Enterprise extends the complete open platform where larger or regulated organizations need more operational depth. It does not replace the open governance loop.
Open foundation: 29 wired modules · 26 compliance framework catalogs · 157 public integrations.
Identity & access
The open build provides complete single-IdP OIDC and SAML, WebAuthn/FIDO2, PIV/CAC and non-human identity lifecycle. Enterprise adds per-tenant multi-IdP federation, SSO enforcement, SAML SP metadata, CyberArk Conjur integration and seat entitlement beyond the community cap. These are scale and policy-operating capabilities, not a replacement for open identity security.
Content & data security
Open includes deterministic PII, injection and jailbreak guardrails plus a deny-closed DLP egress gate. Enterprise adds deep content inspection across messages, retrieval, MCP renders and Claude Code hook input, as well as enhanced erasure coordination and computer-use governance. The extra depth targets injection, exfiltration and unsafe-action patterns across more governed channels.
Threat & incident
The open build includes guardian findings, tier floors and the estate kill switch. Enterprise adds threshold-based automatic suspension, curated threat intelligence, continuous attack-graph scanning and bidirectional incident close-loop workflows. Operators configure thresholds, cooldown and escalation rather than delegating every decision to automation.
Compliance & regulatory
Open maps 26 framework catalogs and exports sealed OSCAL evidence. Enterprise adds DORA register structuring, ISO 42001 AIMS readiness material, SSP and POA&M workflows, and sector-specific overlays. These add-ons automate evidence gathering and report structuring. They do not certify the organization or guarantee compliance.
Operations & resilience
Open includes S3 Object Lock WORM archival, a signed ledger and backup/restore with chain verification. Enterprise adds named regulatory retention floors, long-horizon legal hold, examiner evidence bundles, Azure and GCS immutable sinks, and durable at-least-once event delivery. It adds regulated operating depth without removing the open resilience baseline.
Integration
Open provides static upstream credentials, a CAEP receiver, Terraform, SDKs and typed webhooks. Enterprise adds RFC 8693 token exchange, outbound CAEP SETs, deny-closed tool-definition pinning and an MCP elicitation mediator. These capabilities harden short-lived credentials and runtime trust between systems.