One meter across every product. An intercepted action is an authorisation decision, whether it comes from your own agents, an Authorised Agent, or an MCP client. Agents, Redact, and the Provenance Vault all draw from the same pool.
Every plan includes the full authorisation pipeline. What changes is included volume, the enforcement primitives available to you, and how you are allowed to deploy.
Starter
For teams putting their first agents into production and needing every action on record.
Annual or monthly. Overage billed per 1,000 decisions.
What you getGrowth
For teams running agents across multiple systems, with humans in the loop on the decisions that matter.
Annual commitment. Lower per-decision overage rate than Starter.
Everything in Starter, plusEnterprise
For regulated environments with residency, isolation, air-gap, or cross-organisation requirements.
Priced against your committed volume and deployment model.
Everything in Growth, plus| Starter | Growth | Enterprise | |
|---|---|---|---|
| Volume | |||
| Authorisation decisions included | 50k / mo | 500k / mo | Committed |
| Registered agents | 5 | 50 | Unlimited |
| Seats | 3 | 15 | Unlimited |
| Overage | Per 1k | Per 1k, lower rate | Negotiated |
| Enforcement | |||
| Deterministic and semantic policies | ✓ | ✓ | ✓ |
| Scoped, time-bound delegation | ✓ | ✓ | ✓ |
| Shadow mode and backtesting | ✓ | ✓ | ✓ |
| Mandates & Charter | — | ✓ | ✓ |
| Intent Contracts | — | ✓ | ✓ |
| Access Profiles | — | ✓ | ✓ |
| Risk Verdict | — | ✓ | ✓ |
| Escalations and human review | — | ✓ | ✓ |
| Breakglass protocol | — | — | ✓ |
| Runtime containment and kill switch | — | — | ✓ |
| Cross-organisation federation | — | — | ✓ |
| Products | |||
| Authorisation Layer | ✓ | ✓ | ✓ |
| Authorised Agents | ✓ | ✓ | ✓ |
| Provenance Vault | 90 days | 12 months | Unlimited |
| Xybern Redact | Add-on | ✓ | ✓ |
| MCP gateway | ✓ | ✓ | ✓ |
| Custom agent builds | — | — | ✓ |
| Deployment and support | |||
| Xybern Cloud | ✓ | ✓ | ✓ |
| Self-hosted relay | — | ✓ | ✓ |
| On-premise or air-gapped | — | — | ✓ |
| Data residency (US, EU, UK) | — | — | ✓ |
| SSO / SCIM | — | SSO | SSO + SCIM |
| Support | Priority | Named engineer | |
| SLA | — | 99.5% | 99.9% |
Priced separately because they are not metered work.
A scoped engagement where we build an Authorised Agent for your workflow, with its skills, connectors, and mandate set defined alongside your team. Included on Enterprise, available to Growth as a fixed-scope project.
We sit with your risk, legal, or security team, translate your existing control framework into mandates, backtest them against real traffic, and sign them into your Charter before you enforce.
If you only need PII stripped from LLM calls and not the full authorisation layer, Redact is available on its own, metered by redacted requests. Included at no extra cost from Growth upwards.
What exactly counts as an authorisation decision?
One intercepted action, one verdict. If an agent attempts a wire transfer, a database query, or a delegation to another agent, that is one decision each. Retries of the same action inside a single intercept do not double count. Denials count the same as authorisations, because a denial is the outcome you are paying for.
Do Authorised Agents cost extra?
No. Authorised Agents are built on the same layer, so their actions draw from the same decision pool as your own agents. You are not billed twice for running our agents through our layer.
What happens when we exceed the included volume?
Additional decisions are billed per thousand and you get an alert well before you get an invoice. We do not throttle or block production traffic for billing reasons. An authorisation layer that stops working when a meter runs out is not an authorisation layer.
Can we start with one workflow?
That is how most deployments begin. Pick the workflow with the highest consequence, put it behind the layer in shadow mode, and watch what would have been blocked before you enforce anything. Most teams are enforcing inside a week.
Do we have to move our agents onto your platform?
No. The layer is model and framework agnostic. It works with CrewAI, LangGraph, AutoGen, MCP clients, and custom systems, and it does not replace your models. Authorised Agents are an option, not a requirement.
Can we run this entirely inside our own infrastructure?
Yes. Growth includes the self-hosted relay, which evaluates policies locally and forwards only what it must. Enterprise supports full on-premise and air-gapped deployment with no external dependency.
Tell us how many agents you run and what they are allowed to touch. We will size it with you.