THE GOVERNED MCP GATEWAY EVERY PLAN: DEFAULT DENY · HIDDEN DISCOVERY · BROKERED CREDENTIALS · AUDIT

Pricing

Pay for scale.
Not for security.

Everything that makes it safe — deny by default, tools invisible until approved, credentials that never touch the agent, a full audit trail — is on every plan, including free. Plans differ in how much you govern, what you integrate, and how we support you.

▲ TRY BEFORE YOU COMMIT — SEE HOW A 4–6 WEEK PILOT WORKS ↓
FREE
For a solo builder running real work.
$0
hosted · forever free
  • 5 MCP servers · 2 API sources
  • 250k governed calls / month
  • 1 environment
  • Default-deny Cedar policy + explicit deny
  • Policy-filtered discovery
  • Credential broker — service accounts + user OAuth
  • Audit search · 7-day retention
  • gatewayctl CLI + admin API
  • Community support · best-effort availability
Start free
TEAM
For a platform team going first.
$149 / mo
per gateway deployment
  • Everything in Free
  • 25 MCP servers · 10 API sources
  • 1M governed calls / month
  • 3 environments (dev · stage · prod)
  • All credential modes — OAuth user-delegated, agent-scoped, workload
  • Policy simulation before rollout
  • OpenAPI → MCP conversion
  • Audit · 30-day retention
  • Email support
Book a walkthrough
ENTERPRISE
For regulated estates and strict data boundaries.
Custom
annual · talk to us
  • Everything in Business
  • Unlimited servers, sources & calls
  • Dedicated single-tenant, in your own cloud, or fully self-hosted with no vendor egress
  • Multi-cluster / multi-region
  • Custom audit retention + export contracts
  • Dedicated security review & onboarding
  • Signed releases: Cosign + SBOM evidence packet
  • Air-gapped packaging (roadmap)
  • SLA + custom terms · named support
Talk to the team

Compare

Every limit, on the record.

The governance core never varies by plan. If a row reads "all plans," that's a guarantee, not marketing.

Capability Free Team Business Enterprise
MCP servers525100Unlimited
API sources (OpenAPI → MCP)21050Unlimited
Governed calls / month250k1M10MUnlimited
Environments13UnlimitedUnlimited
Default-deny Cedar policyALL PLANS
Policy-filtered discoveryALL PLANS
Emergency disable + revocationALL PLANS
Credential modesService + user OAuthAll modesAll modesAll modes
Policy simulation
SAML SSO (admin)
Private connectors
SIEM export
Audit retention7 days30 days90 daysCustom
DeploymentHostedHostedHosted · HA profileDedicated · your cloud · or self-hosted
AvailabilityBest effortStatus commitmentsHA profileContractual SLA
SupportCommunityEmailPriorityNamed + SLA

Over a call limit, new sessions are throttled — the gateway never fails open and never bypasses policy to keep traffic flowing.

How a pilot works

Prove one boundary. Then decide.

A pilot is a sign-off-driven plan with named owners and dates — 4–6 weeks, one governed boundary, proven end to end on your infrastructure. Not a roadmap tour: one real MCP server or API operation, one allowed call, one denied call, one revocation.

SCOPE one boundary W0 STAND UP your cluster · idp W1–2 POLICY allow ✓ · deny ✕ W2–3 PROVE revoke live · siem W3–5 DECIDE go · extend · no-go W6 EVIDENCE AT EVERY STEP — THE SIGN-OFF IS YOURS, ROW BY ROW
The pilot, drawnThe number you take to the board comes from week 6
WeekMilestoneYou sign off when
W0Kickoff & scopeCharter and one concrete use case signed
W1Environment stand-upGateway running in your chosen mode: hosted, dedicated, or self-hosted
W1–2Identity wiredYour IdP resolves real actor context
W2–3Capability + policyOne server or API operation approved; one allow and one deny rule simulated and accepted
W3–4Credentials + routing + revocationOpaque-reference resolution verified; no secret in any log; revoke reaches live sessions
W4–5Audit + SIEMMetadata-only events landing in your SIEM
W6Readout & decisionGo · extend · or no-go, with documented reasons

What you bring

  • A security owner and a platform owner committed to the decision
  • One concrete use case, named up front
  • A non-production tool or API (or an accepted fixture)
  • Your deployment mode: hosted, dedicated, or self-hosted

Who signs off

  • Security: denied tools hidden, every call attributable, no secrets in any record, revocation works
  • Platform: repeatable install on the deployment mode you chose, your data stores, and no vendor egress when self-hosted
  • Developers: one governed call succeeds end to end with validation enforced

How it ends

  • Go — expand to the next boundaries on a paid plan
  • Extend — one defined gap, one new exit criterion
  • No-go — documented reason; you keep everything you learned

FAQ

Fair questions.

What counts as a governed call?

One tool invocation through the gateway — policy evaluation, credential resolution, routing, and the audit event included. Discovery requests and denied calls don't count against your quota; you are never billed for being protected.

Is the free plan really default-deny?

Yes. The policy engine, hidden discovery, fail-closed behavior, and metadata-only audit are identical on every plan. We don't sell a less-safe version of a security product.

What happens when I hit a limit?

Soft limits, fail-safe semantics: new sessions throttle and you get an operator alert. The gateway never fails open, so an over-quota deployment keeps enforcing policy on existing traffic. There is no card on file for free plans, so you are never surprised by a bill. Per-minute rate limits apply on every plan to keep one workload from starving another.

Can I run production on the free plan?

Yes, and we mean it. 250k governed calls a month is roughly 8,000 a day, which covers a solo builder's real automation load, not just a demo. What free doesn't buy is a promise: availability is best effort with no SLA, and the fences that matter as your stakes rise are separate environments, longer audit retention, and SSO.

Which plans can self-host?

Enterprise. Team and Business run on our hosted plane so you get the governed path in minutes with nothing to operate. For regulated estates, Enterprise deploys dedicated single-tenant, into your own cloud account, or fully self-hosted with no vendor egress (Helm into your cluster, your PostgreSQL/Valkey/IdP/secret manager), verifiable at your firewall.

Can we try it before committing?

Yes — that's the pilot above: 4–6 weeks, one governed boundary on your infrastructure, with sign-off criteria your security and platform teams agree to up front. Early design partners also shape the roadmap.

Next step

Start with one boundary. Free.

Start the free plan in minutes with nothing to run, or bring your architecture to a 25-minute walkthrough.

Start free Book a walkthrough