Frequently asked questions.
Everything you need to know about the Forensk platform.
Forensk is an AI-powered MSP Security Operations Platform. It combines forensic investigation (DFIR), ticketing/PSA, compliance automation, alert pipeline, auto-healing, and vCIO tools in one platform. Instead of juggling 5-8 separate tools, MSPs use Forensk as their single platform for security operations.
Forensk is built exclusively for Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs). If you manage IT and security for multiple client organizations, Forensk is designed for you. Our sweet spot is MSPs with 500-25,000 managed endpoints across 15-100+ client organizations.
Huntress does detection. ConnectWise does operations. Nobody does investigation at MSP prices. When Huntress finds a threat, someone needs to investigate the full scope, determine root cause, and generate reports for insurance and compliance. That's what Forensk does — plus operations, compliance, and strategic services.
Forensk is also stack-agnostic: it integrates with ANY combination of EDR/RMM/BCDR tools. SentinelOne's Purple AI only investigates SentinelOne data. Forensk investigates across all your integrated tools.
No. Forensk is an orchestration platform — it connects to your existing tools via API. Keep your NinjaOne (RMM), SentinelOne (EDR), Huntress (MDR), Axcient (BCDR), Avanan (email security), DNSFilter, KnowBe4, and Duo. Forensk aggregates data from all of them into one dashboard and adds forensic investigation, compliance, and strategic services on top.
Professional: $3,999/month (up to 1,000 endpoints, 15 client orgs, 8 hrs/mo analyst).
Enterprise: $7,999/month (5,000 endpoints, 50 orgs, named advisor, 24/7 SOC).
Commander: $14,999/month (25,000 endpoints, unlimited orgs, dedicated team).
Premier: $24,999/month (unlimited everything, SLA with financial penalties).
Every tier includes AI investigation, human analyst hours, and IR retainer coverage. No per-incident fees for standard investigations.
Forensk replaces $64K-$253K/year of separate tools and services:
- DFIR retainer: $37K-$200K/yr → included in Forensk
- PSA/ticketing: $9K-$18K/yr → built into Forensk
- Compliance consultant: $10K-$25K/yr → automated by Forensk AI
- SOW/contract writing: $3K-$10K/yr → AI-generated by Forensk
- QBR preparation: $5K-$15K/yr → AI-generated by Forensk
- Dark web monitoring, training management: $5K-$10K/yr → included
At $3,999/month ($48K/year), Forensk saves 55-80% vs. buying these separately.
Monthly subscriptions: no long-term commitment. Cancel anytime with 30 days' notice. Annual subscriptions offer a discount and can be cancelled with a pro-rata refund after the first 90 days. We don't believe in locking customers in — we believe in earning your business every month.
Yes — that's the model. MSPs typically charge their clients $350-$700/month for "Managed Security + IR Coverage + Compliance" powered by Forensk. At Professional ($3,999/mo for 15 clients), that's $267/client/month cost. Charging $550/client = 2x markup, well within the 133% MSP cybersecurity standard.
Yes. Every Forensk tier includes incident response retainer coverage with human analyst hours. Professional includes 8 hours/month, Enterprise 20 hours, Commander 40 hours, and Premier unlimited. When an incident happens, AI-powered investigation starts immediately, and a human analyst reviews findings within the SLA timeframe. No additional per-incident fees for standard investigations.
Forensk uses a 7-step AI investigation pipeline powered by Claude (Anthropic):
- Collect evidence from all integrated sources
- Analyze artifacts and extract forensic indicators
- Correlate IOCs across sources and historical cases
- Reconstruct the attack timeline with confidence scores
- Identify root cause and initial access vector
- Generate attack narrative
- Produce reports (executive, technical, insurance, regulatory, chain-of-custody)
Every AI decision is logged in an immutable audit trail. Human analysts review all forensic-grade output before release.
Forensk integrates with 10+ tools across 7 categories:
- RMM: NinjaOne, Syncro
- EDR: SentinelOne, CrowdStrike
- MDR: Huntress, Blackpoint
- BCDR: Axcient, Datto
- Email Security: Avanan (Check Point Harmony)
- DNS Filtering: DNSFilter
- Training: KnowBe4, Huntress SAT
- Identity/MFA: Duo, Azure AD
New integrations are added regularly. Custom integrations available on Commander and Premier tiers.
The Forensk Agent is a lightweight service (~5MB) that runs on Windows, macOS, and Linux endpoints. It collects forensic telemetry (system baseline, security software status, users, processes, network connections, persistence mechanisms) and reports to the Forensk platform. It does NOT replace your EDR or RMM — it sits alongside them and adds forensic intelligence.
Deployment: one-click install via email link, RMM push, GPO, Intune, or command line. Zero kernel drivers, read-only, less than 1% CPU impact.
Forensk's compliance engine supports NIST Cybersecurity Framework (CSF), CIS Critical Security Controls v8, SOC 2 Type II, HIPAA Security Rule, and PCI DSS v4.0. Assessments are AI-powered from real security data — not questionnaires. The engine evaluates each control against your actual EDR coverage, backup status, MFA enrollment, training completion, and incident history.
Forensk implements 8-layer defense in depth: network isolation (AWS VPC), TLS 1.3 encryption in transit, KMS encryption at rest, JWT authentication with RBAC, PostgreSQL Row-Level Security for multi-tenant isolation, Fernet encryption for integration credentials, immutable audit logging with SHA-256 integrity chains, and human verification of all AI forensic output. See our Privacy Policy for full details.
Upon cancellation, your data remains accessible for 30 days to allow export. After 30 days, all data is permanently deleted except audit logs (retained 7 years per regulatory requirements). You can export all your data at any time via API or by requesting a data export from our support team — we provide it in standard formats (JSON, CSV, PDF) within 10 business days. No hostage data. No exit fees.
AI-generated reports should be reviewed and validated by qualified forensic analysts before use in legal proceedings. Every Forensk tier includes human analyst hours specifically for this purpose. Our platform maintains chain-of-custody tracking, evidence integrity hashing (SHA-256), and immutable audit logs that support the evidentiary process — but the human review step is critical for court-admissible output.
Most MSPs are operational within 1-2 hours. Sign up, connect your integrations (API keys), deploy the Forensk Agent to a few test endpoints, and you're live. Full onboarding with all clients typically takes 1-2 weeks. Enterprise and Commander tiers include dedicated onboarding support.
We offer a 30-minute demo where we walk through the platform with your actual use cases. We can also provide a limited trial for qualified MSPs. Request a demo to get started.
Still have questions?
Book a 30-minute walkthrough and we'll answer them live — no commitment, no credit card.
Request a demo →