PRICING
Three tiers. No surprises.
Start on a 15-day free trial. Team is a flat monthly rate with predictable overage. Enterprise is annual, with custom RBAC and deployment options.
Plans
Trial
No card required. At day 15, keys pause until you upgrade. 7-day grace before data is purged.
- 2 virtual keys
- 2 MCP connections
- All LLM providers
- 50k requests, 50k Shield scans
- 1 user
- 7-day audit retention
- Baseline Shield profile
- Community support
Team
Managed cloud. Email OTP with company domain whitelist. Predictable overage, invoiced monthly.
- 25 virtual keys
- 5 MCP connections
- All LLM providers
- 500k requests / month
- 500k Shield scans / month
- 5 users (admin, member, auditor roles)
- 30-day audit retention
- Baseline + strict Shield profiles
- Per-tool, per-key access control
- Email support, 24-hour response
Enterprise
Annual. Unlimited everything. Managed cloud, self-hosted, or air-gapped deployment with a named TAM.
- Unlimited keys, connections, users
- Custom request / scan volumes
- Custom RBAC roles
- 90+ day audit retention
- Policy-as-code via git
- HMAC-signed decision receipts
- Custom PII recognizers
- GPU-accelerated Shield
- Priority support, named TAM, 4-hour SLA
- Managed cloud, self-hosted, or air-gapped
Team plan details
Flat monthly. Predictable overage. No surprises at month-end.
Overage
Invoiced monthly, 7-day payment window.
- Requests: $0.50 per 1k
- Scans: $2.00 per 1k
Auth
Email OTP sign-in with company domain whitelist. No shared credentials.
Deployment
Managed cloud. Self-hosted and air-gapped are available on Enterprise.
RBAC — Team plan
Three built-in roles. Auditors see everything, change nothing.
| Capability | Admin | Member | Auditor |
|---|---|---|---|
| Billing, plan changes | — | — | |
| Invite / remove users | — | — | |
| Edit Shield profile | — | — | |
| Create / delete keys | — | — | |
| Add MCP connections | — | ||
| Edit access rules | — | — | |
| Approve HOLD calls | — | ||
| View audit traces | |||
| Export audit logs | — |
Enterprise supports custom RBAC roles beyond these three.
FAQ
Before you ask your CFO.
Put a governance layer in front of your agents.
FAIL_CLOSED by default. Every tool call scanned. Every decision signed.