Pricing

Investigate websites in isolated cloud browsers with live analysis and agent access. Choose Guard Analyst for yourself or Guard Team for a shared workspace.

Guard Analyst

Isolated browsing and live analysis for one person.

Seats1 seat

One person, one workspace. Teams start at three seats.

$29per month

Billed monthly. Cancel any time.

Add a card to start. Cancel before the trial ends and you will not be charged; otherwise billing begins afterwards.

Prices are in USD and exclude any VAT or sales tax that applies.

AnalystTeam
Browsing, analysis and access
InvestigationsUnlimitedUnlimited
Browser choices88
Exit locations100+ in 100 countries100+ in 100 countries
Residential egress
Included residential data10 GB / month10 GB per seat, pooled
Your own proxy or WireGuard profiles
Resources for demanding websites
Session lengthUp to 18 hUp to 18 h
AI verdicts and follow-up questions
Daily AI analysis budgetFair useFair use
Live evidence while the session runs
Threat-intelligence database72 million entries, 38 feeds72 million entries, 38 feeds
One-click IOC copy
Browser extensions for Chrome, Edge, Firefox and Brave
REST API and CDP access
Agent access over MCP
Team and workspace
Seats13 to 50
Investigations running at onceUp to 3Up to 3 per person
Allowances pooled across the workspace
Member management and seat assignment
Microsoft Entra SSO and tenant auto-join
Workspace branding
Priority support
EU data residency and self-serve DPA
30-day trialUp to 5 seats
Explore plan features

Included in both plans

  • Unlimited investigations

    Investigate as many sites as you need. Run up to three investigations at once, each in an isolated browser on Guard.ch infrastructure.

  • Eight browsers

    Choose from eight browsers, including Chrome, Edge, Firefox, Brave and Tor. Open the site in the browser that fits your investigation.

  • 100+ exit locations

    Choose an exit location in over 100 countries. Switch between datacenter and residential connections to see how a site responds to traffic from different networks.

  • Live analysis with AI verdicts

    See the requests, trackers and technologies behind a page as you browse. AI explains the findings with visible sources; AI usage is subject to fair use.

  • Threat-intelligence database

    Every verdict is computed against one reference database of about 72 million entries: 25.2 million hostnames, 27.3 million domains, 6.1 million IP ranges and 38 independent feeds, refreshed every day.

  • Agent access over MCP

    Connect your agent through MCP to open and control cloud browsers. REST and CDP access are included for tools such as Playwright and Puppeteer.

  • Extensions for Chrome, Edge, Firefox and Brave

    Send a link straight to Guard.ch from Chrome, Edge, Firefox or Brave. Start an investigation from the page you are on with a right-click or keyboard shortcut.

  • 10 GB residential data

    Use 10 GB of residential traffic per billing cycle to investigate sites through residential connections. This helps when a site treats datacenter traffic differently.

  • Your own proxy or WireGuard

    Connect your own proxy or a WireGuard profile for the workspace. Use your own exit connection when an investigation requires a particular network.

  • Resources for demanding websites

    Computing resources and memory for demanding websites and investigations with several browser tabs.

  • Sessions up to 18 hours

    Keep a session open for up to 18 hours to work through longer investigations. It ends sooner after inactivity or disconnection.

  • Priority support

    Get priority in the support queue when you need help. A person handles your request, whether it concerns your account or an investigation.

  • EU data residency and DPA

    EU data residency and a data processing agreement are included. Access the agreement through self-service for your organisation’s internal review.

Additional features with Guard Team

  • 3 to 50 seats

    Bring 3 to 50 people into one Workspace, with one member per purchased seat. Each person gets the same browser and investigation features.

  • Member management

    Invite colleagues and manage Workspace membership in one place. Remove members when access is no longer needed and keep the team within your purchased seat count.

  • Microsoft Entra SSO

    Let your team sign in through Microsoft Entra SSO. Tenant auto-join and Workspace branding help you fit Guard.ch into your organisation’s existing setup.

  • Pooled allowances

    Share the data allowance across your Workspace so it is available where the team needs it. Each purchased seat adds to the shared allowance.

  • One invoice, lower price per seat

    Manage the team through one subscription and one invoice. The price per seat decreases as you add seats, with the total shown in the plan picker.

Frequently asked questions

Investigations and API calls are not charged individually. Each paid seat includes up to three concurrent investigations, 10 GB of residential data per billing cycle and AI analysis subject to fair use. On Team, members share the residential allowance. You can see current usage in your dashboard.
Explore our threat data

One database behind every verdict.

Analyst and Team use the same database: about 72 million entries covering hosts, domains, networks and certificate authorities. It is updated daily. As of September 15, 2026.

  • 25.2 million

    Hostnames checked

    25,215,102 hosts with reputation, category and ranking data on file.

  • 27.3 million

    Registrable domains

    Popularity rankings on file for 7,517,089 of them.

  • 6.1 million

    IP ranges

    Covering 3.7 billion IPv4 addresses, with their networks and owners.

  • 81,974

    Autonomous systems

    Mapped to their organisations across 250 countries and territories.

  • 445,807

    Tagged IP prefixes

    Cloud, VPN, Tor, bot and abusive networks, clearly labelled.

  • 181

    Certificate authorities

    83 trusted and active, checked against 4 trust stores.

  • 38 independent threat and reference feeds, most of them refreshed daily: 36 of 38 had refreshed within the last day at the time of this snapshot.
  • Only trusted sources can classify a host as malicious, including Google Web Risk, abuse.ch URLhaus and ThreatFox, and national CERT feeds. Community reports appear as attributed evidence. They cannot establish that classification on their own.
  • 1.05 million hostnames are flagged as malicious by threat-intelligence feeds. Over 10 million hostnames have at least one blacklist entry or category assignment.
  • Popularity rankings for 7.5 million domains and 30 content categories help the engine interpret findings differently on established sites and unfamiliar hosts.

Figures are exact counts from the snapshot of September 15, 2026. The database is refreshed every day.