Business, its four add-ons and Enterprise extend the complete open platform where larger or regulated organizations need more operational depth. Each paragraph names the edition that sells the capability; the add-ons require an active Business subscription and are bought self-serve. The open governance loop is never replaced.
Open foundation: 30 wired modules · 26 compliance framework catalogs · 158 public integrations.
Identity & access
The open build provides complete single-IdP OIDC and SAML, WebAuthn/FIDO2, PIV/CAC and non-human identity lifecycle. The Identity & Scale add-on for Business adds per-tenant multi-IdP federation, group mapping, require-SSO enforcement, SAML SP metadata, read-only CyberArk Conjur and more than one active identity provider. Above five active providers, or above two production deployments, the scope moves to Enterprise. These are scale and policy-operating capabilities, not a replacement for open identity security.
Content & data security
Open includes deterministic PII, injection and jailbreak guardrails plus a deny-closed DLP egress gate. The AI Runtime Security add-on for Business adds deep content inspection across messages, retrieval, MCP renders and Claude Code hook input; computer-use governance and further runtime controls join the same add-on, at the same price, as each passes its gate. Enhanced right-to-erasure coordination belongs to the Regulated Operations add-on instead. The extra depth targets injection, exfiltration and unsafe-action patterns across more governed channels.
Threat & incident
The open build includes guardian findings, tier floors and the estate kill switch. Business, in its Starter preset, adds the threat-intel catalog on a declared cadence; the Regulated Operations add-on adds bidirectional incident close-loop workflows with PagerDuty and Opsgenie. Operators keep configuring the open enforcement points: the paid pieces add catalogue and workflow depth, not autonomy.
Compliance & regulatory
Open maps 26 framework catalogs and exports sealed OSCAL evidence. The Compliance Packs add-on for Business adds DORA register structuring, ISO 42001 AIMS readiness material, SSP and POA&M workflows, and sector-specific overlays. It automates evidence gathering and report structuring: it drafts, and your counsel or auditor reviews. It does not certify the organization or guarantee compliance.
Operations & resilience
Open includes S3 Object Lock WORM archival, a signed ledger and backup/restore with chain verification. The Regulated Operations add-on for Business adds named regulatory retention floors, long-horizon legal hold and examiner evidence bundles; the Identity & Scale add-on adds durable at-least-once event delivery over your own NATS. LTS, air-gapped and OTA-mirror operation, multi-entity setups and more than two production deployments are Enterprise. It adds regulated operating depth without removing the open resilience baseline.
Integration
Open provides static upstream credentials, a CAEP receiver, Terraform, SDKs and typed webhooks. Business, in its Starter preset, adds deny-closed tool-definition pinning; the AI Runtime Security add-on adds the MCP elicitation mediator; custom, scoped credential exchange is agreed under Enterprise. These capabilities harden short-lived credentials and runtime trust between systems.
Enterprise only
Enterprise is not a hidden pile of extra modules: it is contracted work, sold by annual order form over email and never through self-serve checkout. It covers custom, scoped credential exchange; scoped dedicated engineering such as policy authorship, tuning and bespoke connectors; LTS, air-gap and OTA-mirror operation; multi-entity structures; more than two production deployments; more than five active identity providers; OEM, MSP and redistribution rights; capped indemnity; DPA and procurement paperwork; and best-effort first-response objectives. Everything else on this page is sold self-serve as Business or one of its four add-ons.