Enter the customer's AI estate. One balance of Qualys Units buys every TotalAI capability at once — they pick the mix against the ratios below, and move licenses between SKUs mid-term without a new procurement cycle.
InputCount | Output# of QLU's | |
|---|---|---|
Secure AI WorkforceLicensed per AI-active user, not per workload — one unique email or account identifier observed using AI during the measurement period. One entitlement covers both the desktop browser plugin and the SaaS (SSPM) connectors. This SKU governs user activity only — the AI SaaS workloads themselves are covered under Secure AI Workloads, below. | ||
AI-active users Workforce AI Security (SaaS) — 3 QLUs per user | # of QLU's: 3,000 | |
Secure AI WorkloadsPosture and Runtime may be applied to the same workload or independently. Count each workload once, in the row that matches the coverage it gets. Workloads running in SaaS are counted here, the same as self-hosted ones — where a model runs does not change what it is. | ||
What counts as an AI workload? One discrete AI entity of a billable type, counted once regardless of how many processes serve it or how many vantage points observe it. The billable entity types are:
| ||
Workloads with AI-SPM only AI Security Posture Management — 5 QLUs per workload | # of QLU's: 0 | |
Workloads with Runtime Security only TotalAI Runtime Security — 10 QLUs per workload | # of QLU's: 0 | |
Workloads with AI-SPM + Runtime Security Full coverage — 5 + 10 = 15 QLUs per workload | # of QLU's: 3,000 | |
Security Testing for AI WorkloadsRed Teaming covers models and MCP servers; agent red-teaming is not in TotalAI 2.0. A remote endpoint the customer supplies consumes the Red Teaming ratio only — it is tested, but it is not an AI workload. | ||
LLMs red-teamed 300 QLUs per model · 5 scans per model per rolling 30 days | # of QLU's: 3,000 | |
MCP servers red-teamed 30 QLUs per server · unlimited on-demand scans | # of QLU's: 150 | |
At or above the 7,500 QLU threshold — QFlex-convertible. These QLUs may convert to platform-wide QFlex units at 1:1, redeemable across the full Qualys portfolio.
This is why QLU exists. The balance is not locked to a SKU. Every TotalAI SKU is provisioned at the customer's full QLU value up front, so a team turns a capability on the day they want it — no sub-allocation to request, no internal reshuffling, no new procurement cycle, and nothing to wait on from Qualys. Priorities change mid-term; the licenses follow.
Each figure below is what the whole balance buys in that one SKU — alternatives drawn from the same pool, not additive. Max provisioning enables the capabilities, not the entities: individual workloads are still counted only when assessment is enabled for them, and consumption is reconciled against the purchased balance at renewal.
users
Workforce AI Security
AI workloads
AI-SPM
AI workloads
Runtime Security
models
Red Teaming — LLM
MCP servers
Red Teaming — MCP
Discovery is included at no charge. AI workloads are counted only when the customer enables assessment for them — discovered entities are not automatically enrolled or metered.
| Per AI-active user | Units | QLU's |
|---|---|---|
| Workforce AI Security (SaaS) | 1 | 3 |
| Per AI workload | ||
| TotalAI Security Posture Management (AI-SPM) | 1 | 5 |
| TotalAI Runtime Security | 1 | 10 |
| Per red-team target | ||
| Red Teaming — LLM, per model | 1 | 300 |
| Red Teaming — MCP, per MCP server | 1 | 30 |
A model served by multiple worker processes, replicas or load-balanced endpoints is one workload. A host serving several distinct models is one workload per model. A cloud AI service reached by many callers is one workload per model deployment, not per caller.
An entity observed from a host agent, network scanner, cloud log, SaaS connector and browser reconciles to a single workload.
Workload and user consumption is a daily active count averaged over a rolling 90 days; at renewal the most recent 90-day average governs. Intermittent or decommissioned entities are reflected in the average rather than counted at peak, and roll off automatically — nothing to un-enroll.
One entitlement permits one model or one MCP server, scanned any number of times within the scan limits. Entitlements count distinct targets scanned in the trailing 90 days; a target not scanned for 90 days frees its entitlement for another.
LLM scans run the full OWASP Top-10 for LLM suite with judge-LLM evaluation, mapped to the EU AI Act and MITRE ATLAS.
Prompt and response activity is attributed by originating principal: human-originated activity is licensed under Workforce AI Security per user; application- or service-originated activity is licensed under Runtime Security per workload. The sensor that observes it does not change the attribution.
Posture, Runtime Security and Red Teaming are separate capabilities and may apply to the same entity. An MCP server assessed for posture, monitored at runtime and red-teamed consumes all three ratios — 5 + 10 + 30 = 45 QLUs.
At 7,500 QLUs or more, TotalAI QLUs may convert to platform-wide QFlex units 1:1, redeemable across the full Qualys portfolio. Below that threshold, conversion is not available.