The autonomous SOC for modern cloud infrastructure
Turn logs into investigations.
Flarehawk is the autonomous control layer for security operations. It ingests security telemetry, investigates incidents with AI agents, and generates remediation plans your team can act on quickly. Built for teams that need investigations, not another alert queue.
How it works
The autonomous control layer for security operations
Flarehawk ingests telemetry, builds customer-specific context, investigates incidents automatically, and produces remediation plans your team can review and apply.
Log ingestion with long-term retention
Flarehawk ingests security telemetry in real time and keeps the evidence available for detection, investigations, audits, and historical analysis.
The Flarehawk Fabric
Flarehawk builds a security graph from each customer's telemetry, connecting requests, identities, and changes so relevant anomalies surface with the right context.
Autonomous investigation
Security tools generate alerts. Flarehawk spins up investigation agents that analyze events in context, explain what happened, and turn raw detections into incidents.
One-click remediation
Every incident comes with a remediation plan your team can review and apply. Tighten access, block abusive traffic, and take action through workflows non-experts can use confidently.
Aegis
Alerts are not investigations
Most security tooling stops at the alert. Aegis turns detections into an incident narrative with evidence, context, and a clear remediation plan your team can understand and act on.
Workflow:
- Ingest
- Detect
- Correlate
- Analyze
- Triage
- Report
Ingest
Cloudflare logs streaming
via Logpush or Worker Middleware
COMPLETE
6/6
▲GET /admin 403 45.33.32.156 0.02s
▲POST /login 401 203.0.113.47 0.45s
✓GET /api/users 200 198.51.100.23 0.12s
▲PUT /settings 403 45.33.32.156 0.08s
✓GET /dashboard 200 104.26.10.89 0.23s
✘POST /admin/../ 403 45.33.32.156 0.01s
From raw alert to incident story, remediation plan, and next action.
Pricing
Find the right plan
Scope your usage and get a recommendation. Every plan includes the Flarehawk Fabric and real-time detection.
What best describes your Cloudflare usage?
- Hobby < 1M req/mo
- Startup ~10M req/mo
- Growth ~50M req/mo
- Scale ~150M req/mo
- Enterprise 250M+ req/mo
- Custom
Our recommendation for ~12M logs/month
Basic $299/mo
- +Everything in Free
- +Up to 100M logs/mo included
- ~$2.50/M per additional 1M logs
| Free | Basic | Complete | Enterprise | |
|---|---|---|---|---|
| Monthly price | Free | $299 | $699 | Let's talk |
| Log volume included | 1M | 100M | 200M | Unlimited |
| Overage pricing | Upgrade required | $2.50/M | $3.00/M | Custom |
| How long logs are kept | 7 days | 30 days | 1 year | Custom |
| Ingest Cloudflare logs | ✓ | ✓ | ✓ | ✓ |
| Threat detection | ✓ | ✓ | ✓ | ✓ |
| AI-powered investigations | – | – | ✓ | ✓ |
| One-click fixes | – | – | ✓ | ✓ |
| Dedicated Slack channel | – | – | – | ✓ |
| Multi-tenant / MSP | – | – | – | ✓ |
Included in every plan
- SSO
- Notifications
- Cloudflare integration
- SQL queries
- Compliance exports
- API access
- Unlimited team members
What's next
Expanding across the security stack
Flarehawk starts with Cloudflare and is adding support for cloud, identity, and endpoint telemetry sources.
Live
Coming soon
and more…
See everything. Fix anything. Sleep soundly.
Flarehawk gives modern security teams an autonomous control layer that ingests telemetry, investigates incidents, and helps them act with confidence.