Pricing

One plan. Every feature.
Price drops as you grow.

Start free with visibility and risk scores for up to 5 users. Full access starts at $7/user/mo — blocking, redaction, endpoint agent, SSO, SIEM, everything. Graduated pricing: your first 50 users are $7, the next 150 are $6, and beyond that $5. Your effective rate drops automatically as you grow.

users
$42 /mo
$7/user · Team tier
Free
$0
up to 5 users
visibility & risk scores only
Team
$7/user
first 50 users
all features included
Growth
$6/user
users 51–200
all features included
Scale
$5/user
users 201–500
all features included
Enterprise
Custom
500+ users
What's included

Every paid user gets everything. No feature gates.

Protection

  • Active blocking & redaction
  • Full prompt details & logging
  • Custom policies by group
  • Custom detectors / regex
  • Warning mode (advise users)
  • 200+ built-in detection rules

Deployment

  • Browser extension (Chrome, Firefox, Edge, Safari)
  • Endpoint agent (macOS, Windows, Linux)
  • MDM force-install bundles
  • One-click self-install

Identity & access

  • Google Workspace SSO
  • Okta, Azure AD, SCIM
  • OneLogin, JumpCloud, SAML 2.0
  • Per-user risk scoring

Compliance & integrations

  • SOC 2 / HIPAA / GDPR reports
  • SIEM & webhook stream
  • Audit log export
  • Slack & email alerts

Need to cover desktop apps, CLI tools, and unmanaged devices too? Add a Gateway device to any plan — starting at $999.

AI Gateway device

For office networks & everything the extension can't see

ships in 5 business days · 30-day returns
Blacksight Gateway G1
Gateway G1 — Mini

Office desktop

Small offices and remote sites up to 50 devices.

$999
one-time · includes 1 yr management
  • Devices supportedup to 50
  • Throughput1 Gbps
  • Form factordesktop
  • PowerUSB-C / 30W
  • Warranty2 years
Order G1
Blacksight Gateway G2 — Unit 1 Blacksight Gateway G2 — Unit 2
Gateway G2 — Pro

Multi-floor / HQ

Mid-sized companies up to 500 devices. Includes 2 units for redundant failover.

$1,799
one-time · 2 units · includes 1 yr management
  • Devices supportedup to 500
  • Units included2 (HA pair)
  • Throughput10 Gbps
  • Form factor1U rack
  • Powerredundant PSU
  • Warranty3 years
Order G2
Gateway — Enterprise

Custom deployment

Unlimited devices, multi-site, custom SLAs, and dedicated support.

Custom
tailored to your infrastructure
  • Devices supportedunlimited
  • Sitesunlimited
  • Throughputcustom
  • Replacementnext-business-day
  • Supportdedicated engineer
Talk to sales
Frequently asked

Pricing & deployment questions

See all features
Do all paid users really get every feature?
Yes. There are no feature gates. Every paid user gets blocking, redaction, custom policies, SSO, SIEM, the endpoint agent, and everything else. The only thing that changes with volume is your per-user price — it goes down as you add more people.
What does the Free tier include?
Free gives you the browser extension for up to 5 users with visibility, risk scores, and top destinations. It doesn't include prompt details, blocking, redaction, or the endpoint agent. Want all features for a small team? Just upgrade to $7/user/mo — works for any team size, even under 5.
How does per-user pricing work?
Pricing is graduated — like tax brackets. Your first 50 users cost $7/user/mo, users 51–200 cost $6/user/mo, and users 201–500 cost $5/user/mo. Each band applies only to the users in that range, so your effective per-user cost drops as you grow. For example, 100 users costs $650/mo ($6.50/user effective). Over 500, contact sales for custom pricing.
Can I really see results in 10 minutes?
Yes. Install the extension on 5 devices via the one-click installer. Have those people use AI for a few minutes. Open the dashboard — you'll see destinations, counts, and a risk score immediately.
Do I need both the extension and the Gateway?
Not necessarily. The extension covers any browser-based AI usage — which is most of it. Add the Gateway if you have desktop AI apps (Claude Desktop, ChatGPT app), CLI agents (Cursor, Cline), or BYOD/contractor devices on your office network that you can't install software on.
How does Blacksight handle our data?
All DLP scanning runs locally — inside the browser extension or on the gateway appliance. We only receive verdicts and metadata: the detector class that matched, the destination domain, the policy outcome, a hashed user ID. We never receive the actual prompt content, file contents, or AI-service responses.
Is there a discount for annual billing?
Yes — 20% off when paid annually. Talk to sales for multi-year discounts and Gateway hardware bundles.
Can I self-host?
Self-hosting the dashboard / control plane is available for Enterprise customers. The DLP and gateway components already run inside your perimeter on every plan.

Start free. Upgrade when you've seen enough.

No credit card. Free for 5 users. 14-day trial of the full platform.

Get Started Free Talk to sales