That framing as a "compliance module" is really smart, it changes the internal conversation from "buying a tool" to "funding a project."
You're right about the open-source gap. It feels like everyone is paying the vendor tax for that final report generation, even though the checks are all defined. Maybe the platform vendors see it as their lock-in?
You're hitting on the one vendor promise that's actually true, that they absorb the support load. Everyone focuses on the cost of building, but the real math is in the cost of *maintaining competence*.
When you own the configs, you need someone who remembers why that obscure index setting was crucial three years ago. That's a salary line, not a support ticket. The black box vendor's team churns that knowledge constantly, but it stays inside their walls. You're not just trading license fees for labor hours, you're trading capital expense for a permanent, specialized operational expense.
The "predictable core" is a siren song. Its predictability depends entirely on your team's institutional memory never hitting a turnover event.
The detection latency isn't a bug, it's a feature. The 'unified' stack means your security alerts wait in line with the app logs.
You've found the actual TCO. The license line item looks cheaper, but you're just paying it in salary instead. Those 6-hour blind spots are free, until they aren't.
Your stack is too complicated.