Pricing

Free to run.
Priced to operate an organization.

The runtime is Apache-2.0 and always free to self-host. Hosted plans give your people and every AI working for you one shared understanding of how the organization works.

MonthlyAnnual
01

Free

For one person, and for every engineer who self-hosts.

$0/month
  • Everything in the open-source runtime, unlimited and forever
  • 1 connected system, 1 seat
  • 21 days of history, backfilled on connect
  • 15 extraction runs a month
  • 5,000 governed actions a month
  • 1,000 agent questions a month
Start free

npx memnox setup — no account needed to self-host

02

Pro

For the person who wants their own history working for them.

$29/month
  • Everything in Free, plus:
  • 3 connected systems, 90 days of history
  • Extraction on a schedule, not by hand
  • Search across everything your systems have said
  • 60 extraction runs, 100,000 governed actions
  • 5,000 agent questions a month
  • 6 hours of meeting recording a month
Most Popular
03

Team

From 5 people. For when decisions need someone else's approval.

$18/person/month

from 5 people — $90/month to start

  • Everything in Pro, plus:
  • Unlimited connected systems, a full year of history
  • Invites, roles, and a shared review queue
  • What gets blocked most, pooled across your teams and anonymized
  • Compliance bundle and audit export
  • Learns your organization: 40 extraction runs per person, a month
  • Governs your AI: 200,000 governed actions per person, a month
  • Answers 2,000 agent questions per person, a month
  • 4 hours of meeting recording per person, a month
  • Extra recording hours any time, $2 an hour
04

Enterprise

For organizations where procurement has questions.

Custom
  • Everything in Team, plus:
  • SSO and SAML
  • Bring your own model key — your Anthropic or OpenAI account, your rates
  • Classification levels enforced per fact, per person, per agent
  • Unlimited everything, custom contract, named support
05

Platform

For companies building AI that works inside other companies.

Custom

priced on customer organizations and governed actions

Your agents already know how to reach their tools. Memnox gives them the organization: who is asking, who they represent, what they may know, and who has to approve. One API, whatever built the agent, priced on what you deploy rather than on how many people work for you.

Talk to sales

What your agents get

  • The open-source SDK, and the same API over MCP
  • Agent identity, with the person each one acts for
  • Organizational context, filtered per agent
  • Allow, deny, ask, delegate, escalate or clarify
  • Human approval routed to whoever holds the authority

What you get to sell

  • Customer organizations, isolated from each other
  • Per-customer policies, roles and audit
  • Usage-based pricing on governed actions
  • Embedded or white-labelled in your own product
  • SSO, SLA, and a security review that ends

Every plan includes the deterministic policy gate, human approvals, and the hash-chained audit log. Those are Apache-2.0 and never behind a price.

Frequently asked questions

Everything you need to know

Straight answers on what Memnox understands, what your AI workers are allowed to do, and what stays your call.

Memnox is the operating system for organizations that run on AI. It continuously builds a live understanding of how your business actually works: goals, teams, customers, projects, policies, approvals, workflows, priorities, dependencies and live operations.

Every person, every AI agent and every application then works from that same operational context, instead of each holding a fragment of it.

Most AI answers questions. Memnox answers the questions an organization runs on: who owns this, what should happen next, is this blocked, does this need approval, is another team already working on it, does this conflict with policy, which department does it affect.

Those need an understanding of the business, not of your documents.

Automation runs a path you wired up in advance. Memnox coordinates: it understands what an event means for the rest of the organization, then informs the right people, starts the right agents, updates the right systems and routes the right approvals, without anyone having to define that path first.

No. There is no new place to work and no stack to rebuild. Your teams stay in the tools they already use; Memnox connects to them and coordinates across them.

No, it is the layer that makes them agree. What changes is that your systems stop holding separate, conflicting pictures of the same business.

It starts the moment the first systems are connected, and keeps going: how decisions get made, how approvals flow, how departments collaborate, where work slows down. This is not a configuration project you finish. It keeps learning as the company changes.

It stays. Why a customer is on non-standard terms, which supplier was ruled out and on what grounds, what the last incident changed: that context is held by the organization rather than by the person who happened to be in the thread.

A role changing hands is a handover, not a reset. Whoever picks it up inherits the decisions, the owners and the open threads already in flight.

The runtime is, under Apache-2.0, and it is the part that enforces. Policy enforcement, human approvals, the tamper-evident audit log, secret and PII scanning and prompt-injection defence are free on every tier, including no tier at all. Self-host it and pay nothing, forever.

What the hosted plans price is the organizational side: the living model of how your company works, kept current from the work itself, and the review queue your people share.

Yes. Slack, Gmail, Calendar, GitHub, Jira, Linear, Notion, Google Drive, Microsoft 365, Salesforce, HubSpot, Stripe, your ERP and your internal APIs, plus the AI agents your teams already run.

No, that is the point. Claude, ChatGPT, Gemini, n8n and your own agents keep doing their work. They simply stop guessing, because they read the same goals, owners, approval chains and limits everyone else does.

Yes. Anything you build can read the organization's context and check an action against it before taking it, over MCP or the API.

Anything with an API can be connected, and internal or homegrown systems are first-class: they usually hold the context nothing else has.

For the tools you buy, no, connecting them is an administrator's job. Engineering is only involved where you want your own internal systems in the picture.

No. Connecting a system backfills its history first, so the understanding starts with what your company already decided rather than from the day you signed up. How far back is a matter of the plan.

Every AI worker has an identity rather than a shared key: a place in the organization, the systems it may reach, and a person who answers for it. An agent acting for someone acts in its own name and theirs, and both are on the record.

That is what makes the rest possible. An action taken by a key nobody owns cannot be governed, only discovered afterwards.

A ceiling set per agent, and graded by consequence rather than by endpoint. Publishing a public document and moving $100,000 are not the same action, and are not treated as one.

An agent carries a slice of its owner's authority and never more, so it cannot grant itself what the person behind it does not have. Authority lent for an afternoon expires on its own.

Each one is measured against its own history, so unusual is defined by what that agent normally does rather than by a generic threshold. Something out of character is raised before it reaches anything outside the company.

One switch stops an agent mid run, and the record shows what it had already done. Retiring it is the same motion: access withdrawn everywhere at once and its credentials rotated, rather than a key left live in a system nobody remembers.

Yes, and that is usually the harder half. An agent you bought reaches your systems through the same layer as one you wrote, so your policies apply to it without the vendor implementing anything.

One set of permissions covers Claude, ChatGPT, Gemini, n8n and whatever your teams adopt next, rather than one per platform.

The organization stays. Models and agents are the replaceable part; who owns what, which approvals apply and what was already decided are not, and they do not live inside a vendor's product.

As much as it has earned, and it is a level you move rather than a switch you flip. Start with an agent that only proposes, watch what it would have done, then widen the range where its record supports it.

Readiness is checked before the range widens, so autonomy grows on evidence rather than on optimism.

It moves the work and stops at the decisions that should be human. A signed contract can create onboarding, notify finance, update the CRM and schedule kickoff by itself. Whether to sign it, waive a limit or approve an exception stays with a person.

You do. Memnox learns the approval chains you already have rather than imposing new ones, and then applies them consistently, including to your AI agents. A ceiling above them cannot be waved through, whoever or whatever is asking.

The request finds whoever actually holds the authority, which is not always the name on the org chart that day. It escalates rather than expiring quietly, and a decision two departments share reaches both of them instead of whichever one was asked first.

Nothing consequential proceeds because a request went unanswered. Waiting is the safe direction, and the queue shows what is waiting and on whom.

The way departments do: one asks another for something and hands over the context with it, so the second is not starting from a sentence.

Authority narrows as work crosses and never grows. An agent cannot reach something it was not entitled to by asking a colleague that was.

Yes, that is the common failure and the reason the record exists. An agent checks what the company has already settled before acting against it, and says which decision it is following.

It runs the other way too: an exception a person approves today becomes the rule that is applied tomorrow, instead of being asked again next quarter.

The agent responsible can be stopped mid run, and the work it triggered elsewhere is visible rather than scattered across six systems.

Then the record answers why: every action carries who asked, the rule that decided it, the evidence behind it and the systems it reached, and any decision can be replayed end to end. What changes afterwards is the rule that let it through, so the same call goes differently next time.

Yes. Start in observation, see what it would have decided, and widen its autonomy as those decisions prove out. Understanding first, action second, always in that order.

Memnox knows before the work starts. Duplicated effort, conflicting decisions and dependencies nobody flagged surface as they appear, rather than in a retro.

People and agents see what their role in your organization already entitles them to. Memnox reads the ownership and permissions you have; connecting a system does not widen access to it.

An agent gets the slice its task needs rather than the whole company, and one agent's access is never every agent's.

Private stays private. A direct message, an HR file or a board document does not become an answer for someone who was not entitled to it, whichever agent is asking and however the question is phrased.

Classification is honoured on every request rather than at connection time, so a document reclassified this morning is treated as confidential this afternoon.

It reads and never writes. There is no tool behind it that changes a policy, an approval or a fact, so the worst a compromised agent can do through it is ask a question it is not entitled to, and be refused.

It carries a grant of its own rather than the credential your agent acts with, restricted material is refused to a machine whatever that grant says, and every answer reports how much it withheld.

No. Your organizational context is yours. It is used to answer your questions and govern your work, not to improve a model anyone else uses.

Yes. Actions are checked against data classification and jurisdiction before they happen, so a transfer your policy forbids is stopped rather than logged after the fact.

Yes. Each decision records who or what took it, the policy version in force, what it matched and what it reached, and stays replayable long after the people involved have moved on.

The log is the evidence. What an AI worker was allowed to do, who approved the exceptions and what actually happened is the control an auditor asks about, exportable rather than reconstructed from screenshots the week before the review.

It does not certify you, and we do not claim a certification we have not finished. Where you are in SOC 2 or ISO 27001 and where we are is a conversation with both teams in the room.

Yes. Architecture, data handling and our current compliance posture are covered directly with your security and legal teams. Book a demo and we will set that up.

Start free and connect your first systems yourself, or book a demo and we will map Memnox to how your organization actually runs. Either way, nothing gets rebuilt.

Yes, and most do. One department is enough to be useful on its own, and the value compounds as the teams it hands off to come on.

Connecting the first systems is the work of an afternoon. Coordination follows once Memnox has seen enough of how your work moves. This is measured in days, not quarters.

Free covers one person connecting their first system, and the self-hosted runtime is free for everyone, always. Pro is $29 a month and Team is $18 per person from five people. Enterprise is sized against your organization, so talk to us.

An administrator who can connect the first systems, and someone who can say how approvals actually work today. Not a data project, not a taxonomy exercise, and not a list of workflows written in advance.

Still have questions?

Bring the workflow that crosses the most teams and we will walk through exactly how Memnox would coordinate it.

Book a demo