Pay when the model thinks. Never for the ability to govern.
A platform fee with an included credit allowance, metered beyond it. Deterministic skills cost nothing to run. Every tier ships the full fail-closed gate chain, cost caps, and the tamper-evident Trust Ledger.
Credits pool across the workspace · overage $0.008/credit, billed in arrears · seats are fair use, not a billing lever
Rate card
One credit is a cent. A run costs what it consumes.
Two units, on purpose: a run is the unit of work and the audit record, a credit is what it costs. Here is the whole conversion.
What runs
Credits
Cost
Deterministic or calculation skill
Pure code — no model call, so there is nothing to charge for. It still passes all 8 gates and still lands in the ledger.
0 credits
free
Connector or MCP tool call
A governed call into a connected system, through the audit and DLP layer.
1 credit
$0.01
Simulation-backed skill
3 credits
$0.03
AI skill run — standard model
The everyday unit. Your included allowance is sized in these.
5 credits
$0.05
AI skill run — advanced model
25 credits
$0.25
Long-context surcharge (over 10k input tokens)
Cost scales with context, so a flat rate would invert the economics on the heaviest skills.
+10 credits
+$0.10
Multi-agent crew run
A crew is metered as the steps it performs, never as a flat premium.
per step
—
Resolved outcome (packaged verticals)
Priced per completed outcome, with an accuracy and latency SLA.
—
$0.79
Frontier model
Run on your own provider account so the model bill stays yours and predictable.
your own key
—
Overage past your allowance: $0.008 / credit, billed in arrears
What's always included
Governance isn't a line item. It's the runtime.
On most platforms, controls are an enterprise upsell. On Cortex, you cannot run an agent without the full gate chain — on every plan, including Premium. That is why a deterministic skill costs zero credits and is still fully governed and fully audited: you pay for model work, never for the ability to govern it.
Every run passes 8 gates: identity → budget → guardrails → registry → control tower → execute → output guard → audit
Hard cost caps fail-closed at 100% — a runaway agent is blocked with a 402 before spend
Out-of-policy actions return 403; conflicting writes return 409 — deny is the default
Every outcome lands in a tamper-evident ledger (hashOk:false flags any edit)
Four things that are commonly metered elsewhere and are free here, because charging for them would price the wrong thing.
$0 · Catalog breadth
Twenty thousand skills cost nothing until one is run.
$0 · Deterministic skills
They make no model call. You pay when the model thinks.
$0 · Building
Designing agents, crews and skills in the studio is free. Only execution meters.
$0 · Growth in headcount
Seats are a fair-use limit, not a lever. Adding people does not raise the price.
Compare plans
Every feature, side by side.
The governance runtime is identical across plans — what scales is the meter, catalog breadth, crews, autonomy, identity controls, deployment, and support.
Feature
Premium
Pro
Recommended
Enterprise
Plan & meter
Platform fee
$299 / mo
$999 / mo
Custom, annual
Billed annually (save 25%)
$2,691 / yr
$8,991 / yr
Negotiated
Included credits / month
50,000
250,000
Negotiated
Included AI skill runs
~10,000
~50,000
Negotiated
Effective credit rate
$0.006
$0.004
Custom
Overage
$0.008 / credit
$0.008 / credit
Volume commitments
Console seats (fair use)
10
50
Unlimited
Skills library
Skill catalog
Curated (~2,000)
Full (20,000)
Full + private
Deterministic skills run free
Private team skills with versioning
Curated org catalog + approval policies
Agents & Studio
Agents
Single agents
Multi-agent crews
+ custom orchestration
Building agents, crews & skills
Free
Free
Free
Shared studio (drafts, review, versioning)
Sandbox + staging environments
Runs & Workflows
Autonomy
Manual runs
Event + scheduled
+ priority queue
Human-in-the-loop approval steps
Models
Standard
Standard + advanced
+ frontier (own key)
LLM key
We supply
We supply or yours
Yours, by default
API rate limit
100 / hr
1,000 / hr
Custom
Governance & security (runtime included in every plan)
Fail-closed gate chain (8 gates)
Tamper-evident Trust Ledger
Guardrails
Standard
Standard + configurable
Custom policy packs
Audit retention
90 days
1 year
Custom, multi-year
Observability
Dashboards
+ OpenTelemetry export
+ custom retention
Red-teaming
Scheduled
Continuous + reports
SSO / SCIM
Add-on
Data residency · VPC / air-gapped
Integrations & support
Connectors / MCP
3 connectors
Unlimited + MCP
+ private / on-network
Outcome packs with SLA
Add-on
Included / custom
Support
Email
Priority
Dedicated CSM + SLA
Uptime SLA
99.9%
Security-review concierge
What a run is
A run is a governed invocation — executed, held, or blocked.
Every one of these writes a ledger entry. That is the audit record; the credit cost is a separate question, answered by the rate card above.
Executed
Executed
Passed all 8 gates, acted, and wrote a signed receipt to the ledger.
Hold
Held
Stopped at an oversight gate for human approval — recorded, replayable, awaiting sign-off.
Blocked
Blocked
Denied at a gate — 402 over budget, 403 out of policy, 409 on conflict.
Three ways in
Try it, bring your own key, or buy the outcome.
14-day trial, no card
On a real workspace, not a sandbox, with the full feature set of the tier. A hard cap of 5,000 credits means a trial can never run up an unbounded bill. At the end, convert or drop to a read-only state that keeps your data and configuration intact.
Bring your own model key
Use your own Vertex or Anthropic account and the model spend stays on your bill. The platform fee is unchanged and AI runs drop to a flat 1-credit governance fee — we still meter, govern, rate-limit and audit every call. This is the default on Enterprise.
Outcome packs — $0.79 per outcome
For packaged verticals such as Claims Triage or US Tax, priced per completed outcome with an accuracy and latency SLA, or as a fixed monthly fee by volume band. Sold only where the outcome is measurable, so it can be verified rather than argued about.
audit/verify
head 0x9f3a…c1ok: true
verifyChain ▸ chained SHA-256 · signed receipts
Enterprise
Run Cortex your way.
Regulated enterprises deploy Cortex in their own boundary: VPC, on-premise, or fully air-gapped, with data residency pinned per tenant and the Trust Ledger intact. Your security reviewers get a concierge, not a PDF chase.
A credit is the unit we bill in, and it costs $0.01. What varies is how many credits a run consumes: a deterministic skill costs 0, a connector call 1, a standard AI skill run 5, an advanced-model run 25. You are paying for model work, not for the ability to govern it.
What counts as a run?
A run is one governed agent invocation that passes through the 8-gate chain and produces a ledger entry — whether it executes, is held for human approval, or is blocked (402/403/409). Example: an agent that reads a claim, drafts a summary, and proposes a payout is one run; if the payout crosses your approval threshold and waits for sign-off, it is still one run. Runs and credits are separate ideas: the run is the unit of work and the audit record, the credit is what it costs.
Why are deterministic skills free?
Because they make no model call. A rules or calculation skill runs as pure code — it still passes every gate and still writes to the Trust Ledger, but there is no inference cost behind it, so we do not charge for one. Platforms that meter a flat 'action' bill these at the full rate because their metering cannot tell the difference.
Is there a discount for paying annually?
Yes — 25% off the platform fee on both Premium and Pro. Premium is $299 a month billed monthly, or $2,691 a year; Pro is $999 a month, or $8,991 a year. The discount applies to the fee only — your included credit allowance and the overage rate are identical on both cycles, so annual buys you a cheaper platform, not a bigger meter. Enterprise is annual by default and priced per deal.
What happens when we use up the included credits?
Nothing stops mid-workflow. Usage past your included allowance meters at $0.008 per credit and bills in arrears, and your usage meter warns you well before you get there. The allowance is a billing threshold, not a wall — there is no mid-run cutoff. Hard cost caps are a separate control you set deliberately, and those do fail closed with a 402.
Are credits pooled across the team?
Yes. Credits are a single workspace allowance, not a per-person quota — heavy operators draw from headroom that lighter users leave. Premium includes 50,000 credits per month and Pro includes 250,000; Enterprise sizes a negotiated allowance with volume commitments.
Do extra people cost extra?
No. Seats are a fair-use limit, not a billing lever — Premium is sized for 10 console seats and Pro for 50, and adding people inside that does not raise the price. What you pay for is the platform and the credits your agents consume, so growing the team does not by itself grow the bill.
Can we bring our own model key?
Yes, and it is the default on Enterprise. Point Cortex at your own Vertex or Anthropic account and the model spend stays on your bill; the platform fee is unchanged and AI runs drop to a flat 1-credit governance fee, because we still meter, govern, rate-limit and audit every call.
What are outcome packs?
For packaged verticals such as Claims Triage or US Tax, we price per completed outcome — $0.79 each — with an accuracy and latency SLA, or as a fixed monthly fee by volume band. We sell these only where the outcome is measurable, so it can be verified rather than argued about. Included on Enterprise; available as an add-on on Pro.
Do you train models on our data?
No. Your prompts, documents, and run outputs are never used to train models — on any plan. Enterprise adds contractual no-training guarantees, custom retention, and data-residency controls.
Is governance an add-on or extra cost?
Governance is never an add-on. The fail-closed gate chain — Agent IAM, cost caps, guardrails, policy-as-code, oversight modes, and the tamper-evident Trust Ledger — is included in every plan, including Premium. You cannot run an agent on Cortex without it, which is also why a zero-credit deterministic skill is still a fully governed, fully audited run.
Can I try Cortex before I commit?
Yes — a 14-day trial on a real workspace, not a sandbox, with the full feature set of the tier and no card required. A hard cap of 5,000 credits means a trial can never run up an unbounded bill. At the end you convert, or drop to a read-only state that keeps your data and configuration intact. Self-serve signup is opening in waves — join the waitlist and we will invite you in.
Which SSO options come with which plan?
SSO and SCIM are included on Enterprise, mapped to your identity provider's groups with fine-grained RBAC. On Pro they are available as an add-on. Premium does not include SSO.
Can we deploy on-premise or in an air-gapped environment?
Yes — on Enterprise. Single-tenant, VPC, on-premise, and air-gapped deployments are supported, with data residency pinning. Signed Solution Packs verify by hash and signature offline, so governed solutions install into environments with no outbound connectivity.
Which compliance frameworks is Cortex aligned with?
Cortex is built for and aligned with SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, the EU AI Act, NIST AI RMF, and FINRA. We are not making certification claims on this page — visit the Trust Center for current attestation status and security documentation.
“We budgeted for a governance project on top of the platform cost. With Cortex there wasn't one — the controls our auditors wanted shipped on day one, on the plan we already had.”
Illustrative persona · VP, Platform EngineeringRegulated healthcare provider (representative scenario, not an attributed quote)
Get in line for access. Scale when it works.
Join the waitlist for the full Pro plan — full catalog, multi-agent crews, event-driven autonomy, and 250,000 credits a month. Residency, SSO/SCIM and air-gapped deployment come with Enterprise, sized once you're in.