Pricing

Everything that stops the agent is free.

One paid option, and it buys an artefact rather than a subscription to your own tooling.

Free
$0
MIT, forever, no account
  • The whole policy engine, 45 rules armed by default
  • Day, session and total spend caps enforced at the tool boundary (pr guard budget 25)
  • The same policy in an interactive session, in claude -p and in CI
  • /guard-status, /guard-card and the local decision journal
  • Signed, hash-chained receipts (pr guard receipt)
  • pr spend, and pr reconcile against a provider invoice
  • Both open-source verifiers, offline or in the browser
  • One independent RFC 3161 timestamp, free, so you can see what an outside party's receipt looks like on your own run
  • Community support
Install the plugin

Nothing that refuses a tool call is behind a payment, and nothing is metered. The paid option adds an outside party's signature on the time. Your agent records stay on your own infrastructure either way, including when you pay. 14-day refund.

What changes when you pay

Almost nothing, and that is deliberate. The engine that refuses a tool call, the cap that stops the spend and the cryptography that makes a decision checkable are the same code whether or not you pay. What money buys is an outside party's signature on the time, because that is the one thing you cannot produce for yourself.

Scroll the table sideways if it does not fit.

CapabilityFreeAnchored statements
Guardrail rules at the tool boundaryYesYes
Spend cap that refuses the next tool callday, session or totalYesYes
The same policy in claude -p and CIYesYes
Signed, hash-chained decision receiptsYesYes
Both open-source verifiersYesYes
Reports and self-contained packs from the CLIYesYes
AI code attribution (pr attest)signed, local, free for goodYesYes
Anchoring the root of your chainto our service, or to a server you runOne, freeUnlimited
RFC 3161 timestamp from a public authorityOne, freeUnlimited
Public receipt page an outside party can openOne, freeUnlimited
Run the whole thing yourself insteadSelf-host the AGPL serverSelf-host the AGPL server

Pricing questions

Is anything metered?
No. There is no quota to run out of and no counter to watch. The policy engine runs on your machine, it makes no network call to decide anything, and the paid option is a flat monthly licence rather than usage.
Is the spend cap a paid feature?
No, and it never will be. Charging for the thing that stops a runaway bill would be a strange way to run this. pr guard budget 25 works on a free install with no account.
Does the free option expire?
No. It is MIT licensed source you already have. There is no trial clock and no card required.
Is the cryptography weaker without paying?
No. Hash-chain integrity, Ed25519 signatures and the open-source verifier are the same code either way. Paying adds RFC 3161 timestamps from an external time authority, which prevents back-dating; it does not make the chain itself any stronger.
Do you store my agent records?
No. Provenrail hosts identity and billing only. Agent records live in your own sink, on your own infrastructure. That is a deliberate design choice, and it is why the verifier runs entirely in your browser at provenrail.com/verify with no upload.
Can I self-host instead of paying?
Yes. The client, SDK, verifier and spec are MIT-licensed and the server is AGPL-3.0-or-later. Run the whole thing yourself at no cost. The paid option exists for external time and independent anchoring, not to unlock the core. There is no hosted tier to buy: you run the sink either way.
What is independent anchoring, and what leaves my machine?
Your records are hashed into a chain. Independent anchoring sends us the single root of that chain, 32 bytes, plus how many records it covers. Nothing else is sent, because the endpoint has no field anything else could arrive in. We timestamp that root, keep an append-only history of it, and publish it at a URL anyone can read without an account. Your client or auditor recomputes the root from the records you show them and checks it matches. If you later edit or delete a record, it stops matching, and neither you nor we can make it match again.
Why can I not just anchor my own chain?
You can, and the tooling is free. What you cannot do is be your own independent party. A timestamp you produced yourself proves the chain is internally consistent, not that it existed before the dispute. That is the only thing a paid plan sells that self-hosting cannot reproduce, which is also why the first one is free: you should see the difference on your own run rather than take this paragraph's word for it.
Is the hosted anchor service running today?
Yes. pr anchor-push bundle.json sends a 32-byte fingerprint of your records and nothing else, and returns a receipt carrying an RFC 3161 timestamp from a public authority. There is no signup step beyond buying it: the licence key you activated is the credential, and the command picks it up on its own. You keep every record; we never receive one, which is why this is the only part of Provenrail we can host. Every account gets one anchor free, so you can see the receipt before you decide.
Why is this the only thing you charge for?
Because it is the only thing that has to run on someone else's machine to mean anything. A timestamp you issue yourself proves your chain is internally consistent, not that it existed before the dispute. Everything else, the rules, the cap, the journal, the receipts, the verifiers, runs entirely on your box, so there is nothing to host and nothing to charge for.
What can you do with what I send you?
Almost nothing, by design. An anchor request carries a stream label, a 64-character fingerprint of your records, and how many records it covers. There is no field a record could arrive in. We cannot read your prompts, reconstruct your chain, or show anyone what your agents did, because we were never sent it. What we can do is refuse to sign a rewritten history: coverage of a stream only grows, and the same length cannot get two different fingerprints.
How do refunds work?
14 days, no questions. Billing runs through Polar as merchant of record, so cancellation and refunds are handled from the same portal you subscribed in.
Can I pay annually, or in euros?
Billing is monthly in US dollars today. If annual billing or another currency is a blocker for you, write to [email protected] and say so; that is the kind of request that decides what ships next.
← Back to home