- How does the 60-day, $7,500 pilot work?
- Founding-customer pricing, limited seats. $7,500 flat for an 8-week engagement: Week 1–2 we run a full MCP audit across your dev fleet and stand up the allowlist. Week 3–4 we deploy the control plane and wire per-tool-call audit to your SIEM. Week 5–8 is policy tuning, dashboard handoff, and team training. Convert to the Team plan ($29/seat) from month 4 only if it lands — otherwise you keep the audit report and the free agent forever. Apply at /enterprise/pilot.
- Why per-seat instead of flat pricing?
- Per-seat is what platform and AppSec leads already buy. It scales linearly with the population you're governing (your engineers), which matches the audit and policy load. Volume discounts kick in at 100 seats. Annual billing saves ~17%.
- What's actually live today vs. roadmap?
- All Team features are live: allowlist push, audit log, multi-IDE enforcement, Sentinel agent, basic RBAC. Enterprise controls — SSO, SIEM export, self-hosted — are stood up per design-partner pilot. We don't sell roadmap; if it's on this page, you can run it during the pilot.
- Can I run this entirely on-prem?
- Yes — it's stood up during the pilot. The control plane ships as a Docker image with Postgres backing — runs in your VPC, no data leaves your network. The agent is local-first by design (the CLIs are open-source, MIT-licensed). On-prem is the standard offer for AppSec-led procurement, not a stretch deliverable.
- What does "Sovereign Certified" mean?
- Every server we list goes through a human security review: credential handling, network egress, code patterns, dependency audit. 70 servers approved, 22 rejected to date. The same review backs the policy templates your admins import — risk-classified, ready to allowlist.