Editions
Compare the Community, Professional, and Enterprise editions and see which one fits.
QRadar AI Copilot comes in three editions. All of them connect to your existing IBM QRadar 7.5 and install the same way. Every edition uses the same archive, and the activated license decides which capabilities are on.
Positioning
- Community: free. Ask AI, offenses, security posture, masking, and audit for 1 user on a single host. The archive is on GitHub Releases; every edition uses the same archive.
- Professional: licensed per user. Unlocks the four AI engines (offense batch triage, offense investigation, rule copilot, platform-ops copilot) and reports for one team on one node.
- Enterprise: everything in Professional, plus single sign-on, audit forwarding to an external SIEM, LLM failover, and offline activation, on unlimited nodes.
Capability comparison
| Capability | Community | Professional | Enterprise |
|---|---|---|---|
| Query and alerts | |||
| Natural-language query with follow-ups | |||
| Result and log explanations | |||
| Offense sync, AI summaries, and write-back | |||
| Security posture overview | |||
| Data and compliance | |||
| Log-source whitelist | |||
| Field masking (cloud, private, offline) | |||
| Notifications (Feishu, DingTalk, WeCom, and more) | |||
| Local audit log | |||
| AI engines | |||
| Offense batch triage | |||
| Offense investigation and incident reports | |||
| Rule copilot | |||
| Platform check-up and interpretation | |||
| Reports and scheduled reports | |||
| Enterprise | |||
| Single sign-on (OIDC) | |||
| Audit log forwarding | |||
| LLM failover | |||
| Offline activation | |||
| Deployment and licensing | |||
| Users | 1 | Per user | Per contract |
| Nodes | 1 | 1 | Unlimited |
| License | Free | Commercial (monthly or annual subscription) | Commercial (annual subscription) |
Trial and purchase
A trial license opens every Enterprise capability for 14 days on one node.
Every edition uses the same archive. Without a license the paid features show as locked, clicking one offers the upgrade, and the rest of the product keeps running.
To upgrade a Community install, an administrator activates the license. No reinstall is needed; data and the host fingerprint are kept.
Trials and licenses: console.reallysec.com.