specification: FinOps Framework specificationVersion: '1.0' schema: https://www.finops.org/framework/ provider: Censys providerId: censys created: '2026-05-29' modified: '2026-05-29' reconciled: false tags: - FinOps - FOCUS - Security - Internet Intelligence - Attack Surface Management description: 'FOCUS-aligned FinOps for Censys: tiered subscription with credit-based metering for search, view, aggregate, scan, and CensEye operations across the Platform and Asset Graph APIs.' sources: - https://censys.com/pricing/ - https://docs.censys.com - https://docs.censys.com/reference alignedWith: framework: FinOps Foundation Framework frameworkUrl: https://www.finops.org/framework/ dataSpec: FOCUS dataSpecVersion: '1.3' dataSpecUrl: https://focus.finops.org/focus-specification/v1-3/ publisherName: Censys, Inc. serviceCategory: Security Intelligence billingModel: pricingCategory: Tiered Subscription + Credit-Based Usage billingFrequency: Monthly (Individual) / Annual (Security Operations, Threat Hunting) billingCurrency: USD chargeCategories: - Usage - Purchase - Tax - Adjustment - Refund - Credit focusColumns: ServiceName: Censys Platform ServiceCategory: Security Intelligence ProviderName: Censys PublisherName: Censys, Inc. InvoiceIssuerName: Censys, Inc. BillingCurrency: USD ChargeCategory: Usage RegionId: global meters: - name: search_queries unit: query aggregation: sum dimensions: - api - tag - result_count - name: aggregate_queries unit: query aggregation: sum dimensions: - api - tag - name: host_views unit: lookup aggregation: sum dimensions: - host_id - name: certificate_views unit: lookup aggregation: sum dimensions: - certificate_id - name: webproperty_views unit: lookup aggregation: sum dimensions: - webproperty_id - name: on_demand_scans unit: scan aggregation: sum dimensions: - scan_id - target - name: censeye_jobs unit: job aggregation: sum dimensions: - job_id - name: asset_graph_executions unit: execution aggregation: sum dimensions: - graph_id - name: collections_active unit: collection aggregation: max dimensions: - collection_uid - name: seats_active unit: seat aggregation: max dimensions: - organization_id - user_id - name: credits_consumed unit: credit aggregation: sum dimensions: - organization_id - user_id - operation principles: - name: Visibility description: Use /v3/accounts/{org_id}/credits and /v3/accounts/{org_id}/credits/usage to monitor tenant- and member-level credit consumption. Audit events stream via /v3/accounts/{org_id}/audit-log-events. The Censys Platform UI dashboards mirror these endpoints. - name: Allocation description: Tag spend by organization_id, user_id, and Collection. Per-member credit usage endpoint (/v3/accounts/{org_id}/members/{user_id}/credits/usage) supports chargeback to specific analysts or teams. - name: Optimization description: Use Collections to memoize frequent queries; prefer aggregate over result-set pagination when only counts are needed; bound history windows to your plan; reserve on-demand scans and CensEye jobs for genuinely high-value pivots. - name: Accountability description: Assign a Censys Platform Administrator persona who owns the Personal Access Token inventory, monitors credit burn, and reviews audit logs. Configure RBAC on Security Operations and Threat Hunting tiers to enforce least-privilege and prevent credit-budget overruns.