We charge per verified bundle, not per seat — so cost scales with what you protect, not how many people browse the dashboard.
Plans
Numbers are anchor points for early conversations — final pricing is shaped per ICP. USD, monthly, billed annually.
Full comparison
| Capability | Free OSS | Team | Enterprise | Regulator |
|---|---|---|---|---|
| Pricing | ||||
| Monthly anchor | $0 | $500 | $5,000 | Contact |
| Verified bundles / month | Self-hosted | 100k | 2M | Custom |
| Core Verification | ||||
| OSS verifier CLI (P1–P8) | ✓ | ✓ | ✓ | ✓ |
| Hosted SaaS aggregator | — | ✓ | ✓ | ✓ |
| Confidential Verify (TEE) | — | — | Add-on | ✓ |
| Proxy re-encryption auditor handover | — | — | Add-on | ✓ |
| Agent Security | ||||
| Runtime IDS (tool-call sandbox) | — | Basic | Full | Full |
| Pre-execution risk scoring | — | — | ✓ | ✓ |
| Incident timeline replay | — | 7-day retention | 90-day retention | Custom retention |
| Vulnerability Discovery | ||||
| Automated vuln scans / month | — | 1 | 4 | Weekly |
| Adversarial fixture generation | — | ✓ | ✓ | ✓ |
| Compliance | ||||
| SOC 2 / ISO 42001 evidence pack | Manual export | Generated | Auto + review | Auto + custody chain |
| Dedicated tenancy / regional sovereignty | — | — | Add-on | ✓ |
| Support | ||||
| Support SLA | Community | Email · 2-biz-day | P1 4h / P2 1-biz-day | Custom + on-call |
A "bundle" is one cryptographically-sealed evidence package — typically covering one audit period (hourly, daily, or per-incident depending on your retention policy). Cost grows in lockstep with the audit surface you protect, not how many people sit in the dashboard.
Add-ons (TEE-hosted Confidential Verify, Proxy Re-Encryption auditor handover, dedicated tenancy) layer on top of the base tier. Regulator Edition is bespoke — contact us with your jurisdiction and bundle volume.
FAQ
Yes for the OSS verifier — that's the entire point. For the SaaS aggregator and dashboard, on-prem deployment is available at Enterprise and above via K8s manifests and Helm chart.
One ZIP with one bundle-manifest.json.
Granularity is your choice — most teams ship hourly or per-incident;
high-risk regulated workloads ship per-call.
Yes. Automated Vulnerability Discovery is purchasable without a SaaS subscription — your engineering team gets a private corpus and agent that continuously probes your AI gateways.
Yes. The verifier, schema, and demo bundles stay Apache 2.0 — enforced by ADR-09. The closed-source pieces (SaaS aggregator, billing, OAuth) are the parts that don't affect audit re-verification.
Pin a version, point it at your audit.jsonl,
ship the proof_hash to your auditor.
When you're ready for hosted aggregation or design-partner pilots, we're an email away.