Enterprise

Least privilege, an audit trail, and rollback your security review can check.

Enterprise adds the controls security teams ask for before they approve an agent integration. Each is off until an administrator turns it on, and each is enforced on the server.

From $12,000 a year, invoiced yearly.

Controls in the Enterprise plan

Tamper-evident log
Every action log row is sealed into a SHA-256 hash chain within minutes, with a daily checkpoint signed by the site’s Ed25519 key. wp agentwarden log verify reports edited, removed, or inserted rows.
SIEM push
Sealed rows and checkpoints go to syslog over TLS, TCP, or UDP, Splunk HTTP Event Collector, Datadog Logs, or Elasticsearch every five minutes. Each event has a stable ID, so retries never duplicate.
Lockdown
Turn off the MCP adapter’s default server and stop application passwords from running abilities, so governed agents are the only way AI clients act on the site.
Retention and legal hold
Keep agent history from 30 days to 10 years. A legal hold stops every deletion, uninstall included, until it is released, and both events are recorded in the sealed log.
Signed compliance report
A quarterly summary of agents, activity, approvals, controls, and log integrity, signed with the site’s checkpoint key so an auditor can verify it offline.
Contract and support
A data processing agreement, a named support contact, and an SLA. Priced per organisation, for up to 50 sites, up to 250, or unlimited.

Verifiable from the command line

The log chain, its checkpoints, and compliance reports can be checked without trusting the admin screens that show them.

WP-CLI reference
Terminal
wp agentwarden log verify
wp agentwarden retention set 2555
wp agentwarden compliance report --quarter=2026-Q3
wp agentwarden compliance verify

Bring us your security questionnaire

Tell us how many sites you run and what your review needs. We answer with the controls that cover it and a quote.