The business model rests on one number: the marginal cost of adding a customer. If it is near zero, this is a software company with a channel. If it is a hundred and fifty dollars a month, it is a reseller with a margin problem. The number depends on a single architectural dependency, and I want to be precise about how proven it is.
The original model, and why it was wrong
The first serious cost model put cost-to-serve at $155–200 per tenant per month, almost all of it inference. That is not a disaster — it supports a price — but it produces a service business shape: every new customer costs real money, margins are moderate, and growth consumes cash.
That model was built when the agent ran against a model endpoint I paid for. Once inference moved into the customer's own cloud, the entire line disappeared from my side of the ledger.
| Cost line | Provider-paid inference | Customer-tenant inference |
|---|---|---|
| Inference per tenant | $155–200/mo | $0 — on their bill |
| Compute / hosting | Mine | Theirs |
| Deployment labour | Mine | The partner's billable work |
| Tier-1 support | Mine | The partner's |
| Residual per tenant | — | ~$10–20 (endpoint calls, base threat intel) |
What that does to the shape of the business
With near-zero marginal cost, unit economics stop being the interesting question. A flat per-tenant wholesale price becomes almost pure contribution margin, and the only real cost is central and fixed: research and development, and the threat intelligence baseline.
Break-even stops being a property of each deal and becomes a function of how large you let the fixed cost grow — which is a lever you control, not a market condition you suffer. That is the difference between a business you can run deliberately and one that runs you.
It also restores something the in-tenant architecture appeared to destroy. Deploying separately into every customer's tenant kills shared runtime — no pooled infrastructure, no multi-tenant efficiency. But it keeps shared research. One improvement to the investigation method is built once and ships to every tenant. That pooled-R&D leverage, not shared compute, is the actual economy of scale.
Three conditions, and how solid each one is
Near-zero marginal cost is conditional, not achieved. Three things have to hold, and they are not equally proven.
One: the in-tenant inference migration ships everywhere. The path works and is running. Until every deployment is on it, the residual from the sovereignty chapter is also a cost residual — my key, my bill.
Two: the customer can actually provision the model. Some model backends on some clouds require per-subscription approval, which is a gate I do not control and cannot promise a partner will clear. I have observed the gating; I have not diligenced how reliably it opens for an arbitrary small-business tenant. This is the condition I would attack first if I were assessing this business from the outside.
Three: capability parity. The agent must not depend on anything a vanilla customer deployment lacks — no special-access features, no elevated-tier capability, nothing that works on my development account and silently degrades on theirs. Every prompt and tool schema tuned against one model has to be revalidated on the model the customer will actually run, and "it works on mine" is not evidence.
The number, and what it does not cover
The most recent full run measured $0.1305 per investigation across thirty incidents. That is a real measurement from a real run, and it is the number I would quote.
It is also measured on a quiet tenant during setup activity, with no attacks in the population and two of seven telemetry sources producing nothing at all. A tenant with real incidents runs longer investigations, dispatches more specialists, and asks more questions. I do not know what the cost per case looks like there, and anyone who tells you they know their agent's production cost from a lab corpus is extrapolating.
There is a volume cap in the pricing for exactly this reason — a tail-risk fuse that should never bite a normal small business, and exists so that a pathological tenant cannot turn a flat price into an unbounded liability.
Why this chapter exists
Because "near-zero marginal cost" is the kind of claim that sounds like a boast and is actually a dependency. If condition two fails at scale — if provisioning the model inside customer tenants turns out to be unreliable for small businesses — the cost structure reverts, the flat price stops being comfortable, and the business is a different business.
I would rather write that down while it is still an open question than discover it in a renewal conversation.