Bindfort/Pricing

Published launch pricing

Know what your agents did. Prove it.

Policy enforcement on proxied MCP tool calls, plus tamper-evident evidence an authorized reviewer can verify locally.

Self-hosted-firstCustomer-controlled evidenceFull-path latency measured per deployment

Choose a launch package

Start with evidence. Add enforcement when agents enter the call path.

The Free scanner is downloadable now with no account. Paid gateway activation remains guided while self-serve checkout and general-availability packaging are completed.

Available now

Free

$0

For evaluating the installed dependency risk behind MCP servers.

  • Installed dependency-tree scanning, beyond declared manifests
  • Public OSV advisory matching
  • Local CLI workflow with no Bindfort account or API key
  • Table and JSON reports with configurable CI exit thresholds
  • Windows, macOS, and Linux downloads with published checksums
Download the CLI

Scanner-only public release. No account, API key, or sales conversation required.

Design-partner access

Business

$999/ month

For teams with a named audit or assurance obligation.

  • Everything in Team
  • Expanded MCP server scope agreed for the pilot
  • Guided self-hosted deployment
  • Customer-defined retention in operator-controlled storage
  • Review-ready evidence bundle workflow
  • Named technical contact and priority support
Apply for Business access

SSO/SAML and packaged SOC 2, ISO 27001, DORA, and NIS2 mappings remain roadmap items.

Scoped engagement

Enterprise

Custom

For deployment, residency, and procurement requirements outside the launch packages.

  • Everything in Business
  • Custom retention and data-residency design
  • DPA, security review, and procurement support
  • Deployment architecture and continuity planning
Contact

Air-gapped delivery and source escrow are not generally available and require separate written scoping.

Three places

We're taking three design partners.

The Business launch package is free for three months, with direct founder support and meaningful influence over the product.

In exchange, we ask for weekly written feedback, one reference call, and permission to use your logo only after you approve the exact use.

At the end of month three, continue on a paid plan only after written confirmation. There is no automatic charge without that confirmation.

Requirements: Agents running in a production environment, plus an audit obligation you can name — SOC 2, ISO 27001, DORA, or NIS2.

Apply as a design partner

FAQ

What the price includes—and what it does not.

Capability, availability, and roadmap claims are kept separate so an evaluation can start from evidence.

Read the public security posture →
What exactly gets recorded?

An executed call receipt records identifiers for the call, server, and tool; request and response hashes; a server fingerprint; a timestamp; and the fields required to verify its HMAC chain. Raw arguments are not stored in the receipt. A separate tamper-evident audit stream records policy decisions and operational context, including denied calls, with configured scrubbing applied to tool arguments.

How is tampering detected?

Each receipt-log record carries an HMAC over its contents and the previous record HMAC. The local verifier recomputes the chain and identifies the first record that fails verification. It runs in your environment and does not need to call Bindfort.

What is the performance cost?

Current public measurements cover individual policy-path microbenchmarks, including roughly 0.9 microseconds per dispatch operation in the published test setup. That is not an end-to-end gateway latency claim. Full-path allow and deny latency depends on transport, upstream server, policy, logging, and storage, so it is measured in each pilot environment.

Where does my evidence data go?

In a self-hosted evaluation, gateway receipts and audit evidence are written to storage the operator controls. Website inquiries and product-evaluation communications are handled separately under the Bindfort Privacy Policy. Do not send production secrets or customer data before a written agreement is in place.

Does this make us compliant?

No. Compliance is a program, not a product. Bindfort provides technical controls and evidence that may support security, audit, vendor-risk, and regulatory reviews; it does not by itself make a system compliant with SOC 2, ISO 27001, DORA, NIS2, the EU AI Act, or any other framework.

What if Bindfort goes away?

Self-hosted evidence remains in operator-controlled storage, and the current receipt fields and local verification workflow are documented. Continuity commitments beyond that are agreed in writing; source escrow is not included in the launch packages.

Can I switch tiers?

Yes, by written agreement during the guided-access phase. A tier change does not transfer ownership of existing customer-controlled evidence, and any change to retention or support terms is confirmed before it takes effect.

Can I buy through self-serve checkout today?

The Free scanner is available immediately without an account. Team card checkout is not live yet; paid gateway activation and payment terms are still confirmed directly. Business and Enterprise require written deployment scoping.

Claim boundary

Bindfort provides technical controls and evidence; it does not make a system compliant. Pricing and roadmap may change before general availability, but any paid engagement is governed by the written terms accepted for that engagement.