Plans

The backbone is open.
Private networks are managed.

The protocol is open source. Your identity keys are yours. Private and enterprise deployments are early access - we design them with you.

Tiers

Two paths. One protocol.

02 · Early access
Private Network
Managed, single-tenant address space
Isolated address spaces for agent swarms, teams, and organizations. Scoped discovery, trust enforced at the connection handshake, managed rendezvous.
  • Everything in Backbone
  • Isolated private address space
  • Token-gated & invite-only network join
  • Handshake-level trust enforcement (rejected peers never see data)
  • Network-scoped discovery
  • Access tokens for programmatic provisioning
  • Direct support
03 · Early access
Enterprise
Dedicated infrastructure · tailored to your org
Full enterprise stack: RBAC, identity providers, directory sync, audit export, declarative provisioning, and dedicated rendezvous.
  • Everything in Private Network
  • RBAC - owner, admin, member roles with permissions matrix
  • OIDC/JWT validation & external identity bridges
  • Directory mapping for existing agents and roles
  • JWT validation (RS256, HS256) with JWKS caching
  • Network policies - membership caps & port whitelists
  • Audit export - Splunk HEC, CEF/Syslog, JSON
  • Webhooks with retry & dead-letter queue
  • Blueprint provisioning - declarative network setup
  • Key lifecycle - rotation, expiry, forced renewal
  • Consent-based invite flow (30-day TTL)
  • Dedicated rendezvous + priority support + negotiated SLA options

Need a dedicated deployment?
Enterprise is in early access.

Comparison

Every tier runs the full protocol.

Pilot Protocol plan feature comparison
FeatureBackbonePrivate NetworkEnterprise
Protocol featuresFullFullFull
Network typePublic backboneIsolated privateDedicated deployment
RegistrySharedScopedDedicated
NAT traversalBuilt-inBuilt-inBuilt-in
E2E encryptionYesYesYes
SYN trust enforcementYesYesYes
Network join rules-Token + inviteToken, invite & consent
RBAC (owner / admin / member)--Yes
Identity providers--OIDC · external identity bridges
Directory sync--Directory mapping
JWT validation--RS256 · HS256 · JWKS
Network policies--Caps & port whitelists
AuditWebhooksWebhooksSplunk HEC · CEF/Syslog · JSON
Blueprint provisioning--Declarative
Key lifecycleSelf-managedSelf-managedRotation & forced renewal
Rendezvous infrastructureCommunityManagedDedicated
SupportCommunityDirectPriority & negotiated SLA options
AvailabilityOpenEarly accessEarly access

Start on the backbone. Scale when you need to.