Priced on the risk you are covering.
Governance is not a per-seat tool. You are buying the ability to constrain what autonomous agents do on your store and to prove it afterward. Annual billing takes two months off.
Agent Audit
$0
No account required
See what agents can already read and do on your public site. Read-only, nothing modified. Re-run it whenever you like.
Guardian
$900 / month
One property · $9,000 billed annually
All seven controls, live. Policy limits, verify-or-block, independent verification, injection screening, approval gates, kill switch, and a tamper-evident audit trail you can export.
Guardian Business
$3,500 / month
Up to 10 properties · $35,000 billed annually
Everything in Guardian, plus SSO and SAML, role-based access, approval workflows, SIEM and webhook delivery, evidence export, and continuous monitoring across every property.
Deployed in your environment
From $75,000 / year
Runs inside your infrastructure or air-gapped. Custom policy authoring, your own model or gateway, compliance evidence packs, named support with an SLA, and security review support. For teams where the audit trail has to satisfy someone outside the company.
What you are actually buying
A single unauthorized discount applied at scale, one fraudulent agent checkout, or one dispute you cannot evidence will cost more than a year of Guardian. Governance is priced against that exposure, not against how many people log in.
Guardian sits deliberately under most procurement thresholds so an owner can approve it without a committee.
Questions people ask before buying
| Question | Answer |
|---|---|
| Do you see our customer data? | No. The product runs local-first. Merchant knowledge, telemetry, policies and credentials stay inside your environment by default. We hold no operational data. |
| Do we have to use your AI? | No. Choose a local model, bring your own API key, bring your own model, or route through your existing gateway. There is no mandatory vendor. |
| What if we have no agent traffic yet? | Then start with the free audit and Guardian on one property. The controls are cheapest to put in before the volume arrives, not after an incident. |
| Can an agent be talked out of the rules? | No. The controls are deterministic code, not instructions in a prompt. A model cannot reason past them, and injected text in page content cannot widen a capability. |
| What happens if something goes wrong? | The kill switch halts all autonomous action immediately without a deploy, and the hash-chained audit trail shows exactly what was permitted, attempted and completed. |
| Can we start small? | Yes. Guardian is one property, month to month, cancel any time. Most customers start there and add properties. |