Indicative launch pricing · subject to change

The check is free.
The guarantee is not.

You never pay to check. Point-of-use checks are free and unlimited — they must be, because revocation is live and a cached permit is a stale permit. You pay for governed acts: the signed attestations and decision records Bridle produces — the tamper-evident evidence. Your tier sets the conformance level, MCP access, data residency and support.
Monthly
Annual 2 months free
Developer
Build and prove the flow in a sandbox.
Free
No card required
L1 · Verifiable
  • 250 governed acts / mo
  • 3 protected subjects
  • Sandbox issuer + trust anchor
  • SDK, API & MCP (dev keys)
  • Community support
Start free
Studio
Production governance for a synthetic-media operator.
£499 /mo
billed monthly
L2 · Attested
  • 5,000 governed acts / mo, then £0.06/act
  • 25 protected subjects
  • Production API keys + MCP (M2M)
  • @bridle/sdk private-registry access
  • Attestations, decision records, audit
  • UK/EU residency · email support · 99.5%
Book a demo
Scale
Higher volume, SSO, and early anchoring.
£1,999 /mo
billed monthly
L2 + L3 early access
  • 50,000 governed acts / mo, then £0.04/act
  • 150 protected subjects
  • Everything in Studio, plus:
  • SSO · higher rate limits · multiple MCP clients
  • L3 anchoring early access as it lands
  • Priority support · 99.9%
Book a demo
Enterprise
Underwriter-grade evidence and a real fiduciary.
Custom
Talk to us
L3 · Anchored
  • Custom volume & subjects
  • L3 anchoring — eIDAS TSA + witness
  • Dedicated fiduciary / issuer integration
  • Data-residency guarantee · SLA
  • Insurable evidence pack · certification mark
  • Procurement, GC & underwriter support
Talk to sales

Add-ons: additional MCP clients · extra protected subjects · UK/EU data-residency guarantee · certification mark · priority anchoring. Unions & CMOs: ask about fiduciary onboarding.

What your subscription includes

Keys, API, SDK and MCP — one integration surface.

trust anchor · keys

Keys

Your issuer public-key trust anchor plus scoped M2M credentials (client id + secret) per environment. You hold no private key — and neither does Bridle.

/v0 · REST

API

The governance endpoints: subjects, grants, check (free & live), attest, audit. Validated at the wire against the H2A schemas.

@bridle/sdk · adapters

SDK

@bridle/sdk + @bridle/adapters from the private registry — the governedGenerate seam for Synthesia / HeyGen / ElevenLabs.

HTTP + SSE · M2M

MCP server

A Bridle MCP server so agentic clients act compliantly: check_grant, attest, list_grants, get_decision_record, audit — scoped per studio.

signed · tamper-evident

Decision records

The signed record of every act — the commercial product. Hash-chained (chain_intact) and, at L3, externally anchored and designed to be insurable.

L1 → L2 → L3

Conformance

Your tier sets the level you can prove. L1 verifiable today; L2 attested; L3 anchored — the level an underwriter relies on.

Compare plans

Every feature, by tier.

FeatureDeveloperStudioScaleEnterprise
Governance
Point-of-use checksFree ∞Free ∞Free ∞Free ∞
Governed acts / month2505,00050,000Custom
Protected subjects325150Custom
Evidence
Attestations & decision recordsSandbox
Audit chain (chain_intact)
L3 external anchoring (eIDAS + witness)Early access
Insurable evidence pack
Integration
REST API
@bridle/sdk + adapters (private registry)Dev
MCP server (M2M)Dev1 clientMultipleCustom
SSO
Operations
UK/EU data residencyGuaranteed
SupportCommunityEmailPriorityDedicated
Uptime target / SLA99.5%99.9%SLA
Certification markAdd-on

Worked example

What it costs a studio.

An illustrative synthetic-media studio governing a roster of performers across promotional work — the shape of Bridle's customer-zero.

A studio governs 48 performers and runs about 12,000 governed renders a month — promotional video, UK & EU, each under a scoped 500-render-minute mandate with a sub-30ms revocation horizon. Every render leaves a signed decision record; the chain stays intact, witnessed.

48performers under governance
12,000governed acts / month
£0.17all-in per governed act
<30 msrevoke → halt, measured

With Bridle — Scale

£1,999 / month (≈ £24k / year). 12,000 acts sit well inside the 50,000 allowance. Every act is a signed, tamper-evident record — the artefact procurement and an underwriter rely on.

Without it — the exposure

A single contested synthetic-likeness use can mean £50k–£250k+ in legal defence and settlement, a stalled production, and reputational damage — with no defensible account of what was allowed.

Illustrative economics. Figures are indicative for scale, not a quote or a guarantee; legal-exposure ranges are market colour, not a claim about any specific matter. Bridle produces signed, tamper-evident records and is designed to be insurable at L3 — it is not insurance.

Roadmap

Conformance climbs L1 → L2 → L3.

Honest by construction: a level claims only what it can prove. A live deployment is L1 today. Here's what's real now, and what each tier unlocks as it lands.

L1 · Now

Verifiable Live

Schema-valid grants, the fail-closed verification algorithm, and real ES256 status-list signing & verification with an internal chain_intact audit.

All tiers
L3

Anchored — underwriter-grade Planned

External anchoring: eIDAS-qualified TSA timestamps + an independent witness co-signature; the issuer signing key in genuine fiduciary custody. The level an underwriter can rely on.

Scale (early access) · Enterprise
Sprint 6

Governed console Planned

A console to enrol actors, issue & revoke grants, and watch the decision-record trail live — mapping grant scope to Equity Rider fields for procurement.

Studio · Enterprise
Beyond

Certification & ecosystem Planned

A certification mark for conformant pipelines, more generator adapters (Synthesia / HeyGen / ElevenLabs), and the H2A v1.0 format freeze.

Enterprise

Questions

Pricing, plainly.

Why do I pay for "governed acts" and not checks?

Checks must be free and live — revocation happens in real time, so a cached or metered check would be a stale check. What you pay for is the guarantee: the signed attestation and decision record Bridle produces for each act of use. As the docs put it, "the check is free; the guarantee is not."

Is my performers' likeness data stored with Bridle?

No. Bridle governs and records — it doesn't generate, and it holds no private key. Biometric data stays in the operator's own infrastructure; Bridle works over grant IDs, output hashes and signed status lists.

What does "L3 / designed to be insurable" mean?

L3 adds external anchoring — eIDAS-qualified timestamps and an independent witness co-signature — so the record doesn't rely on anyone's own clock. That's the level an underwriter can rely on. We say "designed to be insurable," not "insured."

Who can revoke — and how fast?

Only the rights-holder's fiduciary, by re-signing the status list at their own service. Bridle just fetches and verifies it, and fails closed. Withdrawal takes effect at the next point-of-use check, within the grant's revocation horizon.

How do I get access?

Book a demo. You'll receive your trust anchor, scoped API keys, private-registry access to @bridle/sdk, and your MCP client. Onboarding is currently guided.

Get started

See it live, then pick a plan.

A ten-minute walkthrough of the governed actor — and we'll size the right tier with you.