the data controller for your data.
Data access and custody
You should have access to your own data (logs, events, dashboards) through your SIEM/analytics pipelines or export features.
CHEQ should provide mechanisms to retrieve or export data in common formats (e.g., JSON, CSV, logs in your data lake/S3, or SIEM integrations) on request or per data retention policies.
Data retention and deletion
The contract should specify data retention windows for logs and events, with options to retain longer for compliance or security investigations.
Deletion rights: upon contract termination, CHEQ should provide a data deletion process that securely erases or returns your data within a defined period (e.g., 30–90 days) and provides verification when feasible.
Scaling Up / Down
Elastic scaling terms
CHEQ Essentials should support scalable protection for varying traffic loads, with pricing reflecting consumption (e.g., requests per second, protected endpoints, or data volume).
Upgrades/downgrades: you should be able to adjust the scope (endpoints, regions, features) with a defined process and impact on pricing.
Notice and lead time
Scaling up or down typically requires a notice period (e.g., 30 days) to adjust licensing, provisioning, and service configurations.
Pricing implications
Scaling up may trigger revised tiering, new SLA commitments, or expanded feature access.
Scaling down should ensure you aren’t billed for unused capacity beyond the agreed
minimums, and may involve a wind-down of certain resources or a phased decommissioning.
Migration and provisioning
When scaling, expect coordinated changes across DNS/edge configurations, CDN integrations, and policy deployments.
Any non-disruptive deployment options (e.g., staged rollouts, canary pilots) are preferable for large-scale changes.
Contract alignment
Any scaling policy should be reflected in the master agreement, with attachment details for pricing, service levels, and scope.
The terms & conditions for contract renewal and cancellation
Renewal terms
Most contracts are annual or multi-year with automatic renewal unless either party provides notice.
Renewal pricing may be fixed for a period or subject to annual uplift (e.g., CPI-based or % increases).
Renewal notices typically require a minimum lead time (e.g., 60–90 days before renewal).
Termination for convenience
Termination rights often exist with a notice period; some contracts include a termination fee if canceling before the term ends.
Clean termination windows and data handoff/transition assistance are commonly offered.
Cancellation and data return
Upon cancellation, a defined data export window and format should be provided.
Deletion timelines post-termination (e.g., 30–90 days) are typically specified.
Restoration of customer data or migration support may be included or offered as a professional service.
Service levels and credit
If CHEQ misses agreed SLA targets, you may be eligible for service credits; terms and calculation methods should be specified.
Renewal options and renegotiation
Right to renegotiate terms, explore alternate SKUs, or switch to different feature sets at renewal.
Change-control processes for scope adjustments during renewal cycles.
Compliance with law and export controls
Termination provisions may also consider regulatory changes or export controls that affect ongoing usage.
Data retention post-renewal or termination
Clarify how long CHEQ retains data after renewal ends or contract terminates and when data is fully purged.
Compliance
ISO/IEC 27001: Information security management systems.
SOC 2 Type II (Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, Privacy).
SOC 3: Public-facing summary of SOC 2 controls.
GDPR: Data processing and privacy considerations for EU residents; data transfer mechanisms where applicable.
CCPA/CPRA: Consumer privacy protections for California residents (where applicable).
HIPAA/HITECH (if applicable to healthcare data) and corresponding business associate agreement (BAA) availability, when required.
CSA STAR or cloud security alliance mappings (if applicable to cloud integrations).