Pricing
Start free. Prove trust. Scale when ready.
Every plan runs the VOUCH loop. You pay as your fleet grows — not for seats, not for shelfware.
Free
No card required
- ✓SAUTERA™ Witness + read-only trust scores
- ✓Up to 10 devices, free for 30 days from your first device
- ✓BEACON triage board
- ✓30-day retention
- ✓Community support
Pro
/ year · first 50 devices included
- ✓Everything in Free — live, not read-only
- ✓Device trust + posture
- ✓Closed-loop remediation (human-approved)
- ✓Standard compliance reports
- ✓90-day retention · shared infrastructure
- ✓$120 / device / yr above 50
Enterprise
ACV · contact sales
- ✓Everything in Pro, plus:
- ✓Zero Trust identity integration (combined trust decision)
- ✓SSO / SCIM · API + RBAC
- ✓Custom frameworks — SOC 2 / ISO / HIPAA
- ✓Multi-framework compliance evidence
- ✓Read-replica isolation · contractual SLA
- ✓365-day retention + cold archive
- ✓Dedicated namespace · dedicated CSM
- ✓$150 / device / yr above 250
Pro is $5,000/yr with the first 50 devices included — then a flat $120/device/yr above 50, with no hard cap. So 50 devices is $5,000 and 100 is $11,000. Free covers up to 10 devices for 30 days from your first connected device. Enterprise starts at $100K ACV (250 devices included, then $150/device) — contact sales.
Not sure which tier fits your estate? Book a 30-minute meeting and we’ll size it with you.
Plan catalog synced from the SAUTERA platform · 2026-07-01
Federal & Sovereign
Contact salesOne tier with ascending, per-contract levels — scoped and priced per contract. Base Sovereign is a dedicated single-tenant, region-pinned stack with air-gap / GovCloud, a dedicated CSM/TAM, and the longest retention with full archive. Accreditation stacks on top:
Base Sovereign
Dedicated single-tenant · region-pinned · air-gap / GovCloud · CSM/TAM
+ FedRAMP / ATO
Authorization boundary + continuous monitoring
+ IL4 / IL5 / DoD
Federal / DoD accreditation, scoped per contract
What changes by tier
The loop is the same. The reach grows.
| Free | Pro | Enterprise | |
|---|---|---|---|
| Price | $0 | $5,000/yr | From $100K ACV |
| Devices included | 10 | 50 | 250 |
| Per-device beyond | — hard cap | $120/device/yr | $150/device/yr |
| Data retention | 30-day | 90-day | 365-day + cold archive |
| SAUTERA Witness + trust scores | Read-only | ✓ | ✓ |
| Device trust + posture | — | ✓ | ✓ |
| Closed-loop remediation (human-approved) | — | ✓ | ✓ |
| Zero Trust identity integration (combined trust decision) | — | Add-on | ✓ |
| Compliance reporting | — | Standard | Multi-framework |
| Custom frameworks (SOC 2 / ISO / HIPAA) | — | — | ✓ |
| SSO / SCIM | — | — | ✓ |
| API + RBAC | — | — | ✓ |
| Read-replica isolation | — | — | ✓ |
| SLA | — | — | Contractual |
| Support | Community | Standard | Dedicated CSM |
| Isolation | Shared | Shared | Dedicated namespace |
Federal & Sovereign includes everything in Enterprise plus dedicated single-tenant, region-pinning, air-gap / GovCloud, and FedRAMP / IL4 / IL5 / DoD — see the callout above.
On remediation
SAUTERA surfaces recommended fixes and applies them only on human approval — closed-loop remediation, human-approved — on Pro and above, including OS patching, service, and configuration changes applied by the opt-in SAUTERA Witness sensor. A no-human remediation path is excluded by the architecture, not switched off pending confidence — a platform that adjudicates trust should not be able to make an irreversible change to your production estate on its own.
On Zero Trust
Zero Trust integration joins your IdP’s verified identity with SAUTERA’s infrastructure-trust verdict into one auditable ALLOW / DEGRADE / DENY decision — through Okta, Microsoft Entra ID, or a generic access-decision API for any other identity provider. Every decision carries a signed, verifiable attestation and is logged as SOC 2 (CC6.1) / NIST (PR.AA) / FedRAMP (AC-3 / AC-4) evidence.
By design, identity authority stays with your IdP — SAUTERA never overrides a deny — and enforcement stays at your existing PEP: SAUTERA informs the decision, it doesn’t replace your tooling. Okta and Microsoft Entra ID are both supported today. Standard on Enterprise and Sovereign; available to Pro as an add-on.
Add-ons
À la carte, on top of your base tier
Add-ons attach to a base subscription as separate line items or per-tenant overrides. “Contact” means negotiated per deal.
| Add-on | Applies to | Price basis |
|---|---|---|
| Dedicated-infra / single-tenant isolation uplift | Enterprise | Contact — guide ≈ +$24K/yr |
| FedRAMP / ATO package | Sovereign | Contact — anchors ~$1M+ |
| IL4 / IL5 / DoD accreditation | Sovereign | Contact — anchors ~$5M+ |
| Air-gap / GovCloud deployment | Sovereign | Contact |
| Zero Trust identity integration | Pro | Contact — quote per deal |
| Additional compliance frameworks | Pro / Ent / Sov | Per framework (contact) |
| Extended retention / long-term cold archive | Ent / Sov | Contact — usage-based |
| Device packs / overage | All paid tiers | Tier rate — $120 / $150 / $175 |
| Premium SLA (uptime + response) | Ent / Sov | Contact — base uplift |
| Dedicated TAM | Ent / Sov | Contact — annual |
| White-glove onboarding / professional services | Ent / Sov | Contact — one-time |
| Extra environments (staging / DR / sandbox) | Ent / Sov | Contact — per environment |
| Extra CSM hours | Ent / Sov | Contact — hourly block |
Questions
Pricing, answered plainly
Is the Free plan really free?
Yes — up to 10 devices, read-only: SAUTERA Witness, trust scores, and the BEACON triage board, at no cost and no card. It runs for 30 days, and the clock starts when you connect your first device, not when you sign up — so you can take as long as you need to get set up. When the 30 days are up your devices stop being assessed, but nothing is deleted: your assessment history, trust scores and evidence stay readable. Free doesn't include remediation, compliance export, or certification — those start at Pro.
What does Pro's $5,000/yr cover?
The first 50 devices are included in the $5,000 annual base — so any fleet up to 50 devices is a flat $5,000/yr. Past 50, each additional device is a flat $120/year. A 100-device fleet, for example, is $5,000 + 50 × $120 = $11,000/yr.
Do you actually fix things, or just alert?
Pro and above include closed-loop remediation, human-approved: SAUTERA recommends the fix and applies it — OS patching, service, and configuration changes via the opt-in SAUTERA Witness sensor — only after a human approves. A no-human remediation path is excluded by the architecture, not switched off pending confidence — it is not on the roadmap, and we would encourage you to ask any vendor who is proud that no human is involved what happens when it is wrong at 3am.
What's the difference for Enterprise?
Enterprise starts at $100K ACV (contact sales): 250 devices included then $150/device, plus Zero Trust identity integration, SSO/SCIM, API + RBAC, custom frameworks (SOC 2 / ISO / HIPAA), multi-framework evidence, read-replica isolation, a contractual SLA, a dedicated namespace, 365-day retention with cold archive, and a dedicated CSM.
How does Zero Trust work with SAUTERA?
Zero Trust integration joins your identity provider's verified identity with SAUTERA's infrastructure-trust verdict into one auditable ALLOW / DEGRADE / DENY decision on each access request. Wire it through Okta, through Microsoft Entra ID, or through the generic access-decision API for any other identity provider; every decision carries a signed, verifiable attestation and is logged as SOC 2 (CC6.1) / NIST (PR.AA) / FedRAMP (AC-3 / AC-4) evidence. Two deliberate boundaries: your IdP stays the authority on identity — SAUTERA never overrides a deny — and enforcement stays at your existing PEP, so SAUTERA informs the decision without replacing your tooling. Okta and Microsoft Entra ID are both supported today. Standard on Enterprise and Sovereign; a Pro add-on (contact us for a quote).
What is Federal & Sovereign for?
Federal and MILDEP estates that need a dedicated single-tenant, region-pinned stack with air-gap / GovCloud and FedRAMP / IL4 / IL5 / DoD accreditation. It's one tier with ascending levels — base, +FedRAMP / ATO, then +IL4 / IL5 / DoD — scoped and priced per contract. Contact sales for a quote against your authorization boundary.
Can I add capabilities without changing tier?
Yes — the add-on catalog above attaches to your base subscription as separate line items or per-tenant overrides: dedicated infrastructure, extra frameworks, extended retention, premium SLA, a dedicated TAM, extra environments, and more.
Not sure what you would even be buying yet?
The Zero Trust Completeness Audit is a fixed-price, expert-led assessment from $2,500 that tells you where you actually stand — no deployment required. The whole fee credits against a subscription if you sign one within 90 days.
Still deciding which tier fits?