Platform subscription
Visibility
$4 / endpoint / month
billed annually · from
The endpoint sensor + discovery console: full AI inventory across eleven signal classes, risk scoring, compliance mapping, audit trail. For teams starting an AI-governance programme.
Posture & response
$9 / endpoint / month
billed annually · from · everything in Discover
Adds the content-DLP policy engine, Slack & Jira workflow, signed compliance-evidence export, and SSO (OIDC) & SCIM. For teams operating AI risk day to day.
In-VPC & scale
Custom
annual · volume pricing
Fully in-VPC deployment (zero egress), data-residency pinning, custom integrations, dedicated support and onboarding. For regulated and large fleets.
| Example fleet | Discover (annual) | Secure (annual) |
|---|---|---|
| 1,000 endpoints | from ~$48k / yr | from ~$108k / yr |
| 5,000 endpoints | from ~$204k / yr (vol. disc.) | from ~$456k / yr (vol. disc.) |
| 25,000+ endpoints | Enterprise — custom volume pricing + in-VPC | |
Indicative starting prices — volume and annual-commit discounts apply, and non-profit/startup rates are available. Final pricing is scoped to your fleet in the scoping call. Weigh it against the analyst time you get back.
What counts as an endpoint? One enrolled host running the discovery sensor — a Windows 10/11 or Windows Server (Server is beta), macOS or Linux laptop, desktop, server or cloud VM. One host = one endpoint, whoever uses it. Cloud-connector discovery (AWS today; Azure and Google Cloud on connect) is scoped at the estate level, not billed per cloud resource. Billed annually; each edition carries an annual platform floor, so you pay the greater of the floor or endpoints × rate. Full deployment and data-handling detail is in the FAQ.
What’s in each edition
| Discover | Secure | Enterprise | |
|---|---|---|---|
| Price | $4 / endpoint / mo | $9 / endpoint / mo | Custom |
| AI discovery (11 signal classes) + AI-BOM + risk scoring | ✓ | ✓ | ✓ |
| Compliance mapping (NIST AI RMF · OWASP LLM · ISO 42001 · EU AI Act) | ✓ | ✓ | ✓ |
| RBAC · MFA · append-only audit log | ✓ | ✓ | ✓ |
| Content-DLP policy engine (block · redact · warn) — secrets/PII/PCI/PHI/code, per tenant & per machine | — | ✓ | ✓ |
| Device revocation · binary attestation · tamper-resistant sensor · remote-pause | ✓ | ✓ | ✓ |
| Slack & Jira workflow · signed compliance-evidence export | — | ✓ | ✓ |
| SSO (OIDC) · SCIM 2.0 | — | ✓ | ✓ |
| Rogue-agent-process kill · inline browser DLP · SAML 2.0 (roadmap) | — | Roadmap | Roadmap |
| In-VPC / zero-egress · data-residency pinning | — | — | ✓ |
| Support | Community | Priority · 8×5 | Premier · 24×7 + TAM |
| Onboarding | Self-serve | Standard | Dedicated |
“Roadmap” items are in active development — ask on the scoping call for current availability. Uptime / SLA terms are set in the order form for Secure and Enterprise.
Fixed-fee services
Every engagement is fixed-fee against a scope agreed up front, and every assessment includes a 30-day re-test after fixes ship.
| Engagement | Duration | Best for |
|---|---|---|
| Araghatta | 1–2 weeks | The inventory a governance programme starts from. |
| AI Security Assessment | 2 weeks + re-test | Defensible evidence for one production AI app. |
| Full AI Red Team | 4 weeks + re-test | App + RAG + agent/MCP, chained attack paths. |
| EU AI Act Readiness | 2–3 weeks | Where you stand vs Art. 9 & 55, with the evidence structure. |
| Continuous AI Testing | Rolling | Keeps the harness running as your models change. |
| Embedded AI Programme | Ongoing | Own your AI risk programme without a full-time hire. |
Full scope and deliverables are on the ServicesIntegrations page. See a sample report before you buy.