Safety is free.
Managed access is optional.

Bring your own AI key with no card. Production use is free up to 10,000 enforcement calls per calendar month under the package license. Spend caps, circuit breaker, capability gating, and optional receipt signing are available without a managed plan. Managed adds OpenRouter provisioning and support.

FREE BYO

Bring your own key

Use your own OpenAI, Anthropic, Bedrock, or OpenRouter account. AgentGuard evaluates configured policy locally before provider dispatch.

Free

$0 / mo

Production use up to 10,000 enforcement calls per calendar month. No card.

  • Spend caps
  • Circuit breaker
  • Capability gating
  • Optional Ed25519 receipt signing
  • BYO key
  • Unlimited local policies
  • No card
Build your AI team

$99 MANAGED

We handle AI access

No OpenRouter setup. No API key to manage. Your runtime still calls OpenRouter directly, and optional receipt signing remains available.

Managed

$99 / mo

Preview one hosted, signed routing record without a card. The preview does not call a model. Upgrade to provision managed inference.

  • Everything in free
  • No API key to manage
  • $40 monthly inference allowance after upgrade
  • Cite-or-refuse checks
  • Vertical guardrails
  • Content-free receipts when signing is configured
  • Email support
Preview managed routingUpgrade to managed

30-day money back · No questions · Refund yourself from the dashboard, no email needed. Coupons supported: SOLO365 and PRO50

$499+ TEAMS

Bigger teams

For bulk seats, higher limits, vertical enablement, and enterprise intake. Same zero data plane runtime boundary.

Team

$499+ / mo

Bulk seats, higher limits, longer retention, and onboarding help for teams with multiple workflows.

  • Everything in managed
  • Bulk seats
  • Higher workflow limits
  • Longer receipt retention
  • Vendor diligence packet
  • Priority onboarding and support
Request access
Outcome routing included. AgentGuard assigns each configured outcome to the cheapest capable allowed model and reasoning effort from the current catalog, then applies your cap and downgrade rules before the provider call. A chronology, a workpaper check, and an FBA claim can each use a different route without sending prompts or keys through AgentGuard.
Compliance posture note. OpenRouter does not publish a HIPAA Business Associate Agreement. If you select Pro for law, accounting, or insurance workflows, AgentGuard asks you to sign a limitation acknowledgment before checkout. For PHI or privileged work product, choose BYO with a BAA-covered provider.
Same signing optionEvery tier can sign Ed25519 receipts when keys are configured and supports public browser verification.
Same capsPer-call, daily, monthly, workflow, and posture caps work across both rails.
No proxyBYO calls your provider directly. Pro calls OpenRouter directly from your runtime.
0% inference markupPro overage is pass-through at OpenRouter list cost until explicit written clearance.

Common questions

Does Pro send prompts through AgentGuard?

No. The SDK fetches a provisioned key, injects it only for the OpenRouter host, and your runtime calls OpenRouter directly.

Can I switch from Pro to BYO?

Yes. Pro removes setup friction. BYO remains available when your team wants its own provider contract or BAA-covered path.

What does the SDK collect?

License validation uses license and seat identifiers. Prompts, completions, provider keys, signing keys, and policy bodies do not go to AgentGuard.

Can I verify a receipt before buying?

Yes. Use agentguard.run/verify and load the demo receipt.