Ransomware does not wait for the practice to open. It arrives at the hour when nobody is looking, encrypts what it can reach, and leaves a note where the schedule used to be. These six lines put a behavioral agent on every managed machine, feed what it sees into one correlated stream, and place people in front of that stream around the clock. What separates the lines is not how much they see. It is what happens next.
A detection product on its own produces a queue. Somebody has to work the queue, and in a fourteen person practice that somebody is usually the office manager who also handles payroll, the fax line, and the patient who is unhappy about a copay. The queue does not get worked. It gets muted.
What we sell here is the working of the queue. The SentinelOne agent detects behavior rather than matching a list of known files, which is what catches the attacks that arrive freshly compiled. Fluency then holds and correlates activity across sources, so an analyst opening a case sees the sequence around an event instead of the event alone.
Managed detection notifies. Someone reads the alert, judges it, and contacts you with what they found and what they recommend. That is the right shape for a practice with an on-call technical person and a tolerance for a phone call.
The extended tier widens the picture to take in servers, cloud workloads, network activity, and directory events, with hunting continuing overnight. The plus tier goes one step further and lets the operations team remediate directly rather than waiting for a callback. That last difference sounds small on a price list and is enormous at four in the morning on a holiday weekend.
Each figure here is read live out of billing. Whatever you pick sits waiting on the side panel while you keep reading down the page.
A behavioral endpoint agent on every machine you enroll, watched continuously by an operations team that reads what it produces. When something matters, a person contacts you with the finding and a recommendation rather than a dashboard link.
| Product | SentinelOne, with monitoring by Fortify 24x7 |
|---|---|
| Reaches | Windows, macOS, and Linux endpoints you enroll |
| Watch | Continuous monitoring and alerting |
| Response | Notification and written recommendation |
| Best suited to | Reception, clinical rooms, and the back office |
| Counted as | One protected endpoint, charged monthly |
The wider version. Detection stops being an endpoint-only conversation and starts including servers, cloud workloads, network activity, and directory events, with threat hunting running through the night against the whole picture.
| Product | SentinelOne Complete, with Fluency correlation |
|---|---|
| Reaches | Endpoints plus server, cloud, network, and directory sources |
| Watch | Continuous monitoring with active hunting |
| Response | Notification, guidance, and coordinated action with your team |
| Best suited to | Multi-site groups and anywhere with servers or cloud workloads |
| Counted as | One protected endpoint, charged monthly |
Everything the extended tier covers, with the authority to remediate identified events directly. Nobody has to reach a practice owner at four in the morning to get permission to isolate a machine that is actively encrypting a share.
| Product | SentinelOne Complete, with Fluency correlation |
|---|---|
| Reaches | Endpoints plus server, cloud, network, and directory sources |
| Watch | Continuous monitoring with active hunting |
| Response | Direct remediation of identified events |
| Best suited to | Practices with no technical staff available overnight |
| Counted as | One protected endpoint, charged monthly |
For groups running container workloads, usually behind a patient portal, an analytics pipeline, or a home-grown integration between systems. Priced per node rather than per endpoint because that is the unit a cluster is built from.
| Product | SentinelOne for Kubernetes |
|---|---|
| Reaches | Kubernetes nodes you enroll |
| Watch | Continuous monitoring and alerting |
| Response | Notification and written recommendation |
| Best suited to | Groups running containerized workloads of their own |
| Counted as | One kubernetes node, charged monthly |
The extended tier applied per node. Cluster activity joins the same correlated stream as your endpoints and cloud accounts, so an analyst is not switching consoles halfway through working out what happened.
| Product | SentinelOne Complete for Kubernetes |
|---|---|
| Reaches | Kubernetes nodes plus the correlated wider estate |
| Watch | Continuous monitoring with active hunting |
| Response | Notification, guidance, and coordinated action |
| Best suited to | Clinical software teams and analytics platforms |
| Counted as | One kubernetes node, charged monthly |
The remediation tier for containerized workloads. Identified events get acted on by the operations team at the node, on the same terms as the endpoint plus tier.
| Product | SentinelOne Complete for Kubernetes |
|---|---|
| Reaches | Kubernetes nodes plus the correlated wider estate |
| Watch | Continuous monitoring with active hunting |
| Response | Direct remediation of identified events |
| Best suited to | Production clusters with no overnight engineering cover |
| Counted as | One kubernetes node, charged monthly |
This category is sold almost everywhere as though it abolishes bad days. It does not, and the edge deserves to be drawn precisely.
Heads up: card statements show FORTIFY 24X7 - Care Secure Systems is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.