CirvixPricing

Enforcement runs local. You pay for volume.

Cirvix is an in-process runtime tool-call authorization layer: every tool, resource or action an agent attempts is evaluated against policy on your machine before it runs — not a scanner, firewall, IdP, or observability dashboard. Every policy decision is made on your machine, not in our cloud — nothing about your agents, your policies or your traffic is sent anywhere. What a plan sets is how many decisions a day that machine may make.

Free is available now and installs without an account. Paid tiers and the hosted control plane are in early access — join the waitlist and paid-tier buttons open the enterprise contact form until checkout is live.

$0free tier, forever
4 self-serve tiersplus Enterprise, scoped to you
Localpolicy, risk, secrets, approval
2 monthsfree on annual billing
Available now

Free is the whole engine,
capped at 100 a day.

No account, no card, no expiry. Install it with npx @cirvix_ai/agent-control scan and watch a decision resolve. Paid tiers and the hosted control plane are early access — the waitlist decides who gets in next.

01

100 decisions a day — refused calls not counted

One intercepted tool, resource or action decision is one protected execution. A call the engine refuses is not counted against the quota.

02

1 agent, 1 seat

Real protection for one agent run by one person, forever.

03

Local audit chain, kept for the life of the deployment

Every decision lands in a SHA-256 hash-linked record on your machine. Nothing prunes it; retention is bounded by your own store, not ours.

04

Ephemeral secret handles

The agent uses a secret without ever seeing it — but handles do not survive a restart. A vault that persists is what Starter is for.

05

Over the limit: DENY, never pass-through

Once the daily allowance is spent, further decisions are refused until the counter resets at 00:00 UTC, and nothing is billed. A security control that waves calls through when a counter runs out is not a degraded product — it is an absent one.

Start where you are

Six tiers.
One control plane.

MonthlyAnnual2 months free

What happens when you pick a plan: you sign in or create an account, confirm your email, and checkout opens for the exact plan you chose — your selection is remembered through sign-in, so you never pick twice. Cancelling a checkout changes nothing.

Every plan runs the same local enforcement engine. Higher tiers add coordination — shared policy, approvals, identity, central audit — not stronger enforcement. The free local runtime stays free: install it and write a policy without an account.

Founding 100 — the first hundred people running the engine on real work get a founder badge, early access to paid-tier features, and a private channel. It is an application, not a discount.

Unsure what tier fits your fleet? Run the Plan Audit & Entitlements Diagnostic to calculate decision volume and security requirements.

The upgrade path

You move up for
control, not volume.

Volume is rarely the reason to change plan, and there is no overage to buy your way out with — a spent allowance is refused until it resets. Every step below buys a capability instead.

Check the usage cost

What will the
volume cost?

Move the slider to your real volume to see which daily allowance covers it. Nothing is sold beyond that allowance, so the tier you land on is the whole bill.

The metering model

What counts as
an execution.

A protected execution is one intercepted tool, resource or action decision processed by the local AgentControl runtime.

01 / Local · unmetered
Policy + risk engineEvery decision, on your machine
Secrets + approvalVault, handles, human-in-the-loop
MCP + audit writeInterception and local record
02 / The boundary
LOCAL ENFORCEMENT

Your machine decides

No network hop per decision
No payload leaves the host
Quota counts decisions, not calls
03 / Cloud · metered
Team + identity syncShared policy, RBAC, SCIM
Central audit + analyticsIngestion, retention, export
Enterprise controlSIEM streaming, evidence

Centralised audit ingestion, cloud analytics, remote policy sync, SIEM export and long-term storage are metered separately from execution quota. Five million local decisions are not five million billed cloud transactions, and we do not price them as if they were.

Compare everything

Every feature,
every tier.

The enforcement engine is identical across tiers. What changes is coordination, identity, retention and deployment.

Early-access honesty note: Free is live today. Paid-tier rows below describe the designed capability at each tier — custom policy authoring, persistent vault, human-in-the-loop approvals, shared policy with RBAC, SSO/SCIM and scoped Enterprise deployment — available through the waitlist, not live checkout. Until the control plane is deployed, paid-tier buttons open the enterprise contact form so no purchase is taken for access that does not exist yet.

Where each row is proven: runtime and interception → execution flow; policy verdicts and default-deny → policy engine; decision records, replay and export → audit chain; identity, retention and certification status → security; deployment models → deployment; the adversary model and what is out of scope → threat model. Evaluating instead of buying? Read the objection library.

Why this exists

What an ungoverned
agent costs.

Not hypotheticals. These are the failure modes the runtime was built around.

An agent reads .env

A coding agent is asked to "check the config" and reads a credential file into its context. The secret is now in a model provider's logs, an autocomplete cache, and a transcript you do not control. Rotating it is the cheap part; knowing it happened is the hard part.

The control

Credential-file protection and secret detection deny the read before it runs, and brokered handles let the agent use a secret without ever seeing it. Policy engine →

A tool call nobody sanctioned

An agent chains to a tool it was never scoped for — a webhook, an internal API, a delete. Nothing in the framework says no, because frameworks are built to be capable, not to refuse.

The control

Unmatched actions are denied rather than passed through: the absence of a rule is never treated as permission. Control plane →

It is 3am and you cannot answer "what ran?"

Something happened overnight. The logs are scattered across a framework, a provider and a shell history, and none of them agree. You are reconstructing intent from side effects.

The control

A hash-linked decision record for every action, with cirvix why to explain a verdict and cirvix replay to re-evaluate it without ever re-executing. Audit chain →

An approval that quietly went stale

Someone approved an operation last week. The request has changed since. The approval is still attached to it.

The control

Approvals bind to a content hash, so editing the request un-approves it. There is no way to inherit a sign-off for arguments nobody reviewed. Security →

Billing

Questions, answered.

If something is unclear before you commit, ask rather than guess.

System status

One intercepted tool, resource or action decision processed by the local runtime. A single agent task that touches six tools is six protected executions. Decisions are counted; the enforcement itself happens on your machine and costs you nothing per call.

Yes. The local runtime is free forever, with no account and no expiry — install it, use official built-in policy packs, and watch a decision resolve. The free tier covers 100 decisions a day against one agent with curated built-in packs. Lite at $29/mo raises that to 500 a day with a second agent; authoring custom policies and 1,500 decisions a day start on Starter at $79/mo.

Two months. Every paid tier is ten months of the monthly rate for a full year — $29 becomes $290, $79 becomes $790, $199 becomes $1,990, and Team is $3,490 per seat. That is about 17%.

Further decisions are refused until the counter resets at 00:00 UTC, and nothing is billed for them — there is no overage on any tier. That refusal is deliberate: a security control that keeps waving calls through once a counter runs out is not a degraded product, it is an absent one. Enforcement already running on your machine continues to protect anything inside your allowance, and cirvix upgrade raises the limit immediately.

Because the tier contains things whose cost varies by an order of magnitude. A fifty-person company wanting VPC and SSO, and a multinational wanting air-gapped deployment with customer-managed keys and its own identity provider, are not the same contract — and a printed number would anchor both to the wrong one. Quotes are built from base platform, seats, execution volume, deployment complexity, support and SLA, and compliance requirements. The four tiers below Enterprise are fixed and published, so you always know where the ladder starts.

Free — 100 decisions a day, 1 agent, local audit chain, ephemeral secret handles, $0 forever, no account. Paid tiers and the hosted control plane are early access via the waitlist: choosing a paid tier opens the enterprise contact form, and you hear from us when there is access to give. No card is taken for access that does not exist yet.

None of those. It is an in-process runtime tool-call authorization layer: each proposed agent action is evaluated against policy before it runs, and the decision is recorded as SHA-256 hash-chained evidence. It does not replace your identity provider — if a directory account is compromised, the approval authority attached to it is compromised too — and it does not detect prompt injection itself; it enforces the boundary so that even a fooled model still has its tool calls evaluated and deniable. See the threat model for what is deliberately out of scope.

Not on this site. We publish no unverified SLA claims. Availability commitments are contractual and agreed per Enterprise deployment against the topology you actually run. SOC 2 and ISO 27001 work is in progress and we do not describe ourselves as certified.

Not sure which tier fits?

Describe the agents you are running and the boundary you need. We will tell you the smallest plan that actually covers it. Still evaluating the category? The objection library answers each doubt technically.

Talk to us
Govern what ships

Bring every agent
under control.

Set durable policy, preserve a verifiable record, and give teams a safer way to put intelligent systems to work.

Copied to clipboard