Book a meeting →

Push Logo

Pricing

Standard
Up to 500 employees
$
5
User/month
MonthlyAnnually
Enterprise
500+ employees
Let's talk
Volume discounts
Trusted by:
Sophos
Gitlab
Cribl
greynoise
Ramp
upvest
Thinkst
Portswigger

Features

Threat detection

  • AitM / reverse-proxy phishing detection
  • Cloned login page detection
  • Browser-in-the-Browser (BitB) detection
  • ClickFix / clipboard injection blocking
  • Session hijacking detection
  • Credential stuffing detection
  • URL blocking
  • Custom detection rules
  • Autonomous threat hunting agents
  • Screenshot capture on detection events
  • Configurable response modes (monitor, warn, block)
  • Mail forwarding rule monitoring (M365 / Google)

AI visibility & control

  • Shadow AI app discovery
  • Agentic browser detection (Comet, Atlas, Dia)
  • AI prompt & data input monitoring
  • AI app clipboard monitoring & blocking
  • AI file upload monitoring
  • AI OAuth / agent permission monitoring
  • AI browser extension inventory
  • AI usage policy enforcement (block unsanctioned tools)

Identity & authentication

  • SSO login detection & non-SSO login visibility
  • Ghost login detection (password fallback paths)
  • MFA status monitoring
  • MFA enforcement via in-browser guardrails
  • SSO login guidance guardrails
  • Weak / reused / leaked password detection
  • Password strength enforcement
  • Shared account detection
  • Login method visibility (password, SSO, OIDC)
  • Identity provider detection
  • SSO usage trend monitoring
  • Employee identity verification codes
  • Password logging prevention
  • Password protection (prevent reuse on critical apps or credential entry on malicious pages)
  • Browser sync detection

SaaS & app discovery

  • Shadow SaaS discovery
  • App classification and labeling
  • App approval workflows
  • Dormant account identification
  • Login method tracking per app
  • Usage tracking
  • Password manager visibility

OAuth & third-party integrations

  • OAuth consent monitoring
  • OAuth consent blocking
  • OAuth app management and removal
  • Connected scope and permission visibility
  • Real-time user warnings on consent grants
  • Device code phishing

Browser extension security

  • Full extension inventory
  • Malicious extension detection and blocking
  • Extension risk scoring
  • Extension allowlisting (default-deny management)
  • Supply chain change monitoring (ownership transfers, permission escalations, delisting)
  • Extension removal

Data controls & DLP

  • File download telemetry and configurable blocking
  • File upload telemetry and configurable blocking
  • Clipboard telemetry and configurable blocking with content pattern rules
  • Domain-based access blocking
  • Application categorization and blocking

Investigation & response

  • User and session timelines
  • Trace and path reconstruction across tabs/popups
  • Domain analysis enrichment
  • Browser telemetry storage

Integrations & data outputs

  • SIEM integrations (Microsoft Sentinel, Datadog, Splunk Cloud, SentinelOne, etc.)
  • Webhooks
  • Chat alerts (Slack / Teams)
  • IdP integrations (Google Workspace, Microsoft 365, Okta)
  • REST API

Deployment

  • MDM deployment
  • Direct install
  • Incognito mode force-install (Chrome/Edge, macOS/Windows)
  • BYOD / unmanaged device deployment (no MDM required)
  • User agent marker injection (for IdP conditional access)

Administration

  • Central management interface
  • Employee management (add/remove users, manage licenses)
  • Custom login domain configuration
  • License utilization tracking
  • User groups management
  • Custom data retention policy
  • License management (auto-licensing, auto-unlicensing)
  • Custom branding for end-user banners
  • Configurable exceptions (MFA, password findings)
  • Admin audit logs (regular and extended)

Hear what people are saying about Push

Common evaluation questions

Frequently asked questions

Every Push license includes the full platform. Whether you're deploying to 100 users or 100,000, every employee gets behavioral phishing detection, credential security, session hijacking detection, browser extension management, AI visibility, SaaS discovery, DLP building blocks, investigation tools, and custom detection rules.

Push supports Chrome, Edge, Firefox, Safari, Brave, Opera, and Arc — plus enterprise browsers like Island and Prisma Access Browser, and agentic browsers like Comet, Atlas, and Dia. Because Push is a browser extension rather than a standalone browser, adding support for new Chromium-based browsers is straightforward. See our full list of supported browsers for the latest details.

Most customers deploy Push to their users in under a day, during normal office hours with zero downtime. Push is a browser extension — it can be force-installed via MDM (Intune, Jamf, Google Admin Console), distributed through email enrollment, or self-enrolled by employees via a landing page. No browser migration, no network reconfiguration, no endpoint agent rollout.

Push has native SIEM integrations for Microsoft Sentinel, Splunk Cloud, Datadog, Panther, and Cribl Cloud, with standard webhook support for any other platform. Push also integrates with Slack and Microsoft Teams for security team alerts, has a native Tines integration for SOAR workflows, and provides a REST API for custom integrations. All forwarded events include full context: attack technique, severity, user, application, timestamp, and referrer URL.

Yes. Push costs $6 per employee/month when billed monthly and $5 per employee/month on an annual contract. Both options are billed in advance.

Yes. You can add and remove employees from the Push platform at any time. Go to the Employees page, click Add employees, and select the users you want to cover. If you need additional licenses beyond your current allocation, you'll be guided through the purchase at that point. Licenses from departed employees are freed up automatically.

We accept card payments via Stripe and direct bank transfers on request. You can view upcoming invoices by logging into Push and navigating to Plan & Billing in settings.

Yes. If you have more than 500 employees, contact us to discuss Enterprise pricing. The bigger the deployment, the more value Push surfaces — and our pricing reflects that.

Push uses a local-first, detection-triggered data architecture. Routine browsing activity is never transmitted to Push — only activity matching threat detection rules leaves the browser. All platform data is stored in the EU (Dublin, with backup in Paris), encrypted at rest with AES-256 and in transit with TLS 1.2+. Push holds SOC 2 Type II, ISO 27001, ISO 27701, GDPR compliance, and Cyber Essentials certifications. Security documentation is available under NDA from our trust center.

You can review our T&Cs here.