Pricing

Start with one module. Add the rest without a second rollout.

One platform fee, then per-module pricing scaled to what you actually connect. No separate charge for the findings queue, automations, integrations or reports — those are the platform, not an upsell.

Team

For a security team of one to five, protecting a single cloud estate and a handful of repositories.

From $2,400 / mo

Billed annually · up to 250 identities

Talk to us
  • Includes
  • Any one module of the four
  • Unified findings queue and verification workflow
  • Automations, integrations and scheduled reports
  • SaaS control plane, region of your choice
  • Simulation on every enforcement surface
  • Email support, next business day
Most chosen

Enterprise

For regulated estates, sovereignty requirements, or anyone who needs the control plane inside their own boundary.

Custom

Annual · unlimited identities

Talk to us
  • Everything in Business, plus
  • Self-hosted control plane
  • Data residency and retention controls
  • Custom detection rules and policy-as-code
  • Auditor pack generation and evidence retention
  • Named engineer and onboarding programme
  • Contractual SLA and security review support

Indicative list pricing. Final figures depend on identity count, connected cloud accounts, repository volume and AI asset count — tell us those four numbers and we will come back with a fixed annual figure.

Never an add-on

The parts that make it a platform are not billable extras

If we charged separately for correlation, you would be paying us to fix a problem we created by shipping four disconnected products.

Findings queue

One queue across every module you own, with correlation and verification built in.

Automations

Unlimited rules and runs. Trigger from any module, act across any integration.

Integrations

The full catalogue, the API and webhooks. No per-connector fee, ever.

Reports

Board, CISO, engineering, auditor and customer-assurance presets included.

The honest comparison

What you are replacing

Most teams arrive holding three or four contracts. Here is what consolidation actually changes — including the parts that stay hard.

Point tools SanCipher
Contracts and renewals Three to five, on different cycles One, with per-module lines
The same incident Filed in three queues, owned by three people One finding, three sources, one owner
Data inspection Content copied to a vendor cloud Analysed on device or in your VPC
Enabling a block rule Ship it and hope, or run a manual pilot Replay against 30 days of real history first
Compliance evidence Exported per tool, reconciled by hand Assembled across modules into one pack
Rollout effort Separate per tool, repeated each time Once — later modules reuse the same connections
Still hard Deciding what to actually enforce Also this. Simulation helps; it does not decide for you
Questions

Asked on most first calls

Do we have to buy all four modules?
No. Most teams start with one — usually browser or AI security, because those are the surfaces nothing else covers. The platform fee is the same either way, and adding a module later reuses the connections you already made rather than starting a second rollout.
What actually leaves our network?
A finding record: severity, matched rule, redacted context, asset identifier, timestamp, and an attestation of where the analysis ran. Raw content — the document, the source file, the prompt, the credential itself — stays inside your perimeter. If you self-host the control plane, nothing leaves at all.
Is there an agent to install on endpoints?
No kernel agent. Browser security runs as a sidecar inside the browser, pushed through the MDM you already use. Cloud and code scanning run on nodes in your VPC or your existing CI runners.
How long does deployment take?
A cloud account or repository connects in under an hour, including the permission preview and dry run. A browser pilot group is typically live within a day of the MDM push. Enforcement is deliberately slower — we recommend running in observe mode for a fortnight before enabling any block rule.
Can we bring our own detection rules?
Yes. Custom secret detectors for internal token formats, custom red-team probes, and policy-as-code rules versioned alongside the platform's own. Your rules are never overwritten by a platform update.
Do you claim compliance certification?
Never. We produce evidence — the artefact each control generated, with a timestamp and a source — and we show you the controls where no evidence source exists at all. What an auditor concludes from that is between you and the auditor.
What happens if we leave?
Findings, evidence packs, audit log and configuration export in open formats through the API. Scanner nodes were always yours; you simply stop running them. There is no data of yours held hostage in our tenancy, because there was never much of it there.

Want a number for your environment?

Tell us your identity count, cloud accounts and repositories. We will come back with a fixed annual figure.

No credit card. No agent on the endpoint. Nothing leaves your network.