Pricing
Priced per governed identity, not per person.
One credential is reused across three tiers of value — least privilege inside your tenant, verified delegation to counterparties, and portable attestation. Account value expands as the credential travels, so you pay for the authority you actually govern. Per-identity price points are being set with design partners and are not yet published.
Control plane
For the CISO or IAM lead replacing borrowed logins and shared static keys with a distinct identity per agent. This is the layer budgeted today on IAM/PAM lines.
- Distinct cryptographic identity per agent in a canonical directory
- Short-lived credentials scoped to a named human sponsor
- Policy evaluated at the moment of execution
- Immutable log of every authorization decision
- Governance console: approval gates and revocation controls
- Maps to SOC 2 / ISO 27001 service-account and key-management expectations
Verified delegation
For teams whose agents transact across a boundary — with a vendor, a bank, or another company's agent — and need that authority accepted, not reconciled afterward.
- Everything in Control plane
- The same credential issued as a portable W3C Verifiable Credential
- Credential binds agent to a legal entity, authority scope, value and transaction thresholds, expiry, and the accountable human fiduciary
- Real-time verification API for counterparty checks before transacting
- Revocations propagated across the network so no counterparty relies on stale authority
- Metered fees on verification checks
Attestation registry
For agentic-commerce and regulated 'know your agent' use cases that need network participation and settlement-grade authority under an enforceable fiduciary record.
- Everything in Verified delegation
- Portable Verifiable Credential issuance and registry participation
- Settlement-grade agent-to-agent authority
- DIFC forum in which the fiduciary record is enforceable
- Named human sponsor on record for every credential
- Custom policy constraints and approval chains
Human sponsors and administrators are the accountable parties, not billable agents. Pricing follows the prevailing per-account IAM/PAM subscription model; per-identity price points and verification attach rates are unvalidated and treated as assumptions until proven by paying customers.
Questions
What determines price, and how we sell.
What counts as a billable agent identity?
An active agent identity is a distinct non-human actor registered and governed in the directory — an autonomous agent, a scheduled job acting with delegated authority, or a tool-using model instance. Issuing many short-lived credentials to one agent over its lifetime is still one identity; the price follows the governed actor, not the number of credentials it rotates through.
What drives the total cost?
Three things, matching what you actually use: the number of active agent identities governed in your environment, the volume of cross-boundary verification checks metered through the API, and whether you take the attestation registry tier for portable credential issuance and network participation. If you only need internal least privilege today, you only pay for the control plane.
Which budget does this come from?
Customers typically fund the control plane from existing IAM/PAM and secrets-management lines — it addresses the least-privilege, service-account and SOC 2 problems a security team already owns. Verified delegation and the attestation registry are separate expansions taken on as counterparties come online, so they do not need to be justified before the control-plane value is proven.
How do you sell it — is there a self-serve price list?
No published price list yet. We run design-partner-led founder sales with CISOs and IAM and platform-engineering leaders, converting to inside sales as the category matures. In the early phase we set terms directly with each design partner so pricing reflects real fleet size and usage rather than a speculative number.
Do you require the verification and registry tiers to start?
No. You can deploy the control plane on its own for internal least privilege and attribution. Verified delegation and the attestation registry are only relevant once your agents transact across a boundary with counterparties who need to check their authority. We would rather you adopt the layer you have a budget line for today than pay for cross-boundary features before they are load-bearing for you.
What does procurement need from us?
We support the standard enterprise security review: the platform maps to SOC 2 / ISO 27001 service-account and key-management expectations, and the governance console provides the evidence trail of what each agent was permitted to do and what it actually did. As an FTLAB AI-born company operating from the DIFC, the fiduciary record naming the accountable human sponsor is enforceable in a defined forum.
Price it against your agent fleet.
Tell us how many agents you run, whose logins or keys they borrow today, and whether they transact across a boundary. We will model the terms and show you the control failure it replaces.