The autonomous SOC for modern cloud infrastructure

Turn logs into investigations.

Flarehawk is the autonomous control layer for security operations. It ingests security telemetry, investigates incidents with AI agents, and generates remediation plans your team can act on quickly. Built for teams that need investigations, not another alert queue.

How it works

The autonomous control layer for security operations

Flarehawk ingests telemetry, builds customer-specific context, investigates incidents automatically, and produces remediation plans your team can review and apply.

Log ingestion with long-term retention

Flarehawk ingests security telemetry in real time and keeps the evidence available for detection, investigations, audits, and historical analysis.

The Flarehawk Fabric

Flarehawk builds a security graph from each customer's telemetry, connecting requests, identities, and changes so relevant anomalies surface with the right context.

Autonomous investigation

Security tools generate alerts. Flarehawk spins up investigation agents that analyze events in context, explain what happened, and turn raw detections into incidents.

One-click remediation

Every incident comes with a remediation plan your team can review and apply. Tighten access, block abusive traffic, and take action through workflows non-experts can use confidently.

Aegis

Alerts are not investigations

Most security tooling stops at the alert. Aegis turns detections into an incident narrative with evidence, context, and a clear remediation plan your team can understand and act on.

Workflow:

  • Ingest
  • Detect
  • Correlate
  • Analyze
  • Triage
  • Report

Ingest

Cloudflare logs streaming

via Logpush or Worker Middleware

COMPLETE

6/6
▲GET /admin 403 45.33.32.156 0.02s
▲POST /login 401 203.0.113.47 0.45s
✓GET /api/users 200 198.51.100.23 0.12s
▲PUT /settings 403 45.33.32.156 0.08s
✓GET /dashboard 200 104.26.10.89 0.23s
✘POST /admin/../ 403 45.33.32.156 0.01s

From raw alert to incident story, remediation plan, and next action.

Pricing

Find the right plan

Scope your usage and get a recommendation. Every plan includes the Flarehawk Fabric and real-time detection.

What best describes your Cloudflare usage?

  • Hobby < 1M req/mo
  • Startup ~10M req/mo
  • Growth ~50M req/mo
  • Scale ~150M req/mo
  • Enterprise 250M+ req/mo
  • Custom

Our recommendation for ~12M logs/month

Basic $299/mo

  • +Everything in Free
  • +Up to 100M logs/mo included
  • ~$2.50/M per additional 1M logs
Free Basic Complete Enterprise
Monthly price Free $299 $699 Let's talk
Log volume included 1M 100M 200M Unlimited
Overage pricing Upgrade required $2.50/M $3.00/M Custom
How long logs are kept 7 days 30 days 1 year Custom
Ingest Cloudflare logs ✓ ✓ ✓ ✓
Threat detection ✓ ✓ ✓ ✓
AI-powered investigations – – ✓ ✓
One-click fixes – – ✓ ✓
Dedicated Slack channel – – – ✓
Multi-tenant / MSP – – – ✓

Included in every plan

  • SSO
  • Notifications
  • Cloudflare integration
  • SQL queries
  • Compliance exports
  • API access
  • Unlimited team members

What's next

Expanding across the security stack

Flarehawk starts with Cloudflare and is adding support for cloud, identity, and endpoint telemetry sources.

Live

Coming soon

and more…

See everything. Fix anything. Sleep soundly.

Flarehawk gives modern security teams an autonomous control layer that ingests telemetry, investigates incidents, and helps them act with confidence.