Skip to content

Community · Pro · Enterprise

Start free. Add a boundary the agent cannot switch off.

Community is free and open source, useful from the first agent. Pro buys the full single-operator kernel boundary (Linux) online and upgrades from Community in minutes. Enterprise runs that same enforcement at fleet scale with the assurance and org controls security review asks for.

Open source

Community

$0
Free forever · open source · Linux, macOS, Windows

Guard every agent, on every OS. Screen what it does before it does it.

  • Open source (Apache-2.0): read and build the exact code at github.com/InnerWarden/inner-warden
  • Deterministic screening of integrated commands and MCP/tool calls, allow / review / deny (71 agent-threat rules + 27 injection patterns)
  • MCP inspection that can deny a tool call before it forwards (guard mode)
  • Agent discovery and token intelligence (Claude Code, Codex)
  • AI Jail: sandbox a supported agent on Linux / macOS, monitor by default
  • Local decisions, session activity, and a redacted narrative audit graph
  • Local read-only dashboard, alerts (Telegram/Slack/Discord/webhook), cross-platform
Self-serve

Pro

$49/agent · mo
billed annually ($588/agent/year) · save $120 · cancel anytime

The full single-operator kernel boundary (Linux). The same enforcement as Enterprise, bought self-serve, upgradable from Community in minutes.

  • Everything in Community
  • Agent-scoped Execution and Secret Read gates on supported BPF LSM kernels (Linux)
  • Kernel observability (Linux): eBPF sensor + 82 host detectors + 69 cross-layer correlation rules
  • DNS Guard, binary integrity checks, restart supervision, and live control-state verification
  • Verified response: block IP, kill process, suspend user, honeypot
  • Signed off-host audit anchors for your host
For teams

Enterprise

Custom
Scoped per deployment · agents, hosts, and assurance requirements

Everything in Pro, run at fleet scale with the assurance and org controls production security review asks for.

  • Everything in Pro, across multiple hosts
  • Fleet: multi-host + per-tenant attribution for Kubernetes pods
  • Multi-user / multi-seat operator access and RBAC
  • Anomaly model trained on your own infrastructure
  • Curated policy, managed allowlist, and configuration service
  • Quarterly assurance audit: a full re-check that enforcement stays verified
  • SLA + support, ISO 27001 / MITRE mapping, and air-gapped or sovereign deployment design

Pro is billed per protected agent. Running several agents on a single host, or a fleet of 15+ agents? Talk to security and we'll bundle them and scope volume pricing. Enterprise is scoped per deployment: a single production host, a Kubernetes fleet, and an air-gapped environment carry different policy and assurance needs.

Platform / OEM: ship the guardrail inside your product

Embed the runtime boundary in the Linux environment you ship to customers, with tenant attribution and pod-scoped enforcement. Volume or revenue-share licensing.

Become a design partner

When teams upgrade

Teams pay for containment that does not ask the agent anything.

Community already gives integrated agents a useful action and MCP guardrail, and the agent has to keep calling it. The paid tiers add that containment, plus operational assurance and fleet control:

Contain a compromised agent

Community screens commands and MCP calls. Pro adds an agent-scoped Linux boundary that can deny unauthorized execution and secret reads even after the agent-facing layer is bypassed.

Prove it to someone

An auditor, a customer's security review, a cyber insurer. Signed off-host audit anchors turn a local record into third-party tamper-evidence.

Don't operate it alone

Curated policy, a managed allowlist, fleet aggregation, SLA, and support, for teams that need the outcome without running the machinery.

Compare the tiers

Community, Pro, and Enterprise, feature by feature

Pro is everything in Community plus the Linux kernel boundary. Enterprise is everything in Pro plus fleet scale, org controls, and assurance, scoped with our security team.

Capability
Community
Free · open source
Pro
from $49/agent/mo
Enterprise
Custom
Screening & guardrail: userspace, cross-OS
Command + MCP/tool screening, allow / review / deny (71 rules + 27 injection patterns)
MCP inspection that denies a tool call in-path (guard mode)
Agent discovery and token intelligence
AI Jail: sandbox a supported agent (Linux / macOS)
Local dashboard, alerts, and redacted audit graph
Runs on Linux and macOS, Windows experimental
Kernel enforcement: Linux, BPF LSM (Pro & Enterprise)
Execution Gate + Secret Read Guard a compromised agent cannot switch off
eBPF sensor + 82 host detectors + 69 cross-layer correlation rules
DNS Guard, binary-integrity checks, live control-state verification
Verified response: block IP, kill process, suspend user, honeypot
Signed off-host audit anchors1 hostFleet
Scale, assurance & org: sold through contact
Multi-host fleet + per-tenant attribution for Kubernetes pods
Multi-user / multi-seat operator access + RBAC / SSO
Anomaly model trained on your own infrastructure
Curated policy, managed allowlist, and configuration service
Quarterly assurance audit: a full re-check that enforcement stays verified
SLA + support, ISO 27001 / MITRE mapping, air-gapped deployment
Get itInstall freeBuy onlineTalk to security

Production security pilot

Prove the boundary on one critical agent workflow.

Start with a bounded production pilot: one threat model, one deployment architecture, measurable enforcement criteria, and a clear path to fleet rollout. You work directly with the founding security team from design through evidence review.

Start free today
npm install -g innerwarden
Linux, macOS, Windows · prebuilt, signed npm provenance
curl -fsSL https://innerwarden.com/free | sh
signed release, no Node required · macOS, Linux
All install methods and how to verify →

Enterprise security review

Need Enterprise? Show us where your agents operate.

Community and Pro are self-serve. For fleet scale, multi-user access, an anomaly model trained on your infrastructure, and the quarterly assurance audit, work directly with the founding security team on a 1:1 threat model, deployment architecture, and pilot success criteria across your real agent workflows.

No generic sales sequence. You leave with a concrete view of agent exposure, enforcement points, and the fastest safe path to production.

Request a security design review

Reviewed by security engineering

Tell us what the agents can reach. Every request gets a personal reply.

Sent to our self-hosted Mautic instance. By submitting, you agree that we may contact you about InnerWarden early access. See our privacy policy.