02

Billing model

Individual users can stay on Free forever. Paid evaluation starts as a 30-day trial that can be cancelled without leaving a paid card on file. Business and Enterprise billing is denominated in SAR, with a scaffold prepared for PayTabs, HyperPay, STC Pay, and mada. No live payment keys ship in code.

Free forever 30-day trial SAR No live keys
03

What drives your cost

Your cost comes from automatic privacy routing, the AI provider, token usage, and any agreed per-route minimum. You pay for the requests and tokens you actually use.

Factor
Detail
Privacy route

Tokenized external routing can be cheaper; Saudi region (me-central-1) routing may cost more

AI provider

Provider token rates vary by model — passed through, not marked up

Token usage

Input + output tokens consumed per request

Route base charge

Optional per-request minimum per route — set in the rate card, not a hidden fee

04

Packaging tiers

Use these tiers to route the purchase internally. The free individual tier remains free forever. Pilot evaluation can stay Free or negotiated flat fee. Typically 2–4 weeks. Paid organizations then convert to SAR Business or Enterprise billing.

Free

Individual

Free forever for individual users.

  • 100 /v1/detect calls/day per device key
  • 1 seat
  • 7-day retention flag; cleanup enforcement pending
  • Green-lane API exploration
Trial

30-day paid trial

30-day reversible paid-tier trial; no paid card is required to enroll or cancel.

  • Green-lane API key or browser-extension device JWT
  • Full trial feature flags; cleanup enforcement pending
  • 5 seats
  • Cancel without leaving a paid card on file
Business

Paid API

Pay-per-request in SAR with a tenant rate card and dashboard billing statements.

  • 365-day retention flag; cleanup enforcement pending
  • Up to 25 seats
  • Audit exports and billing statements
  • Saudi payment rails scaffold: PayTabs, HyperPay, STC Pay, and mada
Enterprise

Custom SAR contract

Negotiated rate card for enterprise procurement, customer-hosted paths, volume discounts, or additional diligence requirements.

  • 2555-day Article 17 retention target; enforcement pending
  • Custom branding and enterprise controls
  • Contractual SLA available in writing
  • Saudi deployment path agreed during diligence
05

Core platform controls

The commercial tier changes limits, retention, seats, audit exports, and support promises. The privacy gateway controls remain the same operating baseline.

  • Three-lane PII detection + routing (green / amber / red)
  • AES-256-GCM encrypted vault with per-tenant derived keys
  • Tier-aware retention flags: 7 days, full trial window, 365 days, or 2555 days; cleanup enforcement pending
  • Subject rights tooling is admin-authorized today; backend tier middleware remains pending
  • Multi-provider AI routing — Claude, GPT, Gemini, Llama, operator-configured Saudi region (me-central-1) paths
  • Customer dashboard with tier badges, usage metering, rate limiting, and billing visibility
06

On the commercial roadmap

Next investments on the commercial side — explicit and dated. None of these block a pilot today.

  • Contractual SLA (uptime guarantee)Not yet — pilot operates on best-effort basis.
  • SOC 2 report / ISO 27001 auditNot yet — internal controls are implemented, formal audit is planned.
  • Provider-level token streaming parity across every backendNot yet — API-level SSE streaming exists today, but backend depth still varies.
  • Dedicated support tiers (24/7, SLA-bound)Not yet — direct founder support during pilot.
  • Cross-cloud database replication and operator-directed failoverSaudi region (me-central-1) multi-region drill standby (GCP Dammam, me-central2) is provisioned and drill-rehearsed for DNS / GKE / TLS routing as of 2026-05-16; data-tier failover and full unplanned region tolerance remain operator-directed.
  • HSM / external key managementPartial roadmap item — KMS bootstrap exists, but steady-state external KMS/HSM custody is not yet the live claim.
07

Billing transparency

Live cost visibility, not month-end surprises. Every billable event is itemized in the dashboard the moment it happens. Payment-provider code is scaffold-only until pilot customer keys, signing, callbacks, and PCI scope are reviewed.

  • Overviewtoday's and this month's billable amount, updated in real time.
  • Historyper-request cost breakdown with lane, provider, and token counts.
  • Billingdownloadable monthly statements ready for procurement and finance.
  • Payment railsPayTabs, HyperPay, STC Pay, and mada are abstracted behind a BillingProvider scaffold; no live keys are committed.
  • Settingsrole-scoped controls — only super_admins can change rate-card settings.

See it work on your data.

Evaluate →