Enterprise
Least privilege, an audit trail, and rollback your security review can check.
Enterprise adds the controls security teams ask for before they approve an agent integration. Each is off until an administrator turns it on, and each is enforced on the server.
From $12,000 a year, invoiced yearly.
Controls in the Enterprise plan
- Tamper-evident log
- Every action log row is sealed into a SHA-256 hash chain within minutes, with a daily checkpoint signed by the site’s Ed25519 key. wp agentwarden log verify reports edited, removed, or inserted rows.
- SIEM push
- Sealed rows and checkpoints go to syslog over TLS, TCP, or UDP, Splunk HTTP Event Collector, Datadog Logs, or Elasticsearch every five minutes. Each event has a stable ID, so retries never duplicate.
- Lockdown
- Turn off the MCP adapter’s default server and stop application passwords from running abilities, so governed agents are the only way AI clients act on the site.
- Retention and legal hold
- Keep agent history from 30 days to 10 years. A legal hold stops every deletion, uninstall included, until it is released, and both events are recorded in the sealed log.
- Signed compliance report
- A quarterly summary of agents, activity, approvals, controls, and log integrity, signed with the site’s checkpoint key so an auditor can verify it offline.
- Contract and support
- A data processing agreement, a named support contact, and an SLA. Priced per organisation, for up to 50 sites, up to 250, or unlimited.
Verifiable from the command line
The log chain, its checkpoints, and compliance reports can be checked without trusting the admin screens that show them.
WP-CLI referenceTerminal
wp agentwarden log verify
wp agentwarden retention set 2555
wp agentwarden compliance report --quarter=2026-Q3
wp agentwarden compliance verifyBring us your security questionnaire
Tell us how many sites you run and what your review needs. We answer with the controls that cover it and a quote.