Private preview

Design Partner

Freethrough preview

For teams already running agents with write access who want the control plane in front of them now, and are willing to shape it.

  • Up to 5 agents, 1 environment
  • Warden Cloud, shared inference fleet
  • Full policy engine, approvals and audit ledger
  • Weekly working session with the engineering team
  • Locked preferential pricing at general availability
Regulated & at scale

Enterprise

Customannual contract

For organisations that cannot send prompt content to a vendor, or that are governing agents across many business units.

  • Unlimited agents and decision volume
  • Self-hosted inference in your VPC, or fully air-gapped
  • Dedicated GPU capacity for the guard models
  • SAML SSO, SCIM provisioning, custom roles
  • Policy-as-code pipelines and simulation against your own traffic
  • Evidence packs for NIST AI RMF, EU AI Act and SOC 2 audits
  • Named engineer, 24/7 incident line, contractual SLA

Warden is in private preview. These figures are indicative and will be confirmed at general availability — design partners keep the pricing they start on. Prices exclude tax.

The controls are not the upsell

Security features that only appear in the top tier are how breaches happen at everyone below it. Every plan gets the whole enforcement path.

Enforcement

Full policy engine

Identity, data-class scope, spend caps, blast radius and egress control — the same engine in every plan.

Enforcement

Human-in-the-loop holds

Any action can be held for an owner rather than allowed or blocked outright, on every tier.

Evidence

Tamper-evident ledger

Hash-chained, signed decision records with full replay. Retention is what differs between plans, not the record.

Intelligence

Guard models inline

Injection, sequence and PII models run on every decision. There is no cheaper tier that skips the inference.

Operations

Kill switch

Freeze one agent, one tool or the whole fleet from the console or one API call.

Operations

Simulation mode

Run a new policy against yesterday’s traffic before you enforce it. Included everywhere.

Before you ask us

What counts as an agent?
A distinct workload identity that Warden issues credentials to. Scaling one agent to fifty replicas is still one agent. Two agents that share a codebase but run with different entitlements are two, because they carry different risk.
What counts as a decision?
One authorisation of one tool call — allow, hold or block — including the model scoring and the audit record behind it. Retries of the same call within a session count once.
What happens if we go over the included volume?
Nothing gets blocked and nothing gets silently dropped. Overage is billed per million decisions and we will tell you before you cross the line, not after.
Why is self-hosted inference Enterprise-only?
Because it means running and supporting the guard models on your GPUs, which is a real operational commitment on both sides rather than a feature flag. If your regulator requires it and you are not an enterprise, tell us — we would rather solve it than lose the deployment.
Can we start on Design Partner and move up?
That is the intended path. Design partners keep the pricing they start on when Warden reaches general availability, and there is no migration — it is the same control plane with the limits lifted.
Do you offer a free trial?
Not yet. Warden is in private preview, so access is by application rather than sign-up. The design-partner tier is the free path in for teams that qualify.

Start with the agents that can cost you something.

Tell us what your agents are allowed to do today. If a design-partner slot fits, we will say so; if it does not, we will tell you that too.