mnueron
ENTERPRISEEnterprise
Custom infrastructure + procurement-friendly contract for regulated industries.
- Everything in Team
- SAML SSO + SCIM provisioning
- Custom contract + security review fit for procurement
- On-prem Postgres or VPC peering
- Customer-managed encryption keys (CMEK)
- Dedicated Slack + SLA + named CSM
What you get
Everything in Team, plus SAML SSO + SCIM, on-prem deployment, customer-managed encryption keys, dedicated support, and a custom contract for your security team. HIPAA BAA + SOC 2 Type II are on the roadmap — contact sales for current status.
Compliance posture (current)
Today: AES-256-GCM envelope encryption for credentials + SP private keys, RLS tenant isolation, append-only audit log + CSV export. Roadmap: HIPAA BAA (2027), SOC 2 Type II (in progress), content-at-rest encryption for memory bodies, PHI-aware redaction. We share status candidly during procurement — see /docs/security.
Customer-managed encryption
Bring your own KEK in AWS KMS / Azure Key Vault / GCP KMS. Per-org envelope encryption end-to-end. Revoke the key, revoke our access.
On-prem or VPC
Deploy mnueron into your AWS / Azure / GCP VPC via Terraform. Or fully self-hosted with Helm. Air-gapped install bundles available.
Unlimited memories
No cap. Pool size scales with your subscription. Storage cost is a small line item next to the underlying infra you're already paying for.
SAML + SCIM
Single sign-on via Okta, Azure AD, Google Workspace, Auth0. SCIM provisioning for automated team-membership sync. Your IT already loves these.
Dedicated support
Named customer success manager. Shared Slack channel. 99.9% SLA. Engineering escalation path for outages.
Who uses Enterprise
Healthcare org evaluating Mnueron
Honest status: BAA + content-at-rest encryption + PHI redaction are on the roadmap, not deliverables today. If you need a signed BAA right now we are not the right vendor — let's talk again in 2027. If your use case can wait, we can structure a pilot contract with annual security review.
Financial services
Audit log + CSV export + customer-managed encryption keys today. SOC 2 Type II audit in progress (not yet certified). On-prem deployment available under custom contract.
Defense / federal
Air-gapped install. No outbound calls from the cluster. Helm chart + signed image manifest. Updates applied at your pace.
FAQ
What does Enterprise cost?
Annual contracts negotiated based on team size, deployment topology (hosted / VPC / on-prem), and support level. Typical starting point is $30K-50K/year for a mid-size dev team with hosted single-tenant. Volume pricing for larger orgs.
How long does Enterprise procurement take?
Security review + commercial typically lands in 4-8 weeks. We've done it as fast as 2 weeks with a motivated buyer. Healthcare procurement requiring a BAA is blocked on our roadmap — we expect to be BAA-ready in 2027.
Can we trial Enterprise before signing?
Yes — 60-day paid pilot with success criteria. If we don't meet them, you walk away and we refund. Bigger pilots get a dedicated solutions engineer.
What about FedRAMP?
Not yet. On the roadmap if a customer commits. The architecture supports it (encrypted everything, audit log, RBAC) — it's the paperwork that takes 6+ months.
Can we self-host without a contract?
The hosted backend is source-available under FSL-1.1-Apache-2.0. Self-host for internal use without paying us. The Enterprise license adds support, SSO/SCIM, on-prem-specific features, and indemnification.
Ready for Enterprise?
Talk to our team about your security requirements, deployment topology, and success criteria.