Ring 0 is open to design partners running agents against production systems. Request access

Pricing

Priced on what runs, not who logs in.

Seat pricing makes no sense for infrastructure that agents use and humans only approve. You pay for governed execution: the hours a session is live, and the fleet it runs on.

01 / plans

Developer

Free

forever

One engineer proving the idea on a laptop.

  • Local kernel with real microVM isolation
  • Full policy engine, no feature gates
  • Local evidence chain and verifier
  • All SDKs, adapters, and the CLI
  • Community support

One concurrent session. No managed hosts, no hosted approvals.

Team

$0.09

per governed session-hour

A team running agents against real systems.

  • Managed microVM fleet across six regions
  • Hosted approvals via Slack and email
  • Evidence retention for 12 months, exportable
  • SSO, SCIM, and role-based access
  • Up to 200 concurrent sessions
  • Support with a one business-day response

Metered on session-hours plus egress. No commitment required.

Enterprise

Annual

licence

Regulated estates and platform teams.

  • BYOC in your AWS, GCP, or Azure account
  • Air-gapped deployment with signed bundles
  • Unlimited sessions and concurrency
  • Custom evidence retention and legal hold
  • Customer-managed encryption keys
  • SOC 2 report, DPA, and BAA
  • Named engineer and a 99.95% SLA

Priced on fleet size, not seats or sessions.

02 / a session-hour

What you are actually metered on.

A session-hour is one governed session being live for an hour. Suspended sessions cost nothing, because they are a snapshot rather than a running machine.

Counted
Wall-clock time a session holds a sandbox. Billed per second, rounded up to the minute.
Not counted
Suspended sessions, policy evaluations, approvals, evidence writes, and idle time between tool calls.
Egress
$0.02 per GB leaving the gateway. Denied traffic is free, because it never leaves.
Storage
Snapshots and evidence at $0.03 per GB-month, or free if you point them at your own bucket.
GPU sessions
Metered separately at the underlying instance rate plus the same governance margin.
BYOC
You pay your cloud provider for compute. The licence covers the software and the control plane.

03 / a worked example

$1,940

velone team, per month

Twelve coding agents, each averaging sixty session-hours a month, plus 400GB of egress. One line item, one contract, one audit surface.

~$6,400

the stack it replaces

A sandbox API, an LLM gateway, a secrets manager tier, and observability — plus roughly a quarter of an engineer maintaining the glue between them.

The engineer is the real cost. Vendor invoices for that stack land around $2,600; the rest is the person who owns four integrations and gets paged when the policy repo and the gateway disagree.

04 / questions

Is the free tier crippled?

No. The local kernel is the same binary with the same isolation and the same policy engine. What it lacks is the managed fleet, hosted approvals, and concurrency — infrastructure, not features.

Why not price per agent?

Because an agent is not a stable unit. Teams spawn a hundred short-lived children for one task, and counting them would punish exactly the architecture we recommend.

Do you charge for denied calls?

No. A denial costs us a policy evaluation and costs you nothing. It would be a strange incentive to bill for the product working.

What does Enterprise actually cost?

It scales with fleet size and starts in the mid five figures annually. We will give you a number on the first call rather than after three.

Startup or research pricing?

Yes. If you are pre-seed or academic, tell us and we will discount or waive it. We would rather have the design feedback than the invoice.

Can we move from Team to BYOC later?

Yes, and we do not charge to migrate. Sessions, policy, and evidence are portable by design — see deployment models.

Ring 0

Tell us the workload and we will price it.

Session count, average duration, and where it has to run. That is enough for a real number on the first call.

curl -fsSL velone.in/install.sh | sh