The challenges enterprise teams bring to us
Governance, audit, procurement, and enforcement for AI at scale
No policy enforcement
Engineers choose models by habit. There are no routing rules, no budget caps, and no approval gates to stop runaway spend.
Audit trails are missing
Security teams cannot answer who used which provider, with which key, or what prompts were sent — because nothing logs it.
Procurement lacks evidence
Finance teams need chargeback reports, cost attribution, and spend forecasts before they can reconcile AI into the budget.
SSO and RBAC are gaps
Enterprise procurement requires SAML 2.0, SCIM provisioning, and role-based access before any tool enters the stack.
Sensitive data exposure risk
Prompts pass through unapproved providers with no DLP scanning, no redaction, and no data-residency guarantees.
Reliability depends on one provider
When a provider has an incident, agentic workflows fail completely. There are no fallback routes or health-aware retries.
What's included in Enterprise
SSO / SAML 2.0 + OIDC
Okta, Azure AD, Google Workspace, PingIdentity, and any SAML 2.0 IdP. Enforce SSO and disable password login.
SCIM 2.0 provisioning
Automatically provision and deprovision users from your IdP. RFC-compliant Users and Groups endpoints.
Policy as code
Declare routing, budget, and access rules in YAML. Deploy via CI/CD. Full version history with rollback.
DLP scanning
Internal regex patterns plus Nightfall AI integration. Block, redact, or flag sensitive data before it leaves your network.
Model access governance
Per-user, per-team, per-role tier limits. Block specific providers for GDPR compliance. Enforce approval workflows.
OpenTelemetry traces
Every request emits spans: routing, DLP, budget, execution. Export to Jaeger, Datadog, New Relic, or any OTLP collector.
SIEM audit export
CEF format for Splunk/QRadar. JSONL for Elastic/OpenSearch. Real-time push streams with configurable retention.
Evaluation framework
Run test datasets against multiple models. Score quality with LLM-as-judge. Validate before you change routing configs.
Prompt registry
Semantic versioning for system prompts. Draft → staging → production workflow. Diff view, rollback, eval integration.
Chargeback reports
Monthly PDF/CSV reports allocating AI spend to teams and departments. Delivered automatically to finance.
Self-hosted deployment
Docker Compose and Helm chart for air-gapped or VPC deployments. Zero data leaves your infrastructure.
Quarterly governance report
Board-ready PDF: spend trends, risk summary, compliance status, team adoption, cost efficiency recommendations.
Compliance and security
ModelSpend is built for regulated industries. Every enterprise deployment includes full documentation for security reviews.
Common questions
Does ModelSpend support SSO?
Yes — SAML 2.0 and OIDC, with native connectors for Okta, Azure AD, Google Workspace, and PingIdentity. You can enforce SSO organisation-wide and disable password login.
Is ModelSpend SOC 2 compliant?
A SOC 2 Type II audit is in progress. A pen test report is available on request, and GDPR/HIPAA BAA documentation is available for all enterprise customers.
Can I deploy ModelSpend on-premise or in a private VPC?
Yes. We provide Docker Compose and Helm chart for VPC or air-gapped deployments. In air-gapped mode, zero data leaves your infrastructure.
How does pricing work for Enterprise?
Enterprise starts at $299/month (or $229/month billed annually). Volume pricing is available for teams routing more than 500,000 executions per month. Request an enterprise evaluation for a custom quote.
Evaluating the technical depth behind these features?
Read the technical moat pageIntegrates with your observability and security stack
- OpenTelemetry
- Datadog
- New Relic
- Jaeger
- Splunk
- Elastic
- Sentry
- Nightfall