Simple, transparent pricing. No hidden fees. Start free, upgrade when you are ready.
๐ Customer 1-pagers
These 1-pagers explain the technical depth behind each tier and module for sales engineers, security architects, and procurement teams. They follow the established pattern of being self-attested (we engineer the scanner; a Notary Body or counsel provides the certification / legal opinion).
| 1-pager | What it explains |
|---|---|
| Trust Framework 1-pager | The 6th pillar (per-agent identity, capability contracts, real-time trust scoring, signed attestations) |
| Federated IOC Library 1-pager | “1 customer’s threat = all AegisGate customers protected” โ the network effect |
| EU AI Act 1-pager | EU AI Act compliance (120 controls, Professional+ tier) |
| Lens โ Platform Upsell 1-pager | The 4-stage conversion funnel (individual โ team โ POC โ production) |
| Case Study: Series-B SaaS + SOC 2 with Trust Framework | How a 200-person Series-B SaaS passed SOC 2 Type II in 90 days using AegisGate |
The case study is representative, not a real customer. It is built from anonymized patterns across multiple AegisGate customers. We publish composite case studies to illustrate the value of AegisGate for a customer segment without disclosing customer information.
By purchasing a subscription or add-on, you agree to the Terms of Service and Privacy Policy.
Community
Free forever: Lens browser extension + Platform server-side protection with 4 community frameworks.
- Unlimited proxy RPM (soft-throttle)
- 5 concurrent users
- 176+ security detection patterns
- 8 MCP guardrails
- 8 A2A guardrails (mTLS, HMAC, capabilities, rate limiting)
- MITRE ATLAS (66 techniques)
- NIST AI RMF support
- OWASP LLM Top 10
- Built-in Certificate Authority
- 7-day audit log retention
- Community support (GitHub Issues)
Developer
For growing teams building AI-powered applications.
- 1,000 proxy RPM / 500 MCP RPM
- 25 concurrent users
- Everything in Community, plus:
- mTLS authentication (proxy + A2A)
- A2A capability persistence
- SSO authentication
- RBAC permissions
- Advanced ML anomaly detection
- Grafana integration
- SQLite and Redis storage
- Code execution sandbox
- Priority email support
- gRPC API access (7 services, 50 RPCs)
Professional
For teams with serious security and compliance requirements.
- 10,000 proxy RPM / 5,000 MCP RPM
- 100 concurrent users
- Everything in Developer, plus:
- A2A agent registry & trust scoring
- A2A task-level ACLs
- A2A artifact validation
- Trust Framework (6th pillar) โ per-agent identity, capability contracts, real-time trust scoring, signed attestations. Read the 1-pager
- Federated IOC library โ opt-in sharing of detected threats. Read the 1-pager
- Custom RBAC policy engine
- Department separation
- Kubernetes and Helm deployment
- PostgreSQL and S3 storage
- Process-level MCP sandboxing
- SIEM integration (11 platforms: Splunk, Datadog, ELK, and more)
- 90-day audit log retention
- Priority support
- gRPC API access
Enterprise
Mission-critical deployments with advanced security and dedicated support.
- Unlimited proxy & MCP RPM
- Unlimited concurrent users
- Everything in Professional, plus:
- A2A notification verification
- A2A cross-agent attack detection
- Custom ML models and zero-day detection
- HSM and LDAP integration
- High availability and air-gapped deployment
- Auto-scaling and multi-region
- 1-year audit log retention
- Business Associate Agreement (BAA)
- Data Processing Agreement (DPA)
- Dedicated support engineer with 4-hour SLA
Compliance Modules (Add-ons)
Add individual compliance modules to any paid tier. Modules are billed separately and can be turned on or off at any time from the customer portal. 27 modules across 31 frameworks โ 4 are free (Community tier), 23 are paid add-ons.
Free Community Modules
These 4 modules are included free with every tier (Community and above):
OWASP LLM Top 10
Community tier
10 controls covering prompt injection, insecure output handling, training data poisoning, and more. All 10 controls are automated.
OWASP Web Top 10
Community tier
10 controls covering injection, broken auth, sensitive data exposure, and more. All 10 controls are automated.
MITRE ATLAS
Community tier
6 controls covering adversarial tactics and techniques against AI systems. All 6 controls are automated.
NIST AI RMF
Community tier
50 controls across Govern (14), Map (10), Measure (13), and Manage (13) functions. 30 automated, 20 manual.
Developer Modules โ $149/month
HIPAA
Requires Developer tier or above
54 controls: 24 automated, 30 manual. PHI detection (SSN, MRN, DOB, health plan IDs), Business Associate Agreement (BAA) support, audit-ready evidence. View HIPAA self-assessment
PCI-DSS
Requires Developer tier or above
152 controls: 75 automated, 77 manual. Payment card data detection, PCI-scoped audit logs, card data tokenization. PCI-DSS SAQ A self-assessment.
SOC 2
Requires Developer tier or above
64 controls: 32 automated, 32 manual across 4 Trust Services categories (Security, Availability, Processing Integrity, Confidentiality). SOC 2 Type 1 readiness self-assessment.
ISO 27001
Requires Developer tier or above
116 controls: 92 automated, 24 manual. Annex A controls covering organizational, people, physical, and technological security domains.
CCPA/CPRA
Requires Developer tier or above
26 controls: 14 automated, 12 manual. Consumer privacy rights, data deletion, opt-out of sale, and data portability enforcement.
GDPR
Requires Developer tier or above
99 controls: 12 automated, 87 manual. Lawful basis tracking, data subject rights (access, erasure, portability), DPIA support, ROPA generation.
Professional: Security Foundation โ $79/month
CIS Critical Security Controls
Requires Professional tier or above
50 controls: 38 automated, 12 manual. CIS Controls v8 IG1/IG2/IG3 implementation levels with tiered enforcement.
NIST Cybersecurity Framework
Requires Professional tier or above
131 controls: 23 automated, 108 manual. Full NIST CSF 2.0 coverage across Govern, Identify, Protect, Detect, Respond, and Recover functions.
CSA STAR
Requires Professional tier or above
16 controls: 16 automated. Cloud Security Alliance STAR Level 1 self-assessment with automated control checking.
NIST AI 600-1
Requires Professional tier or above
12 controls: 12 automated. AI risk management profile covering trustworthy AI characteristics.
Professional: Industry-Specific โ $199/month
ISO 42001 (AI Management)
Requires Professional tier or above
38 controls: 18 automated, 20 manual. AI management system standard covering context, leadership, planning, support, operation, and performance evaluation.
EU AI Act
Requires Professional tier or above
120 controls: 17 automated, 103 manual. Risk classification, conformity assessment, transparency obligations, and GPAI requirements. View EU AI Act self-assessment
FIPS 140-2/140-3
Requires Professional tier or above
40 controls: 27 automated, 13 manual. AegisGate is FIPS-compliant (uses FIPS-approved algorithms) but the Go runtime is not CMVP-validated. Federal agencies need a CMVP-validated execution environment.
SOX (Sarbanes-Oxley)
Requires Professional tier or above
80 controls: 27 automated, 53 manual. Financial reporting controls, IT general controls (ITGCs), change management, and segregation of duties.
GLBA (Gramm-Leach-Bliley)
Requires Professional tier or above
14 controls: 14 automated. Financial privacy rules, safeguards rule, and pretexting protection.
CJIS Security Policy
Requires Professional tier or above
64 controls: 24 automated, 40 manual. FBI CJIS Security Policy covering access control, audit, integrity, personnel, and physical security.
NERC CIP
Requires Professional tier or above
55 controls: 31 automated, 24 manual. Critical infrastructure protection for bulk electric system operators.
FERPA
Requires Professional tier or above
45 controls: 31 automated, 14 manual. Student education records privacy, directory information, and data breach notification.
HITECH Act
Requires Professional tier or above
35 controls: 23 automated, 12 manual. Electronic health records security, breach notification, and HIPAA enforcement enhancements.
FFIEC Banking Guidance
Requires Professional tier or above
40 controls: 25 automated, 15 manual. Federal Financial Institutions Examination Council cybersecurity assessment and resilience guidance.
TSA Security Directive
Requires Professional tier or above
35 controls: 22 automated, 13 manual. Transportation Security Administration pipeline security directive compliance.
ISO 21434 (Automotive)
Requires Professional tier or above
42 controls: 25 automated, 17 manual. Automotive cybersecurity engineering standard for road vehicle E/E systems.
Enterprise โ $499/month
FedRAMP
Requires Enterprise tier
170 controls: 153 automated, 19 manual. FedRAMP Moderate baseline. AegisGate is NOT a FedRAMP-accredited 3PAO. The platform generates technical evidence; the 3PAO assessment and ATO issuance is the customer's responsibility.
CMMC Level 2
Requires Enterprise tier
150 controls: 89 automated, 61 manual. Cybersecurity Maturity Model Certification Level 2 (advanced/progressive) covering all 14 domains plus CUI protection.
NIST 800-171
Requires Enterprise tier
110 controls: 68 automated, 42 manual. Protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.
HITRUST CSF
Requires Enterprise tier
200 controls: 50 automated, 150 manual. HITRUST CSF e1/i1/r2 assessments covering consolidated healthcare and security requirements.
TISAX AL2
Requires Enterprise tier
65 controls: 31 automated, 34 manual. Automotive industry information security assessment (Trusted Information Security Assessment Exchange) at AL2 level.
Vertical Accelerator Bundles
Save up to 37% by bundling compliance modules for your industry. Each bundle includes the relevant modules at a discounted price vs. purchasing individually.
Privacy & Data Protection
Requires Developer tier
GDPR + CCPA/CPRA + HIPAA. Complete data protection and privacy compliance for organizations handling personal data across jurisdictions. Individual price: $447/mo โ save $298/mo.
SaaS / B2B Technology
Requires Developer tier
SOC 2 + ISO 27001 + ISO 42001. Security and AI management for SaaS and B2B technology companies. Individual price: $497/mo โ save $298/mo.
Financial Services
Requires Developer tier
PCI-DSS + SOX + SOC 2 + GLBA + FFIEC + ISO 27001. Comprehensive financial services compliance. Individual price: $1,044/mo โ save $795/mo.
Healthcare
Requires Developer tier
HIPAA + HITECH + FedRAMP. Healthcare and health IT compliance with breach notification and federal requirements. Individual price: $847/mo โ save $648/mo.
EU Compliance
Requires Developer tier
GDPR + ISO 27001 + EU AI Act. European regulatory compliance for organizations operating in the EU market. Individual price: $547/mo โ save $398/mo.
Energy & Critical Infrastructure
Requires Professional tier
NERC CIP + TSA SD + ISO 21434. Energy sector and critical infrastructure protection across power, transportation, and automotive. Individual price: $597/mo โ save $298/mo.
Defense & Government
Requires Enterprise tier
FedRAMP + CMMC L2 + NIST 800-171 + CJIS + FIPS. Full defense and government compliance stack. Individual price: $1,895/mo โ save $696/mo.
Cross-Framework Traceability
All AegisGate compliance modules map to a unified set of 78 AegisGate hub controls. The cross-framework mapping matrix provides bidirectional traceability across 31 frameworks with 1,720 control references. This means evidence collected for one framework automatically satisfies requirements in mapped frameworks โ reducing audit effort by up to 60%.