From 9bd9164cb0ab7b506a36659fbf51f66d488fbe6c Mon Sep 17 00:00:00 2001 From: Maxime Lamothe-Brassard Date: Mon, 5 Oct 2026 01:52:23 +0000 Subject: [PATCH 1/2] Describe Email and Code Security subscription billing --- .../billing/security-products.md | 166 +++++++----------- .../code-security/getting-started.md | 15 +- docs/email-security/getting-started.md | 13 +- docs/email-security/policy.md | 16 +- docs/email-security/setup-cli.md | 15 +- 5 files changed, 98 insertions(+), 127 deletions(-) diff --git a/docs/7-administration/billing/security-products.md b/docs/7-administration/billing/security-products.md index 34bffcedc..8aa9e796b 100644 --- a/docs/7-administration/billing/security-products.md +++ b/docs/7-administration/billing/security-products.md @@ -1,21 +1,23 @@ # Email Security and Code Security billing -Email Security and Code Security have separate paid coverage. Paying for endpoint -security or another product does not automatically buy either one. Enabling an -extension starts setup; paid coverage requires explicit price acceptance and -confirmation from the protection service. +Subscribing to the extension purchases coverage, just like other LimaCharlie +extensions. Email Security uses `ext-email-security`; Code Security is included +in `ext-cloud-security`. On a paid plan, coverage starts automatically when the +organization is subscribed and has a payment method or authorized invoicing. +A paid organization is one that is off the free tier. Review the extension's +pricing when subscribing. | Product | Paid rate | New organization trial | |---|---|---| | Email Security | $1 per protected mailbox-month | 14 days, up to 25 mailboxes | -| Code Security | $0.80 per protected repository-month, plus the existing Cloud Security base fee | 14 days, up to 10 repositories | +| Code Security | $0.80 per protected repository-month, plus the Cloud Security base fee | 14 days, up to 10 repositories | Trials cover the organization across its connections. Shared mailboxes and repeated references to the same repository count once when they have the same stable identity. Code includes hosted repositories and external scanner imports; container images do not contribute to this repository meter. Telemetry and other services remain separately -priced. The console shows the organization's actual Cloud base fee; it is not included -in the $0.80 rate. +priced. Review the Cloud Security base fee in the extension listing before subscribing; +it is not included in the $0.80 rate. ## Trial and coverage @@ -28,8 +30,7 @@ the enforcement instant. Their existing protected set stays free for those 14 da including sets above 25 mailboxes or 10 repositories. This exception preserves the existing set; it does not allow unlimited expansion or swapping in an unlimited number of new resources. New organizations and growth beyond that baseline follow the normal -limits. Existing paid protection is not silently converted into a new charge without -price acceptance. +limits. Trial-period usage stays free for everyone, including organizations on paid plans. Use Email Security mailbox scope and exclusions to choose coverage. Code's scanning settings select repository coverage. Review resources that are discovered but not @@ -39,77 +40,37 @@ data follow the product's retention policy and scheduled-deletion notices. Revie those notices before the deadline; paying does not retroactively analyze work missed while coverage was paused. -## Purchase and check acknowledgement - -In **Billing & Usage**, or the product's overview, review trial status, protected -count, limits and the current rates. Add a payment method through the billing page -(or use authorized invoicing), then select the price-acceptance checkbox and -**Activate paid coverage**. - -Billing status requires `org.get` and `billing.ctrl`. Changing paid coverage also -requires `user.ctrl`. Analysts without billing permission can still inspect product -coverage and trial information through the product's read surface without access to -payer or financial details. - -A request can remain **Pending** while billing or protection reconciles. Do not treat -an HTTP success or a saved configuration as paid coverage. Refresh until the server -reports acknowledged paid protection. A failed or unavailable response does not -establish coverage; correct the payment method or contact support as indicated. -An HTTP 200 mutation with `acknowledged: false` is committed but pending; poll GET -until its control settles and protection matches the requested change. HTTP 503 -is retryable after refreshing status and does not confirm paid coverage. Activation -may be temporarily unavailable during rollout while reads and stop remain available. - -The billing API uses the same routes for both products: - -| Operation | Route | -|---|---| -| Status and cost | `GET /v1/orgs/{oid}/billing/security/{product}` | -| Accept pricing and request activation | `POST /v1/orgs/{oid}/billing/security/{product}` with `{"accept_pricing":true,"accepted_quote":}` | -| Request paid stop | `DELETE /v1/orgs/{oid}/billing/security/{product}` | - -`product` is `mail_security` or `code_security`. Optional GET parameters `from` and -`until` must be supplied together as UTC dates `YYYY-MM-DD`. The beginning is -inclusive, the end exclusive, and the maximum range is 366 days. Without a custom -range, use the returned billing period; an invoice interval can differ from a calendar -month. The normalized `status` contains phase, acknowledged protection, trial limits, -pending control, rates and costs. Fields whose authority is unavailable are omitted -or null; do not interpret missing fields as paid or as zero cost. - -### Accept the exact quoted price - -GET returns `status.quote_guard_version: 1` and `status.pricing_quote`. All nine -quote fields are required: `version`, `quote_id`, `product`, `currency`, -`monthly_cents`, `days_per_month`, `cloud_base_monthly_cents`, `meter_price_id`, -and `cloud_price_id`. Email's Cloud amount is `0` and price ID is an empty string; -these fields are still required. Review the rates and send the entire quote unchanged -in `accepted_quote`. Its opaque ID binds organization, payer and billing mode as -well as prices. It accepts rates, not a fixed future population or monthly total. - -If pricing changed, POST returns HTTP 409 `reason: security_quote_changed` before -recording consent or performing purchase effects. Refetch GET, review the new quote, -and obtain fresh consent. The console clears its checkbox. Do not silently accept -a freshly fetched replacement quote. Missing pricing or an unsupported quote guard -pauses purchasing. - -With a CLI version supporting quoted purchases, save the quote you will review: - -```sh -limacharlie billing security get mail_security --oid --output json > security-status.json -python3 -c 'import json; s=json.load(open("security-status.json")); assert s["status"]["quote_guard_version"] == 1; print(json.dumps(s["status"]["pricing_quote"], indent=2))' > accepted-quote.json -cat accepted-quote.json -# After reviewing the quote: -limacharlie billing security activate mail_security --accepted-quote accepted-quote.json --accept-pricing --oid --output yaml -limacharlie billing security get mail_security --oid --output yaml -# Explicit manual stop; then poll GET for acknowledgement: -limacharlie billing security stop mail_security --confirm --oid --output yaml -``` - -Use `code_security` for Code; its quote also discloses the separate Cloud fee. -The SDK class `limacharlie.sdk.billing.Billing` accepts `Billing(org).activate_security("mail_security", accept_pricing=True, -accepted_quote=reviewed_quote)`, with the complete quote from -`Billing(org).get_security("mail_security")`. Both surfaces preserve pending -responses and API errors instead of claiming that purchase has completed. +## Subscribe and check coverage + +In **Extensions**, review pricing and subscribe to Email Security or Cloud +Security. Subscribing on a paid organization with a payment method or authorized +invoicing automatically enables paid coverage. Moving a subscribed organization +from the free tier to a paid plan, or adding a payment method to a subscribed paid +organization, also enables it automatically. Trial-period usage remains free. + +A free-tier organization receives the trial and pauses when it expires. To keep +protecting resources after the trial, move the organization to a paid plan and +keep the extension subscribed with a payment method or authorized invoicing. + +Billing status requires `org.get` and `billing.ctrl`. Analysts without billing +permission can inspect product coverage and trial information through the +product's read surface without access to payer or financial details. + +Coverage can remain **Pending** while billing or protection reconciles. Refresh +status until the protection service acknowledges the transition. A saved +configuration or subscription alone does not prove that protection has started. +If coverage is suspended or unavailable, correct the payment method or contact +support as indicated. + +Read billing status and costs with +`GET /v1/orgs/{oid}/billing/security/{product}`, where `product` is +`mail_security` or `code_security`. Optional GET parameters `from` and `until` +must be supplied together as UTC dates `YYYY-MM-DD`. The beginning is inclusive, +the end exclusive, and the maximum range is 366 days. Without a custom range, +use the returned billing period; an invoice interval can differ from a calendar +month. The normalized `status` contains phase, acknowledged protection, trial +limits, pending control, rates and costs. Fields whose authority is unavailable +are omitted or null; do not interpret missing fields as paid or as zero cost. ## How cost is calculated @@ -132,24 +93,27 @@ still increase. Closed days are settled separately. Accrued cost is an estimate, a finalized invoice or the total across telemetry, Cloud fees, tax, discounts and other products. See the invoice for the final amount. -## Stop, payment failure and recovery - -**Stop paid coverage** requests an end to future paid eligibility. Check the returned -pending control and refresh until the protection service acknowledges the stop. -Already accrued usage remains payable; the final day's peak is preserved. Stopping -does not reset the trial or immediately erase configuration and data. Any remaining -valid trial or grant can still permit unpaid coverage under its limits. - -Stopping Code paid coverage **keeps the separate Cloud Security subscription and -base fee**. Stopping that subscription is a separate operation and also affects Code -eligibility. Do not assume the repository stop removes every Cloud charge. - -A first failed payment does not immediately remove existing paid protection. Owners -are notified while Stripe retries, with a maximum seven-day grace. Protection stops -at terminal unpaid/canceled status or the grace deadline. Scheduled cancellation -keeps coverage until its effective end. Payment recovery can resume previously -consented, payment-suspended coverage; it does not undo a voluntary product stop. - -Keep the billing contact and payment method current, and inspect pending or suspended -status promptly. Neither a payment-method update nor a callback alone proves that -protection has resumed: verify the authoritative product acknowledgement. +## Unsubscribe, payment failure and recovery + +Unsubscribe from the extension to stop future billing. Moving the organization +back to the free tier also stops paid coverage. Refresh billing and product status +until the protection service acknowledges the change. Already accrued usage +remains payable; the final day's peak is preserved. Neither change resets the +trial or immediately erases configuration and data. Any remaining valid trial or +grant can still permit unpaid coverage under its limits while subscribed. + +Unsubscribing from Cloud Security stops Code Security coverage and the Cloud +Security base fee. It also affects the other features of that extension. Review +that impact before unsubscribing. + +A first failed payment does not immediately remove existing paid protection. +Owners are notified while Stripe retries, with a maximum seven-day grace. +Protection stops at terminal unpaid/canceled status or the grace deadline. +Scheduled cancellation keeps coverage until its effective end. Payment recovery +can resume coverage when the organization remains subscribed and on a paid plan; +it cannot resume an unsubscribed extension or make a free-tier organization paid. + +Keep the billing contact and payment method current, and inspect pending or +suspended status promptly. Neither a payment-method update nor a callback alone +proves that protection has resumed: verify the authoritative product +acknowledgement. diff --git a/docs/cloud-security/code-security/getting-started.md b/docs/cloud-security/code-security/getting-started.md index 3f7b087c7..c08028dc1 100644 --- a/docs/cloud-security/code-security/getting-started.md +++ b/docs/cloud-security/code-security/getting-started.md @@ -236,15 +236,18 @@ If a repository stays unscanned, see [Troubleshooting](troubleshooting.md). ## Trial, coverage and billing -Code Security has independent paid repository coverage: $0.80 per protected -repository-month plus the existing Cloud Security base fee. A new organization +Subscribing to Cloud Security purchases Code Security coverage: $0.80 per protected +repository-month plus the Cloud Security base fee. A new organization receives a 14-day trial for up to 10 repositories across hosted connections and external imports. Container images do not contribute to the repository meter. Existing enabled organizations receive the fresh trial and preserved-set grant at enforcement; their deadline is not backdated to an old Cloud trial. -In Billing & Usage or Code Security, inspect the canonical trial limit and -acknowledged protection, choose coverage in scanning settings, and explicitly -accept pricing to activate paid coverage. The separate Cloud entitlement and -base fee remain distinct. See [Security product billing](../../7-administration/billing/security-products.md) +Review pricing in Extensions before subscribing. Paid coverage starts +automatically when the organization is off the free tier with a payment method +or authorized invoicing. Trial-period usage remains free. A free-tier organization +pauses at trial expiry; move it to a paid plan to continue coverage. Inspect the +canonical trial limit and acknowledged protection, and choose coverage in scanning +settings. Unsubscribing from Cloud Security stops Code coverage and its Cloud +base fee. See [Security product billing](../../7-administration/billing/security-products.md) for daily high-water marks, cost calculation, payment grace and stopping coverage. diff --git a/docs/email-security/getting-started.md b/docs/email-security/getting-started.md index 6a0f606c2..7bee958b3 100644 --- a/docs/email-security/getting-started.md +++ b/docs/email-security/getting-started.md @@ -26,18 +26,19 @@ A **credential** is the key the product uses to access your mail provider. A **secret** is the securely stored copy of that credential in LimaCharlie. A **connection** combines that secret with your provider and mailbox choices. -!!! info "Trial and independent paid coverage" +!!! info "Trial and subscription billing" New organizations receive **14 days** for up to **25 mailboxes**, starting at the first protected mailbox. Resubscribing does not restart the trial. Existing enabled organizations receive a fresh 14-day trial at enforcement with their current protected set preserved. See [Security product billing](../7-administration/billing/security-products.md). - Paid Email Security requires explicit pricing acceptance and protection - acknowledgement; endpoint security quota does not buy it. At effective trial - expiry unpaid ingestion may pause and data follows the product's retention - and scheduled-deletion policy. Check actual trial and coverage status rather - than assuming a configuration save establishes protection. + Subscribing purchases Email Security at **$1 per protected mailbox-month**, + divided by 30 per UTC mailbox-day. Paid coverage starts automatically on an + organization off the free tier with a payment method or authorized invoicing. + Trial-period usage remains free. On the free tier, ingestion pauses at trial + expiry and data follows the retention and scheduled-deletion policy. Check + actual trial and coverage status to confirm protection has started. ## 1. Enable Email Security diff --git a/docs/email-security/policy.md b/docs/email-security/policy.md index f951b458a..9e3536e96 100644 --- a/docs/email-security/policy.md +++ b/docs/email-security/policy.md @@ -609,7 +609,7 @@ None of them needs anyone to ask. The 30-day delay exists so that unsubscribing by mistake, letting a trial lapse over a holiday, or moving billing around is recoverable — and undoing the thing that started the clock is all the recovery takes. The two cancellations are **not interchangeable**: resubscribing does not -cancel a deletion scheduled because a trial ended, and paid activation does not cancel +cancel a deletion scheduled because a trial ended, and restoring paid coverage does not cancel one scheduled because the organization unsubscribed. Each undoes only what it contradicts. @@ -633,11 +633,12 @@ re-sent for the new date. ## Plans, the free trial, and the mailbox cap -Email Security must be available to your organization before setup. It has an -independent paid product: **$1 per protected mailbox-month**, divided by 30 per -UTC mailbox-day. Paying for endpoint security or increasing its quota does not -activate paid Email Security. See [Security product billing](../7-administration/billing/security-products.md) -for price acceptance, payment methods, costs and pending acknowledgements. +Email Security must be available to your organization before setup. Its +subscription price is **$1 per protected mailbox-month**, divided by 30 per UTC +mailbox-day. Subscribing purchases coverage; it starts automatically when the +organization is off the free tier with a payment method or authorized invoicing. +Trial-period usage remains free. See [Security product billing](../7-administration/billing/security-products.md) +for payment methods, costs and pending acknowledgements. | | Trial | Paid | |---|---|---| @@ -663,7 +664,8 @@ available on each subscription. Unpaid ingestion can pause when the effective trial expires. Configuration and previously analyzed mail remain subject to [data retention and deletion](#data-retention-and-deletion), including scheduled-deletion notices and grace. Reading and acting on retained -messages remain available to authorized analysts. Explicit paid activation resumes +messages remain available to authorized analysts. Moving the subscribed +organization to a paid plan with a payment method or authorized invoicing resumes eligible protection after acknowledgement; it does not retroactively analyze mail delivered while ingestion was paused. diff --git a/docs/email-security/setup-cli.md b/docs/email-security/setup-cli.md index 2d85da12e..ae54b1c4e 100644 --- a/docs/email-security/setup-cli.md +++ b/docs/email-security/setup-cli.md @@ -33,17 +33,17 @@ create automation policy records. With no automation policy, automatic actions are off; a new automation rule defaults to `alert_only`, so it records intent without moving mail. See [Policy Reference](policy.md). -!!! info "Trial and independent paid coverage" +!!! info "Trial and subscription billing" New organizations receive 14 days with up to 25 protected mailboxes, starting at the first protected mailbox. Unsubscribe/resubscribe does not restart the trial. Existing enabled organizations receive the once-only fresh trial and preserved baseline described in [Security product billing](../7-administration/billing/security-products.md). - Email Security paid coverage is independent of endpoint security quota. - Review and accept $1 per protected mailbox-month, calculated using UTC daily - high-water marks and a fixed 30-day month, through Billing & Usage. Inspect - coverage and billing status until protection is acknowledged; saving a - connection or receiving a pending response does not establish coverage. + Subscribing purchases Email Security at $1 per protected mailbox-month, + calculated using UTC daily high-water marks and a fixed 30-day month. Paid + coverage starts automatically on an organization off the free tier with a + payment method or authorized invoicing. Trial-period usage remains free. + Inspect coverage and billing status until protection is acknowledged. At expiry unpaid ingestion may pause, with data retained under the product's retention and deletion policy. Read [Plans, the free trial, and the mailbox cap](policy.md#plans-the-free-trial-and-the-mailbox-cap) @@ -270,7 +270,8 @@ entitlement: ``` `mailboxes_over_cap` is the number that matters: those mailboxes were found and -are not being watched. Narrow the connection's `scope`, or explicitly activate paid Email Security. See +are not being watched. Narrow the connection's `scope`, or move the subscribed organization to a paid +plan with a payment method or authorized invoicing. See [Plans, the free trial, and the mailbox cap](policy.md#plans-the-free-trial-and-the-mailbox-cap). !!! note "Backfill is judged, and acts on nothing" From 09d4036be99d8a35369d76b174fe50ab3b1d8035 Mon Sep 17 00:00:00 2001 From: Maxime Lamothe-Brassard Date: Mon, 5 Oct 2026 05:24:44 +0000 Subject: [PATCH 2/2] Clarify when trial coverage becomes billable --- .../billing/security-products.md | 27 ++++++++++++------- .../code-security/getting-started.md | 7 ++--- docs/email-security/getting-started.md | 6 ++--- docs/email-security/policy.md | 7 ++--- docs/email-security/setup-cli.md | 5 ++-- 5 files changed, 32 insertions(+), 20 deletions(-) diff --git a/docs/7-administration/billing/security-products.md b/docs/7-administration/billing/security-products.md index 8aa9e796b..5994fb76d 100644 --- a/docs/7-administration/billing/security-products.md +++ b/docs/7-administration/billing/security-products.md @@ -7,7 +7,7 @@ organization is subscribed and has a payment method or authorized invoicing. A paid organization is one that is off the free tier. Review the extension's pricing when subscribing. -| Product | Paid rate | New organization trial | +| Product | Paid rate | Free-tier trial | |---|---|---| | Email Security | $1 per protected mailbox-month | 14 days, up to 25 mailboxes | | Code Security | $0.80 per protected repository-month, plus the Cloud Security base fee | 14 days, up to 10 repositories | @@ -21,16 +21,22 @@ it is not included in the $0.80 rate. ## Trial and coverage -A new trial starts at the first protected resource. Unsubscribing, resubscribing or -restarting a connection does not restart it. Use the server's trial deadline and +A new free-tier trial starts at the first protected resource. Unsubscribing, +resubscribing or restarting a connection does not restart it. Use the server's trial deadline and coverage status instead of calculating entitlement from a browser clock. Organizations enabled before billing enforcement receive a fresh 14-day trial from -the enforcement instant. Their existing protected set stays free for those 14 days, -including sets above 25 mailboxes or 10 repositories. This exception preserves the +the enforcement instant. While trial coverage is active, their existing protected +set stays free, including sets above 25 mailboxes or 10 repositories. This exception preserves the existing set; it does not allow unlimited expansion or swapping in an unlimited number of new resources. New organizations and growth beyond that baseline follow the normal -limits. Trial-period usage stays free for everyone, including organizations on paid plans. +limits. Usage while trial coverage is active is free. + +Paid coverage starts billing after the protection service acknowledges it. It can +start before the original trial deadline when the subscribed organization is on a +paid plan with a payment method or authorized invoicing. Paid coverage does not +reset the trial history. Returning to the free tier while subscribed can resume +any remaining original trial under its limits; it does not create another trial. Use Email Security mailbox scope and exclusions to choose coverage. Code's scanning settings select repository coverage. Review resources that are discovered but not @@ -46,7 +52,8 @@ In **Extensions**, review pricing and subscribe to Email Security or Cloud Security. Subscribing on a paid organization with a payment method or authorized invoicing automatically enables paid coverage. Moving a subscribed organization from the free tier to a paid plan, or adding a payment method to a subscribed paid -organization, also enables it automatically. Trial-period usage remains free. +organization, also enables it automatically. Billing begins after paid coverage +is acknowledged; usage while trial coverage is active is free. A free-tier organization receives the trial and pauses when it expires. To keep protecting resources after the trial, move the organization to a paid plan and @@ -75,8 +82,10 @@ are omitted or null; do not interpret missing fields as paid or as zero cost. ## How cost is calculated Each UTC day uses the **highest paid protected resource count** reached that day. -Removing resources later that day does not erase the day's peak. Trials are free; -trial observed counts do not become billable resource-days. +Removing resources later that day does not erase the day's peak. Usage observed +only under trial coverage is free. Once paid coverage begins, the paid protected +count contributes to that UTC day's peak, even if the original trial deadline is +still in the future. Earlier trial-only days are not billed retroactively. The monthly resource rate is divided by a fixed **30** to price each resource-day. The billing period sums daily peaks and rounds the resulting period amount; it does diff --git a/docs/cloud-security/code-security/getting-started.md b/docs/cloud-security/code-security/getting-started.md index c08028dc1..f79c88f19 100644 --- a/docs/cloud-security/code-security/getting-started.md +++ b/docs/cloud-security/code-security/getting-started.md @@ -237,7 +237,7 @@ If a repository stays unscanned, see [Troubleshooting](troubleshooting.md). ## Trial, coverage and billing Subscribing to Cloud Security purchases Code Security coverage: $0.80 per protected -repository-month plus the Cloud Security base fee. A new organization +repository-month plus the Cloud Security base fee. A new free-tier organization receives a 14-day trial for up to 10 repositories across hosted connections and external imports. Container images do not contribute to the repository meter. Existing enabled organizations receive the fresh trial and preserved-set grant @@ -245,8 +245,9 @@ at enforcement; their deadline is not backdated to an old Cloud trial. Review pricing in Extensions before subscribing. Paid coverage starts automatically when the organization is off the free tier with a payment method -or authorized invoicing. Trial-period usage remains free. A free-tier organization -pauses at trial expiry; move it to a paid plan to continue coverage. Inspect the +or authorized invoicing. Usage while trial coverage is active is free; billing +begins after paid coverage is acknowledged. A free-tier organization pauses at +trial expiry; move it to a paid plan to continue coverage. Inspect the canonical trial limit and acknowledged protection, and choose coverage in scanning settings. Unsubscribing from Cloud Security stops Code coverage and its Cloud base fee. See [Security product billing](../../7-administration/billing/security-products.md) diff --git a/docs/email-security/getting-started.md b/docs/email-security/getting-started.md index 7bee958b3..64e74a6bb 100644 --- a/docs/email-security/getting-started.md +++ b/docs/email-security/getting-started.md @@ -27,7 +27,7 @@ A **credential** is the key the product uses to access your mail provider. A **connection** combines that secret with your provider and mailbox choices. !!! info "Trial and subscription billing" - New organizations receive **14 days** for up to **25 mailboxes**, starting + New free-tier organizations receive **14 days** for up to **25 mailboxes**, starting at the first protected mailbox. Resubscribing does not restart the trial. Existing enabled organizations receive a fresh 14-day trial at enforcement with their current protected set preserved. See @@ -36,8 +36,8 @@ A **credential** is the key the product uses to access your mail provider. A Subscribing purchases Email Security at **$1 per protected mailbox-month**, divided by 30 per UTC mailbox-day. Paid coverage starts automatically on an organization off the free tier with a payment method or authorized invoicing. - Trial-period usage remains free. On the free tier, ingestion pauses at trial - expiry and data follows the retention and scheduled-deletion policy. Check + Usage while trial coverage is active is free; billing begins after paid + coverage is acknowledged. On the free tier, ingestion pauses at trial expiry and data follows the retention and scheduled-deletion policy. Check actual trial and coverage status to confirm protection has started. ## 1. Enable Email Security diff --git a/docs/email-security/policy.md b/docs/email-security/policy.md index 9e3536e96..3c8781e63 100644 --- a/docs/email-security/policy.md +++ b/docs/email-security/policy.md @@ -637,7 +637,8 @@ Email Security must be available to your organization before setup. Its subscription price is **$1 per protected mailbox-month**, divided by 30 per UTC mailbox-day. Subscribing purchases coverage; it starts automatically when the organization is off the free tier with a payment method or authorized invoicing. -Trial-period usage remains free. See [Security product billing](../7-administration/billing/security-products.md) +Usage while trial coverage is active is free; billing begins after paid coverage +is acknowledged. See [Security product billing](../7-administration/billing/security-products.md) for payment methods, costs and pending acknowledgements. | | Trial | Paid | @@ -647,8 +648,8 @@ for payment methods, costs and pending acknowledgements. | Product features | Identical | Identical | Organizations enabled before enforcement get a fresh 14-day trial from the -enforcement instant. Their existing protected set remains free for those 14 days, -including a set above 25. The exception preserves that set; new organizations and +enforcement instant. While trial coverage is active, their existing protected set +remains free, including a set above 25. The exception preserves that set; new organizations and expansion beyond the permitted baseline follow the standard cap. ### The 14-day clock diff --git a/docs/email-security/setup-cli.md b/docs/email-security/setup-cli.md index ae54b1c4e..a0834bb84 100644 --- a/docs/email-security/setup-cli.md +++ b/docs/email-security/setup-cli.md @@ -34,7 +34,7 @@ are off; a new automation rule defaults to `alert_only`, so it records intent without moving mail. See [Policy Reference](policy.md). !!! info "Trial and subscription billing" - New organizations receive 14 days with up to 25 protected mailboxes, starting + New free-tier organizations receive 14 days with up to 25 protected mailboxes, starting at the first protected mailbox. Unsubscribe/resubscribe does not restart the trial. Existing enabled organizations receive the once-only fresh trial and preserved baseline described in [Security product billing](../7-administration/billing/security-products.md). @@ -42,7 +42,8 @@ without moving mail. See [Policy Reference](policy.md). Subscribing purchases Email Security at $1 per protected mailbox-month, calculated using UTC daily high-water marks and a fixed 30-day month. Paid coverage starts automatically on an organization off the free tier with a - payment method or authorized invoicing. Trial-period usage remains free. + payment method or authorized invoicing. Usage while trial coverage is active + is free; billing begins after paid coverage is acknowledged. Inspect coverage and billing status until protection is acknowledged. At expiry unpaid ingestion may pause, with data retained under the product's