Pricing · pre-launch

Open-source SDK is free forever.
Hosted tiers start at $1,500/month.

The KGE SDK is Apache-2.0 — drop it in, ship audit-stream + vault contracts, never pay us anything. Hosted tiers add the parts a busy B2B SaaS company would rather not run themselves: Decision Card review, vault contract hosting, quarterly Pulse positioning, integration support.

Free SDKUse the package without a commercial commitment. Hosted tiers are for proof operations, not runtime lock-in.
Buyer proofTurn audit-stream, vault contracts, and Decision Cards into material a security reviewer can inspect.
Revenue dragReduce repeated questionnaire work and stalled enterprise reviews when trust evidence is the bottleneck.
Board storyPackage the investment as saved review time, cleaner evidence, and fewer deal-blocking trust gaps.

Three tiers · one architecture

All tiers use the same Apache-2.0 SDK. The difference is what's hosted for you and how much of the buyer-facing diligence response we run alongside.

Solo

$1,500/mo · annual

For B2B SaaS doing first SOC 2 readiness, embedding KGE to back the trust-boundary claim.

  • Open-source SDK (Apache-2.0, all versions)
  • Hosted Decision Card validator
  • 1 hosted vault contract surface (read-only)
  • Quarterly Pulse self-score badge
  • No live integration support
  • No custom Decision Card review
  • No RFP / questionnaire response assistance
Scale

$7,500/mo · annual

For B2B SaaS embedding into regulated verticals (HealthTech, FinTech, GovTech) where deals stall on security review.

  • Everything in Team
  • Unlimited hosted vault contract surfaces
  • Live integration support (Slack channel)
  • One RFP packet assembly per quarter
  • One AI tabletop facilitation per year
  • White-label Trust Center mirror at your subdomain
  • Quarterly private Pulse vertical brief

Choose by trigger event

The right tier is not about company vanity. It is about the buyer moment you need to survive without making engineering, security, and revenue teams rebuild the same packet every quarter.

Solo trigger

First serious security review

Pick Solo when one product line needs a credible audit-stream and Decision Card story, but you are not yet running multiple enterprise diligence tracks at once.

Team trigger

Repeat questionnaires are slowing sales

Pick Team when the same buyer questions keep pulling engineers into review calls and you need reusable answer logic, hosted proof, and quarterly positioning.

Scale trigger

Regulated buyers need a full packet

Pick Scale when HealthTech, FinTech, GovTech, or enterprise security teams expect a fuller proof room, RFP packet support, and live integration guidance.

Buyer-ready deliverables

Hosted tiers are priced around the proof objects buyers can review. The goal is to make the trust claim inspectable before it turns into another custom security-review project.

Decision packet

Reusable answers for the buyer room

  • Decision Card validator surface
  • Evidence language for RFP and questionnaire reuse
  • Buyer-readable claim boundaries
Evidence trail

Hosted proof instead of screenshots

  • Vault contract surfaces by product line
  • Audit-stream posture buyers can inspect
  • Quarterly proof refresh cadence
Executive readout

Clear language for spend approval

  • Pulse positioning brief by tier
  • Board-facing ROI narrative
  • Risk, cost, and deal-review framing

Honest ROI math

These numbers come from public industry benchmarks for B2B SaaS in regulated verticals. Your actual numbers will differ. The framing is for executive sponsors who need to defend a $1.5K–$7.5K monthly line item against the alternative — which is usually another consultant retainer plus three internal hours per security questionnaire.

Per quarter (Team tier reference)

24 hrs
Security questionnaire response time saved vs. starting from scratch each cycle
3-5 days
Enterprise deal-cycle compression when buyers can verify trust-boundary claims at signature time
$24K-$60K
SOC 2 audit prep cost reduction in year 1 when audit-stream + vault contracts are already in place

Synthetic but defensible. Public benchmarks: Vanta industry report (questionnaire response time), Bessemer Cloud 100 (deal cycle data), AICPA SOC 2 cost surveys. We'll show you the citations in a discovery call.

→ Run the ROI calculator on YOUR numbers

What's included in every tier

Every tier ships against the same Apache-2.0 SDK. The differences above are about what's hosted and how much of the response work we share, not about the underlying technology.

SDK · always free

kinetic-gain-embedded

TypeScript dual ESM/CJS · zero runtime dependencies · Node 20+ · hash-chained audit · Decision Card vault contract enforcement · ed25519 signing.

View on GitHub →

PROCUREMENT PACKET · always free

17-section starter template

Fill-in template for the security review packet enterprise buyers expect. §8 makes 4 KGE-backed verifiable claims. Aligned with SOC 2 CC9.2 + ISO/IEC 27018 + GDPR Art. 28 vocab — without claiming what you haven't earned.

View on GitHub →

What this replaces

KGE hosted tiers should be evaluated against the work they remove or standardize, not against the free SDK. If one of these costs is already showing up in your operating rhythm, the hosted tier has a clearer buyer case.

Consultant drag

Recurring retainer work that mostly repackages evidence your product should already be producing.

Questionnaire loops

Repeated engineering interruptions to answer the same audit-stream, AI, data, and access-control questions.

Trust-center gaps

Static trust pages that claim readiness without giving buyers a verifiable Decision Card or vault-contract trail.

Board ambiguity

Vague security-progress updates that do not tie spend to buyer friction, deal review, and evidence reuse.

Honest pre-launch framing

What you're getting on the waitlist · what you're not

KGE is pre-commercial. The open-source SDK is production-stable (v1.0-prod). The hosted tiers are not yet purchasable — we're collecting waitlist + first-customer interest signal before opening commercial flow. When you join the waitlist, here's what you're committing to and what we are:

  • You get: early-customer pricing locked at the rates above for 12 months from public launch, monthly product-update emails, priority slot when commercial flow opens.
  • You don't pay: nothing until you choose to opt in to a tier after commercial launch.
  • We won't: oversell, claim SOC 2 we don't have, claim certifications we haven't earned, or pretend the hosted tiers are live until they are.
  • What's blocking commercial launch: EIN → bank → Stripe → invoicing infrastructure (mechanical work, weeks not months).

If you need this productized for a specific deal in flight, say so on the contact form — that's the signal that triggers an out-of-band response.