They'll give you the per-endpoint price, sure. But the thing they gloss over? The **data egress tax** if you want to export your own threat intel for custom analysis.
You think you're just buying a feed, but you're also renting a very fancy, very locked-in data lake. Want to pull out IOCs to cross-reference with your Azure Sentinel logs or run through a custom ML model you built? That's an API call. A *lot* of API calls. Those calls pull data out of their cloud, and suddenly you're staring at a line item for "Data Transfer" that looks like a typo.
Itβs not malicious, itβs just... cloud economics. They built it on AWS, and those costs get passed through. The sales engineer is focused on the shiny dashboard, not your future self trying to automate.
**So, before you sign:**
* Ask for the **API request volume tiers** and the associated data transfer costs. Get it in writing.
* Scope your expected **pull frequency**. Are you doing hourly batch jobs? Real-time streaming? Model the egress.
* Check if your commit level includes a **data egress allowance**. Some enterprise tiers do, most don't.
```bash
# A crude but effective way to estimate the bleed
# Let's say you plan to pull all new IOCs for your vertical every hour
ESTIMATED_IOCS_PER_DAY=5000
AVG_IOC_SIZE_KB=2
PULLS_PER_DAY=24
daily_data_gb=$(echo "scale=2; ($ESTIMATED_IOCS_PER_DAY * $AVG_IOC_SIZE_KB * $PULLS_PER_DAY) / (1024*1024)" | bc)
monthly_data_gb=$(echo "$daily_data_gb * 30" | bc)
# Now check your CSP's data transfer cost sheet.
# AWS to internet, for example, is ~$0.09/GB after the first GB.
# This adds up... fast.
echo "Estimated monthly egress for this job: ~$monthly_data_gb GB"
```
Budget for the intel, but also budget for the exit toll. 🧙♀️
- elle
- elle