Priced for how enterprises actually buy security.
Three tiers plus an enterprise track. Access is invitation-based — every conversation starts with a demo, and a 14-day trial is available on request.
Starter
Runtime enforcement for a first team.
- Runtime prompt scoring
- Inline DLP detection & redaction
- Natural-language policies
- One workspace
- Single-team seat band
- Email alerts
Growth
Posture and agents, not just prompts.
- Everything in Starter
- AI DSPM & datastore inventory
- Code & model-artifact scanning
- Agent governance & quarantine
- MCP server registry
- Red-team campaigns
- Slack notifications & REST API
Enterprise
Audit-grade evidence at org scale.
- Everything in Growth
- SSO
- Auditor portal & evidence locker
- Signed audit exports (Ed25519)
- Multi-workspace isolation
- RBAC with five roles
- Scheduled reporting
- Dedicated onboarding
Every capability, by tier.
| Capability | Starter | Growth | Enterprise |
|---|---|---|---|
| Runtime | |||
| Eight-dimension prompt scoring | ● | ● | ● |
| Inline DLP detection & redaction | ● | ● | ● |
| Natural-language policies & presets | ● | ● | ● |
| Bulk & API scanning | ● | ● | ● |
| Posture | |||
| AI DSPM & posture dashboard | — | ● | ● |
| Datastore inventory & identity risk | — | ● | ● |
| Shadow-AI log ingestion | — | ● | ● |
| Code & model-artifact scanning | — | ● | ● |
| Agents | |||
| Agent discovery & drift detection | — | ● | ● |
| Blast-radius policy & quarantine | — | ● | ● |
| MCP server registry | — | ● | ● |
| Red-team campaigns & weekly probes | — | ● | ● |
| Compliance | |||
| Tamper-evident audit chain | ● | ● | ● |
| PDF reports & framework mapping | ● | ● | ● |
| Ed25519-signed audit exports | — | — | ● |
| Auditor portal & evidence locker | — | — | ● |
| DSR handling & ROPA records | — | — | ● |
| Enterprise | |||
| Workspaces | 1 | 1 | Multi-workspace |
| SSO | — | — | ● |
| RBAC with five roles | — | — | ● |
| REST API & API keys | — | ● | ● |
| Slack notifications | — | ● | ● |
| Scheduled reporting | — | — | ● |
| Dedicated onboarding | — | — | ● |
A 30-day guided pilot, configured by us.
We configure the deployment, policies and detectors for your environment.
Success criteria are agreed up front, in writing.
You get preferential first-year pricing.
In exchange, you act as a reference when the pilot succeeds.
Asked before the PO.
How does deployment work?+
Three paths, all live the same afternoon: a PAC file pushed via Windows GPO or macOS MDM, a Manifest V3 browser extension for Chrome, Edge, Brave and Arc, or an OpenAI-compatible API proxy for your own applications and agents.
Do we need to change our firewall or network?+
No. None of the three deployment paths requires an NGFW change, an agent rollout, or a network-edge ticket.
Where is our data hosted?+
Deployment region and residency options are confirmed in writing during procurement — contact us and we will confirm what is available for your region before you commit.
What happens to our data if we leave?+
Your audit chain and evidence exports are signed with Ed25519 and remain verifiable after export. Tenant data is deleted on contract termination; retention terms are defined in the order form.
How does the trial work?+
A 14-day trial is available on request. Access is invitation-based — request a demo and we will provision a tenant against a pilot group.
Can we cancel?+
Yes. Subscriptions can be cancelled at the end of the current term. Because deployment is reversible (a PAC file, an extension, or a base URL), offboarding leaves no residual infrastructure in your estate.
Access is invitation-based — no self-serve signup.