What Is Trend Vision One? XDR, Risk Management and Licensing Guide
In short: Trend Vision One is Trend Micro's XDR and cyber risk management platform that unifies signals from endpoints, email, network, cloud, identity and data in one console; since March 2026 it is officially TrendAI Vision One. It is licensed with TrendAI Flex credits, and the right package depends on the layers you protect, team capacity and data residency.
What is Trend Vision One, and why is it now called TrendAI Vision One?
Trend Vision One (Trend Micro's XDR and cyber risk management platform) is an enterprise security platform that collects telemetry from several security layers into one data layer, correlates it and runs the response from the same console. On 23 March 2026 Trend Micro announced that its enterprise cybersecurity business would operate as TrendAI, while the legal entity remains Trend Micro Incorporated; current vendor pages and documentation therefore say "TrendAI Vision One".
The vendor's platform page (accessed 7 October 2026) groups Vision One into three areas: Cyber Risk Exposure Management (CREM), Security Operations (XDR, Agentic SIEM and Agentic SOAR) and layered protection. The protection layer lists Endpoint, Email, Network, Cloud, Identity, Data and AI Security solutions.
For the product introduction and feature list, see our Trend Vision One product page; this article covers the decision side: what it solves, how the parts fit, who needs which package and what to clarify before licensing. We explain how XDR differs from EDR and MDR in our EDR vs XDR vs MDR comparison.
Which problems does Trend Vision One solve?
Trend Vision One mainly targets alerts that sit in separate consoles and never get linked into one attack chain; unseen assets, hard prioritization and fragmented licensing come on top:
- Disconnected alerts: the platform aims to correlate low-confidence alerts and events into prioritized, high-confidence insights.
- Unknown assets: CREM continuously discovers unknown, unmanaged and third-party assets and scores risk by asset criticality, threat activity and business impact.
- Limited analyst capacity: TrendAI Companion helps with triage and queries; managed detection and response (MDR) under TrendAI Vision One Services moves monitoring outside.
- Tool and license sprawl: the vendor states that one credit balance can be used across more than 30 Vision One solutions.
A neutral framework shows where the platform contributes and where your work begins. The NIST Cybersecurity Framework (CSF) 2.0, published on 26 February 2024, organizes security outcomes into six Functions; we built the mapping below from the vendor's component descriptions.
| CSF 2.0 Function | Vision One counterpart | What stays with you |
|---|---|---|
| Govern | No direct counterpart; CREM risk scores and compliance reports feed management decisions | Risk appetite, policy, roles, budget |
| Identify | CREM: asset discovery, vulnerability and exposure management, identity security posture | Asset ownership and criticality classification |
| Protect | Endpoint, Email and Collaboration, Network, Cloud, Identity and Data Security | Policy tuning, exceptions, patching |
| Detect | XDR sensors, Agentic SIEM, Workbench | Who reviews alerts, and how fast |
| Respond | Agentic SOAR playbooks, response actions, MDR and incident response services | Decision rights, internal communication, legal notifications |
| Recover | No backup or disaster recovery component is listed on the platform page | Backup, restore testing, business continuity |
Vision One contributes most to Identify, Detect and Respond; governance and recovery need separate processes and products. NIST SP 800-61 Rev. 3 (April 2025) likewise treats incident response as part of all risk management activities, not a single product.
How do the platform components fit together?
Read Vision One as a data flow: sensors collect, security operations correlates, CREM scores risk, automation and people respond:
- Sensors collect data. The Security Operations page lists six native XDR areas: XDR for Endpoints (EDR), Networks (NDR), Identity (ITDR), Email (EmDR), Cloud (CDR) and Data (DDR).
- Third-party logs are added. Agentic SIEM ingests logs from sources such as firewalls or identity providers, with analytic or archival (compliance, infrequent query) retention.
- Events are correlated. XDR correlation joins steps from different layers into alerts and insights in Workbench.
- Risk is scored. CREM ranks vulnerabilities, misconfigurations and identity risks per asset; attack path prediction sits in the Essentials package.
- Response is automated. Agentic SOAR runs containment and remediation through natural-language playbooks and guided workflows.
- People decide. Your own team, an MDR service or a service provider makes the call.
Console access has two tiers. Essential Access comes at no additional charge with a valid license for a supported product such as Apex One or Deep Discovery Inspector and offers a limited app set; Advanced Access is the full set, only for organizations with credits. Existing products such as Deep Security server protection or Deep Discovery network detection can therefore be connected before you buy credits.
Which organization needs which part?
The starting point depends on your weakest layer and on who can review alerts; there is no need to roll out the whole platform at once. Packages are tiered:
- Endpoint Security: Core covers anti-malware, web reputation, firewall, device and application control, DLP and desktop IPS. Essentials adds XDR for Endpoints (EDR); Pro adds integrity monitoring, log inspection and server IPS.
- Email and Collaboration Security: Core and Essentials support API-based and MX-based deployment; Pro adds XDR for Email.
- Cyber Risk Exposure Management: Core includes attack surface discovery, exposure management, identity security posture and a network vulnerability scanner. Essentials adds attack path prediction, security awareness and compliance management.
The decision matrix below is our own assessment; the final scope should come from your inventory and risk analysis.
| Organization profile | Sensible starting point | Add later | Watch out for |
|---|---|---|---|
| Uses Apex One or Deep Security, small security team | Essential Access with the existing license, then Endpoint Security Essentials | Email and Collaboration Security, CREM Core | Migration timeline for the on-premises management server |
| Microsoft 365-centric, high phishing exposure | Email and Collaboration Security plus Endpoint Security Essentials | XDR for Email, Identity Security | Per-user metering |
| Own SOC with an existing SIEM | Security Operations (XDR) plus data export to the existing SIEM | Agentic SIEM, Agentic SOAR playbooks | Log volume (GB) drives credit use |
| Cloud-workload-heavy | Cloud Security: Cloud Risk Management, Server and Workload Protection, Container Security | XDR for Cloud | Resource tiers per cloud account |
| Manufacturing or campus network with many unmanaged devices | XDR for Networks (Virtual Network Sensor or Deep Discovery Inspector) | Network Security IPS | Metered on monitored throughput (Mbps) |
| Regulated, with data residency requirements | Assess sovereign/private cloud or on-premises deployment | Layered protection | Infrastructure and operations stay with you |
Moving an existing endpoint estate is covered in our Apex One to Vision One Endpoint Security migration plan. For small businesses without a security team, our Worry-Free or Vision One decision guide compares the platform with a simpler product. See also our enterprise antivirus comparison and the full portfolio on our Trend Micro solutions page.
Are TrendAI Companion and AI Security the same thing?
No: TrendAI Companion is an AI assistant for analysts, while AI Security is a separate solution family that protects your organization's own AI use and applications. The shared "AI" label often confuses quotes.
The documentation describes Companion as a built-in AI cybersecurity adviser for investigating, analyzing and responding to incidents and alerts. Example tasks include listing exposed assets, prioritizing CVEs, triaging Workbench alerts, checking endpoint sign-ins and estimating the monthly credit drawdown. According to the documentation, Companion can also search the internet to supplement answers with current external data.
Settle two points before rollout. First, permissions: rights such as initiating response actions or collecting files from endpoints can be limited by role, so decide who approves what the assistant suggests. Second, scope: AI Security aims to test AI applications against attacks such as prompt injection and protect them at runtime, while AI Secure Access controls employees' access to generative AI. We look at network-layer options in our article on controlling generative AI use with a firewall.
How does Trend Vision One licensing work, and what drives the price?
Since January 2026 the TrendAI Flex (credits) license is the only Vision One license on sale; credits are bought for a set term and drawn down monthly by actual usage. Per the documentation, existing licenses converted automatically with the same value, utility and expiry date, and on 2 February 2026 the "Vision One Credits" license was renamed TrendAI Flex (credits).
The drawdown is deducted on the first day of the next month, using one of two methods. Snapshot-based packages record the number of units in use each day and bill on the 85th-percentile day, ignoring the highest 15% of usage days. Volume-based packages sum usage accumulated over the month. Credits expire with the license; if usage exceeds the balance, it shows a negative value until you buy credits or reduce usage, and the platform keeps working.
| Solution | Metering unit | Method |
|---|---|---|
| Endpoint Security (Core, Essentials, Pro) | Per endpoint | Snapshot |
| Email and Collaboration Security | Per user | Snapshot |
| Cyber Risk Exposure Management | Assessed desktop/server and network device; resource tier per cloud account | Snapshot |
| XDR for Networks | Monitored throughput (per 500 Mbps) | Snapshot |
| Agentic SIEM | Data ingested and retained (GB) | Volume |
| Zero Trust Secure Access | Per user | Snapshot |
You can estimate credit needs before asking for a quote with this formula: monthly credits ≈ Σ (85th-percentile units × monthly credit requirement for snapshot packages) + Σ (total monthly usage × unit credit requirement for volume packages). Annual need is twelve times the monthly estimate plus your own buffer for the pilot, incidents and growth. Per-package credit requirements are published in the documentation; the price per credit comes with the quote, so we give no amounts here.
Volume packages are the most underestimated item: a firewall connected to Agentic SIEM before its log volume is measured can push the drawdown above plan. The vendor also recommends activating new snapshot packages early in the month. For wider planning, see our 2026 cybersecurity budget priorities.
Share your endpoint, user, server, cloud account and log volume inventory, and we can work out the package mix and a credit estimate with you. Get a Quote
Which deployment decisions should you make before rollout?
The three critical decisions are where data lives, how long it is kept and who operates on-premises components. The vendor describes these options:
| Option | Where it runs | Situation the vendor points to |
|---|---|---|
| SaaS | Hosted in a public cloud by TrendAI or its partners; GovCloud option available | Fast rollout, reliable internet, moderate residency constraints |
| Sovereign or private cloud | Your own AWS, Azure or Google Cloud environment | Regulated industries, strict residency mandates |
| On-premises | Your own data center | Data must stay inside the organization |
| Air-gapped / offline | Environment with no external connectivity | Limited or no internet access |
With SaaS, the console is provisioned in the region chosen at setup, and data is stored and processed there. According to the vendor's knowledge base article, sites are the US, EU (Germany), Japan, Singapore, Australia, India, MEA (UAE), UK, Canada, South Africa and Indonesia; there is no data center in Türkiye on the list. The data privacy document adds that TrendAI operations, threat research and (if enabled) support teams may access information from outside the region. Organizations in Türkiye should review this with legal counsel under KVKK, the Turkish data protection law; for technical measures see our KVKK technical measures checklist.
Retention also shapes the license: per the same document, raw data is kept for 30 days by default unless extended storage is bought, Workbench alerts and audit logs for 180 days; longer retention consumes credits. If you have statutory log retention duties, plan which system holds which records (see our article on Law 5651 log retention for Türkiye).
In hybrid setups, a Service Gateway virtual appliance in the local network relays services such as ActiveUpdate and Smart Protection Services to on-premises products. If you keep an on-premises management server, patching it is your job: CISA's Known Exploited Vulnerabilities catalog (KEV, 4 October 2026 version) lists 12 Trend Micro entries, all for endpoint products and management components such as Apex One, OfficeScan, Worry-Free Business Security and Apex Central. Follow the vendor's security bulletins for those servers.
Which questions should you ask before licensing?
Answering these internally before requesting a quote makes the estimate realistic; the affected decision is in brackets:
- Scope: Which layers do we protect in year one? (package choice)
- Inventory: How many endpoints, servers, mail users, cloud accounts, and how much traffic to monitor? (credit estimate)
- Logs: Which third-party logs, how many GB per day, analytic or archival retention? (Agentic SIEM consumption)
- Monitoring: Who reviews alerts out of hours: our team, MDR or a provider? (services)
- Residency: Which SaaS region is acceptable, or do we need sovereign cloud or on-premises? (architecture)
- Existing licenses: When do current licenses expire, and what credit value do they convert to? (migration timeline)
- Integration: How does it relate to our SIEM and ticketing? (Agentic SIEM or data export)
- Permissions: Which actions may Companion suggestions and automated playbooks take without approval? (role design)
- Exit: If the license lapses, when is data purged and what must be exported first? (contract)
Then run the evaluation in this order:
- Put inventory and current license expiry dates in one table.
- If you hold a supported license, open the Essential Access console and connect existing products.
- Limit the pilot to one layer and a representative user group; Essential Access customers may be eligible for a full-platform trial.
- Track real usage in Platform Usage and Credits during the pilot and update the formula's assumptions.
- Measure alert volume and review workload, then decide whether you need MDR.
- Request the annual quote with the updated credit estimate, deployment model and retention period.
FAQ
Are Trend Vision One and TrendAI Vision One the same product?
Yes. On 23 March 2026 Trend Micro announced that its enterprise cybersecurity business would operate as TrendAI, and current pages and documentation call the platform TrendAI Vision One. The legal entity is still Trend Micro Incorporated, so older documents and quotes may use the Trend Vision One name.
Is Trend Vision One just an XDR product?
No. XDR is one part of the platform's Security Operations area. The same console also offers exposure management (CREM), third-party log analytics (Agentic SIEM), automation (Agentic SOAR) and layered security solutions. You decide which of them to enable from your credit balance.
What determines Trend Vision One pricing?
Cost is the product of each package's credit requirement and your metering units: endpoints and users, assessed devices and cloud accounts, monitored network throughput, ingested log volume and retention type. The price per credit is set in the quote. Share your inventory to request a credit estimate and quote.
Can I use the Vision One console with my Apex One or Deep Security license?
Yes, to a limited extent. A valid license for a supported product provisions a Vision One console at the Essential Access tier at no additional charge, with apps such as Search, Targeted Attack Detection, Security Assessment and Cyber Risk Overview. Advanced Access, the full app set, is available only to organizations with credits.
What happens to our data if the license expires?
According to the documentation, the platform stays usable during a 30-day grace period after expiry. A 30-day lockout follows, blocking browser and API access while the account remains recoverable; after it, associated data is purged. Credits also expire with the license, so plan renewal ahead of this timeline.
In which country is Vision One data stored?
With SaaS, the console is provisioned in the region you choose at setup, and data is stored and processed there. The current site list includes the US, EU (Germany), UAE, UK and India, among others; there is no data center in Türkiye. Stricter residency needs point to sovereign cloud, private cloud or on-premises deployment.
Conclusion
- Trend Vision One, now TrendAI Vision One, goes beyond XDR: risk management, SIEM, automation and layered protection share one console.
- It contributes most to identification, detection and response; governance, backup and recovery need separate planning.
- Since January 2026 licensing uses only TrendAI Flex credits; metering units and log volume drive cost.
- Data region, retention and operation of on-premises components should be settled before the quote.
Sora Yazılım provides selection, procurement, installation, support and managed services for Trend Micro products; we can review a package and credit plan for your inventory and team with you.
Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com
Sources
- TrendAI Vision One platform pages — TrendAI (Trend Micro), 2026: Platform, Security Operations, Cyber Risk Exposure Management, AI Security, Deployment Options, Services (accessed 7 October 2026)
- Credits and licensing — TrendAI documentation: Credit requirements, How credit usage is calculated, Credits, Licenses converted into credits, TrendAI Flex licensing now available (accessed 7 October 2026)
- Console access tiers — TrendAI documentation: Access tiers, Essential Access (accessed 7 October 2026)
- TrendAI Companion — TrendAI documentation. docs.trendmicro.com (accessed 7 October 2026)
- Data privacy, security, and compliance — TrendAI documentation. docs.trendmicro.com (accessed 7 October 2026)
- KA-0015959: region and Data Center location — TrendAI support. success.trendmicro.com (accessed 7 October 2026)
- Service Gateway overview — TrendAI documentation. docs.trendmicro.com (accessed 7 October 2026)
- Trend Micro's Enterprise Business is now TrendAI — Trend Micro Newsroom, 23 March 2026. newsroom.trendmicro.com (accessed 7 October 2026)
- The NIST Cybersecurity Framework (CSF) 2.0 — NIST CSWP 29, 26 February 2024. csrc.nist.gov (accessed 7 October 2026)
- SP 800-61 Rev. 3, Incident Response Recommendations and Considerations — NIST, April 2025. csrc.nist.gov (accessed 7 October 2026)
- Known Exploited Vulnerabilities Catalog, version 2026.10.04 — CISA. raw.githubusercontent.com (accessed 7 October 2026)
How this article was prepared
Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical information was checked against the vendor and official sources linked in the article as of 7 October 2026.
Related articles
- Migrating from Apex One to Trend Vision One Endpoint Security — moving on-premises endpoint protection to the platform.
- Trend Micro Worry-Free or Vision One? — selection criteria for SMBs.
- EDR vs XDR vs MDR — which detection and response model fits you.
- Enterprise antivirus: Bitdefender vs Trend Micro — a profile-based endpoint comparison.
