Free on our infrastructure. Unmetered on yours.
There is no meter to read from. One agent on our hosted console is free; the paid tier is a deployment inside your own network — VPC, on-premises, or air-gapped — with no agent count and no token bill.
You pay for where it runs, never for how many agents
On our infrastructure you get one agent, free — and discovery at any scale. On yours nothing is metered at all: free on the open-source engine, flat-priced on the platform.
- Runs on
- Your own process
- Bounded by
- Your hardware
- Discover
- The endpoint, on your machines
- Diamond
- —
- Dome
- The engine, in your process
- Darwin
- —
Vijil Dome, the control engine, under Apache-2.0 — read it, fork it, change it. pip install vijil-dome
- Runs on
- console.vijil.ai, at our cost
- Bounded by
- One agent
- Discover
- Any scale
- Diamond
- One agent, scored
- Dome
- One agent, enforced
- Darwin
- One pull request
Not a crippled version of the paid one — found, scored, enforced and improved.
- Runs on
- Your VPC, datacenter, or a network with no egress
- Bounded by
- Your hardware
- Discover
- Any scale, in your network
- Diamond
- Your policy, on a cadence
- Dome
- The whole coalition
- Darwin
- Continuous
Every agent, every handoff, every evaluation. No count, no token meter.
The combination missing is ours‑at‑your‑scale: we do not sell a hosted tier for a whole population. If that is the shape you want, say so — it is a gap rather than a policy.
Four products, three places to run them
The first column is what runs on your own machine for nothing. Only Dome and the Discover endpoint are open source — the Diamond and Darwin clients are free to install but are not, and that is worth saying here rather than leaving to a license file.
| On your machine | Hosted — free | Air-gapped | |
|---|---|---|---|
| Runs on | Your own process | console.vijil.ai, at our cost | Your VPC, datacenter, or a network with no egress |
| Bounded by | Your hardware | One agent | Your hardware |
| Discover | Installers for macOS, Windows and Linux, plus a browser extension. Open source. | Every GitHub org and cloud account, scanned as often as you like | Every surface, including what a hosted scan cannot reach |
| Diamond | pip install vijil-sdk — evaluate, harnesses, reports. Free, not open source. | One agent scored against the Vijil baseline harness | Every agent, scored as often as you like. No per-evaluation meter |
| Dome | pip install vijil-dome — guards on inputs, LLM calls, tool calls, outputs. Apache-2.0. | One agent enforced, with the flow monitor across its handoffs | Every agent and every handoff. No per-agent count, no token meter |
| Darwin | pip install vijil-sdk — adapt, evolve, proposals, genomes. Free, not open source. | One agent, one failure, one pull request against your own repo | Every agent, with proposals arriving as the failures do |
Answered, including the ones that do not flatter us
So what does it actually cost?
For one agent on our console, nothing. Beyond that you are buying a deployment rather than a quantity: a flat price for the platform running inside your own network, with no agent count and no token bill. Services publishes the shape of the engagement that gets you there — what it does not publish is a number, because the scope of a first deployment is the thing we work out together.
Is the free tier self-serve?
Not yet. Today you ask and we open an account, usually the same day. The open-source engine needs nobody’s permission and you can have it running in the next ten minutes; the hosted platform still goes through us.
What exactly is open source?
Vijil Dome — the control engine — under Apache-2.0. That is the whole answer today. The CLI and the Python client install freely from PyPI, and their source is not yet published.
Three more, answered the same way
Do we have to send you our data?
On the free tier, yes — it runs on our console, so evaluation traffic and decision traces reach us. On the paid tier, no: the platform runs inside your VPC or on your own hardware, and it is designed to run in a network with no egress at all. That is the reason the paid tier is unmetered: we cannot count what we cannot see. We do not train on customer data — not on the free tier and not on any other. What we will do is help you train on your own data inside your own network, where it never egresses. Our Trust Center carries the security program, and the privacy policy names every subprocessor and where each one processes.
What does the free tier not do?
It governs one agent on our console, so it cannot show you the failure that only appears between two of them — which is the failure this company exists to address. What it can finish: a baseline score with the transcripts behind every failure, one agent enforced end to end, and one pull request against your own repository. Those are whole answers, not samples. It holds recent history rather than a year of it, and it will not export. Nothing about it expires.
Why is discovery free at any scale?
Because a count you cannot obtain is worth nothing to you, and an agent we cannot see is worth nothing to us. Metering visibility would mean charging you to find out how much you owe — and on the paid tier there is nothing to owe, because the inventory never leaves your network.
Start with the agent you are least sure about
One agent is free and it is the whole product. If it tells you something you did not know, the conversation about the rest is a short one.