Ship AI without shipping risk.
Pricing

AI-native identity security. Built to scale, priced to match.

Flexible packages for every size and industry — pay for the work, not every seat.

  • No seat tax
  • Cost Intelligence built in
  • SOC 2 · ISO 27001 · HIPAA + BAA available
Enterprise

Built for the team running enterprise identity.

C1 is a hosted multi-tenant SaaS in AWS US. Tenant data is isolated by decryption boundaries — internet-facing services can't decrypt customer data, and engineers don't have access to production.

Platform

  • Tenant isolation by design
    Included

    Tenants are isolated by decryption boundaries; internet-facing API services cannot decrypt customer data. Applies to every customer.

  • AWS multi-region · US
    Included

    Hosted in AWS US-West-2 + US-East-2 with cross-region replication and continuous DynamoDB backups. Applies to every customer.

  • No employee access to production
    Included

    Engineers do not have remote access to production. EKS Managed Node Groups eliminate workstation paths to prod. Applies to every customer.

  • EU data residency
    In progress

    EU-region hosting for customers with data residency requirements. Talk to an architect to be on the early-access list.

  • FedRAMP Moderate
    In progress

    FedRAMP Moderate authorization in the US Federal hosting environment, for public-sector and regulated commercial workloads. Talk to an architect to be on the early-access list.

Data protection

  • Encryption in transit · TLS 1.2+
    Included

    All customer traffic over TLS 1.2 or greater; internal service-to-service traffic uses mutual TLS. Applies to every customer.

  • Encryption at rest · AWS KMS
    Included

    Objects encrypted at rest in AWS DynamoDB. API keys and secrets are double-encrypted with AWS KMS symmetric keys before storage. Applies to every customer.

  • Least-privilege connectors
    Included

    Every connector defines minimum scopes. Customers control connector tokens; rotate or revoke from your IdP at any time. Applies to every customer.

  • No training on customer data
    Included

    Customer data is never used to train foundation models. AI features run on customer-scoped context with documented retention. Applies to every customer.

  • Customer-managed keys (BYOK)
    Roadmap

    Bring your own KMS keys; rotate, revoke, and audit independently.

Access & audit

  • SAML SSO
    Included

    Federated authentication via your IdP. Included on every plan with no SSO tax.

  • Directory sync (includes SCIM)
    Included

    Native pull from Active Directory, Okta, Entra ID, HRIS systems, and SCIM endpoints. Lifecycle events from any source, normalized.

  • MFA enforcement
    Included

    Enforce MFA at the IdP for federated users; native MFA for non-federated admins. Available on every plan.

  • Audit log export
    Included

    Export to S3 in OCSF format, plus other common SIEM providers. Available on every plan.

  • IP allowlisting
    Included

    Restrict admin access to allowlisted IP ranges. Available on every plan.

Operations

  • Named CSM
    Available

    Dedicated customer success manager. Strategic CSM on Mission Critical.

  • 24×7 P0 on-call
    Available

    30-minute response on Enterprise · 15-minute on Mission Critical.

  • 99.99% SLA with service credits
    Available

    Financial credits for missed SLAs on Enterprise and Mission Critical.

  • Coordinated vulnerability disclosure
    Included

    Public security contact, responsible disclosure policy, and an internal triage cadence. Applies to every customer.

  • Annual DR drills · annual pen-test
    Included

    Documented disaster-recovery runs and third-party penetration tests on a yearly cadence. Applies to every customer.

Procurement

  • AWS Marketplace · Private Offers
    Available

    Private Offers for 1+ year committed-spend agreements on Business and Enterprise. Lets you draw down AWS committed spend (EDP) against your C1 contract.

  • PO billing · NET terms
    Available

    Procurement-friendly invoicing on annual and multi-year contracts.

  • Custom MSA · DPA · BAA
    Available

    Standard process; we work directly with your legal and procurement teams.

  • Custom SKUs · custom metering
    Available

    Custom C1 Token weights for non-standard workloads, volume floors, or bundled outcomes.

Compliance & attestations
  • SOC 2 Type II
    Certified
  • ISO 27001
    Certified
  • HIPAA + BAA
    Available
  • GDPR + DPA
    Available
  • PCI DSS
    Roadmap
  • FedRAMP Moderate
    In progress

SOC 2 Type II + ISO 27001 reports available under NDA. HIPAA + BAA available on Enterprise. FedRAMP Moderate is in progress; PCI DSS is on our compliance roadmap.

Ready to talk pricing?

A C1 expert will walk you through a plan built around your environment and use cases.