
AI-native identity security. Built to scale, priced to match.
Flexible packages for every size and industry — pay for the work, not every seat.
- No seat tax
- Cost Intelligence built in
- SOC 2 · ISO 27001 · HIPAA + BAA available
Built for the team running enterprise identity.
C1 is a hosted multi-tenant SaaS in AWS US. Tenant data is isolated by decryption boundaries — internet-facing services can't decrypt customer data, and engineers don't have access to production.
Platform
- Tenant isolation by designIncluded
Tenants are isolated by decryption boundaries; internet-facing API services cannot decrypt customer data. Applies to every customer.
- AWS multi-region · USIncluded
Hosted in AWS US-West-2 + US-East-2 with cross-region replication and continuous DynamoDB backups. Applies to every customer.
- No employee access to productionIncluded
Engineers do not have remote access to production. EKS Managed Node Groups eliminate workstation paths to prod. Applies to every customer.
- EU data residencyIn progress
EU-region hosting for customers with data residency requirements. Talk to an architect to be on the early-access list.
- FedRAMP ModerateIn progress
FedRAMP Moderate authorization in the US Federal hosting environment, for public-sector and regulated commercial workloads. Talk to an architect to be on the early-access list.
Data protection
- Encryption in transit · TLS 1.2+Included
All customer traffic over TLS 1.2 or greater; internal service-to-service traffic uses mutual TLS. Applies to every customer.
- Encryption at rest · AWS KMSIncluded
Objects encrypted at rest in AWS DynamoDB. API keys and secrets are double-encrypted with AWS KMS symmetric keys before storage. Applies to every customer.
- Least-privilege connectorsIncluded
Every connector defines minimum scopes. Customers control connector tokens; rotate or revoke from your IdP at any time. Applies to every customer.
- No training on customer dataIncluded
Customer data is never used to train foundation models. AI features run on customer-scoped context with documented retention. Applies to every customer.
- Customer-managed keys (BYOK)Roadmap
Bring your own KMS keys; rotate, revoke, and audit independently.
Access & audit
- SAML SSOIncluded
Federated authentication via your IdP. Included on every plan with no SSO tax.
- Directory sync (includes SCIM)Included
Native pull from Active Directory, Okta, Entra ID, HRIS systems, and SCIM endpoints. Lifecycle events from any source, normalized.
- MFA enforcementIncluded
Enforce MFA at the IdP for federated users; native MFA for non-federated admins. Available on every plan.
- Audit log exportIncluded
Export to S3 in OCSF format, plus other common SIEM providers. Available on every plan.
- IP allowlistingIncluded
Restrict admin access to allowlisted IP ranges. Available on every plan.
Operations
- Named CSMAvailable
Dedicated customer success manager. Strategic CSM on Mission Critical.
- 24×7 P0 on-callAvailable
30-minute response on Enterprise · 15-minute on Mission Critical.
- 99.99% SLA with service creditsAvailable
Financial credits for missed SLAs on Enterprise and Mission Critical.
- Coordinated vulnerability disclosureIncluded
Public security contact, responsible disclosure policy, and an internal triage cadence. Applies to every customer.
- Annual DR drills · annual pen-testIncluded
Documented disaster-recovery runs and third-party penetration tests on a yearly cadence. Applies to every customer.
Procurement
- AWS Marketplace · Private OffersAvailable
Private Offers for 1+ year committed-spend agreements on Business and Enterprise. Lets you draw down AWS committed spend (EDP) against your C1 contract.
- PO billing · NET termsAvailable
Procurement-friendly invoicing on annual and multi-year contracts.
- Custom MSA · DPA · BAAAvailable
Standard process; we work directly with your legal and procurement teams.
- Custom SKUs · custom meteringAvailable
Custom C1 Token weights for non-standard workloads, volume floors, or bundled outcomes.
- SOC 2 Type IICertified
- ISO 27001Certified
- HIPAA + BAAAvailable
- GDPR + DPAAvailable
- PCI DSSRoadmap
- FedRAMP ModerateIn progress
SOC 2 Type II + ISO 27001 reports available under NDA. HIPAA + BAA available on Enterprise. FedRAMP Moderate is in progress; PCI DSS is on our compliance roadmap.
Ready to talk pricing?
A C1 expert will walk you through a plan built around your environment and use cases.