
One platform. Two ways to buy.
Choose predictable, SKU-based Platform pricing or Flex pricing that scales with consumption.
- SKU-based or consumption pricing
- Exact pricing scoped with you
- Commercial, regional, and federal hosting paths
C1 trust and security review
Built for enterprise deployment.
C1 runs as a hosted multi-tenant SaaS in AWS US, with tenant isolation, multi-region resilience, and no employee access to production.
- Tenant isolation by designIncluded
Tenants are isolated by decryption boundaries; internet-facing API services cannot decrypt customer data. Applies to every customer.
- AWS multi-region · USIncluded
Hosted in AWS US-West-2 + US-East-2 with cross-region replication and continuous DynamoDB backups. Applies to every customer.
- No employee access to productionIncluded
Engineers do not have remote access to production. EKS Managed Node Groups eliminate workstation paths to prod. Applies to every customer.
- EU data residencyComing soon
Coming-soon EU-region hosting planned for customers with data residency requirements.
- Federal / FedRAMP Class C targetComing soon
Coming-soon Federal hosting targeting FedRAMP Class C Certification. No current federal certification or authorization is claimed.
Protect customer data by default.
C1 encrypts customer traffic and stored data, limits connector scopes, and never uses customer data to train foundation models.
- Encryption in transit · TLS 1.2+Included
All customer traffic over TLS 1.2 or greater; internal service-to-service traffic uses mutual TLS. Applies to every customer.
- Encryption at rest · AWS KMSIncluded
Objects encrypted at rest in AWS DynamoDB. API keys and secrets are double-encrypted with AWS KMS symmetric keys before storage. Applies to every customer.
- Least-privilege connectorsIncluded
Every connector defines minimum scopes. Customers control connector tokens; rotate or revoke from your IdP at any time. Applies to every customer.
- No training on customer dataIncluded
Customer data is never used to train foundation models. AI features run on customer-scoped context with documented retention. Applies to every customer.
- Customer-managed keys (BYOK)Roadmap
Bring your own KMS keys; rotate, revoke, and audit independently.
Make every administrative path attributable.
SSO, directory sync, MFA, IP restrictions, and audit export give teams a controlled, reviewable operating boundary.
- SAML SSOIncluded
Federated authentication via your IdP. Included on every plan with no SSO tax.
- Directory sync (includes SCIM)Included
Native pull from Active Directory, Okta, Entra ID, HRIS systems, and SCIM endpoints. Lifecycle events from any source, normalized.
- MFA enforcementIncluded
Enforce MFA at the IdP for federated users; native MFA for non-federated admins. Available on every plan.
- Audit log exportIncluded
Export to S3 in OCSF format, plus other common SIEM providers. Available on every plan.
- IP allowlistingIncluded
Restrict admin access to allowlisted IP ranges. Available on every plan.
Operate with documented commitments.
Support coverage, service levels, disaster-recovery drills, penetration tests, and vulnerability disclosure define how C1 runs with your team.
- Named CSMAvailable
Dedicated customer success manager. Strategic CSM on Mission Critical.
- 24×7 P0 on-callAvailable
30-minute response on Enterprise · 15-minute on Mission Critical.
- 99.99% SLA with service creditsAvailable
Financial credits for missed SLAs on Enterprise and Mission Critical.
- Coordinated vulnerability disclosureIncluded
Public security contact, responsible disclosure policy, and an internal triage cadence. Applies to every customer.
- Annual DR drills · annual pen-testIncluded
Documented disaster-recovery runs and third-party penetration tests on a yearly cadence. Applies to every customer.
Fit C1 into enterprise procurement.
AWS Marketplace offers, annual invoicing, standard legal agreements, and scoped commercial terms give procurement a clear path to close.
- AWS Marketplace · Private OffersAvailable
Private Offers for 1+ year committed-spend agreements on Business and Enterprise. Lets you draw down AWS committed spend (EDP) against your C1 contract.
- PO billing · NET termsAvailable
Procurement-friendly invoicing on annual and multi-year contracts.
- Custom MSA · DPA · BAAAvailable
Standard process; we work directly with your legal and procurement teams.
- Custom SKUs · custom meteringAvailable
Custom C1 Token weights for non-standard workloads, volume floors, or bundled outcomes.
Bring evidence into the security review.
C1's certifications, available agreements, and roadmap items make current status visible before procurement starts.
- SOC 2 Type IICertified
- ISO 27001Certified
- HIPAA + BAAAvailable
- GDPR + DPAAvailable
- PCI DSSRoadmap
- FedRAMP Class C targetComing soon
SOC 2 Type II + ISO 27001 reports are available under NDA. HIPAA + BAA is available on Enterprise. Federal is coming soon and targets FedRAMP Class C Certification; no current federal certification or authorization is claimed. PCI DSS is on the roadmap.