Safety is free.
Managed access is optional.
Bring your own AI key forever with no card. Spend caps, kill switch, circuit breaker, capability gating, and signed receipts are never paywalled. Managed adds hosted OpenRouter provisioning and support when you want AgentGuard to handle AI access.
FREE BYO
Bring your own key
Use your own OpenAI, Anthropic, Bedrock, or OpenRouter account. AgentGuard enforces safety locally before any provider call.
Free
$0 / mo
Bring your own AI key, free forever. No card.
- Spend caps
- KILL SWITCH
- Circuit breaker
- Capability gating
- Ed25519 signed receipts
- BYO key
- Unlimited local policies
- No card
Build your AI team
$99 MANAGED
We handle AI access
No OpenRouter setup. No API key to manage. Your runtime still calls OpenRouter directly and receipts still stay signed.
Managed
$99 / mo
Try managed free: about 5 runs on us, no card needed. Add a card when you want to keep going.
- Everything in free
- No API key to manage
- About $40 inference included after upgrade
- Cite-or-refuse checks
- Vertical guardrails
- Audit receipts
- Email support
Try managed freeUpgrade to managed30-day money back · No questions. Coupons supported: SOLO365 and PRO50
$499+ TEAMS
Bigger teams
For bulk seats, higher limits, vertical enablement, and enterprise intake. Same zero data plane runtime boundary.
Team
$499+ / mo
Bulk seats, higher limits, longer retention, and onboarding help for teams with multiple workflows.
- Everything in managed
- Bulk seats
- Higher workflow limits
- Longer receipt retention
- Vendor diligence packet
- Strategic intake available
Request access
Outcome routing included. AgentGuard assigns each configured outcome to the cheapest capable allowed model and reasoning effort from the current catalog, then applies your cap and downgrade rules before the provider call. A chronology, a workpaper check, and an FBA claim can each use a different route without sending prompts or keys through AgentGuard.
Compliance posture note. OpenRouter does not publish a HIPAA Business Associate Agreement. If you select Pro for law, accounting, or insurance workflows, AgentGuard asks you to sign a limitation acknowledgment before checkout. For PHI or privileged work product, choose BYO with a BAA-covered provider.
Same receiptsEvery tier signs Ed25519 receipts and supports public browser verification.
Same capsPer-call, daily, monthly, workflow, and posture caps work across both rails.
No proxyBYO calls your provider directly. Pro calls OpenRouter directly from your runtime.
0% inference markupPro overage is pass-through at OpenRouter list cost until explicit written clearance.
Common questions
Does Pro send prompts through AgentGuard?
No. The SDK fetches a provisioned key, injects it only for the OpenRouter host, and your runtime calls OpenRouter directly.
Can I switch from Pro to BYO?
Yes. Pro removes setup friction. BYO remains available when your team wants its own provider contract or BAA-covered path.
What does the SDK collect?
License validation uses license and seat identifiers. Prompts, completions, provider keys, signing keys, and policy bodies do not go to AgentGuard.