Pay for authorisation.
Nothing else.

One meter across every product. An intercepted action is an authorisation decision, whether it comes from your own agents, an Authorised Agent, or an MCP client. Agents, Redact, and the Provenance Vault all draw from the same pool.

How Billing Works

Three numbers, and only one of them moves much.

Primary meter

Authorisation decisions

Every action your agents attempt passes the layer once and receives one verdict. That verdict is one decision. Denied actions count the same as authorised ones, because stopping the wrong action is the work.

Capacity

Registered agents and seats

Agents are the identities you register and govern. Seats are the humans who write mandates, review escalations, and pull proof. Both scale with the plan rather than being billed separately.

Overage

Pay as you go, never a hard stop

Pass your included volume and additional decisions are billed per thousand at your plan's rate. We never block production traffic for a billing reason. You get an alert, not an outage.

Plans

Three plans. Priced on volume,
not on the number of products.

Every plan includes the full authorisation pipeline. What changes is included volume, the enforcement primitives available to you, and how you are allowed to deploy.

Starter

For teams putting their first agents into production and needing every action on record.

50,000 decisions / month 5 registered agents · 3 seats · 1 workspace

Annual or monthly. Overage billed per 1,000 decisions.

What you get
The full pipeline: intercept, identify, authorise, decide, record Deterministic and semantic policies Authorisation receipts on every decision Shadow mode and backtesting before you enforce Agent registry, roles, and scoped delegation Python and TypeScript SDKs, MCP gateway Xybern Cloud, 90-day Provenance Vault retention Email support
Book a demo

Enterprise

For regulated environments with residency, isolation, air-gap, or cross-organisation requirements.

Committed annual volume Unlimited agents · unlimited seats

Priced against your committed volume and deployment model.

Everything in Growth, plus
On-premise, private cloud, or air-gapped deployment Data residency in US, EU, or UK with workspace isolation Cross-organisation federation for partner agents Breakglass protocol with mandatory justification Runtime containment: session budgets and kill switch Proof Packs with public, offline-verifiable share links Custom mandate authoring and custom agent builds SCIM, unlimited vault retention, 99.9% SLA Named engineer, security review, MSA and DPA
Talk to sales
Compare

Every plan, side by side.

  Starter Growth Enterprise
Volume
Authorisation decisions included50k / mo500k / moCommitted
Registered agents550Unlimited
Seats315Unlimited
OveragePer 1kPer 1k, lower rateNegotiated
Enforcement
Deterministic and semantic policies
Scoped, time-bound delegation
Shadow mode and backtesting
Mandates & Charter
Intent Contracts
Access Profiles
Risk Verdict
Escalations and human review
Breakglass protocol
Runtime containment and kill switch
Cross-organisation federation
Products
Authorisation Layer
Authorised Agents
Provenance Vault90 days12 monthsUnlimited
Xybern RedactAdd-on
MCP gateway
Custom agent builds
Deployment and support
Xybern Cloud
Self-hosted relay
On-premise or air-gapped
Data residency (US, EU, UK)
SSO / SCIMSSOSSO + SCIM
SupportEmailPriorityNamed engineer
SLA99.5%99.9%
Beyond the plan

Add-ons and engagements.

Priced separately because they are not metered work.

Custom agent builds

A scoped engagement where we build an Authorised Agent for your workflow, with its skills, connectors, and mandate set defined alongside your team. Included on Enterprise, available to Growth as a fixed-scope project.

Mandate authoring

We sit with your risk, legal, or security team, translate your existing control framework into mandates, backtest them against real traffic, and sign them into your Charter before you enforce.

Xybern Redact standalone

If you only need PII stripped from LLM calls and not the full authorisation layer, Redact is available on its own, metered by redacted requests. Included at no extra cost from Growth upwards.

Questions

What people ask before they sign.

What exactly counts as an authorisation decision?

One intercepted action, one verdict. If an agent attempts a wire transfer, a database query, or a delegation to another agent, that is one decision each. Retries of the same action inside a single intercept do not double count. Denials count the same as authorisations, because a denial is the outcome you are paying for.

Do Authorised Agents cost extra?

No. Authorised Agents are built on the same layer, so their actions draw from the same decision pool as your own agents. You are not billed twice for running our agents through our layer.

What happens when we exceed the included volume?

Additional decisions are billed per thousand and you get an alert well before you get an invoice. We do not throttle or block production traffic for billing reasons. An authorisation layer that stops working when a meter runs out is not an authorisation layer.

Can we start with one workflow?

That is how most deployments begin. Pick the workflow with the highest consequence, put it behind the layer in shadow mode, and watch what would have been blocked before you enforce anything. Most teams are enforcing inside a week.

Do we have to move our agents onto your platform?

No. The layer is model and framework agnostic. It works with CrewAI, LangGraph, AutoGen, MCP clients, and custom systems, and it does not replace your models. Authorised Agents are an option, not a requirement.

Can we run this entirely inside our own infrastructure?

Yes. Growth includes the self-hosted relay, which evaluates policies locally and forwards only what it must. Enterprise supports full on-premise and air-gapped deployment with no external dependency.

Not sure which plan fits?

Tell us how many agents you run and what they are allowed to touch. We will size it with you.