Free (Local)
Any org wanting a real IR plan.
- Full local-first console
- All playbooks + tabletop
- HIPAA + your home state engine
- Tamper-evident hash-chained timeline
- Reminder cascade (local) + letters + exports
- 1 user · on-device only
Team
SMBs · up to 15 users.
- Cloud war-room (multi-user)
- 52 jurisdictions + 7 frameworks (SEC/CIRCIA)
- Reminder cascade → email / Slack / Teams
- Business-day + holiday-aware deadlines
- Cyber-insurance pack + auditor bundle
Pro
Mid-market · up to 50 users.
- Everything in Team
- BYO-AI copilot + letter drafter
- Custom roles & granular scopes
- Cross-product evidence pull
- Regulator submission tracker
MSP
MSPs / vCISOs · min $299/mo.
- Multi-client console
- White-label AARs & PIRs
- Templated playbooks across clients
- Bulk tabletop scheduling
- Per-client deadline dashboards
More, for less than either side of the market
The market splits in two: engineering IR tools that run a slick war-room but know nothing about notification law, and enterprise privacy platforms that automate the law but cost five to six figures and are sales-led. Klaxon is the only product in the SMB band that does both.
| Capability | incident.io eng-IR / on-call |
RadarFirst / BreachRx enterprise privacy |
Klaxon |
|---|---|---|---|
| Slack / Teams war-room | ✓ | ✗ | ✓ + local-first |
| IR playbook library | ✓ | partial (IR plans) | ✓ + legal triggers |
| 50-state breach-notification engine | ✗ | ✓ | ✓ all 50 + DC/PR |
| HIPAA / GDPR / DFARS / PIPEDA / SEC / CIRCIA | ✗ | partial | ✓ 7 frameworks, live clock |
| Reminder cascade (T-48/24/4h/overdue) | ✗ | enterprise | ✓ + opt-in push |
| Business-day + federal-holiday deadline math | ✗ | opaque | ✓ computed offline |
| Tamper-evident hash-chained timeline | ✗ | ✗ | ✓ SHA-256 chain |
| Breach-notification letter generator | ✗ | ✓ | ✓ 9 templates, .txt/PDF |
| Tabletop exercise runner (scored + AAR) | ✗ | ✗ | ✓ built in |
| Local-first (incident never leaves the building) | ✗ cloud-only | ✗ cloud-only | ✓ |
| On-call add-on tax | +$12–$20/user/mo | n/a | none — all included |
| Self-serve (no sales call) | ✓ | ✗ sales-led | ✓ free to start |
| Flat per-company option | ✗ per-seat only | opaque | ✓ $239/co flat |
| Real price | $31–$45/user/mo $19–$25 + on-call | 5–6 figures / yr sales-led, opaque | $0 free · $239 flat |
Pricing reflects publicly reported figures as of 2026 — incident.io Response $19–$25/user/mo + $12–$20/user/mo on-call add-on (Vendr, Instatus, Spike); RadarFirst & BreachRx are enterprise/sales-led with no public price, commonly five-to-six figures per year (Capterra, GetApp). Verify current details with each vendor.
flat, vs ~$450/mo
A 15-person team on incident.io at ~$31/user all-in runs ~$465/mo. Klaxon Team is $239 flat for the same 15 — and adds the entire notification-law engine they don't have.
for the law engine
The 50-state + HIPAA + GDPR + DFARS engine costs five-to-six figures a year from RadarFirst/BreachRx. In Klaxon it's in the free tier (HIPAA + home state) and every paid plan.
per tabletop
Consultants charge $5k–$25k per facilitated tabletop. Klaxon ships a scored scenario runner with an auto-generated after-action report — run them quarterly, in-product, included.
the whole room is in
Per-seat pricing pushes orgs to keep people out of an incident. Flat pricing means the receptionist, counsel, and exec can all be in the war-room without a per-head charge.