Talk to one agent. A whole security fleet goes to work.
Ask a plain-language question. Dozens of specialists investigate in parallel, hand you one clear verdict, and wait for your approval before anything changes. $0 platform fee — you only pay for the usage you run.
- $0
- platform fee — usage only
- 1 credit
- = 1M tokens of work
- One pool
- shared company-wide
aktoh · dispatch console
SimulationAsk the fleet something real:
- specialists working in parallel…
Audit-ready
Data handling, retention, and residency documented
Encrypted end to end
TLS 1.3 in transit, AES-256 at rest, per-tenant keys
Every decision logged
Append-only audit log of agent actions and approvals
48-hour onboarding
Connect a node in minutes; no source access needed
You won't see customer logos here — telling attackers who runs Aktoh would tell them where the traps are. Here's what we show instead →
How it works
Three steps, and starting is smaller than not starting.
01
Connect
Point Aktoh at what you already run — cloud, identity, endpoints. Read-only to begin, minutes not months, no source access.
02
The fleet deploys and adapts
Specialists take up their posts and tune to your environment. EVOLVE keeps them current as things change.
03
You approve what matters
Investigation runs continuously. Anything consequential waits for your click — and is logged forever.
Meet the fleet
Named specialists, not a feature grid.
You only ever talk to the InfoSec Lead. Behind them, each specialist owns one job and does it continuously.
Sleight
InfoSec Lead
Plans the job, dispatches specialists, and reports back in plain language.
Read the brief →
Argus
Exposure & breach
Sweeps breach corpora, dark-web sources, and your external surface.
Read the brief →
Plutus
Financial fraud
Watches payments, invoices, and beneficiary changes for fraud patterns.
Read the brief →
Cerberus
Endpoint & identity
Device posture, identity telemetry, and containment when you approve it.
Read the brief →
Psycher
Social engineering
Recognises scam scripts in calls, texts, and email, and explains why.
Read the brief →
Horsemen
Adversary simulation
Safely reproduces exploit paths so you know what actually lands.
Read the brief →
EVOLVE
Adaptation
Retunes the fleet as your estate and the threat landscape change.
Read the brief →
Dewey
Records & evidence
Keeps the audit trail, evidence packs, and compliance artifacts.
Read the brief →
Choose your path
Nobody should leave here on the wrong track.
Not sure which door is yours? Compare business and household side by side.
Pricing, translated
A pool, a rate, and a cap.
$0 platform fee to start — you still pay for the usage you run · flat fee plus usage · unlimited nodes and devices on every plan, Adventurer included · self-serve credits that re-up automatically, with spend alerts before anything surprises you. Paid plans include a monthly credit pool shared across everyone you cover; past the pool you pay a published per-1M-token rate.
- STEP 01
One pool for the whole company
Your monthly credits sit in a single company pool. Finance, engineering, the shop floor — everyone draws from the same balance, so a busy week in one team doesn't need a new licence.
- STEP 02
1 credit = 1M tokens of agent work
A credit is a unit of thinking, not a seat. Routine monitoring barely touches it; a live investigation spends more, because more specialists run at once.
- STEP 03
Past the pool, you pay per 1M tokens
Nothing stops and nothing gets throttled. Extra work bills at your plan's published rate — $3.00/1M on Operator down to $1.55/1M on Enterprise Plus — or you buy a rollover block up front.
- STEP 04
No surprise bills
Credits re-up automatically as you use them, so the fleet defaults to protecting you rather than stopping at a balance. Alerts at 50%, 80% and 100% of the pool, each with the projected month-end figure, so you always see it coming.
The exception is Adventurer: no platform fee and no pool, just unlimited nodes with usage billed at $5.00 per 1M tokens. It's the free way in, and plenty of small teams stay there.
What will this cost me?
Typical usage
~260 credits/mo
Best-fit plan
Professional
Estimated monthly, billed monthly
$2,800
Includes 900 pooled credits; anything beyond is $2.15 per 1M tokens. The same usage on Adventurer (no pool) would be $1,300. Spend alerts fire at 50%, 80% and 100% of the pool, so nothing arrives as a surprise.
Learn while you're here
Most people aren't buying today. Leave with something anyway.
Threat library
Vendor bank-detail change fraud
A supplier emails new payment details a week before a large invoice is due. The email looks perfect. The account is six days old.
Threat library
MFA fatigue (push bombing)
The attacker already has the password. They just spam approval prompts at 2am until someone taps 'Yes' to make it stop.
Threat Briefing
A plain-language threat brief, sent periodically
Written by the fleet, checked by humans — plus an invitation to our invite-only fireside chat and Q&A forum. Pick business or household when you sign up.
Objections, answered
The questions a salesperson would get.
- What can the fleet do without my sign-off?
- Read-only investigation, monitoring, correlation, and drafting. Anything that changes state — blocking a device, rotating a password, holding a payment — queues for your approval by default, and you choose which classes can auto-run.
- What will it actually cost?
- A flat platform fee plus usage. Paid plans include a monthly pool of credits shared across your whole company or household; one credit is 1M tokens of agent work. Beyond the pool you pay a published per-1M-token rate, or pre-buy cheaper credit blocks. Adventurer has no pool at all: $0 platform fee, pay per million tokens. Credits top themselves up automatically as you use them: the fleet defaults to protecting you rather than stopping at a balance, and you set spend alerts and caps so the bill stays knowable.
- Do you train models on my data?
- No. Your data is never used to train shared models. Agent memory is encrypted per tenant, and fleet improvements are trained on synthetic and public corpora.
- What happens when it's wrong?
- Findings carry confidence levels and the evidence behind them. Because nothing consequential executes without a human approval, wrong calls stay reversible — and every run is replayable from an append-only audit log.
- Why can't I see customer names?
- Telling attackers who runs Aktoh tells them where the traps are. We publish verifiable artifacts — data handling, audit logging, subprocessors, audit reports — instead of borrowed credibility.
Protect your company
One fleet across cloud, endpoints, identity, and payments. Unlimited nodes on every plan.
Protect your household
Everyone under your roof — kids and parents too — in one shared pool.
Buying at enterprise scale? Talk to us →