One engine. Two ways to run it.
DFENS Cloud runs the full engine as a hosted service: point your app at an endpoint and see real verdicts today, free below 100 calls a day, then scale on monthly or annual billing metered by calls, never tokens. When data residency demands your own boundary, Enterprise runs the same engine in your VPC or fully self-hosted. Moving between them is a base-URL change, not a migration.
Design partner programme. Deploy against real traffic, free, with hands-on support and locked-in pricing while we finalize GA figures.
Apply to joinSee real verdicts against your own traffic today. No deployment, no card.
- Hosted proxy endpoint, all five provider adapters
- Full deterministic engine + default rule packs
- Every block names its rule ID
- Signed audit log
- At the cap it fails closed, never uninspected
One production application behind the hosted proxy, metered by what it uses.
- Everything in Developer
- 100,000 calls / month included, metered beyond
- Spend cap you set; at the cap it fails closed
- Optional encrypted history retention
- Business-hours support
Several applications behind one account, each with its own endpoint and rules.
- Everything in Pro
- 500,000 calls / month included, metered beyond
- Multiple apps & environments, per-app rule scoping
- Optional encrypted history (S3-compatible)
- Priority email support
The only tier where the engine leaves our cloud: dedicated instance, your VPC, or fully self-hosted inside your boundary.
- Everything in Team, plus:
- Self-hosted or VPC deployment, licensed per environment
- Signed container images (SBOM + SLSA + cosign)
- Custom call volume, or unmetered when self-hosted
- Multi-tenant rule scoping & per-tenant admin
- ML operators (
:fatimage: PI classifier, toxicity) - Priority SLA & named engineer
- Security questionnaire, DPA, procurement support
* Indicative pricing shown to set expectations; Pro and Team
figures are confirmed at checkout. Annual billing gets two months free. A call is one
proxied model exchange, including its tool-phase inspections; one /v1/inspect
invocation also counts as one call. Nothing on this page is a binding quote until you reach
checkout.
The security floor doesn't move with the price.
▸Same engine everywhere
Cloud and self-hosted run the identical engine, rule packs, and audit format. Moving between them is a base-URL change, not a migration.
▸Readable rules
Every block names a rule ID with a citation and severity. No opaque scores, on any tier.
▸OWASP-mapped detection
The same deterministic engine and default rule packs, mapped to the LLM Top 10.
▸Fails closed
Rate caps and spend caps return an explicit error naming the quota. Traffic is never silently passed uninspected because a meter ran out.
The questions procurement always asks.
How does billing work?
Cloud tiers are metered per call, billed monthly or annually with two months free. The meter counts calls, never tokens, so a verbose model costs no more to inspect. Enterprise self-hosted deployments are licensed per environment per year instead: on your hardware we have no visibility into your volume and take no cut of it.
What counts as a call?
One proxied model exchange, including its tool-phase inspections, counts as one call. One /v1/inspect invocation also counts as one. Note that agent workloads multiply: a single user message can drive several model calls, so size against model traffic, not chat messages.
Do you see our prompts?
On Cloud tiers, necessarily yes: the hosted proxy inspects your traffic on our infrastructure. That is the trade for zero deployment. On Enterprise self-hosted, no: there are no outbound calls to DFENS AI or anyone else for scoring, and that's architectural, not a policy promise. When data residency decides, that's the Enterprise conversation, and your rules and audit format port unchanged.
What happens when we hit a cap?
Requests are rejected with an explicit error naming the quota, and the rejection is auditable like any other decision. DFENS never responds to an exhausted meter by passing traffic uninspected. A firewall that fails open on billing isn't a firewall.
What counts as an "environment"?
For Enterprise self-hosted licensing: a distinct deployment boundary, typically one production install fronting one application or model gateway. Non-production (staging, CI) instances are included with a production licence.
Is there an open-source or free tier?
The Developer tier on DFENS Cloud is free below 100 calls a day, with no time limit. The engine itself is commercial and proprietary; the rule format is a documented, portable spec.
How do updates work?
Cloud is always current; we roll signed updates and new rule packs as attacks evolve. Enterprise self-hosted receives the same signed images and rule packs, and you choose when to roll them; nothing auto-updates inside your boundary.
Can we move between Cloud and self-hosted?
Yes, in either direction. Same engine, same rule syntax, same audit format, so the usual path is Developer to prove it, Pro or Team to run it, and Enterprise when it has to live inside your boundary. Design-partner pricing carries over to whichever tier you land on at GA.
Sign up, or tell us about your deployment.
Developer, Pro, and Team are self-serve: pick a tier and you're through in minutes. For Enterprise or VPC deployment, share your providers, your scale, and whether it's customer-facing or internal, and we'll come back with a deployment plan, usually within one business day.
hello@dfens.ai