Transparent pricing · No per-seat surprises

One path from
sandbox to production

Evaluate one protected-file workflow with software keys. Pay for production authority, evidence retention, and the custody boundary your threat model requires.

Monthly billing. Annual terms are available on contracted plans.

Start here

Taking a sensitive-document workflow into production?

Most teams reach us with a specific blocker — an enterprise customer asking where the keys live, a security review holding up a launch, or an agent moving from demo into a real document workflow. We scope those directly rather than guessing at a plan. Tell us what is blocked and we will tell you whether we can solve it, and what it costs.

Typical response within one business day. Singapore time zone.

Commercial progression

Where the ladder goes once a workflow is in production. Every paid plan covers both Cloak Files and Cloak KMS under one subscription.

Free Developer
$0 /month

Run the KMS agent quickstart with software keys. No credit card.

  • 50 file operations / month
  • 10 signing operations / month
  • Developer sandbox; no team collaboration
  • REST API + Agentic AI (MCP) — software sandbox
  • SoftHSM software-key sandbox
  • Signed audit receipts
  • Hardware HSM key custody
  • Priority support
Start free →
Customer-Controlled Key Custody
$1,499 /month
+ $4,900 one-time setup · 6-month minimum

The protected-file workflow with Cloak Gateway and a supported customer-owned HSM. The setup fee covers compatibility assessment, gateway deployment, recovery planning, and testing.

  • Cloak Gateway with your user-owned HSM devices
  • Contracted users and workloads
  • Enforced key and operation limits by agreement
  • Agentic AI (MCP) access
  • Scoped agent credentials + audit log
  • Documented remote setup and support
  • Gateway setup and recovery responsibilities agreed before production
Request setup assessment →
Enterprise HSM + Signing
Custom
From $24,900 first-year contract value

Dedicated infrastructure, contractual controls, signing add-ons, on-prem deployment options, and support terms by agreement.

  • Dedicated deployment option
  • Contracted limits
  • Signing add-on by agreement
  • SSO / SAML
  • On-prem option
  • SLA by agreement
Talk to us →

Frequently asked questions

What is a signed audit receipt?
Supported protected-file operations return a signed receipt containing recorded workflow fields. A verifier can check the issuer signature and payload integrity offline; it cannot independently prove every real-world claim in the payload. KMS-wide operation receipts are not yet a shipped default.
Which plan should I start with?
Start with the Developer Sandbox and complete one protected-file workflow. Move to the Managed Key Custody for production, or the Customer-Controlled Key Custody when your organization must own the root trust. Vault and Batchsign are optional capabilities for qualified workflows.
What makes KMS "HSM-backed"?
In a hardware-custody configuration, private-key operations execute through the configured HSM and private-key material is not returned by the operation. Isolation, certification, availability, and operator controls depend on the exact managed or customer-controlled device and deployment.
Can AI agents use Cloak products?
Cloak KMS exposes a working MCP endpoint with scoped agent credentials. The protected-file MCP integration is implemented, but the public self-serve file-plus-receipt quickstart remains a launch gate. Vault and Batchsign are not current acquisition surfaces. Per-session budgets are planned, not a shipped plan entitlement.
Is Batchsign AATL-compliant on all plans?
Batchsign certificate-chain and plan terms depend on the configured signing service. Confirm the exact certificate, signer identity, and validation path before production reliance.
Where is data stored?
Deployment region, metadata storage, and plaintext exposure depend on the selected workflow. The protected-file client is designed to encrypt at the client or agent host; KMS still receives the operation inputs submitted by the caller. Review the exact data-flow and deployment document before production use.

Ready to protect your files?

Start free in minutes. No credit card. Full API access from day one.

Cloak is governed by the OMMAU Charter — humans authorize, agents execute, receipts record supported actions.