Skip to content
Pricing

Start with the report.

Every engagement starts with the Agent Exposure Report, free: a read-only deploy that ends with a board-ready artifact of every agent, tool, and MCP connection across your fleet. No commitment, no card.

Start here

Pilot

Freeread-only · no commitment

The Agent Exposure Report engagement. A read-only deploy that ends with a board-ready decision artifact: every AI agent, tool, and MCP connection across the cohort you choose, from one team to your whole fleet. Yours, free.

Get your Agent Exposure Report
  • Read-only deploy across a cohort you choose, up to your whole fleet
  • Board-ready Agent Exposure Report
  • Policy baseline in monitor mode
  • Weekly posture-and-violations reporting
  • Kill-switch drill: we delete the envelope key (or you revoke your BYOK key) and the data is permanently unreadable
  • Concierge onboarding: we do the work with you

Platform

From $3per developer / month

Continuous governance for the whole fleet, priced per developer: the cheapest line item in your AI rollout. Billed annually, scaled to fleet size.

Book a demo
  • Continuous fleet inventory
  • MCP policy: monitor first, enforce when ready
  • Tamper-evident audit chain
  • Data encrypted under a key we delete on account termination or request: permanently unreadable
  • Enterprise SSO (OIDC / SAML)
  • Observatory fleet views
  • Weekly reporting

Enterprise

Talk to uscustom

Scale, key custody, and controls for regulated fleets.

Talk to us
  • Everything in Platform
  • Bring your own KMS key (BYOK), or hold a key you never share with us (HYOK)
  • Spectra SIEM routing
  • SSO / SCIM at scale
  • Extended audit retention
  • Security-guarantees tier as it ships: signed builds, attestations, CVE response SLAs

Governance at $3–10 per developer per month, on an AI investment of $20–40 per developer per month: the cheapest line item in the rollout, and the one that gets it approved.

FAQ

Questions, answered.

How does the pilot work?
It's a free, read-only engagement on a cohort you choose, from one team up to your whole fleet. Beacon deploys read-only and nothing is enforced. It's time-boxed and ends with the board-ready Agent Exposure Report, a policy baseline in monitor mode, weekly posture-and-violations reporting, and a live kill-switch drill with your team. No fee, no card, no commitment: if it earns it, you convert to Platform.
Who holds the keys to my data?
By default your fleet data and the tamper-evident audit chain are encrypted under an envelope key we hold on your behalf and delete on account termination or request, which makes the data permanently unreadable, a crypto-shred. Nothing to configure. If your security team would rather hold the key themselves, enterprises can bring their own KMS key (BYOK): revoke it and watch our access die in your own CloudTrail. Either way, pricing is based on fleet size and tier, never on reading or monetizing your data.
Does Alyria read my data?
Static blobs stored with us are opaque to us at rest. By default they're encrypted under an envelope key we delete on account termination or request; enterprises can bring their own KMS key they hold and revoke. Client-held keys, where we never hold the key at all, are on our roadmap pending an externally audited protocol: future work, not a present guarantee.
Can I self-host, or does Alyria host it?
The platform core is source-available and can run on your own infrastructure. Most teams choose the hosted offering: Observatory hosts the console, SSO, and fleet dashboards. Either way, static blobs stored with us are opaque to us at rest, and enterprises can hold the keys themselves (BYOK/HYOK).
What does open-core actually mean here?
The platform core is source-available (BSL 1.1) and Umbra’s client-side crypto and SDK are fully open (Apache/MPL) so the client-side crypto stays auditable; the full licensing story lives on the security & trust page.
How does enterprise SSO work?
Platform includes enterprise SSO via OIDC or SAML out of the box. Enterprise adds SCIM provisioning, extended audit retention, and SIEM routing at scale for larger, regulated fleets.
What are “security guarantees”?
A distinct Enterprise tier, independent of license, delivered as it ships: SLA, warranty/indemnity, SOC 2 and pen-test attestations, signed/reproducible builds, and committed CVE response windows. Details on the security & trust page.

Find out what your fleet is running. This week.

A free, 30-minute read-only deploy. A board-ready report of every agent, tool, and MCP connection. And a kill-switch drill: the envelope key is deleted, the data goes permanently dark.