Four plans: Community is free forever for individual use, Professional adds detection depth for one power user, Business brings fleet-wide management for teams, Enterprise adds contract terms and integrations. One codebase, one installer, one browser extension for every plan — only the signed license changes.
Community
Free
Forever · 1 user · 1 device
- Full secret, PII & prompt-injection/jailbreak protection
- File & document upload scanning
- OCR for images & scanned PDFs
- Local audit log (7-day retention)
- Up to 5 governed AI sites
- Non-commercial use
Professional
Custom
1 user · 5 devices · commercial use
- Everything in Community
- Custom keyword rules, unlimited AI sites
- Entropy-based unknown-secret detection
- Advanced attack-obfuscation detection (evasion/encoding)
- Outbound (AI response) scanning
- Local AI gateway & multi-provider routing
- 90-day audit retention, cloud export
Business
Custom
Minimum 10 seats · 5 devices/user
- Everything in Professional
- Agentic-risk detection (tool abuse, exfiltration, context-flood)
- Central policy management & sync
- Fleet dashboard, device heartbeat & reporting
- Cloud audit sync, 180-day retention
- SIEM (syslog) export available
Enterprise
Custom
Contract · configurable devices/user
- Everything in Business
- Local ML/NER detection
- SIEM export included
- 365-day audit retention
- GPO / Intune / SCCM deployment
- Priority support
Feature matrix
Detection quality (what gets caught) is the same at every plan — SafePrompt doesn't run a weaker scanner for free users. Plans differ in scanning surface area (files, OCR, outbound responses), fleet-wide management, and audit depth.
| Feature | Community | Professional | Business | Enterprise |
|---|---|---|---|---|
| Core Protection | ||||
| Users / Devices | 1 / 1 | 1 / 5 | Min. 10 seats / 5 | Contract / configurable |
| Commercial use | ❌ | ✅ | ✅ | ✅ |
| Secret & PII detection | ✅ | ✅ | ✅ | ✅ |
| Basic prompt-injection & jailbreak detection | ✅ | ✅ | ✅ | ✅ |
| Advanced attack-obfuscation detection (evasion/encoding) | ❌ | ✅ | ✅ | ✅ |
| Agentic-risk detection (tool abuse, exfiltration, context-flood) | ❌ | ❌ | ✅ | ✅ |
| File & document upload scanning | ✅ | ✅ | ✅ | ✅ |
| Prompt masking / redaction | ✅ | ✅ | ✅ | ✅ |
| Custom keyword rules | ❌ | ✅ | ✅ | ✅ |
| Governed AI sites | Up to 5 | Unlimited | Unlimited | Unlimited |
| Outbound (AI response) scanning | ❌ | ✅ | ✅ | ✅ |
| Detection Engines | ||||
| Entropy-based unknown-secret detection | ❌ | ✅ | ✅ | ✅ |
| OCR (screenshots, scanned PDFs, images) | ✅ | ✅ | ✅ | ✅ |
| Local ML/NER detection | ❌ | ❌ | ❌ | ✅ |
| Gateway | ||||
| Local AI gateway & multi-provider routing | ❌ | ✅ | ✅ | ✅ |
| Policy | ||||
| Allow / Warn / Mask / Block actions | ✅ | ✅ | ✅ | ✅ |
| Local policy engine | ✅ | ✅ | ✅ | ✅ |
| Central policy management & sync | ❌ | ❌ | ✅ | ✅ |
| Audit & Fleet | ||||
| Local audit log | ✅ | ✅ | ✅ | ✅ |
| Audit retention | 7 days | 90 days | 180 days | 365 days |
| Cloud audit export & compliance reports | ❌ | ✅ | ✅ | ✅ |
| Cloud audit sync | ❌ | ❌ | ✅ | ✅ |
| Fleet heartbeat, device reporting & dashboard | ❌ | ❌ | ✅ | ✅ |
| SIEM (syslog) export | ❌ | ❌ | Available | ✅ |
| Deployment | ||||
| Windows installer & browser extension | ✅ | ✅ | ✅ | ✅ |
| GPO deployment | ❌ | ❌ | ❌ | ✅ |
| Intune / SCCM deployment | ❌ | ❌ | ❌ | ✅ (guided) |
Questions
See the full FAQ, or contact us for Professional/Business/Enterprise quotes.