Pricing

Simple, transparent pricing.

One product. Every surface. Free tier included. No credit card required. Works without an account in Local mode.

SDK, gateway proxy, and local MCP server today. Coding agent hooks are GA, with the Cursor and Antigravity adapters in beta and the Kiro IDE hook shipping disabled. Scout and fleet management are coming soon.

Free

$0forever

No credit card required

  • 5,000 actions/month
  • SDK + gateway proxy
  • 1 project, 3 policies
  • 7-day audit retention
  • Basic policies
  • Audit logging
  • Audit export: CSV download from the dashboard
  • Telegram alerts
Get started free
Recommended

Solo

$29/month
  • 50,000 actions/month
  • Unlimited projects and policies
  • 90-day audit retention
  • Gateway request DLP scanning always on; response scanning off by default (a deployment-wide operator setting, not a per-organization option on hosted)
  • Custom DLP rules
  • API access
  • Audit export API: JSON, ArcSight CEF, RFC 5424 syslog
  • All alert channels
Get started

Teams

$199/month
  • 250,000 actions/month
  • Unlimited seats and agents
  • 365-day audit retention
  • Everything in Solo
  • Coding agent hooks (6 agents, 8 surfaces)GA(Cursor and Antigravity adapters BETA; Kiro IDE hook ships disabled)
  • Scout agentCOMING SOON
  • RBAC (7-role hierarchy)BETA
  • Fleet managementCOMING SOON
  • Alert channels (Slack, Telegram, Discord, Email, Webhook)
  • Browser extension (blocks and masks in the page)BETA(manual install; not in the Chrome Web Store)
  • MCP server hostedCOMING SOON
  • SSO/SAMLCOMING SOON
  • Compliance reportsCOMING SOON
Get started

Billing BETA(paid plans live; overage not yet billed)

Paid plans are live: upgrade through Stripe Checkout, manage your subscription in the customer portal, and your plan updates automatically after payment. Metered overage charging is not yet enabled -- see below.

Exceed your limit? COMING SOON

Free: Actions are blocked at the limit today. Solo and Teams: planned overage rates are $10 per 100K (Solo) and $8 per 100K (Teams) additional actions. Overage usage is metered but not yet charged -- until metered billing ships, paid plans keep running past the included amount at no extra cost.

Feature breakdown

Feature Comparison

FeatureFreeSoloTeams
Modes supportedHostedLocalHostedLocalHostedHybridLocal
Actions/month5K50K250K
SDK + Gateway proxyYYY
Basic policies3UnlimitedUnlimited
Projects1UnlimitedUnlimited
Audit loggingYYY
Retention7 days90 days365 days
Overage (metered billing)BlockedCOMING SOONCOMING SOON
MCP server (local mode)YYY
Secrets vaultBETAYYY
Usage meteringYYY
Gateway request DLP scanning always on; response scanning off by default (a deployment-wide operator setting, not a per-organization option on hosted)YY
Custom DLP rulesYY
API accessYY
Audit export: CSV download from the dashboardYYY
Audit export API: JSON, ArcSight CEF, RFC 5424 syslogYY
Alert channels (Slack, Telegram, Discord, Email, Webhook)YY
Coding agent hooks (6 agents, 8 surfaces)GA(Cursor and Antigravity adapters BETA; Kiro IDE hook ships disabled)Y
Scout agent (Shadow AI discovery)COMING SOON
RBAC (7-role hierarchy)BETAY
Fleet managementCOMING SOON
Browser extension (blocks and masks in the page)BETAY
MCP server hostedCOMING SOON
SSO/SAMLCOMING SOON
Compliance reportsCOMING SOON
Seats11Unlimited
Annual billing (save 10%)YY

Deployment option

Self-Managed PRIVATE PREVIEW

Evaluate the gateway, policy engine, audit store, dashboard, and admin CLI on your infrastructure via Docker Compose. The private preview does not yet provide end-to-end self-managed I/O capture across every surface. Scout and fleet management are coming soon. The browser extension is beta: it blocks and masks in the page on supported AI chat sites.

Learn about self-managed

Common questions

Frequently Asked Questions

Do I need an account to start?

No. The SDK and gateway proxy can run in Local mode (no backend required), with or without an account. You get policy enforcement and audit logging locally. Create an account to unlock the dashboard, audit log viewer, blueprints, and policy builder UI.

Can I use the SDK and gateway proxy on the free tier?

Yes. Both integration paths are available on every tier, including free. The same action limits apply regardless of which path you use.

What counts as an action?

Each AI request that passes through the Control Zero gateway, SDK, or coding hook counts as one action. This includes tool calls, LLM requests, and policy evaluations.

What happens if I exceed my monthly limit?

On the Free tier, actions are blocked at the limit. On Solo and Teams, your agents keep running past the included amount and you receive an alert. Metered overage charging (a planned $10/100K for Solo and $8/100K for Teams) is coming soon and is not billed yet -- until it ships, over-limit usage on paid plans is metered but not charged. You can upgrade at any time.

Is there an annual discount?

Yes. Annual billing saves 10% compared to 12 months of monthly on Solo and Teams tiers. Toggle "Yearly" on the pricing cards to see the effective monthly rate, or select annual at checkout.

What surfaces does Control Zero cover?

Control Zero governs AI across multiple surfaces: SDK integration (Python with 11+ framework integrations, plus Node.js in beta), gateway proxy (zero-code, supporting Anthropic, OpenAI, Google, Ollama, DeepSeek, and more), GA coding agent hooks across 6 agents and 8 surfaces (Claude Code, Gemini CLI, Codex CLI, Cursor, Kiro, Antigravity), with the Cursor and Antigravity adapters in beta and the Kiro IDE hook shipping disabled, and MCP server for AI coding assistant integration (including Windsurf). The browser extension is beta and enforces in the page: a deny rule cancels the paste before it lands and cancels the send before it leaves, and a mask rule rewrites the matched value in place. A finding categorised as a secret stops the send whatever its rule action. Enforcement needs a synced ruleset: with no rules to evaluate against, the extension allows and records that it could not scan, rather than reporting a clean pass. Separately, while any live, enabled block rule is scoped to browser_ext_network, it blocks the chat endpoint at the network layer, matched on URL rather than on content; a detect or mask rule on that scope installs no network block. Scout agent for shadow AI discovery and fleet management are coming soon.

How does Local mode work without an API key?

You define policies in a local JSON file. The SDK loads them from disk instead of fetching from the backend. Policy evaluation happens entirely in your process. No network calls. If a policy signature fails verification, the SDK fails closed and denies all requests.

Start governing in under 60 seconds.

No credit card. No sales call. Install the SDK and connect to the dashboard.

Get started free