Governance that scales with your AI stack.
Transparent packaging. No per-seat tax. One integration point.
Pricing tiers
Team
$15/user/mo
$12/user/mo billed annually
Startup or single department. ~10 users. 250K requests/mo + consumption overage.
- 250K req/mo + overage
- 9 providers + BYOE
- DLP: Regex + secret detection
- SSO (SAML 2.0)
- Logs: 30 days
- SLA available under Enterprise MSA
- Support: Email
SMB
Contact Sales
Up to 500 users · billed per user
Small mid-market. 2M requests/mo. AppGuard available as add-on.
- 2M req/mo
- 9 providers + BYOE
- Full 3-tier DLP pipeline with AI entity recognition
- Response inspection & filtering
- Compare & Summarize modes
- Multimodal
- Budget caps & quotas
- Webhooks
- SCIM 2.0 provisioning
- WebAuthn / FIDO2
- MCP Server
- Config versioning & rollback
- Logs: 90 days
- Email & phone support (9×5)
Enterprise
Contact Sales
Annual platform fee · 5,000+ users
For organizations where AI is embedded across business operations at scale. Unlimited requests + overage. AppGuard bundled.
- Unlimited req/mo
- Custom provider config
- Full 3-tier DLP pipeline + custom tuning
- All SMB features
- Hybrid Outpost deployment
- SCIM 2.0
- WebAuthn/FIDO2
- BYOK Encryption
- Compliance reporting
- Air-gap Outpost
- MCP Server
- Custom contracts & MSA
- Logs: 1 year+
- SLA available under Enterprise MSA
- Dedicated CSM
Build with Arbitex
Developer tiers include every platform feature — volume-gated, not feature-gated. Start free at 2,500 requests/month or go to Dev Pro at $49/month flat.
Dev Free
$0
Individual developer or evaluation. All features unlocked — volume-gated, not feature-gated.
- 2,500 req/month (hard cap)
- 9 providers + BYOE
- DLP: Regex + secret detection
- Logs: 7 days
- Community support
Dev Pro
$49/month
Solo builders and small projects shipping to production. All features unlocked — volume-gated, not feature-gated.
- 5,000 req/month + consumption overage
- Full 3-tier DLP pipeline with AI entity recognition
- Response inspection & filtering
- Compare & Summarize routing modes
- Logs: 30 days
- Email support
Go deeper on credential risk.
Credential Intelligence adds breach-dataset detection to the Protection stage — available as an add-on to SMB and Enterprise plans.
CredInt Standard
Know when a credential in your AI traffic has appeared in real-world compromises — checked against a curated breach dataset, refreshed monthly.
- Hash-based comparison against a curated breach dataset
- Frequency-weighted risk buckets: Critical, High, Medium, Low
Contact for pricing
CredInt Enterprise
The Standard dataset, plus live enrichment against current breach intelligence feeds — so your risk signal stays current as new breaches emerge.
- Dataset updated in real time as new breach data is ingested
- Live enrichment against current breach intelligence feeds
Contact for pricing
Full feature comparison
Core Gateway
| Feature | Team | SMB | Enterprise |
|---|---|---|---|
| Requests per month | 250K + overage | 2M (hard cap) | Unlimited + overage |
| LLM providers | 9 | 9 + BYOE | 9 + BYOE |
| Routing modes | Single | Single, Compare, Summarize | Single, Compare, Summarize |
| Real-time SSE streaming | ✓ | ✓ | ✓ |
| Multimodal | — | ✓ | ✓ |
| Budget caps & usage quotas | — | ✓ | ✓ |
| Cost anomaly detection | — | ✓ | ✓ |
| Webhook event system | — | ✓ | ✓ |
| Automatic health monitoring & failover | ✓ | ✓ | ✓ |
| Rate limiting | ✓ | ✓ | ✓ |
| Arbitex AppGuard | Add-on | Add-on | ✓ Included |
| SLA | Custom SLA | Custom SLA | Custom SLA |
DLP & Security
| Feature | Team | SMB | Enterprise |
|---|---|---|---|
| PII detection | ✓ | ✓ | ✓ |
| Secret detection (39 patterns) | ✓ | ✓ | ✓ |
| AI entity recognition | — | ✓ | ✓ |
| Compliance bundles | — | ✓ | ✓ |
| Custom model tuning | — | — | ✓ |
| Request blocking & redaction | ✓ | ✓ | ✓ |
| Response inspection | — | ✓ | ✓ |
| Response filtering | — | ✓ | ✓ |
| Audit anomaly detection | — | ✓ | ✓ |
| DLP trend analytics | — | ✓ | ✓ |
Compliance
| Feature | Team | SMB | Enterprise |
|---|---|---|---|
| Immutable, tamper-proof audit logs | ✓ | ✓ | ✓ |
| Audit log retention | 30 days | 90 days | 1 year+ |
| SOC 2 compliance reports | ✓ | ✓ | ✓ |
| Compliance frameworks | Core | Full (8) | Full + custom |
| Compliance exports | — | ✓ | ✓ |
| Compliance reporting | — | — | ✓ |
| Custom data residency | — | — | ✓ |
Deployment
| Feature | Team | SMB | Enterprise |
|---|---|---|---|
| SaaS (Arbitex-managed) | ✓ | ✓ | ✓ |
| Hybrid Outpost (customer-managed data plane) | — | — | ✓ |
| Air-gap Outpost | — | — | ✓ |
| SSO (SAML 2.0) | ✓ | ✓ | ✓ |
| SCIM 2.0 provisioning | — | ✓ | ✓ |
| WebAuthn / FIDO2 | — | ✓ | ✓ |
| BYOK Encryption | — | — | ✓ |
| MCP Server | — | ✓ | ✓ |
| Config versioning & rollback | — | ✓ | ✓ |
| Custom contracts & MSA | — | — | ✓ |
| SLA guarantees (written) | — | — | ✓ |
Support
| Feature | Team | SMB | Enterprise |
|---|---|---|---|
| Support channel | Email & phone (9×5) | Email & phone (24×7) + CSM | |
| Response time | 48h | 4h | 1h |
| Onboarding assistance | — | ✓ | White-glove |
| Security review support | — | — | ✓ |
| Custom training | — | — | ✓ |
Observability
| Feature | Team | SMB | Enterprise |
|---|---|---|---|
| OpenTelemetry SDK | — | ✓ | ✓ |
| Grafana dashboards | — | ✓ | ✓ |
| SIEM connectors | — | 3 available | 7 + custom |
| Alert rules | — | ✓ | ✓ |
| Usage analytics | ✓ | ✓ | ✓ |
| Cost analytics | — | ✓ | ✓ |
Common questions
How does per-user pricing work for Team and SMB plans?
Team and SMB plans are priced per seat per month, billed to the number of users provisioned in your Arbitex tenant. Volume discounts apply automatically — no manual negotiation required. Annual billing reduces the per-user rate. Enterprise uses a flat platform fee negotiated annually.
How does request-based pricing work?
A request is one API call from your application to an AI provider, routed through Arbitex. Arbitex inspects the request and response, applies your policies, and logs the interaction. Each inbound call counts as one request — the number of tokens or which model you route to does not affect your request count.
Can I self-host Arbitex?
All plans include SaaS deployment hosted and managed by Arbitex. Enterprise plans add Hybrid Outpost: the data plane (local AI proxy) runs in your VPC or on-premises infrastructure, while the Arbitex-hosted control plane handles configuration and policy management. Outpost proxies continue routing traffic independently if the control plane is temporarily unavailable, though most configuration changes require control plane connectivity. There is no fully self-hosted option.
What counts as a request?
One request equals one inbound API call to the Arbitex gateway. Streaming responses count as one request regardless of chunk count. Retries due to gateway-side errors do not count against your quota.
How do I evaluate Arbitex before committing?
We offer structured proof-of-concept engagements for all plans. Contact sales to scope a POC for your environment.
How do I migrate from Portkey or LiteLLM?
Arbitex uses an OpenAI-compatible API surface. Migration is a one-line base URL change. Most teams are fully migrated in under a day.
What compliance frameworks does Arbitex support?
Arbitex includes compliance bundles mapped to twelve regulatory frameworks: PCI-DSS, HIPAA, GDPR, GLBA, SOX, CCPA, BSA/AML, SEC Reg FD, FERPA, the EU AI Act, NIST AI RMF, and ISO/IEC 42001. Each bundle activates the correct DLP detectors and enforcement actions for the data types each regulation covers.
How does provider billing work? Do I pay Arbitex for API tokens?
Provider API keys: Arbitex routes your requests using your own provider API keys (BYOK — bring your own key). Your provider billing stays separate from your Arbitex subscription; Arbitex never touches your provider invoices. Hybrid Outpost is BYOK only.
How long does implementation take?
Most teams complete integration in under a day. Arbitex uses an OpenAI-compatible API — migration is a one-line base URL change. Enterprise Outpost deployments typically complete within a week with dedicated CSM support.
Does Arbitex store my prompts or AI responses?
Arbitex inspects requests and responses in real time but does not persist prompt or completion content beyond the configured audit log retention window. Hybrid Outpost customers can ensure all AI traffic stays within their own infrastructure.
Can I use my own encryption keys?
Enterprise plans support BYOK (Bring Your Own Key) encryption. All plans use AES encryption at rest by default, with key rotation managed through the admin portal.
What happens if I exceed my request quota?
Arbitex sends warnings at 80% and 95% utilization. At the hard limit, new requests receive a 429 status code. Existing in-flight requests complete normally. Contact sales to adjust your plan limits at any time.
Built for regulated industries.
Hybrid Outpost deployment. BYOK encryption. Custom compliance bundles. Air-gap support. Dedicated CSM. If your organization needs control over where AI data flows, let's talk.
Start governing your AI stack.
See how Arbitex governs your AI stack.