Pricing · AI Audit Ledger · no per-seat, no per-decision metering

Free and open source, or deployed and managed for you.

The whole stack is open source under Apache 2.0, free to self-host. When you want it deployed properly, compliance-ready, and supported, contact us for pricing. No per-seat licensing, no per-decision metering. The records are yours, in your own infrastructure, either way.

Pick how it gets delivered. The records are always yours.

Same production-grade system every way, always inside your own environment. The only difference is who runs it.

Open source

Free

Apache 2.0 · self-host

Run the whole stack yourself: ledger, MCP server, Evidence Hub, and dashboards.

  • The full source: ledger, MCP server, Evidence Hub, dashboards
  • Python and Node SDKs, and the CDK deploy scripts
  • A zero-config public sandbox to try every tool
  • Community support via GitHub
The honest anchor

The deployed price is less than a day of a Big Four compliance consultant, and you own it forever. A rounding error next to a single EU AI Act penalty, and the one control you cannot retrofit after the fact.

What it costs to run, honestly.

The ledger is storage and serverless requests, not an LLM-driven system, so there is no AI inference cost. The run cost sits in your own environment, not on a Zyvra invoice.

No recurring fee by default

  • Self-host or take the deployed option and there is no standing fee to Zyvra at all
  • You pay only your own cloud or on-premises run cost: mostly storage and request volume
  • In the cloud that is typically modest and predictable; on-premises it folds into existing capacity
  • No per-seat licensing, no per-decision metering, ever

Optional, only if you choose it

  • Managed option: a monthly management fee where Zyvra operates it for you inside your environment
  • Enterprise add-ons: SSO, private networking, tenant routing, deep observability, support SLAs
  • Repeated auditor cycles or heavy remediation support
  • All of it quoted up front, none of it a surprise on an invoice

The questions buyers ask before they sign anything.

What's free, and what's paid?

The repositories are open source under Apache 2.0 and free to self-host: the ledger, the MCP server, the Evidence Hub, and the dashboards. Contact us for when you want it deployed properly into your own infrastructure, configured compliance-ready, and handed over with the code, infrastructure-as-code, and runbooks, rather than built from scratch by your team. One fixed price for a single deployment, agreed before any work starts. Larger estates (multi-region, multi-system, SSO, private networking, repeated audit cycles) are scoped and quoted separately, up front, so there are no surprises.

Is there a recurring fee?

Not by default. If you self-host or take the deployed option, there is no standing fee to Zyvra; you pay only your own run cost in your own environment. The only recurring fee is optional: the managed option, where Zyvra operates the system for you inside your environment for a monthly management fee. You keep ownership either way.

What does it cost to run?

The ledger is storage plus serverless requests, with no LLM inference, so the run cost is modest and predictable. In the cloud it sits in your own provider account (AWS, GCP, Azure, or another); on-premises it folds into your existing infrastructure. We model it during setup with the line items called out, so finance can see exactly where the money goes.

Does it run on-premises, not just AWS?

Yes. AWS S3 Object Lock is the cloud reference implementation for immutable storage; on-premises uses equivalent write-once storage and your own IT controls. The ledger, the MCP server, and the Evidence Hub all run inside whichever boundary you choose, cloud or on-premises.

Can we start free and move to paid later?

That's the intended path. Try the sandbox and self-host the open source to prove it out, then bring us in when you want it deployed compliance-ready, supported, or managed. Nothing you build on the open source is wasted; the paid options deploy the same stack.

How does SOC 2 and compliance work with Zyvra?

The trust model is simple, and it's by design: everything runs in your own environment, so the certifications that environment already carries are the ones that apply. In the cloud (AWS, GCP, Azure, or another major provider), those platforms hold the infrastructure certifications you need (SOC 2 Type II, ISO 27001, and sector-specific schemes like HIPAA, PCI DSS, or FedRAMP, depending on cloud and region). On-premises or in your own private cloud, your existing internal IT controls and audits cover the same ground. Either way, your data never touches Zyvra's systems, because there are no Zyvra systems in the data path.

The compliance attestation, the audit relationship, and the regulatory accountability are yours. Zyvra builds and runs the technical surface; your organisation operates and attests to it. The capability we ship (tamper-evident storage, decision logging, completeness proofs, access controls, audit-pack export) produces the evidence your compliance team takes to audit.

One nuance worth naming: if you take the managed option, Zyvra holds ongoing operator access inside your environment, and some procurement teams will reasonably ask what controls cover that access. The ledger still holds no PII and runs in your own environment; the question there is about the managed-service access, not the data. We'll talk it through honestly on the call and scope the access to exactly what you're comfortable with.

Tell us where AI decisions are being made, and who will ask to see them.

A short, honest call about your record-keeping gap: what your AI system decides, which regulator you answer to, and where the audit trail is today. Two business day response, NDA on request.

Talk to us