Pricing

One small monthly base, then a fraction of a cent per screened message. No per-seat fee, no minimum commitment on Basic or Team.

Basic

$99.99per month

Everything needed to stop a bad message and prove it later.

  • 1 deployment
  • 50,000 screened messages included
  • All three kill levels
  • Autopilot thresholds and plain-English rules
  • Insert-only log with hash chain and verification
  • 30 day retention
  • Email alerts
  • SSO and SCIM
  • Data residency
  • Priority support
Start on Basic
Most popular

Team

$499per month

For safety teams running several agents in production.

  • Unlimited deployments and chains
  • 500,000 screened messages included
  • Webhook and Slack alerts
  • 1 year retention
  • Daily anchors and signed audit exports
  • Role based access for the whole team
  • Priority support
  • Self-hosted scorer
  • Data residency
Choose Team

Enterprise

Customannual

Message content never leaves your infrastructure.

  • Self-hosted scorer on your own GPUs
  • EU or US data residency
  • SSO and SCIM
  • Custom retention and legal hold
  • Independent anchoring for third-party proof
  • Security review support
  • Dedicated support channel
Talk to us

Questions

What counts as a screened message?

Every call to the screening endpoint. One chat turn is normally two: the user's message on the way in and the model's reply on the way out. Agent actions count as one each.

What happens past the included volume?

$0.40 per additional thousand screened messages, plus token pass-through at $0.05 per million input tokens and $0.15 per million output tokens. Every event records its own token counts, so the usage page shows real numbers rather than an estimate.

Do you train on our messages?

No. We do not sell your data and we do not train models on the content you send us. On Enterprise you can run the scorer on your own hardware so message content never reaches us at all.

Can we store scores without storing the text?

Yes. Hash-only mode stores a SHA-256 of each message instead of the text. The chain still verifies, and transcripts stop being readable.

Start with monitor-only mode

Score and log everything without blocking anything, then turn enforcement on when the thresholds look right.