Enterprise

Organizations, roles, audit logs, and spend limits

The controls available today, each labeled live, in progress, or roadmap.

What teams get today

  • Orgs with owner / admin / member / viewer roles
  • Email invites with expiring tokens, audit-logged
  • Per-user spend limits and analytics opt-out
  • API keys stored hashed, rotatable from /api-keys
  • Shared org agent feed: every run across the team
Open settings

capabilities

Feature status

Live means it works now. Roadmap means we are building it, and we will scope timelines with you.

live

Organizations, roles, and RBAC

Owner, admin, member, and viewer roles per organization. Invite by email, change roles, remove members; every change lands in the audit log.

live

Audit logs

Settings changes, invites, role changes, and membership removals are recorded per user and per org, queryable from the API and settings.

live

Spend limits

Per-user spend limits are live in settings. Per-workspace limits, capping every member under one budget, are roadmap.

live

API key management

Scoped, rotatable keys, plus bring-your-own provider keys for the gateway. Keys are stored hashed; plaintext is shown once.

roadmap

SSO / SAML + SCIM

Google and GitHub sign-in are live. SAML SSO and SCIM directory sync are roadmap for the contact-sales tier. Talk to us if this is a blocker.

roadmap

Private networking

Dedicated network segments and private egress between your apps, addons, and agents. Roadmap; today each container is isolated with scoped credentials.

roadmap

Data residency

A default GPU region (US or EU) is selectable in settings. Hard residency guarantees that pin data and inference to a jurisdiction are roadmap.

on request

BAA / DPA

A standard DPA is available on request. Healthcare BAAs are handled case by case on the contact-sales tier.

compliance posture

Compliance status

ItemStatusDetail
SOC 2 Type IIin progressControls are being implemented and evidence collected; no report yet. We will not claim certification before it exists.
Data processing agreement (DPA)on requestStandard DPA covering GDPR processor obligations, available for any paid plan via [email protected].
Data export and deletionliveExport or delete your account from settings; both are audit-logged.
Subprocessor listlivePublished on the security page, kept current as infrastructure changes.

Security questionnaires, DPAs, and scoped pilots go to [email protected] — the people who run the infrastructure.

Start with an organization

Create an org, invite your team, and tell us which roadmap item you need.