Start with the report.
Every engagement starts with the Agent Exposure Report, free: a read-only deploy that ends with a board-ready artifact of every agent, tool, and MCP connection across your fleet. No commitment, no card.
Pilot
The Agent Exposure Report engagement. A read-only deploy that ends with a board-ready decision artifact: every AI agent, tool, and MCP connection across the cohort you choose, from one team to your whole fleet. Yours, free.
Get your Agent Exposure Report- Read-only deploy across a cohort you choose, up to your whole fleet
- Board-ready Agent Exposure Report
- Policy baseline in monitor mode
- Weekly posture-and-violations reporting
- Kill-switch drill: we delete the envelope key (or you revoke your BYOK key) and the data is permanently unreadable
- Concierge onboarding: we do the work with you
Platform
Continuous governance for the whole fleet, priced per developer: the cheapest line item in your AI rollout. Billed annually, scaled to fleet size.
Book a demo- Continuous fleet inventory
- MCP policy: monitor first, enforce when ready
- Tamper-evident audit chain
- Data encrypted under a key we delete on account termination or request: permanently unreadable
- Enterprise SSO (OIDC / SAML)
- Observatory fleet views
- Weekly reporting
Enterprise
Scale, key custody, and controls for regulated fleets.
Talk to us- Everything in Platform
- Bring your own KMS key (BYOK), or hold a key you never share with us (HYOK)
- Spectra SIEM routing
- SSO / SCIM at scale
- Extended audit retention
- Security-guarantees tier as it ships: signed builds, attestations, CVE response SLAs
Governance at $3–10 per developer per month, on an AI investment of $20–40 per developer per month: the cheapest line item in the rollout, and the one that gets it approved.
Questions, answered.
- How does the pilot work?
- It's a free, read-only engagement on a cohort you choose, from one team up to your whole fleet. Beacon deploys read-only and nothing is enforced. It's time-boxed and ends with the board-ready Agent Exposure Report, a policy baseline in monitor mode, weekly posture-and-violations reporting, and a live kill-switch drill with your team. No fee, no card, no commitment: if it earns it, you convert to Platform.
- Who holds the keys to my data?
- By default your fleet data and the tamper-evident audit chain are encrypted under an envelope key we hold on your behalf and delete on account termination or request, which makes the data permanently unreadable, a crypto-shred. Nothing to configure. If your security team would rather hold the key themselves, enterprises can bring their own KMS key (BYOK): revoke it and watch our access die in your own CloudTrail. Either way, pricing is based on fleet size and tier, never on reading or monetizing your data.
- Does Alyria read my data?
- Static blobs stored with us are opaque to us at rest. By default they're encrypted under an envelope key we delete on account termination or request; enterprises can bring their own KMS key they hold and revoke. Client-held keys, where we never hold the key at all, are on our roadmap pending an externally audited protocol: future work, not a present guarantee.
- Can I self-host, or does Alyria host it?
- The platform core is source-available and can run on your own infrastructure. Most teams choose the hosted offering: Observatory hosts the console, SSO, and fleet dashboards. Either way, static blobs stored with us are opaque to us at rest, and enterprises can hold the keys themselves (BYOK/HYOK).
- What does open-core actually mean here?
- The platform core is source-available (BSL 1.1) and Umbra’s client-side crypto and SDK are fully open (Apache/MPL) so the client-side crypto stays auditable; the full licensing story lives on the security & trust page.
- How does enterprise SSO work?
- Platform includes enterprise SSO via OIDC or SAML out of the box. Enterprise adds SCIM provisioning, extended audit retention, and SIEM routing at scale for larger, regulated fleets.
- What are “security guarantees”?
- A distinct Enterprise tier, independent of license, delivered as it ships: SLA, warranty/indemnity, SOC 2 and pen-test attestations, signed/reproducible builds, and committed CVE response windows. Details on the security & trust page.
Find out what your fleet is running. This week.
A free, 30-minute read-only deploy. A board-ready report of every agent, tool, and MCP connection. And a kill-switch drill: the envelope key is deleted, the data goes permanently dark.