Skip to main content

Belay Enterprise

The free, open-source Community edition protects a single host: it gates AI coding agents at the tool-call boundary, blocks dangerous actions, escalates ambiguous ones to a human, and keeps a tamper-evident local audit trail. Everything a solo developer or a single VPS needs is in that free build.

Enterprise is for teams and organizations that run Belay across many hosts and need to see, govern, and report on all of them from one place. It is delivered under a commercial license and layers central management, identity, and compliance on top of the same local-first enforcement core — the per-host protection keeps working exactly as it does in Community, even if the central plane is offline.

Talk to us

Enterprise is licensed commercially. To scope a deployment, request a trial, or discuss terms, contact hello@secblok.io.


What Enterprise adds

Each capability below is described by the value it delivers to your organization. Community keeps every host self-sufficient; Enterprise gives you the operations, identity, and audit layer to run a fleet of them.

All Enterprise capabilities are gated behind the enterprise build feature and are stripped from the open build.

Fleet management

A single central console for every protected host in your organization. See posture scores, recent verdicts, and agent activity across the whole estate at a glance, drill into any individual host, and spot the outliers that need attention — without SSHing into machines one by one.

Organizations & multi-tenancy

Org-scoped accounts, roles, and data separation so multiple teams, business units, or customers can share one deployment while each sees only its own hosts and activity. Ideal for MSPs, platform teams, and larger companies that need clean administrative boundaries.

Device management & enrollment

A managed way to bring hosts under protection and keep track of them: enroll new devices, inventory what is currently protected, and retire hosts you no longer manage — so your coverage map always matches reality.

Remote agent command dispatch

Operate protected hosts from the central console instead of touching each machine directly. Push an approved operational action out to a host (or a group of hosts) and see the result centrally, reducing the manual, per-machine toil of running a fleet.

Cross-device correlation

Fleet-wide correlation of security indicators. When the same suspicious pattern shows up across several hosts, Enterprise connects the dots into one picture — surfacing coordinated or repeated activity that is invisible when each machine is viewed in isolation.

Single sign-on (OIDC) & SCIM provisioning

Connect Belay to your existing identity provider. Staff sign in with your corporate SSO (OpenID Connect), and user accounts and group membership are provisioned and de-provisioned automatically through SCIM — so access follows your HR and IT lifecycle instead of being managed by hand.

Hosted / curated advisory feed

A managed vulnerability advisory feed, enriched with EPSS exploit-probability scoring and CISA KEV (Known Exploited Vulnerabilities) flags, delivered to your fleet. This helps your teams prioritize what actually matters — the vulnerabilities most likely to be exploited — rather than triaging a flat list. (The Community build ships a bundled per-ecosystem baseline DB; the curated feed is part of the Enterprise data plane.)

Audit push & central ingest

Protected hosts can forward their tamper-evident audit records to a central store, giving you one durable, queryable history of allow / ask / deny decisions across the fleet — for investigations, retention, and oversight.

Compliance reporting (planned)

The centralized audit history is designed to become the source for compliance evidence — reports that demonstrate your AI-agent controls and activity to auditors, customers, and internal risk teams, mapped to the same standards Belay already aligns to (OWASP Agentic (ASI) Top 10, OWASP LLM Top 10, MITRE ATLAS). This is on the Enterprise roadmap, not yet shipped; talk to us if report generation is a blocker for your evaluation.


How it fits with Community

Community (free)Enterprise (commercial)
Per-host protection & gating
Local audit & tamper-evidence
Static scanner (SARIF)
Firewall + bundled vuln DB✅ (bundled baseline)✅ (+ curated feed, EPSS/KEV)
Messaging approvals & AI explainer
Central multi-host console✅ Fleet management
Org accounts & roles✅ Organizations / multi-tenancy
Device enrollment✅ Device management
Remote command dispatch
Fleet-wide correlation✅ Cross-device correlation
SSO (OIDC) + SCIM
Central audit ingest✅ Audit push
Compliance reporting🔜 Planned

Enterprise never removes anything from Community — it adds a management, identity, and compliance layer around it. A full side-by-side comparison lives on the Community & Licensing page.


Get in touch

Ready to protect a fleet?

Tell us roughly how many hosts you run, which agents your teams use, and any compliance requirements you have, and we will help you scope it.