How we charge
Hourly to get you live. Flat monthly to keep you running.
Pricing and service levels are scoped directly to your deployment, operating requirements, support window, and recovery objectives. We quote against the structure below and finalize everything in a written statement of work and service agreement.
Phase one
Setup
Time and materials with an estimate and a not-to-exceed cap agreed up front.
- Environment scoping and sizing
- Deployment from a published, integrity-verified release
- Domain, TLS, and first-run configuration
- TCB Fingerprint verification of the running Core Loop
- Policy and agent setup tailored to your requirements
- Support for your internal security review and access provisioning
Phase two
Run
A predictable flat monthly fee with SLA tiers for teams and enterprises.
- Updates on the release cadence and security hotfixes
- System monitoring and alerting
- Automated backups configured in your own storage
- Tested restores executed on an agreed schedule
- Severity-based incident response
- Recurring integrity attestation reports
- Resource tuning and log rotation
Always
Bring your own keys
Your model spend never touches our invoice.
- You pay your AI provider directly for tokens
- We never front, mark up, or pool your model spend
- You pay your hosting provider for the machine at cost
- You own and rotate the API keys
Why setup is hourly rather than fixed. Installing SAFi is quick. Getting your organization live involves your security review, access provisioning, environment setup, and policy design. Those processes move at your pace. Billing the setup phase hourly against a capped estimate is the honest way to price work whose duration you control. Once you are live in production, the monthly fee is flat and predictable.
SLA outline: Team and Enterprise
A starting template, finalized with you
This outlines the baseline service agreement. We define specific targets, maintenance windows, and recovery objectives in writing during scoping.
Availability
A monthly uptime target measured on the SAFi service, excluding your hosting provider's outages and our mutually agreed maintenance windows.
Response times
Severity-based routing. A service-down incident triggers immediate acknowledgement and continuous work to restore. Lower severities receive next-business-day handling.
Backups and recovery
Automated backups configured in customer-controlled storage according to an agreed retention period. Restore procedures are tested on a set schedule to validate the recovery objectives defined in the service agreement.
Updates and security
Feature releases deployed on the SAFi cadence with your sign-off on the change window. Security hotfixes are applied promptly upon release.
Integrity attestation
Regular reports proving the running Core Loop matches a published SAFi release by its TCB Fingerprint. Your administrators can review the release and verify the deployment independently.
Data and exit
Your data stays on your machine and is never used for training. On exit, you keep the infrastructure, the keys, and the data following a clean handover protocol.
Scoping
What moves the number
Identical deployments rarely cost the same to operate. We evaluate these specific factors with your team before providing a quote.
- Deployment path. Docker or bare-metal, and the required operating standards.
- Expected load. The number of users and governed turns, and how the machine scales to handle them.
- Support window. Business hours versus extended coverage, and strict severity definitions.
- Recovery objectives. The data loss and downtime thresholds the agreement must guarantee against.
- Policy design. The level of assistance required to author your initial charter and agent policies.
- Tooling. The complexity and number of MCP tool servers and external endpoints the agents require.
- Access controls. Standard admin access versus bastion access with full session logging.
- Handover ambition. The training schedule required to transition operations to your internal IT team.
Outside the fee
What the monthly fee does not cover
- Model tokens. Billed directly to you by your AI provider.
- The machine. Paid to your hosting provider at cost.
- Custom engineering. Operating stock SAFi is the service. Bespoke plugins or feature development require a separate engagement.
- Your compliance decisions. SAFi produces the evidence. Deciding corporate policies and interpreting audit trails remains your responsibility.
- End-user support. We keep the engine running. Supporting your internal staff remains with your IT help desk.
Get a quote scoped to your size and requirements
Tell us about your environment and expected usage. We will deliver an estimate, a not-to-exceed cap for setup, and a fixed monthly figure for operations.