Community · Pro · Enterprise
Start free. Add a boundary the agent cannot switch off.
Community is free and open source, useful from the first agent. Pro buys the full single-operator kernel boundary (Linux) online and upgrades from Community in minutes. Enterprise runs that same enforcement at fleet scale with the assurance and org controls security review asks for.
- CommunityFree forever · open source
- Probilled annually ($588/agent/year)$49 /agent · moBuy online
- EnterpriseScoped per deploymentCustomTalk to security
Community
Guard every agent, on every OS. Screen what it does before it does it.
- Open source (Apache-2.0): read and build the exact code at github.com/InnerWarden/inner-warden
- Deterministic screening of integrated commands and MCP/tool calls, allow / review / deny (71 agent-threat rules + 27 injection patterns)
- MCP inspection that can deny a tool call before it forwards (guard mode)
- Agent discovery and token intelligence (Claude Code, Codex)
- AI Jail: sandbox a supported agent on Linux / macOS, monitor by default
- Local decisions, session activity, and a redacted narrative audit graph
- Local read-only dashboard, alerts (Telegram/Slack/Discord/webhook), cross-platform
Pro
The full single-operator kernel boundary (Linux). The same enforcement as Enterprise, bought self-serve, upgradable from Community in minutes.
- Everything in Community
- Agent-scoped Execution and Secret Read gates on supported BPF LSM kernels (Linux)
- Kernel observability (Linux): eBPF sensor + 82 host detectors + 69 cross-layer correlation rules
- DNS Guard, binary integrity checks, restart supervision, and live control-state verification
- Verified response: block IP, kill process, suspend user, honeypot
- Signed off-host audit anchors for your host
Enterprise
Everything in Pro, run at fleet scale with the assurance and org controls production security review asks for.
- Everything in Pro, across multiple hosts
- Fleet: multi-host + per-tenant attribution for Kubernetes pods
- Multi-user / multi-seat operator access and RBAC
- Anomaly model trained on your own infrastructure
- Curated policy, managed allowlist, and configuration service
- Quarterly assurance audit: a full re-check that enforcement stays verified
- SLA + support, ISO 27001 / MITRE mapping, and air-gapped or sovereign deployment design
Pro is billed per protected agent. Running several agents on a single host, or a fleet of 15+ agents? Talk to security and we'll bundle them and scope volume pricing. Enterprise is scoped per deployment: a single production host, a Kubernetes fleet, and an air-gapped environment carry different policy and assurance needs.
Platform / OEM: ship the guardrail inside your product
Embed the runtime boundary in the Linux environment you ship to customers, with tenant attribution and pod-scoped enforcement. Volume or revenue-share licensing.
When teams upgrade
Teams pay for containment that does not ask the agent anything.
Community already gives integrated agents a useful action and MCP guardrail, and the agent has to keep calling it. The paid tiers add that containment, plus operational assurance and fleet control:
Contain a compromised agent
Community screens commands and MCP calls. Pro adds an agent-scoped Linux boundary that can deny unauthorized execution and secret reads even after the agent-facing layer is bypassed.
Prove it to someone
An auditor, a customer's security review, a cyber insurer. Signed off-host audit anchors turn a local record into third-party tamper-evidence.
Don't operate it alone
Curated policy, a managed allowlist, fleet aggregation, SLA, and support, for teams that need the outcome without running the machinery.
Compare the tiers
Community, Pro, and Enterprise, feature by feature
Pro is everything in Community plus the Linux kernel boundary. Enterprise is everything in Pro plus fleet scale, org controls, and assurance, scoped with our security team.
| Capability | Community Free · open source | Pro from $49/agent/mo | Enterprise Custom |
|---|---|---|---|
| Screening & guardrail: userspace, cross-OS | |||
| Command + MCP/tool screening, allow / review / deny (71 rules + 27 injection patterns) | |||
| MCP inspection that denies a tool call in-path (guard mode) | |||
| Agent discovery and token intelligence | |||
| AI Jail: sandbox a supported agent (Linux / macOS) | |||
| Local dashboard, alerts, and redacted audit graph | |||
| Runs on Linux and macOS, Windows experimental | |||
| Kernel enforcement: Linux, BPF LSM (Pro & Enterprise) | |||
| Execution Gate + Secret Read Guard a compromised agent cannot switch off | |||
| eBPF sensor + 82 host detectors + 69 cross-layer correlation rules | |||
| DNS Guard, binary-integrity checks, live control-state verification | |||
| Verified response: block IP, kill process, suspend user, honeypot | |||
| Signed off-host audit anchors | 1 host | Fleet | |
| Scale, assurance & org: sold through contact | |||
| Multi-host fleet + per-tenant attribution for Kubernetes pods | |||
| Multi-user / multi-seat operator access + RBAC / SSO | |||
| Anomaly model trained on your own infrastructure | |||
| Curated policy, managed allowlist, and configuration service | |||
| Quarterly assurance audit: a full re-check that enforcement stays verified | |||
| SLA + support, ISO 27001 / MITRE mapping, air-gapped deployment | |||
| Get it | Install free | Buy online | Talk to security |
Production security pilot
Prove the boundary on one critical agent workflow.
Start with a bounded production pilot: one threat model, one deployment architecture, measurable enforcement criteria, and a clear path to fleet rollout. You work directly with the founding security team from design through evidence review.
npm install -g innerwardencurl -fsSL https://innerwarden.com/free | shEnterprise security review
Need Enterprise? Show us where your agents operate.
Community and Pro are self-serve. For fleet scale, multi-user access, an anomaly model trained on your infrastructure, and the quarterly assurance audit, work directly with the founding security team on a 1:1 threat model, deployment architecture, and pilot success criteria across your real agent workflows.
Request a security design review
Reviewed by security engineeringTell us what the agents can reach. Every request gets a personal reply.