Enterprise tier
Policy-controlled AI codebase maintenance for regulated engineering teams.
Enterprise is for buyers who need an AI codebase maintenance engineer inside a stricter operating boundary: private deployment, customer key custody, signed release evidence, approval policy, and procurement-ready controls. The order form defines the exact support, data, runtime-signal, and deployment scope.
Securie-managed AI codebase maintenance for regulated engineering teams that need reviewable repairs, procurement-ready evidence, and stronger operational controls.
- ✓Business+ maintenance depth across unlimited repos
- ✓Dual-signature evidence option
- ✓SSO/SAML, SCIM, SIEM export, and audit-log retention
- ✓Custom data residency and model-routing policy
- ✓Named founder/SRE support by contract
Enterprise Sovereign
CustomCustomer-VPC, on-prem, or air-gapped deployment where the customer owns the host and holds the keys.
- ✓Customer-controlled host, network, and key custody
- ✓No-frontier or private-inference topology by contract
- ✓Signed-bundle update stream for restricted environments
- ✓Tenant-controlled GitHub App and attestation key options
- ✓Procurement matrix scoped in the signed order form
Engineering leaders
Keep senior review, tested repairs, regression proof, architecture checks, and release evidence in the delivery path without creating another manual queue.
Security leaders
Add code-level proof, reviewable repair PRs, and policy gates while keeping existing GRC, SIEM, EDR, and incident-response programs in place.
Regulated buyers
Run with customer-controlled deployment, data residency, private inference, and signed evidence scoped in the contract.
Procurement matrix
Managed vs Sovereign, line by line. The matrix shows what is productized and what is order-form scoped.
Deployment
| Line item | Managed | Sovereign |
|---|
| Securie-managed cloud | default | optional |
| Customer VPC | contract option | yes |
| On-premises / air-gapped | not typical | yes |
| Encryption-key custody | Securie or customer-managed | customer exclusively |
Assurance Scope
| Line item | Managed | Sovereign |
|---|
| Maintainer axes | 8 axes | 8 axes |
| Tested repair PRs | contract envelope | contract envelope |
| Release gates | policy-scoped | tenant-policy-scoped |
| Runtime signal validation | contract-scoped | contract-scoped |
Evidence
| Line item | Managed | Sovereign |
|---|
| On-demand sandbox replay (Business+) | contract-scoped | contract-scoped |
| DSSE / in-toto evidence | included | included |
| Dual-signature attestation | option | included when scoped |
| Evidence retention | order-form scoped | order-form scoped |
Controls
| Line item | Managed | Sovereign |
|---|
| SSO/SAML | included | included |
| SCIM | included | included |
| SIEM export | included | included |
| MCP/tool gateway and credential broker | contract option | contract option |
Support
| Line item | Managed | Sovereign |
|---|
| Named support | founder/SRE named in contract | founder/SRE named in contract |
| Onboarding | implementation plan | implementation + deployment plan |
| Response targets | order-form scoped | order-form scoped |
| Custom runbooks | available | available |
Sovereign deployment options
Three topologies. Tenant key custody and signed-bundle update streams are available in every sovereign mode; Securie access paths are scoped in the customer-controlled deployment plan.
Customer VPC
Helm + Terraform modules into the customer's AWS, GCP, or Azure account. Network egress, model routing, and support access are explicitly scoped.
On-premises
Tenant operates the cluster. Securie ships signed update bundles and an implementation plan for tenant-controlled rollout timing.
Air-gapped
Tenant takes signed update bundles through approved transfer. Offline operation and telemetry export are defined in the deployment agreement.
What Enterprise tier does not include by default
Honest scope. These remain contract add-ons, partner motions, or adjacent tools unless explicitly written into the order form:
- - Cash breach indemnification or service-credit warranties
- - Standing 24/7 SOC staffing operated by Securie
- - Dedicated red-team services or scheduled consulting engagements
- - Employee endpoint EDR / EPP
- - Generic malware forensics or nation-state attribution
- - Email gateway, OT / ICS / SCADA, firmware, or hardware security