Agent TrustKit · Pricing

Priced per agent you clear.

You pay for each production agent that is allowed to act on its own, because that is the thing carrying the risk. Not per seat: the people who touch this are a platform lead and a risk officer, and that number never really grows. Not per trace either, since the evaluation runs offline inside your environment, so there is nothing honest to meter, and charging by the run would only push you to evaluate less.

Annual licensePer production agentNo data custodyFirst report free
01 The plans

Four tiers, one license model.

Not yet available

Developer

Free

For an engineer who wants to run the checks locally before involving anybody else.

  • The CLI and the deterministic local checks
  • One agent
  • A basic report, generated on your machine
  • No contract, no call
Join the waitlist →
One agent

Starter

$12,000per year

For a team with one agent in production that needs to stay cleared as the code keeps changing.

  • One production agent, then $4,000 per agent per year
  • The trustkit compare CI gate
  • Comparison reports on every change
  • The opt-in AI-analyst phase
  • Email support
Clear one agent →
Banks and government

Regulated

From $84,000per year

For teams whose evidence has to survive a risk committee, an examiner, or an ATO package.

  • Up to 20 production agents, then $2,500 per agent per year to fifty
  • NIST AI RMF and CSA Agentic Profile crosswalks
  • ATO evidence packs
  • Air-gapped installation
  • One custom trace adapter per year
  • A named support contact
Clear your fleet →
02 Start here

The first report costs nothing.

Before any of the prices above apply, you get one real clearance report on one of your own agents, free.

It runs on your traces, in your environment, and you get the same artifact a paying client gets: a scoped statement of what the agent is and is not cleared for, with every finding quoting the evidence behind it. Sometimes the verdict is unflattering. One of the published samples fails the gate at 97.5% task completion, and two more come back inconclusive. That is deliberate. A report that always says yes is not worth signing.

You need a task contract and a trace export to get there. What you bring covers both. If you have neither yet, the Sprint below is the work of writing them with you.

03 The Sprint

The way most teams start.

The Agent Trust Sprint is fixed scope and fixed price, from $30,000, and twelve months of the Team license comes with it.

Most teams have not written a task contract down. What they have is an agent in staging, a drift harness, and a release meeting that keeps stalling on "but can we rely on it?" The Sprint is the work of turning that into something a person can sign: the contract itself, remediation guidance on whatever the baseline found, a re-run comparison showing what the fixes actually moved, and a CI gate wired into your pipeline and owned by your team.

The license comes with it, so there is no second purchase to make while the work is still fresh. Twelve months later you renew Team, or move up to Regulated, or keep the contract and the gate and walk away. They are yours either way.

A Sprint ends with your team owning the gate. That is the deliverable, not a dependency on us.

How long it takes depends on one thing: how your agent's behaviour gets out of your system and into a trace file. Everything after that — the contract, the baseline, remediation, the re-run, the gate — is the same work at the same pace no matter who you are. So the bands below are priced on the integration, because that is the only part that genuinely varies.

Where you're startingElapsedOur daysSprint
A · Direct exportBedrock Agents with enableTrace, or an OTel/OpenInference export that already carries retrieved text. No integration code — about ten lines to write the trace events to a file.2–3 weeks8–12$30,000
B · One adapter awayLogs and audit tables but no standard telemetry, a vendor OTLP dialect we have not mapped, or OTel that is missing retrieval provenance. We write the exporter or the overlay; it is yours to keep.4–6 weeks15–18$45,000
C · Instrumentation firstAn entry point but no run harness, a framework with no capture adapter yet, or a multi-agent pipeline that needs authoritative ground truth emitted at the gate. Includes a 20–50 task set written with your domain expert.6–10 weeks25–35$65,000
D · GreenfieldThe agent does not exist yet. Contract-first: the contract becomes the acceptance criteria and the trace a first-class output from the first commit. A different engagement shape, quoted against your build plan.QuotedQuotedLet's talk
Why elapsed and effort differ so much

Most of the calendar is yours, not ours.

  • Getting the first export approved. Usually the longest single wait, and it is a conversation with your security team, not with us. The preflight (trustkit inspect) takes five minutes once the file exists.
  • Your stakeholders' calendars. The contract comes out of one working session with whoever actually owns the risk. Booking that session is the bottleneck, not running it.
  • Your domain expert's time. Bands B and C need someone who knows the work to say what a correct answer contains. Nobody outside your organisation can write that down for you.

The bands are ceilings, not guesses — each one is the integration work the tool actually requires for that starting point, not a padded estimate.

04 Scope

What is in, and what is extra.

A fixed price with an open scope is just a slower way of financing somebody else's review process. So the Sprint has counts, and everything past them has a price you can see before you ask.

Included in every Sprint

The counts that make "fixed" mean something.

  • One agent cleared: the contract, baseline, remediation and gate for one distinct role
  • One contract working session with your stakeholders, plus one written revision round
  • Preflight (trustkit inspect) on up to three export attempts
  • One baseline trust report, with a readout session for your team
  • One remediation round, then a re-run and a comparison report showing what moved
  • One CI gate wired into one pipeline, owned by your team afterwards
  • One security review answered from our standard pack: vendor questionnaire, secure-development attestation, architecture document
  • Twelve months of the Team license, which covers running the gate on up to five agents

Most of what follows exists because of compliance, not engineering. A regulated buyer's security review, model-risk committee and procurement portal are real work with real hours in them, and they are work we are happy to do — we would just rather price it than absorb it.

Billed separatelyPrice
Clearing a second agent while we are hereOptional, and not a licensing charge — the Team license already covers five agents, and once the gate is wired you can clear the rest yourself. This is us writing the second contract and running the second baseline instead, while we are already in your environment.$9,000
Bespoke security questionnaireYour own format rather than ours — a SIG, a CAIQ, a bank's internal vendor pack. Our standard pack is included; transcribing it into yours is not.$3,000
Review board or architecture sessionAttending your security, architecture, or model-risk committee. Per session, including preparation.$1,500
In-account analyst setupTrace content that cannot leave your infrastructure. We point the analyst at a Bedrock-hosted Claude in your own AWS account instead of ours.$6,000
NIST AI RMF or CSA Agentic evidence appendixGovernance sign-off needs the crosswalk as a filed artifact. Included at the Regulated tier.$7,500
Air-gapped installationNo egress at all, including the analyst step. Included at the Regulated tier.Quoted
Additional remediation and re-run cycleThe first round moved the gate but not far enough, and you want another pass before sign-off.$9,000
Anything not on this listLegal review beyond our standard agreement, extra stakeholder sessions, procurement onboarding portals. Billed by the day, agreed in writing first.$3,000 / day
What we assume

If these hold, the price holds too.

  • A first trace export within four weeks of kickoff. Everything downstream waits on it, and the wait is almost always your security team rather than your engineers.
  • A named stakeholder who can say what the agent must never do. Not a committee. One person who owns the risk and can commit to a contract.
  • A domain expert for a day, on bands B and C, to say what a correct answer contains. That is the task set, and nobody outside your organisation can write it.
  • If we are blocked for more than four consecutive weeks, the Sprint pauses and restarts at the rates in force when it resumes. We will say so at week two, not at week eight.
None of this is designed to catch you out. It is written down so that the first time you hear a number is on this page, not in an invoice.
05 Compare

What each tier carries.

FeatureDeveloperStarterTeamRegulated
Production agents11Up to 5Up to 20
Additional agents–$4,000 each$4,000 each$2,500 each to 50
Deterministic scoringIncludedIncludedIncludedIncluded
Omission detection–IncludedIncludedIncluded
AI-analyst phase (opt-in)–IncludedIncludedIncluded
trustkit compare CI gate–IncludedIncludedIncluded
Comparison reports–IncludedIncludedIncluded
NIST AI RMF and CSA crosswalks–––Included
ATO evidence packs–––Included
Air-gapped install–––Included
Custom trace adapter–Quoted separatelyQuoted separatelyOne per year
SupportCommunityEmailEmailNamed contact
Billing–Annual, up frontAnnual, up frontAnnual, up front
06 The fine print

How agents are counted.

Worth stating plainly, because it is the number the whole license turns on and nobody should be working it out for the first time at renewal.

  • One agent is one distinct role in production. A planner that hands work to three specialist agents counts as four. Each one gets cleared separately, each carries its own scope, and each can fail on its own.
  • Staging and production copies of the same agent count once. You should not pay to test the thing you are about to clear.
  • Agents added mid-term are trued up at renewal. Nothing stops working in the meantime, because nothing in the tool is counting.
  • Growing never forces you into a tier you do not need. Extra agents cost $4,000 a year each up to twenty, on every plan, so the price rises smoothly with the fleet. The two paths meet exactly at twenty agents, where Team plus overage and Regulated both come to $84,000. You move up for the crosswalks, the ATO packs and the air-gapped install, not because you ran out of room.
  • Past twenty agents the rate drops to $2,500, and past fifty we stop multiplying. A flat per-agent rate stretched across a large fleet produces numbers nobody would say out loud. Above fifty we price the fleet.
How this is enforced

On trust, and a true-up.

There is no license server, no activation key and no usage reporting. Nothing in the tool checks what you are entitled to, and that is on purpose. Anything that phones home is a non-starter inside an air-gapped network, and it is the first thing a security review asks about.

So the accounting lives in the contract instead. You tell us the agent count at renewal and we true it up. It is the same trade most vendors selling into regulated environments end up making, and it works because both sides would rather have that conversation once a year than have a tool that calls out.

07 Design partners

The first few get a discount.

We are taking two or three design partners in financial services, insurance, health or government, at 40 to 50% off the first year, in exchange for a case study and a reference call. Named or anonymized is your choice, and you approve every word before anything gets published.

The full price goes in the contract so the discount stays a discount instead of quietly becoming your baseline. What you are really buying at that rate is influence. Design partners get their trace format supported, their crosswalk controls prioritized, and their objections answered in the roadmap rather than in a support queue.

08 Questions

The ones that decide the contract.

What counts as an agent?

One agent is one distinct role running in production. A planner that hands work to three specialist agents counts as four, because each one gets cleared separately and each one can fail on its own. The same agent running in staging and in production counts once. You should not pay to test the thing you are about to clear.

The license covers five agents. Why is clearing a second one extra?

Because they are two different things. The license is entitlement: it covers running the gate on up to five agents, and nothing about that changes whether we are involved or not. The Sprint is work: writing one task contract, running one baseline, doing one remediation round and wiring one gate, for one agent. Agents two through five are already licensed, and once the first gate is wired you have everything you need to clear the rest yourself. Paying us to do the second one is a convenience while we are already in your environment, not a fee for permission.

What happens if we add agents mid-year?

Nothing breaks. There is no license server and nothing in the tool checks your agent count, so adding an agent mid-term is a contract question rather than a technical one. You tell us the count at renewal and the extra agents are trued up at $4,000 each a year up to twenty, and $2,500 each beyond that. Adding agents never forces you onto a bigger tier. You move up for the compliance features, not for room.

Is the first report really free?

Yes, and it runs on one of your own agents rather than on sample data. We give it away because a real clearance report is the only honest way to show what this produces, and because the result is sometimes unflattering to us. Nothing leaves your environment to produce it.

Do we have to send you our traces?

No. The deterministic evaluation runs entirely inside your environment. The AI-analyst phase is opt-in and can run against a Bedrock-hosted model inside your own AWS account. Agent TrustKit holds no customer trace data at any tier.

What does the Agent Trust Sprint include?

Fixed scope and fixed price, and twelve months of the Team license comes with it. The Sprint turns one baseline report into a practice: a task contract your team owns, remediation guidance, a re-run comparison showing what the fixes actually moved, and a CI gate wired into your pipeline. Price depends on one thing, which is how your agent's behavior gets out of your system and into a trace file: $30,000 if you already export Bedrock or OpenTelemetry traces, $45,000 if we write an exporter or an adapter for you, $65,000 if the agent needs instrumenting and a task set first. Two to three weeks at the first band, six to ten at the third. At the end of the twelve months you renew the license or move up to Regulated.

What happens if our security review takes months?

The Sprint pauses rather than quietly absorbing it, and we tell you at week two rather than week eight. Everything the Sprint includes is stated with a count on the pricing page, and the things that most often blow a fixed price out — a bespoke vendor questionnaire, a model-risk committee session, an in-account analyst setup because trace content cannot leave your infrastructure — each carry a published price instead of being discovered in an invoice. We assume a first trace export within four weeks of kickoff. If we are blocked longer than four consecutive weeks the engagement pauses and resumes at the rates in force then.

Can we buy a license without a Sprint?

Not yet, and we would rather say that than sell you something we cannot hand over. There is no public distribution of Agent TrustKit today: no package to download, no install guide written for your team, no self-serve path. Every engagement runs through us, and the Sprint is how the tool gets delivered — the twelve months of Team license that come with it are what keep the gate running afterwards. If you have a platform team that would rather run the CLI themselves, say so when you get in touch. Standalone licensing is a packaging problem rather than a product one, and a buyer asking for it is the thing that would move it up the list.

Our logs are not standard OpenTelemetry. Does that cost extra?

Usually not much, and often nothing. If you already export traces in some other shape, from CloudWatch, a database or flat files, a small adapter maps your schema onto the canonical model. That is typically half a day of work and the adapter is yours to keep. Regulated includes one custom adapter a year. On Starter and Team we quote it with the engagement, because the effort depends entirely on what your logs look like, and quoting a number before seeing them would be guesswork.

What if we run a lot more than twenty agents?

Talk to us. Agents beyond twenty are $2,500 each a year, and that holds to about fifty. Past that, multiplying a per-agent rate across a large fleet produces a number neither of us would take seriously, so we price the fleet instead. Tell us the size you are heading for and we will quote it properly.

Is there a monthly option?

Not today. Licenses are annual and paid up front. Monthly billing would mean metering and usage reporting, and there is nothing in the tool that phones home, which is the property regulated buyers care about most.

09 Talk to us

Tell us what you are clearing.

Whichever plan fits, the first step is the same: one trace export and a sentence about what the agent was supposed to do. You get a real clearance report back, free, and a straight answer on what a license would cost.

Start with the free report.

Send one trace export and a sentence on what the agent was supposed to do. You get a real clearance report back, whatever it says, and a straight answer on what a license would cost you.

Talk to us →[email protected]Next → Get started