Pricing & editions

Free to build with. Metered when it's in production.

The open-source CLI and everything self-hosted are free forever — scan, gate, broker, the v0.2 MCP gateway with signed per-call provenance, witness, anchor, verify. The paid tier is the hosted /authorize endpoint: priced per authorization, it returns a signed receipt on every call and is neutral by design — an attestor a third party can rely on because you didn't produce it. On-prem, air-gap, and compliance attestations for regulated estates.

Open Source
Free · forever, self-hosted
For builders and security teams running their own agents.
  • The full abom CLI — scan, gate, broker, gateway, verify
  • The MCP gateway (v0.2) — signed, fsync'd provenance per tool call; inspect-only by default, --enforce to block
  • Org floor policies, payload commitments, dispute claims
  • Guardrail adapters — seal Model Armor verdicts into records
  • Self-hosted /authorize API — unlimited calls on your own infra
  • Self-hosted witness & RFC 3161 anchoring
  • Durable Merkle transparency log
  • The open ABOM spec & policy schema
  • Community support (GitHub)
Most teams
Team
Usage-based · per call
For teams shipping agents that need a receipt a third party can trust.
  • Everything in Open Source, plus:
  • Hosted, neutral /authorize endpoint — metered per call
  • A generous free monthly allowance; usage-based above it
  • Independent witness — real non-equivocation on your receipts
  • Queryable registry + SIEM / CycloneDX export
  • Sector policy packs (finance, healthcare, mfg)
  • Email support with an SLA
Enterprise
Custom · annual
For regulated estates with sovereignty and audit requirements.
  • Everything in Team, plus:
  • On-prem / air-gapped deployment
  • eIDAS-qualified timestamp anchoring
  • Signed verification attestations for auditors
  • Composition-match / drift enforcement
  • Integration & onboarding services
  • Priority support, security review support
The line, stated plainly: the CLI and everything you run on your own machine — including the /authorize API self-hosted — is free and open (Apache-2.0), forever. You pay per call only for the hosted, neutral endpoint: a receipt a third party can rely on without trusting you, plus the support and deployment a regulated estate needs. The reasoning in one line: adoption must be free; neutrality is the thing you can’t self-host.
What's in each edition

Free vs. paid, feature by feature

Enforcement is free. Neutrality, scale, and support are the paid tier.

CapabilityOpen SourceTeamEnterprise
Scan → signed manifest
Gate / MCP broker enforcement
MCP gateway (v0.2) — signed provenance per call, floors, commitments
Guardrail adapters (Model Armor → detectors[])
Self-hosted /authorize API + witness + anchor
Hosted neutral /authorize (metered, independent witness)
Queryable registry + SIEM / CycloneDX export
Sector policy packs
On-prem / air-gapped deployment
eIDAS-qualified anchoring + signed attestations
SupportCommunitySLAPriority
Why the paid tier exists

You can self-host the proof. You can't self-host the neutrality.

A witness you run yourself is real defense-in-depth — but you hold both keys, so it isn't proof against you. The value an auditor, insurer, or regulator pays for is a record produced by a party that isn't the one being audited. That's the hosted /authorize endpoint — the one thing in ABOM that is, by definition, not self-hostable.

Book a demo

See ABOM enforce a real agent, then hand the notarized record to a third party who can verify it without trusting you. We'll scope the free line, per-call pricing on the hosted endpoint, and on-prem options for your estate.