Twenty people or two thousand, the install is the same and it takes an afternoon. Everything in Pro, plus the company layer: IP Protection that learns what's sensitive in Salesforce, Slack, Notion, SQL, Workday and more, Governance Policies that travel with every employee and hold inside Claude Code, Microsoft Copilot, Hermes Agent & Private MCP, Private Memory your organization owns, and shadow-AI discovery across every seat.
Max is not a plan you graduate into. It is the plan the moment a second person on your domain needs covering, and it stays the plan as you grow. What changes is the seat price, not the product. There is no trial mode: Max is the full paid product from the first seat, and the free way to feel the engine first is Pro.
Everyone already uses ChatGPT and nobody wrote a policy. Attach your domain, send one installer, and the whole firm is governed by lunchtime. No infrastructure to stand up, no consultant, no security hire. $25 per seat a month at 10 to 99 seats, billed annually.
Provision and de-provision from the domain account, push policy by department, and watch shadow AI surface in a dashboard instead of a breach report. Your biggest customer's security questionnaire gets a straight answer. $21 per seat a month at 100 to 999 seats.
Roll out department by department or all at once. One policy plane holds across Claude Code, Copilot, every chat app and every MCP server, and your auditor gets evidence in one click. $17 per seat a month from 1,000 seats, 43% off the entry rate.
Policies enforced on-device that reason about privacy, intent and risk in real time: out of the box, custom-built, or from the marketplace.
IP Protection starts where your most critical data lives. Max connects to those platforms and learns what's sensitive at the source (customer records, employee data, IP, secrets), so the moment it surfaces in any AI, in a prompt, a paste or an agent's tool call, it's intercepted before it leaves the device.
Accounts, contacts, pipeline and deal terms stay out of every prompt, even when your team puts AI to work on the CRM.
Customer dataChannels are where secrets leak. Keys, credentials and internal chatter are recognized and protected everywhere AI reads or writes.
Secrets & commsCompensation, reviews and personal employee records: governed wherever HR and managers put AI to work.
Employee dataERP and financials (vendor terms, margins, forecasts): shielded from exfiltration across every AI surface your org touches.
FinancialsRoadmaps, specs and internal wikis: your IP and know-how stay yours while your team drafts with AI on top of them.
IP & know-howContracts, board decks and shared files: classified at the source and protected the moment they meet a model.
Files & contractsMax keeps everything you love about Pro (Privacy Twins, real-time on-device interception, SSO) and adds the four things a company needs: IP Protection, Governance Policies, Private Memory and shadow-AI discovery. Together they turn whoever owns risk in your company, the CISO, the COO or the founder, from blocker into enabler.
Max connects to Salesforce, Slack, Notion, SQL, Workday and more, and learns what is sensitive where it actually lives: customer records, employee data, deal terms, credentials, know-how. The moment any of it surfaces in a prompt, a paste or an agent's tool call, it is intercepted before it leaves the device.
Define what your company can do with AI and enforce it on-device. Block models, gate access behind training paths, intercept and steer prompts, redact at the wire. The same policies hold inside Claude Code, Microsoft Copilot, ChatGPT, Gemini, Grok and Hermes Agent, governing what agents can read, write and send.
What one teammate establishes in their AI, the whole team's AIs can know: in twin-space, under policy, with a full audit trail. Team and org scopes, fleet Memory Guard, and a Private MCP memory server so internal agents reach tools, data and org memory without anything leaking to a public host. Explore Private Memory.
Max turns every laptop into its own sensor: the first DSPM that lives on the endpoint discovers, classifies and continuously monitors sensitive IP, PII, PHI and PCI where it actually lives, and surfaces every unsanctioned AI tool before it becomes an incident. Prove it to your auditors with one click.
On-device. Autonomous. Purpose-built to reason about privacy, intent and risk in real time, across every AI your team touches. The policies ship out of the box, you build your own, or you pull from the marketplace. This is what policy management looks like when it's built for the AI OS instead of bolted onto a legacy stack.
Understand what an agent is actually trying to do before it does it. Authorize, alert or quietly redact based on intent, not just keywords.
Catch jailbreaks, tool-call hijacks and exfiltration patterns at the endpoint. The policy reasons about adversarial intent so your humans don't have to.
Drop in a Legal Agent that knows privilege, or a Financial Agent that knows MNPI. Agents bring vertical intelligence to every interaction, without retraining a model.
Customize and ship your own policies, or enable privacy, security and governance policies from the marketplace. Enrich any AI conversation across Claude, ChatGPT, Gemini, Copilot, Grok, Perplexity, Hermes Agent and more.
Governance Policies are enforced on-device, so the same rules apply whether your team is in Claude Code, ChatGPT, Gemini, Microsoft Copilot, Grok, Perplexity, Hermes Agent, or a custom MCP stack you built yesterday. Visibility and control of AI, regardless of which AI.
Agent governance recognizes the repo, the on-device DSPM knows the secrets and PII inside it, and Privacy Twins substitute customer identifiers before any prompt or tool call leaves the laptop. Claude Code keeps moving. Your IP stays put.
Intent Detection recognizes the workflow, the Legal Agent flags an NDA clause, and Privacy Twins scrub vendor names, all before the request leaves the device. The CISO sees the event in the audit log. Nobody loses time.
On-device DSPM has already classified the data as MNPI. Org-wide controls require Copilot users to be in the "client-facing" training cohort. Not enrolled? Blocked at the endpoint. Enrolled? Privacy Twins keep the names out. Either way: no exfiltration.
Engineers, analysts and a custom Financial Agent all share the same internal context, without that context ever leaving the org. Same fluency. Zero exfiltration. Full audit.
Everything Pro protects, plus the agent surfaces where real work now happens. Max governs what every one of them can read, write and send off the device.
| AI system / agent | What Max governs | Status |
|---|---|---|
ChatGPT | Prompts & uploads twinned in real time, web & desktop | Governed |
Claude | Prompts & attachments twinned, web & desktop | Governed |
Gemini | Prompts & uploads twinned, web & desktop | Governed |
Microsoft Copilot | Chat twinned; agent actions controlled at the device level | Governed |
| Grok | Prompts & uploads twinned on grok.com & Grok Bot | Governed |
| PerplexityNew | Questions & attachments protected on perplexity.ai, on by default | Governed |
| Claude Code | Repo-aware agent governance: prompts & tool calls scrubbed before they leave the laptop | Governed · Max |
Copilot agents | What agent actions can read, write & exfiltrate, enforced on-device | Governed · Max |
| Hermes Agent | Covered via the Nous Portal & default Fireworks endpoints | Governed · Max |
| Private MCP | Internal tools over MCP, without leaking connections to a public host | Governed · Max |
Four tiers, applied automatically at checkout and at renewal. Drag to your headcount and the numbers move with you.
Every Max seat carries the full governance plane: IP Protection, Governance Policies, Private Memory and shadow-AI discovery.
| Max volume tier | Annual · per seat / mo | Monthly · per seat / mo | Off the 1-9 rate |
|---|---|---|---|
| 1-9 seatsSmall teams and pilots | $30 | $34 | List price |
| 10-99 seatsDepartments and growing firms | $25 | $29 | 17% annual15% monthly |
| 100-999 seatsCompany-wide rollout | $21 | $26 | 30% annual24% monthly |
| 1000+ seatsEvery employee, company-wide | $17 | $22 | 43% annual35% monthly |
Max is a strict superset of Pro. Use Pro, free for individuals, when it is one person protecting themselves. Use Max, paid from day one, the moment it is the business that needs protecting: IP Protection at the source, Governance Policies across every device and agent, Private Memory your organization owns, and shadow-AI discovery on every seat on your domain. For a self-hosted, sovereign deployment in your own VPC, that is Cloud, our enterprise tier.
| Capability | Pro | Max |
|---|---|---|
| Privacy Twins on-deviceReal-time interception across every AI app, web & desktop | Included | Included |
| PII, HIPAA, PCI & GDPR coverage | Included | Included |
| SSO support | Included | Included |
| IP ProtectionSalesforce, Slack, Notion, SQL, Workday & more: your secrets & IP protected at the source | – | Max only |
| Shadow-AI discoveryFirst-of-its-kind on-device DSPM. Every staff device becomes a sensor | – | Max only |
| Agent governance · Claude Code, Copilot & Hermes AgentNative control across real on-device agents, not just chat | – | Max only |
| Private MCP | – | Max only |
| Governance PoliciesIntent detection, injection guard, vertical & custom policies; block models, require training, intercept | – | Max only |
| Private MemoryOne governed memory across every AI, held in twin-space | – | Max only |
| Agent marketplace | – | Max only |
| Account scopeWho the account belongs to | One individual | The whole company, 2 seats to 2,000 |
| Company domain accounts & volume pricingMore than one user on a domain? The domain runs on Max | – | Max only |
| PricingAnnual billing on Max saves up to 23% | FreeOne person · no credit card, ever | $34 to $22/mo · $360 to $204/yrBy volume, see the tiers above · paid from day one |
Our loan officers were pasting spreadsheets into ChatGPT every day to draft narratives. PrivacyPal made that safe overnight. We didn't have to change a single habit.