Pricing

Priced by the unit the AI Act regulates

One high-risk AI system, one decision-volume band. Self-hosted — your data never leaves your infrastructure. Annual subscription, EUR, excluding VAT.

Verifier

€0 · free, forever

Anyone can open verify.carvetrace.com and verify any CarveTrace bundle in their browser, with no account, no telemetry, and no rate cap. The verifier libraries (Java, Rust/WASM, Python for v0.2) are open-source under Apache 2.0 — fork, audit, or self-host.

This is the differentiator, not a teaser. Anyone with the producer's public key re-derives every binding without trusting CarveTrace.

Starter

€15,000 / year

One high-risk AI system. For teams crossing the August 2026 deadline with one production workflow to evidence.

  • 1 high-risk AI system
  • Up to 500,000 decisions per year
  • 1-year evidence retention
  • Full SDK + CLI + self-hosted operator UI
  • RFC 3161 TSA timestamping
  • Self-hostable independent verifier
  • Standard commercial license, single organization
  • Email support, 2-business-day response
  • Quarterly version upgrades
Request a pilot

Enterprise

Custom · from €90,000

Unlimited high-risk systems. For multi-organization deployments, regulated industries, and DORA-covered entities.

  • Unlimited high-risk AI systems
  • Custom decision-volume scaling
  • Custom retention (10+ years)
  • Everything in Growth
  • Article 14 human-oversight workflows
  • Multi-organization / group-of-companies license
  • Named CSM + on-call SLA
  • Accompanied deployment, custom Article 12 mapping
  • ISO 42001 attestation pack (once we hold it)
  • DORA ICT third-party register fit, exit-plan documentation
  • Custom contract terms
Talk to us

One unit, one mental model. A "high-risk AI system" in CarveTrace pricing corresponds to one production AI workflow you would list in your Article 16 obligations as a deployer or provider — one résumé-screener, one credit-decisioning model, one biometric matcher. The decision-volume band is the count of signed AI inference events written to the CarveTrace chain over a 12-month subscription term. We meter on what the regulator regulates, not on how many people on your compliance team log in.

Common questions

Do we ever host your data?

No. CarveTrace is self-hosted in every tier. The signing keys, the chain, the bundles, and the subjects all stay on your infrastructure. We see only what you choose to share during a support session — and we delete it after the issue is closed.

What if we exceed our decision volume?

We don't break the chain or block writes mid-year. You'll get a friendly notice when you cross the band, and we'll right-size your next renewal to match what you're actually emitting. No surprise overage invoices in-term.

Pilot terms?

Every commercial conversation starts with a 60-day technical pilot against your real chain (or a staging chain). The pilot fee is modest and credited back against your first annual subscription if you convert. Pilots include direct access to the engineering team.

Multi-year discount?

Yes. 2-year prepaid commits land a 10% reduction ; 3-year prepaid commits land 15%. We are an EU SARL, not a private-equity-backed vendor under quarterly bookings pressure — pricing predictability is a feature.

How do you handle DORA's ICT third-party register?

Self-hosting means CarveTrace is rarely a Critical ICT Third-Party Service Provider in the formal DORA sense — but your DORA team will still want documentation. The Enterprise tier ships with a DORA-fit pack : risk profile, sub-processor list, exit-plan documentation, and the contractual fields the register expects.

Open source posture?

The verifier libraries (carvetrace-verify, carvetrace-verify-wasm, carvetrace-protocol, carvetrace-trust-roots) and reference Python verifier are Apache 2.0. The producer-side SDKs, adapters, CLI, server, and operator UI are commercial under the proprietary license. Full matrix on LICENSING.md.

What about US buyers?

We sell to non-EU organizations on the same EUR price card. EU AI Act compliance under Art. 2 reaches non-EU providers whose AI output is used in the EU ; many US-based AI builders are in scope whether or not they choose to deploy in the EU.

Ready to put cryptographic re-verifiability under your AI program?

Talk to us