Skip to main content

PRICING

Free and open source. Enterprise when you need scale.

The community build is complete and free forever under AGPL-3.0. Enterprise adds fleet-scale management and governance under a commercial license.

COMMUNITY

$0 / free forever

Open source · AGPL-3.0-or-later

  • Runtime gating at the tool-call boundary (Claude Code / Codex hooks, hook & gate)
  • MCP stdio proxy — gate every tools/call, fail-closed
  • Deterministic rule catalog (secrets, egress, destructive, RCE, supply-chain, and more)
  • Human-in-the-loop Allow / Deny, with timeout = deny
  • Static pre-install scanner with SARIF 2.1.0 output — covers packages and agent skills
  • Local backend (serve) + the Tauri desktop app UI
  • Hash-chained audit log, signed evidence packs, honeypot canaries
  • Native Rust firewall + bundled vulnerability DB with CISA KEV badges + EPSS scoring (no external tools, no NVD key)
  • Optional egress destination enrichment (reverse-DNS, ASN, owner, country — display-only)
  • Explain & Advise — curated per-rule explanations + optional BYOK AI explainer (advisory only, off by default)
  • Two-way approvals over chat (Telegram, Discord, WhatsApp, Matrix, Mattermost, Slack) + notify-only ntfy/Teams/WeCom/webhook
  • Standards alignment: OWASP ASI/LLM Top 10, MITRE ATLAS
Get started

ENTERPRISE

Talk to us

Commercial license · for teams and fleets

  • Fleet management (multi-host central console)
  • Organizations / multi-tenancy (org accounts, org-scoped login & roles)
  • Device management & enrollment
  • Remote agent command dispatch
  • Cross-device correlation (fleet-wide indicator correlation)
  • SSO (OIDC) and SCIM provisioning
  • Hosted / curated advisory feed (managed vuln DB with EPSS + CISA-KEV enrichment) — the open build shows KEV/EPSS badges from the bundled DB; Enterprise adds the managed, continuously-updated feed
  • Audit push / central ingest
  • Compliance reporting
Contact sales

Enterprise is contract-based, scoped to your fleet. Email hello@secblok.io and we will work out the right plan with you.

Belay is open-core: the community build is AGPL-3.0-or-later; a separate commercial license is available for AGPL-incompatible use and the enterprise components. See Community & Licensing.