Add-ons: additional MCP clients · extra protected subjects · UK/EU data-residency guarantee · certification mark · priority anchoring. Unions & CMOs: ask about fiduciary onboarding.
What your subscription includes
Your issuer public-key trust anchor plus scoped M2M credentials (client id + secret) per environment. You hold no private key — and neither does Bridle.
The governance endpoints: subjects, grants, check (free & live), attest, audit. Validated at the wire against the H2A schemas.
@bridle/sdk + @bridle/adapters from the private registry — the governedGenerate seam for Synthesia / HeyGen / ElevenLabs.
A Bridle MCP server so agentic clients act compliantly: check_grant, attest, list_grants, get_decision_record, audit — scoped per studio.
The signed record of every act — the commercial product. Hash-chained (chain_intact) and, at L3, externally anchored and designed to be insurable.
Your tier sets the level you can prove. L1 verifiable today; L2 attested; L3 anchored — the level an underwriter relies on.
Compare plans
| Feature | Developer | Studio | Scale | Enterprise |
|---|---|---|---|---|
| Governance | ||||
| Point-of-use checks | Free ∞ | Free ∞ | Free ∞ | Free ∞ |
| Governed acts / month | 250 | 5,000 | 50,000 | Custom |
| Protected subjects | 3 | 25 | 150 | Custom |
| Evidence | ||||
| Attestations & decision records | Sandbox | ✓ | ✓ | ✓ |
| Audit chain (chain_intact) | ✓ | ✓ | ✓ | ✓ |
| L3 external anchoring (eIDAS + witness) | — | — | Early access | ✓ |
| Insurable evidence pack | — | — | — | ✓ |
| Integration | ||||
| REST API | ✓ | ✓ | ✓ | ✓ |
| @bridle/sdk + adapters (private registry) | Dev | ✓ | ✓ | ✓ |
| MCP server (M2M) | Dev | 1 client | Multiple | Custom |
| SSO | — | — | ✓ | ✓ |
| Operations | ||||
| UK/EU data residency | — | ✓ | ✓ | Guaranteed |
| Support | Community | Priority | Dedicated | |
| Uptime target / SLA | — | 99.5% | 99.9% | SLA |
| Certification mark | — | — | Add-on | ✓ |
Worked example
An illustrative synthetic-media studio governing a roster of performers across promotional work — the shape of Bridle's customer-zero.
A studio governs 48 performers and runs about 12,000 governed renders a month — promotional video, UK & EU, each under a scoped 500-render-minute mandate with a sub-30ms revocation horizon. Every render leaves a signed decision record; the chain stays intact, witnessed.
£1,999 / month (≈ £24k / year). 12,000 acts sit well inside the 50,000 allowance. Every act is a signed, tamper-evident record — the artefact procurement and an underwriter rely on.
A single contested synthetic-likeness use can mean £50k–£250k+ in legal defence and settlement, a stalled production, and reputational damage — with no defensible account of what was allowed.
Illustrative economics. Figures are indicative for scale, not a quote or a guarantee; legal-exposure ranges are market colour, not a claim about any specific matter. Bridle produces signed, tamper-evident records and is designed to be insurable at L3 — it is not insurance.
Roadmap
Honest by construction: a level claims only what it can prove. A live deployment is L1 today. Here's what's real now, and what each tier unlocks as it lands.
Schema-valid grants, the fail-closed verification algorithm, and real ES256 status-list signing & verification with an internal chain_intact audit.
All tiersES256 verification of the two detached grant signatures (consent + issuance); signature_state becomes real; interim issuer namespace pinned.
Unlocks L2 · StudioReplace the in-memory store with a durable store with data residency — production persistence for decision records and audit.
Studio · ScaleExternal anchoring: eIDAS-qualified TSA timestamps + an independent witness co-signature; the issuer signing key in genuine fiduciary custody. The level an underwriter can rely on.
Scale (early access) · EnterpriseA console to enrol actors, issue & revoke grants, and watch the decision-record trail live — mapping grant scope to Equity Rider fields for procurement.
Studio · EnterpriseA certification mark for conformant pipelines, more generator adapters (Synthesia / HeyGen / ElevenLabs), and the H2A v1.0 format freeze.
EnterpriseQuestions
Checks must be free and live — revocation happens in real time, so a cached or metered check would be a stale check. What you pay for is the guarantee: the signed attestation and decision record Bridle produces for each act of use. As the docs put it, "the check is free; the guarantee is not."
No. Bridle governs and records — it doesn't generate, and it holds no private key. Biometric data stays in the operator's own infrastructure; Bridle works over grant IDs, output hashes and signed status lists.
L3 adds external anchoring — eIDAS-qualified timestamps and an independent witness co-signature — so the record doesn't rely on anyone's own clock. That's the level an underwriter can rely on. We say "designed to be insurable," not "insured."
Only the rights-holder's fiduciary, by re-signing the status list at their own service. Bridle just fetches and verifies it, and fails closed. Withdrawal takes effect at the next point-of-use check, within the grant's revocation horizon.
Book a demo. You'll receive your trust anchor, scoped API keys, private-registry access to @bridle/sdk, and your MCP client. Onboarding is currently guided.
Get started
A ten-minute walkthrough of the governed actor — and we'll size the right tier with you.