Enterprise
Org seals the run.
Humans add bound reviews.
Auditors verify offline.
EPI is a file-first evidence layer for enterprises — not a dashboard login. You get portable cryptographic evidence, org key trust, policy checks, Annex tooling, and CI gates. Optional hosted verify/SCITT for scale. Self-host when you must.
Honest pricing: free forever offline · sprint is the only buyable offer this month · control plane is design partners only. See /pricing.
15-minute path (keep it simple)
Two commands for your engineer. No dashboards. No API keys required for a pilot pack.
pip install epi-recorder
epi enterprise setup
# record one agent run → your-run.epi
epi enterprise pack your-run.epi
# → send auditor-pack.zip to security / audit
Online checks (optional): sign in → Verify a file. Details: Enterprise in 15 minutes.
Shipped for enterprise
- Sealed
.epi+ offline verify/view - Org keys + trust bundles
- Policy + fault analysis
- Annex IV tooling + multi-sign + CLI PDF
- GitHub Action CI gate
- Optional hosted verify + remote SCITT
- Self-hosted gateway / Decision Ops
Services (human + contract)
- Dedicated onboarding / pilot
- Custom hosted volume & ops attention
- Legal & procurement support
- SLA only if signed in writing
Roadmap (not product yet)
- Cloud SSO / SAML
- Multi-tenant SaaS seats
- FDA / HIPAA / NIST adapter suite
- Managed multi-tenant DID registry
Acceptance gate
What PASS means for security and CI.
Modes
- Air-gapped seal:
EPI_NOTARIZE=0 - Standard seal: RFC 3161 on by default (network at seal only)
- Verify / view: integrity + signature offline; identity from local trust store
What PASS means
- Claims / insurers: always
epi verify --policy strict(integrity + org-pinned sealer + completeness) --reviewBinding True → human review bound to sealed evidence- Standard default: unpinned sealer → WARN · UNVERIFIED IDENTITY (valid seal ≠ known who; not claim-ready)