Frequently Asked Questions

The questions security teams, MSSPs, and procurement teams ask before buying HailBytes, with straight answers.

About HailBytes

What does HailBytes do?

HailBytes builds two cloud-native security platforms: HailBytes SAT (Security Awareness Training) for phishing simulation and employee training, and HailBytes ASM (Attack Surface Management) for continuous external reconnaissance. Both deploy to your AWS or Azure account through the cloud marketplace and are priced on infrastructure ($0.24/vCPU/hour) rather than per-seat or per-asset.

How is HailBytes different from KnowBe4 or Proofpoint?

HailBytes SAT is self-hosted in your own cloud account, licensed under the HailBytes Commercial License with source code included for your own security review, and priced on infrastructure rather than seats. A 1,000-user company pays roughly the same as a 200-user company because cost is set by VM size, not headcount. KnowBe4 and Proofpoint are SaaS, per-seat, and proprietary. See the side-by-side comparison for feature, pricing, and architectural differences.

Is HailBytes open source?

No. HailBytes ships under the HailBytes Commercial License, which is a commercial license — not an open-source license and not a source-available license. What you do get is code access: the source that accompanies your deployment can be read, audited, and modified for your own use under the license’s confidentiality terms, so your security team can review every line that runs in your account. You can’t publish or redistribute it, and it never converts to an open-source license.

Pricing & Licensing

How much does HailBytes cost?

$0.24 per vCPU per hour through AWS or Azure Marketplace, for both SAT and ASM. The 8 vCPU entry size runs about $16,800/year at list, or $11,760/year on a 1-year commitment. That is the software fee only — deployments are Bring-Your-Own-Cloud, so the underlying VM, storage, and networking are billed separately by your cloud provider (roughly $280/month at 8 vCPU). Both charges land on the same cloud bill. There are no per-seat, per-asset, or per-scan fees on the platform itself. See the pricing page for the full breakdown.

Are there volume or multi-year discounts?

Yes — save up to 40% with annual commitment: 30% off for a 1-year commitment paid annually upfront, 35% for 2 years, and 40% for 3 years. On the 8 vCPU entry size that is $11,760, $10,920/year, and $10,080/year respectively. A publisher cannot discount a published marketplace metered rate, so these are delivered as private offers (AWS CPPO / Azure MPO). Contact sales for a private offer.

Does the marketplace charge count toward our AWS EDP or Azure MACC?

Yes. Marketplace charges count toward AWS Enterprise Discount Program and Azure MACC commits. This is why most enterprise procurement teams prefer the marketplace deployment path: it draws down existing committed spend instead of adding a new line item.

Is there a free trial?

Yes. The trial is 30 days free through both AWS Marketplace and Azure Marketplace, and it covers the underlying infrastructure on the 8 vCPU entry size, so you can run real campaigns or scans during the evaluation period. That infrastructure cover is specific to the trial — on a paid plan the $0.24/vCPU/hour meter is the software fee only and your cloud provider bills the VM, storage, and networking separately (roughly $280/month at 8 vCPU).

HailBytes SAT

Does HailBytes SAT support Microsoft 365 and Google Workspace?

Yes. SAT works with any SMTP-capable email provider, and the SMTP setup tutorial covers M365 and Google Workspace allowlist configuration explicitly. See SMTP setup for phishing testing.

What about post-click training?

SAT ships with built-in post-click training modules that show employees a short interactive lesson the moment they click a simulated phishing link, with quizzes to confirm comprehension. See the post-click training tutorial, or try the live quiz demo.

Can we run executive-targeted (spear-phishing) simulations?

Yes. SAT supports per-segment campaigns with custom templates so executive simulations can run on tighter cycles than company-wide programs. See executive spear-phishing tutorial.

HailBytes ASM

What does HailBytes ASM actually scan?

ASM continuously enumerates subdomains, fingerprints services and software versions, runs port scans, identifies known CVEs against discovered software, and tracks changes over time. It’s reNgine deployed as a managed service in your cloud account, the same engine many security teams already know.

How is this different from a one-shot pen test?

Pen tests are point-in-time and goal-oriented; ASM runs continuously and surfaces drift such as new subdomains, exposed admin panels, expired certificates, and newly disclosed CVEs against existing services. Most security teams use ASM to fill the visibility gap between pen tests rather than to replace them. See pen test definition.

Can pen-test firms resell ASM to their clients?

Yes, and many do. The pen-test firm playbook covers white-label arrangements, pricing tiers, and engagement mechanics for offering ASM as a recurring deliverable between point-in-time engagements.

Deployment & Technical

How long does deployment take?

Five to ten minutes for the first instance. One-click deploy from AWS Marketplace or Azure Marketplace, then access the web UI as soon as the VM is up. Tutorials walk through the rest of the setup: SAT on AWS, SAT on Azure, ASM on AWS, ASM on Azure.

What VM sizes do you recommend?

8 vCPU / 32GB RAM is the entry size for both products, and for SAT it is also a hard floor rather than just a starting point. For SAT the tiers are stated in active learners, because that is what training load tracks: up to 10,000 learners on 8 vCPU, 10,001–35,000 on 16, and 35,001–100,000 on 32. Which workload you run matters more than the headcount — a training roster is a materially bigger box than the same number of phishing targets, since each active learner streams video or SCORM from the instance, triggers a certificate render, and adds rows the recurring automation sweep has to walk. Training ships with the phishing server, so the training tiers are the default. For ASM, 8 vCPU is the documented production-recommended size and handles 10–50 scheduled scans a day. Larger ASM sizes scan proportionally faster: ASM sizes its scan worker from the host, so 16 vCPU gives the scan engine twice the cores 8 vCPU does. Instances deployed before August 2026 pick this up on the next update. Sizing is throughput, not a seat cap — users are unlimited at every size.

Does HailBytes integrate with our SIEM?

Yes. ASM emits findings to Splunk, Elastic, Microsoft Sentinel, Chronicle, and any SIEM that accepts webhook or syslog input. SAT and ASM both push notifications to Slack and tickets to Jira out of the box. See SIEM integration tutorial and findings routing deep dive.

Where does customer data live?

In your own cloud account. HailBytes runs as a marketplace deployment in the AWS or Azure region you choose. HailBytes the company never holds your campaign data, employee records, or scan findings; there is no shared multi-tenant SaaS to compromise. Where HailBytes acts as a data processor, the Data Processing Agreement sets out the GDPR terms for your review.

Compliance & Security

Does HailBytes support SOC 2, HIPAA, and PCI-DSS evidence?

Yes. Both products generate audit-ready evidence (campaign launches, training completion, branded PDF certificates, structured audit logs) ordered for US Enterprise procurement: North American frameworks first — SOC 2 CC2.2, NIST CSF PR.AT, HIPAA Security Rule §164.308(a)(5), PCI-DSS Requirement 12.6 — then global ISO 27001 A.7.2.2 / A.6.3. Every artifact is CSV-exportable for client-facing reports. See the compliance mapping page.

How does HailBytes handle SSO and identity federation?

Both SAT and ASM support OIDC for enterprise SSO, configured per instance — one identity provider configuration per deployment, not one per client organization. For an MSSP that means a client which needs to federate against its own IdP needs its own instance; clients on a shared, MSSP-operated instance authenticate against the MSSP’s identity provider or receive scheduled reports without logging in at all.

MSSPs & Partners

Can MSSPs white-label HailBytes for their clients?

Yes, under your own brand. Instance branding (logo, favicon, colors, support URL, email-from name) is built in and applies to the whole instance, and the HailBytes Commercial License explicitly permits service-provider rebrand arrangements. The license places no restriction on hosted, managed, or multi-tenant delivery, and your entitlement does not lapse if a HailBytes reseller or marketplace agreement ends. One instance carries multiple client organizations when you operate the platform, with row-level data isolation, per-client sending identities, and per-client hostnames. Clients that require their own branding, their own identity provider, or self-service administration need a dedicated instance — branding and SSO configuration are instance-wide today, not per client. See the full MSSP playbook.

What does white-label margin actually look like?

HailBytes prices by instance size, not by seat, so a client's cost basis stops moving once the instance is sized. One 8 vCPU SAT instance runs ~$20,160/year all-in ($16,800 of metered software plus roughly $3,360 of cloud), or ~$13,440/year on a 3-year commitment. Two things follow. First, the margin story is consolidation: one instance carries multiple client organizations when you operate the platform, with row-level data isolation, per-client sending identities, and per-client hostnames, which lands per-client software cost at roughly $1,100–$3,400 per client per year against $16,800 for a dedicated instance. That per-client figure is the same at every plan size, and we publish no tenants-per-instance count — there is no measured basis for one. Clients that require their own branding, their own identity provider, or self-service administration need a dedicated instance. Second, be realistic about a dedicated instance: break-even against a $35/seat incumbent rate is about 576 seats all-in, including your cloud infrastructure, so a 500-seat client at $17,500/year is cheaper on the incumbent than on a dedicated HailBytes instance. Below 576 seats, put several clients on one instance you operate, or treat the dedicated instance as an isolation requirement rather than a margin play. Concrete tier math and a sample 200-seat P&L: white-label margin economics.

Is there a partner program?

Yes. The HailBytes Partner Program covers reseller economics, AWS and Azure marketplace co-sell motions, and partner enablement materials.

Still Have Questions?

The glossary defines the security terms used across this site, the docs cover product reference, and the contact page reaches sales and support directly.

Start a Free Trial

Pick the product you want to try. We'll deploy a free trial on AWS or Azure and walk you through setup.