Plans & entitlements
A workspace’s plan determines which frameworks, modules, quotas and billing options it can use. Entitlements are enforced server-side, not only hidden in the interface. A capability is available only when the workspace plan allows it and the signed-in user’s role allows it.
Current plan tiers
Section titled “Current plan tiers”- Price: $0.
- Scale: 1 paid seat, up to 3 AI systems and 3 intake records, 1 active assessment at a time, and up to 3 assessment creations per rolling 12 months.
- Framework access: Choose 1 at signup: GTSAF, NIST AI RMF, EU AI Act or NAGF.
- Included: Dashboard, Learning Hub, AI System Records, AI Use Case Intake, assessment, risk register, model cards, CSV export and a limited platform-funded AI-analysis allowance.
- Not included: AI Consultant, reports, evidence tracker, findings register, policy generation, audit-trail module, Discovery, Agentic CISO, Gateway and Claw.
Standard
Section titled “Standard”- Price: $499/month, or $4,990/year.
- Scale: 5 paid seats, up to 25 AI systems and 50 assessments per year.
- Framework access: GTSAF, EU AI Act, NIST AI RMF and NAGF.
- Included: Free capabilities plus policies, AI analysis, bounded policy generation, reports, report export, evidence tracker, findings register, workpaper packs and unlimited free read-only auditor seats.
- Not included: Control testing, AI chat, Agentic CISO, Gateway simulation, Gateway, Claw and Discovery.
Advanced
Section titled “Advanced”- Price: $1,499/month, or $14,990/year.
- Scale: 25 paid seats, up to 200 AI systems and 200 assessments per year.
- Framework access: GTSAF, EU AI Act, NIST AI RMF, NAGF, MAESTRO, ACRS and ATF.
- Included: Standard capabilities plus control testing, AI chat, policy generation, Agentic CISO and Gateway simulation.
- Not included: Production Gateway enforcement, Claw runtime execution and Discovery, which remain Enterprise-only.
Enterprise
Section titled “Enterprise”- Price: Starting at $40,000/year, contact us.
- Scale: 100 paid seats, effectively unlimited AI systems and effectively unlimited assessments.
- Framework access: GTSAF, EU AI Act, NIST AI RMF, NAGF, MAESTRO, ACRS and ATF, plus ISO/IEC 42001 and ISO/IEC 42005 when licence-confirmed.
- Included: Full product access, including Discovery, Agentic CISO, Gateway, Claw, production runtime enforcement, OpenID Connect single sign-on and contracted data-residency options.
- Independent runtime review: the dedicated Runtime Policy Approver role is available for workspace-scoped policy decisions without granting administrator authority.
ISO/IEC 42001 and ISO/IEC 42005 are not automatic plan entitlements. They are enabled only after a valid licence confirmation is recorded.
Standard annual billing saves $998 compared with monthly billing. Advanced annual billing saves $2,998 compared with monthly billing.
Free signup framework choice
Section titled “Free signup framework choice”New public signups start on Free. During signup the user chooses one starting framework from GTSAF, NIST AI RMF, EU AI Act or NAGF. The Free workspace is locked to that selected framework.
GTSAF is the recommended default when the user does not have an immediate framework-specific need: it has the deepest control coverage and maps outward to the other frameworks. If the user needs a specific regulatory or regional view first, they can choose NIST AI RMF, EU AI Act or NAGF instead.
The ACRS score used by intake can still be calculated to route risk. The standalone ACRS assessment module is not included on Free unless the plan is upgraded or a valid boost is active.
Advanced Trial Boost
Section titled “Advanced Trial Boost”Free and Standard workspaces can activate a one-time 14-day Advanced Trial Boost from the billing page. The boost:
- temporarily grants Advanced-tier features;
- includes 50 AI Consultant interactions;
- preserves all data created during the boost after it expires;
- can be used once per workspace;
- requires administrator step-up MFA before activation.
After the boost expires, the workspace returns to its prior plan and the normal entitlements apply.
Quotas
Section titled “Quotas”| Plan | AI analysis quota | Policy generation quota | Audit retention |
|---|---|---|---|
| Free | 20 daily, 20 monthly | 0 daily, 0 monthly | 90 days |
| Standard | 20 daily, 200 monthly | 2 daily, 10 monthly | 365 days |
| Advanced | 50 daily, 500 monthly | 100 daily, 1,000 monthly | 1,095 days |
| Enterprise | 999 daily, 9,999 monthly | 999 daily, 9,999 monthly | 2,555 days |
Policy generation has a separate entitlement and quota. If the policy_generation entitlement is
off, the policy quota is zero even if general AI analysis is available.
Agentic access
Section titled “Agentic access”The agentic stack is split deliberately:
- Advanced can use Agentic CISO, ATF assessment and Gateway simulations.
- Enterprise is required for production Gateway enforcement, Claw dispatch, Claw schedules, BYO runtime credentials, Gateway Event Centre runtime actions and Discovery.
This lets teams design and assess agentic governance before allowing live runtime execution.
Runtime-sensitive actions stay behind the Enterprise gateway entitlement and are checked again
server-side at the access point.
Runtime Access Policy approval is also Enterprise-gated. Assigning an approver role does not create a plan entitlement and cannot make production Gateway enforcement available on another plan.
Two caps, whichever is lower
Section titled “Two caps, whichever is lower”Effective access is the intersection of two limits:
- the workspace plan tier;
- the user’s role product ceiling.
A Standard-role user is capped at Standard capabilities even on an Enterprise workspace. An Advanced-role user can use Advanced capabilities but cannot reach Enterprise-only Gateway or Claw runtime execution. External auditor users are read-only across the assurance surface and do not inherit runtime privileges from the tenant plan.
How gating is enforced
Section titled “How gating is enforced”Every gated capability binds a feature entitlement to one or more RBAC permissions. Requests are checked server-side, including API calls, asset access, report and workpaper scopes, framework writes, Gateway actions and runtime dispatch. The UI is not the security boundary.
The access model uses role-based access plus entitlement dual-gating, row-level tenant isolation, fail-closed checks, CSRF protection, rate limiting, step-up MFA for sensitive changes and full audit records for state-changing actions.
Administering your plan
Section titled “Administering your plan”Administrators can review billing and the current plan from Billing. Standard and Advanced checkout use secure payment flow. Enterprise is handled by contract and invoice.
- Users & roles: the role half of the access gate.
- Frameworks overview: what each framework offers.
- Agentic stack overview: how Agentic CISO, Gateway and Claw fit together.