Pricing

Three arrangements. They differ in who holds your receipt keys and who checks you.

The scan is free. You choose the arrangement and the package in a sign-off review: a 30-minute call where we walk through your scan, and you leave with a memo your security owner can sign.

Available now

Standard

“Do you check yourself?”

Who it is for: Teams putting their first AI agents into production, who check their own controls.

  • Hosted ZIFFER, admin & approval consolesZIFFER runs it for you. The consoles are the screens where you set rules and approve actions.
  • Signed receipts, per-tenant signing keyYour receipts are signed with a key used for your company alone.
  • Hosted external anchoring, auditor CLIReceipts are also published where a party other than ZIFFER can read them, and your auditor checks them with a command-line tool.
  • MCP / SDK / HTTPS integrationThese are the ways your agent’s code connects to ZIFFER.
  • Onboarding starts within 48 hours
Book a 30-min sign-off review →
On request

Assured

“Does someone independent check you?”

Who it is for: Companies whose auditors or enterprise customers want proof checked by someone other than the vendor, with the signing keys in their own cloud so ZIFFER cannot forge a receipt.

  • Verification runs outside production, by a party with no production credentialThe check is done by someone who cannot touch your live systems.
  • Receipt keys in your cloud account: we cannot forge your receipts, and you can revoke us
  • Every signature lands in your audit trail
Book a 30-min sign-off review
On request

Regulated

“Does a regulator dictate how your keys are held?”

Who it is for: Banks, payment and health companies whose regulator dictates how signing keys are held.

  • Mandated custody arrangementsThe key is kept the way your regulator requires.
  • HSM-held keys under external mandateAn HSM is a hardware key vault.
  • For deployments where the key mechanism is prescribed
Book a 30-min sign-off review

Who keeps the key that signs your receipts

Every action ZIFFER approves gets a signed receipt, a proof you can show an auditor. Whoever holds the signing key could, in principle, sign a false one.

How it is priced

Priced by the number of tools you protect: packages of 25, 100 or 250 tools, custom above. No charge per call. Invoiced, no card needed.

25 tools100 tools250 toolscustom

A tool is one thing your agent can do in your systems, such as issue a refund or restart a server. The tool count is the one your scan reports. The price is set in the review call.

Pricing

Three arrangements. They differ in who holds your receipt keys and who checks you.

The scan is free. You choose the arrangement and the package in a sign-off review: a 30-minute call where we walk through your scan, and you leave with a memo your security owner can sign.

Available now

Standard

“Do you check yourself?”

Who it is for: Teams putting their first AI agents into production, who check their own controls.

  • Hosted ZIFFER, admin & approval consolesZIFFER runs it for you. The consoles are the screens where you set rules and approve actions.
  • Signed receipts, per-tenant signing keyYour receipts are signed with a key used for your company alone.
  • Hosted external anchoring, auditor CLIReceipts are also published where a party other than ZIFFER can read them, and your auditor checks them with a command-line tool.
  • MCP / SDK / HTTPS integrationThese are the ways your agent’s code connects to ZIFFER.
  • Onboarding starts within 48 hours
Book a 30-min sign-off review →
On request

Assured

“Does someone independent check you?”

Who it is for: Companies whose auditors or enterprise customers want proof checked by someone other than the vendor, with the signing keys in their own cloud so ZIFFER cannot forge a receipt.

  • Verification runs outside production, by a party with no production credentialThe check is done by someone who cannot touch your live systems.
  • Receipt keys in your cloud account: we cannot forge your receipts, and you can revoke us
  • Every signature lands in your audit trail
Book a 30-min sign-off review
On request

Regulated

“Does a regulator dictate how your keys are held?”

Who it is for: Banks, payment and health companies whose regulator dictates how signing keys are held.

  • Mandated custody arrangementsThe key is kept the way your regulator requires.
  • HSM-held keys under external mandateAn HSM is a hardware key vault.
  • For deployments where the key mechanism is prescribed
Book a 30-min sign-off review

Who keeps the key that signs your receipts

Every action ZIFFER approves gets a signed receipt, a proof you can show an auditor. Whoever holds the signing key could, in principle, sign a false one.

How it is priced

Priced by the number of tools you protect: packages of 25, 100 or 250 tools, custom above. No charge per call. Invoiced, no card needed.

25 tools100 tools250 toolscustom

A tool is one thing your agent can do in your systems, such as issue a refund or restart a server. The tool count is the one your scan reports. The price is set in the review call.

Before your review, run the scan

Finds the tools your code gives an AI model, and the ones that cannot be undone. It writes a report. Run it in the repository where your agent’s tools are built. You need no account, and nothing is sent anywhere. Its result is what the review walks through.

npx @ziffer-io/scan --code --report

Pricing questions

What does the scan cost?

Nothing. The number of tools it finds is the number your package is sized on.

Is there a free trial?

No. The scan is the free part, and you run it before you pay for anything.

What changes between the arrangements?

Who keeps the key that signs your receipts, as drawn under the cards.

Before your review, run the scan

Finds the tools your code gives an AI model, and the ones that cannot be undone. It writes a report. Run it in the repository where your agent’s tools are built. You need no account, and nothing is sent anywhere. Its result is what the review walks through.

npx @ziffer-io/scan --code --report

Pricing questions

What does the scan cost?

Nothing. The number of tools it finds is the number your package is sized on.

Is there a free trial?

No. The scan is the free part, and you run it before you pay for anything.

What changes between the arrangements?

Who keeps the key that signs your receipts, as drawn under the cards.