Per runner, not per seat.
At this price, one prevented 2 a.m. rollback pays for the year. See what that looks like.
Free
For evaluation and solo use.
$0 / forever
Start free- 3 runners
- 1 user
- 7-day audit retention
- All policy features
Team
For production teams.
$20 / runner / mo
Continue with Team- Up to 100 runners
- Unlimited users
- Single sign-on (OIDC)
- 90-day audit retention
- Audit export (CSV + SIEM)
- Email support
- 99.95% uptime target
- Automated invoices
Enterprise
For design partners and regulated teams.
Custom
Talk to sales- Unlimited runners and users
- Everything in Team
- SCIM directory sync
- 365-day audit retention
- Security and procurement review
- Slack and email support
- Design-partner deployment planning
- Rollout support
- 99.99% uptime SLA
- Custom commercial terms
Up and running in minutes
From sign-up to your first audited action
Create an account
Free, no credit card. You're in the console in under a minute.
Install a runner
One command on a Linux or macOS host — the console hands you the install one-liner and watches it connect.
Run an action
Dispatch from the console, or point Claude, ChatGPT, or Cursor at your account's MCP endpoint — and let policy decide.
Compare plans
| Feature | Free | Team | Enterprise |
|---|---|---|---|
| Runners | 3 | 100 | Unlimited |
| Users | 1 | Unlimited | Unlimited |
| Audit retention | 7 days | 90 days | 365 days |
| Policy + approvals | |||
| MCP server | |||
| Pack trust + drift blocking | |||
| SIEM export | — | ||
| Single sign-on (OIDC) | — | ||
| SCIM directory sync | — | — | |
| Uptime | — | 99.95% target | 99.99% SLA |
| Deployment planning | — | — | Design-partner deployment planning |
| Support | — | Email support | Slack and email support |
Frequently asked questions
What counts as a "runner"?
One installation of the emisar binary on one host — VM, container, or bare metal. Run as many runners as your plan allows. Human users are unlimited on Team and Enterprise.
Do you store the output of my commands?
Runner output is redacted before leaving the host and retained in run history. The audit trail stores terminal outcome metadata, including who, when, action, runner, reason, and exit code. Redaction uses 20 built-in patterns plus your own per-action rules.
How does billing work?
Paid plans are billed per runner through Paddle, our Merchant of Record. You get an invoice for each billing period, and Paddle handles sales tax and VAT. We never see or store full card numbers.
Can I self-host?
The current product uses the hosted emisar control plane. The runner, MCP bridge, and packs are Apache-2.0 open source, and the repository includes deployable control-plane code (Business Source License) for evaluation — but supported self-hosted and air-gapped deployments are not generally available today. Tell us if that boundary is a requirement.
Can I cancel any time?
Yes. Cancel from billing settings to stop renewal in Paddle. Paid features and limits remain available until the scheduled end of the billing period, then the account moves to Free limits.
Do you support SSO and SCIM?
Yes. OIDC single sign-on (Okta, Entra ID, JumpCloud, Google Workspace, Keycloak, or any compliant provider) is on Team and Enterprise. Automatic offboarding needs SCIM 2.0 directory sync, which is Enterprise: deactivate someone in your IdP and emisar ends their sessions and revokes their keys without anyone touching the console. With OIDC alone they can't sign in again, but a live session or an existing API key keeps working until you suspend them here.
Do you offer startup discounts?
Yes. Email sales@emisar.dev with your YC or pre-seed letter and we'll take it from there.
More on how we handle data, secrets, and audit on the security page, and how billing and cancellations work in our refund policy.