Pricing

Governance on day one.Scale when you're ready.

Every tier — from a solo deploy to enterprise procurement — enforces the same controls. Tiers differ by scale and support, not by whether governance is included.

Included in every tier — not a paid add-on

Claude · GPT · Gemini · Bedrock · Azure — all five wire formatsGovernance enforced before the call executes — not in a post-hoc reportAppend-only audit trail at the SQL layer from the first requestPII intercepted before any model sees it — fail-closed by defaultNo per-seat pricing below Enterprise

Starter

~$7/mo

Vercel Hobby + Neon Free + Render Starter

For developers and small teams who want governance in place from day one — before it becomes urgent.

  • Full gateway — Claude, GPT, Gemini, Bedrock, Azure OpenAI
  • Spend Tokens — hard budget enforcement per project
  • PII engine — 12 detectors, 3 modes, fail-closed
  • 5 append-only audit tables (SQL-layer enforced)
  • Anomaly detection — volume, cost, model swap, new model
  • Real-time request explorer
  • 1 Clerk organization
  • Self-serve deploy in 30 minutes
  • Community support
  • SaaS connector ingestion (Copilot, Cursor, AgentForce)
  • Multi-org / multi-tenant
  • KMS-backed envelope encryption
  • SSO / SAML
Read the deploy guide
Most popular

Team

~$27–60/mo

Vercel Pro + Neon Launch + Render Standard

For mid-size teams that need Finance to have real numbers and Compliance to have real evidence.

  • Everything in Starter
  • Chargeback CSV — by month, quarter, or custom range
  • GL allocation rules — Finance writes them, engineers don't notice
  • SaaS connectors — Copilot, Cursor, AgentForce, ServiceNow
  • Multi-org (up to 10 Clerk orgs / business units)
  • Per-Spend-Token utilisation monitor + expiry countdown
  • Anomaly inbox with severity tiers — critical first
  • Operator approval queue for self-improving loops
  • Email support
Request a Demo

Enterprise

Custom

Procurement · MSA · SLA · KMS · SAML

For regulated orgs, SOC 2 audits in flight, or multi-business-unit AI deployments that cannot afford an incident.

  • Everything in Team
  • KMS-backed envelope encryption — AWS KMS, Azure Key Vault, GCP Cloud KMS
  • SAML / SCIM via Clerk Enterprise — identity lifecycle management
  • Unlimited orgs, business units, and cost centres
  • Custom model allowlists per org with change-control workflow
  • SOC 2 evidence package — mapped to CC 6.1, 6.7, 7.2, 8.1
  • Deployment assistance + guided onboarding
  • Dedicated support channel + named CSM
  • Custom MSA, BAA available, SLA negotiable
Book a conversation

Frequently asked questions

What AI providers are supported?

Anthropic Claude, OpenAI GPT, Google Gemini, Amazon Bedrock, and Azure OpenAI. The gateway speaks each provider's native wire format — your client code changes one environment variable and nothing else. Switch providers per-project at runtime via policy, not code.

Is governance actually enforced, or just logged?

Enforced. Spend Tokens are hard stops — the gateway rejects the call before it leaves your network when the budget is exhausted. PII detection is fail-closed — if the engine cannot evaluate a request, it blocks. Audit tables use REVOKE at the database role level; the application literally cannot UPDATE or DELETE those rows.

What does the SOC 2 evidence package include?

On Enterprise, we provide a mapped evidence package aligned to CC 6.1 (logical access), CC 6.7 (data transmission), CC 7.2 (monitoring), and CC 8.1 (change management). This includes the append-only log export, the deploy-time smoke check output, PII policy configuration documentation, and the KMS key lifecycle records. Most audit committees can close the AI governance section in a single meeting.

Do I need to pay for every seat?

No. Starter and Team are priced by infrastructure, not by user. Your entire Finance team, Security team, and Engineering org share one deployment — no seat count, no user licenses below Enterprise.

Can I use my own KMS?

Yes, on Enterprise. The KeyProvider interface supports AWS KMS, Azure Key Vault, and GCP Cloud KMS. You bring the key; Visionality handles the envelope encryption. Starter and Team use a master key you supply as an environment variable.

How long does the deploy actually take?

30 minutes for a clean Starter deployment. 45–60 minutes if you configure allocation rules and PII policy at the same time. Enterprise onboarding includes guided deployment assistance — we walk through every environment variable, every Clerk org, and every first Spend Token together.

Is there a free trial?

Starter is effectively free — Neon and Vercel Hobby are free; Render Starter is $7/mo. There is nothing to trial. Deploy it, run a real request through the gateway, and you will have a working audit trail before the coffee is gone.

Need to run this past procurement?

We can provide a vendor questionnaire response, a security review package, or a direct conversation with your compliance team. 30 minutes, no pitch deck.

Request a Demo →