A decision is one intercepted tool call, action trigger, or resource read evaluated by the local policy engine. If an agent calls five tools during a task, that is five decisions. Quota meters decisions, not LLM token counts.
Audit your plan &
runtime entitlements.
Every tier runs the identical local deterministic enforcement engine. What changes across plans is daily decision volume, custom policy authoring rights, cryptographic retention, and enterprise coordination. Audit your fleet requirements below.
Fleet & Entitlements
Requirement Auditor.
Select your agent topology, expected decision volume, and compliance needs to instantly determine which tier covers your operations and what features are contained within it.
1. Agent Fleet & Volume
2. Capabilities & Security Needs
Free Tier
Covers single-agent local development with built-in policy protection packs.
Plan Entitlements Audit:
- ✓ 100 decisions/day quota (Default-deny upon exhaust)
- ✓ 1 Monitored Agent (Single developer seat)
- ✓ Curated Built-in Policy Packs (OWASP LLM Top 10)
- ✓ Local Hash-Linked Audit Chain (SHA-256 tamper-evident)
- 🔒 Custom Policy Authoring (Requires Starter)
- 🔒 SIEM & Webhook Streaming (Requires Pro)
No credit card required. Free tier needs no account.
What each plan
contains in full.
Examine exact technical rights, quotas, and security boundaries across every Cirvix tier.
| CAPABILITY / BOUNDARY | FREE | LITE | STARTER | PRO | TEAM | ENTERPRISE |
|---|---|---|---|---|---|---|
| Daily Decision Quota | 100 / day | 500 / day | 1,500 / day | 12,000 / day | 40,000 / seat / day | Custom / Unlimited |
| Quota Exhaustion Behavior | Refuse (Default Deny) | Refuse (Default Deny) | Refuse (Default Deny) | Refuse (Default Deny) | Refuse (Default Deny) | Custom SLA Burst |
| Monitored Agents | 1 Agent | 2 Agents | 2 Agents | 8 Agents | Unlimited Fleet | Unlimited Fleet |
| Team Seats | 1 Seat | 1 Seat | 1 Seat | 1 Seat | Per Seat ($349/mo) | Custom Org-wide |
| Policy Authoring Rights | Curated Packs Only | Curated Packs Only | Custom Declarative YAML | Custom YAML + Simulation | Shared Org Policies | Multi-Tenant Hierarchy |
| Audit Retention | Local (life of deployment) | Local (life of deployment) | Local (life of deployment) | Local (life of deployment) | Local (life of deployment) | Custom / Extended Retention |
| Offline Root Verification | ✓ Yes (cirvix verify) |
✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| SIEM & Webhook Egress | — | — | — | ✓ Datadog / Splunk | ✓ Real-Time Webhooks | ✓ Kafka / S3 / SIEM |
| Identity & SSO | None (Offline) | Email (dashboard) | Email Magic Link | Email + GitHub OAuth | OIDC / Okta SCIM | Custom SAML / IdP |
| Deployment Topology | Local CLI / Stdio | Local CLI / Stdio | Local / Docker | Docker / Helm Sidecar | Kubernetes Operator | Dedicated VPC / Air-Gap |
| Encryption Keys | Ephemeral Memory | Ephemeral Memory | Host Keyring | AES-256 Vault | Customer Master Key | BYOK KMS / HSM |
Audit active tokens
with cirvix plan.
Security engineers don't need to open a web browser to verify runtime rights. The Cirvix CLI audits plan tokens and quota states directly inside terminal shells and CI/CD pipelines.
Frequently asked
questions.
Clear operational guidance on how quotas, custom policies, and plan changes behave under production loads.
System statusDecisions beyond the daily allowance are refused with a deterministic DENY verdict until the quota resets at 00:00 UTC. There is zero unexpected overage billing. A security control that waives inspection when a quota expires is no control at all.
The Free tier includes full access to all official curated policy packs (file exfiltration protection, credential hiding, SSRF blocking). Authoring custom YAML/JSON policies and tailored team rules starts on the Starter tier ($79/mo).
Yes. Upgrades apply immediately via the hosted checkout (Dodo Payments) or the CLI (cirvix upgrade), immediately raising daily decision limits and unlocking capabilities without requiring agent redeployments.
Deploy the exact plan
your agents require.
Start with the free local engine or upgrade to Starter for custom policy authoring and hash-chained audit retention.