You pay for each production agent that is allowed to act on its own, because that is the thing carrying the risk. Not per seat: the people who touch this are a platform lead and a risk officer, and that number never really grows. Not per trace either, since the evaluation runs offline inside your environment, so there is nothing honest to meter, and charging by the run would only push you to evaluate less.
For an engineer who wants to run the checks locally before involving anybody else.
For a team with one agent in production that needs to stay cleared as the code keeps changing.
trustkit compare CI gateFor a team running a handful of agents that need to stay cleared as the code keeps changing.
trustkit compare CI gateFor teams whose evidence has to survive a risk committee, an examiner, or an ATO package.
Before any of the prices above apply, you get one real clearance report on one of your own agents, free.
It runs on your traces, in your environment, and you get the same artifact a paying client gets: a scoped statement of what the agent is and is not cleared for, with every finding quoting the evidence behind it. Sometimes the verdict is unflattering. One of the published samples fails the gate at 97.5% task completion, and two more come back inconclusive. That is deliberate. A report that always says yes is not worth signing.
You need a task contract and a trace export to get there. What you bring covers both. If you have neither yet, the Sprint below is the work of writing them with you.
The Agent Trust Sprint is fixed scope and fixed price, from $30,000, and twelve months of the Team license comes with it.
Most teams have not written a task contract down. What they have is an agent in staging, a drift harness, and a release meeting that keeps stalling on "but can we rely on it?" The Sprint is the work of turning that into something a person can sign: the contract itself, remediation guidance on whatever the baseline found, a re-run comparison showing what the fixes actually moved, and a CI gate wired into your pipeline and owned by your team.
The license comes with it, so there is no second purchase to make while the work is still fresh. Twelve months later you renew Team, or move up to Regulated, or keep the contract and the gate and walk away. They are yours either way.
How long it takes depends on one thing: how your agent's behaviour gets out of your system and into a trace file. Everything after that — the contract, the baseline, remediation, the re-run, the gate — is the same work at the same pace no matter who you are. So the bands below are priced on the integration, because that is the only part that genuinely varies.
| Where you're starting | Elapsed | Our days | Sprint |
|---|---|---|---|
| A · Direct exportBedrock Agents with enableTrace, or an OTel/OpenInference export that already carries retrieved text. No integration code — about ten lines to write the trace events to a file. | 2–3 weeks | 8–12 | $30,000 |
| B · One adapter awayLogs and audit tables but no standard telemetry, a vendor OTLP dialect we have not mapped, or OTel that is missing retrieval provenance. We write the exporter or the overlay; it is yours to keep. | 4–6 weeks | 15–18 | $45,000 |
| C · Instrumentation firstAn entry point but no run harness, a framework with no capture adapter yet, or a multi-agent pipeline that needs authoritative ground truth emitted at the gate. Includes a 20–50 task set written with your domain expert. | 6–10 weeks | 25–35 | $65,000 |
| D · GreenfieldThe agent does not exist yet. Contract-first: the contract becomes the acceptance criteria and the trace a first-class output from the first commit. A different engagement shape, quoted against your build plan. | Quoted | Quoted | Let's talk |
trustkit inspect) takes five minutes once the file exists.The bands are ceilings, not guesses — each one is the integration work the tool actually requires for that starting point, not a padded estimate.
A fixed price with an open scope is just a slower way of financing somebody else's review process. So the Sprint has counts, and everything past them has a price you can see before you ask.
Most of what follows exists because of compliance, not engineering. A regulated buyer's security review, model-risk committee and procurement portal are real work with real hours in them, and they are work we are happy to do — we would just rather price it than absorb it.
| Billed separately | Price |
|---|---|
| Clearing a second agent while we are hereOptional, and not a licensing charge — the Team license already covers five agents, and once the gate is wired you can clear the rest yourself. This is us writing the second contract and running the second baseline instead, while we are already in your environment. | $9,000 |
| Bespoke security questionnaireYour own format rather than ours — a SIG, a CAIQ, a bank's internal vendor pack. Our standard pack is included; transcribing it into yours is not. | $3,000 |
| Review board or architecture sessionAttending your security, architecture, or model-risk committee. Per session, including preparation. | $1,500 |
| In-account analyst setupTrace content that cannot leave your infrastructure. We point the analyst at a Bedrock-hosted Claude in your own AWS account instead of ours. | $6,000 |
| NIST AI RMF or CSA Agentic evidence appendixGovernance sign-off needs the crosswalk as a filed artifact. Included at the Regulated tier. | $7,500 |
| Air-gapped installationNo egress at all, including the analyst step. Included at the Regulated tier. | Quoted |
| Additional remediation and re-run cycleThe first round moved the gate but not far enough, and you want another pass before sign-off. | $9,000 |
| Anything not on this listLegal review beyond our standard agreement, extra stakeholder sessions, procurement onboarding portals. Billed by the day, agreed in writing first. | $3,000 / day |
| Feature | Developer | Starter | Team | Regulated |
|---|---|---|---|---|
| Production agents | 1 | 1 | Up to 5 | Up to 20 |
| Additional agents | – | $4,000 each | $4,000 each | $2,500 each to 50 |
| Deterministic scoring | Included | Included | Included | Included |
| Omission detection | – | Included | Included | Included |
| AI-analyst phase (opt-in) | – | Included | Included | Included |
trustkit compare CI gate | – | Included | Included | Included |
| Comparison reports | – | Included | Included | Included |
| NIST AI RMF and CSA crosswalks | – | – | – | Included |
| ATO evidence packs | – | – | – | Included |
| Air-gapped install | – | – | – | Included |
| Custom trace adapter | – | Quoted separately | Quoted separately | One per year |
| Support | Community | Named contact | ||
| Billing | – | Annual, up front | Annual, up front | Annual, up front |
Worth stating plainly, because it is the number the whole license turns on and nobody should be working it out for the first time at renewal.
There is no license server, no activation key and no usage reporting. Nothing in the tool checks what you are entitled to, and that is on purpose. Anything that phones home is a non-starter inside an air-gapped network, and it is the first thing a security review asks about.
So the accounting lives in the contract instead. You tell us the agent count at renewal and we true it up. It is the same trade most vendors selling into regulated environments end up making, and it works because both sides would rather have that conversation once a year than have a tool that calls out.
We are taking two or three design partners in financial services, insurance, health or government, at 40 to 50% off the first year, in exchange for a case study and a reference call. Named or anonymized is your choice, and you approve every word before anything gets published.
The full price goes in the contract so the discount stays a discount instead of quietly becoming your baseline. What you are really buying at that rate is influence. Design partners get their trace format supported, their crosswalk controls prioritized, and their objections answered in the roadmap rather than in a support queue.
One agent is one distinct role running in production. A planner that hands work to three specialist agents counts as four, because each one gets cleared separately and each one can fail on its own. The same agent running in staging and in production counts once. You should not pay to test the thing you are about to clear.
Because they are two different things. The license is entitlement: it covers running the gate on up to five agents, and nothing about that changes whether we are involved or not. The Sprint is work: writing one task contract, running one baseline, doing one remediation round and wiring one gate, for one agent. Agents two through five are already licensed, and once the first gate is wired you have everything you need to clear the rest yourself. Paying us to do the second one is a convenience while we are already in your environment, not a fee for permission.
Nothing breaks. There is no license server and nothing in the tool checks your agent count, so adding an agent mid-term is a contract question rather than a technical one. You tell us the count at renewal and the extra agents are trued up at $4,000 each a year up to twenty, and $2,500 each beyond that. Adding agents never forces you onto a bigger tier. You move up for the compliance features, not for room.
Yes, and it runs on one of your own agents rather than on sample data. We give it away because a real clearance report is the only honest way to show what this produces, and because the result is sometimes unflattering to us. Nothing leaves your environment to produce it.
No. The deterministic evaluation runs entirely inside your environment. The AI-analyst phase is opt-in and can run against a Bedrock-hosted model inside your own AWS account. Agent TrustKit holds no customer trace data at any tier.
Fixed scope and fixed price, and twelve months of the Team license comes with it. The Sprint turns one baseline report into a practice: a task contract your team owns, remediation guidance, a re-run comparison showing what the fixes actually moved, and a CI gate wired into your pipeline. Price depends on one thing, which is how your agent's behavior gets out of your system and into a trace file: $30,000 if you already export Bedrock or OpenTelemetry traces, $45,000 if we write an exporter or an adapter for you, $65,000 if the agent needs instrumenting and a task set first. Two to three weeks at the first band, six to ten at the third. At the end of the twelve months you renew the license or move up to Regulated.
The Sprint pauses rather than quietly absorbing it, and we tell you at week two rather than week eight. Everything the Sprint includes is stated with a count on the pricing page, and the things that most often blow a fixed price out — a bespoke vendor questionnaire, a model-risk committee session, an in-account analyst setup because trace content cannot leave your infrastructure — each carry a published price instead of being discovered in an invoice. We assume a first trace export within four weeks of kickoff. If we are blocked longer than four consecutive weeks the engagement pauses and resumes at the rates in force then.
Not yet, and we would rather say that than sell you something we cannot hand over. There is no public distribution of Agent TrustKit today: no package to download, no install guide written for your team, no self-serve path. Every engagement runs through us, and the Sprint is how the tool gets delivered — the twelve months of Team license that come with it are what keep the gate running afterwards. If you have a platform team that would rather run the CLI themselves, say so when you get in touch. Standalone licensing is a packaging problem rather than a product one, and a buyer asking for it is the thing that would move it up the list.
Usually not much, and often nothing. If you already export traces in some other shape, from CloudWatch, a database or flat files, a small adapter maps your schema onto the canonical model. That is typically half a day of work and the adapter is yours to keep. Regulated includes one custom adapter a year. On Starter and Team we quote it with the engagement, because the effort depends entirely on what your logs look like, and quoting a number before seeing them would be guesswork.
Talk to us. Agents beyond twenty are $2,500 each a year, and that holds to about fifty. Past that, multiplying a per-agent rate across a large fleet produces a number neither of us would take seriously, so we price the fleet instead. Tell us the size you are heading for and we will quote it properly.
Not today. Licenses are annual and paid up front. Monthly billing would mean metering and usage reporting, and there is nothing in the tool that phones home, which is the property regulated buyers care about most.
Whichever plan fits, the first step is the same: one trace export and a sentence about what the agent was supposed to do. You get a real clearance report back, free, and a straight answer on what a license would cost.
Send one trace export and a sentence on what the agent was supposed to do. You get a real clearance report back, whatever it says, and a straight answer on what a license would cost you.
Talk to us →[email protected]