Tiers · Fees

Three tiers for individuals.
Three for organizations.
One principle.

Every tier is end-to-end encrypted, post-quantum, and TEE-isolated. The tiers differ only in key custody, memory horizon, and dedication of infrastructure — never in privacy.

For individuals

Professional · Executive · Sovereign

 

Professional

Encrypted AI for regulated practice.
$399per month
Memory7–90 days
KeysPlatform-managed
InfraShared, non-TEE
Models7B / 8B
  • ·Daily encrypted reasoning
  • ·7–90 day configurable retention
  • ·7B / 8B reasoning models
  • ·Ghost Mode per-session toggle
  • ·Vertical Knowledge Packs included
  • ·Brave Search opt-in (freshness)
Retain Professional
Most Discreet

Executive

Private AI. Your keys. 70B reasoning.
$1,199per month
MemoryIndefinite
KeysUser-held (FIDO2 or passphrase)
InfraTEE shared pool
ModelsUp to 70B
  • ·Everything in Professional
  • ·Indefinite encrypted memory
  • ·User-held cryptographic keys
  • ·70B (Qwen 72B / Llama 70B) reasoning
  • ·TEE-isolated inference (GCP A3 CC + NRAS)
  • ·Secure Search with proof-of-purge
  • ·Exportable signed audit log
Start Executive pilot
By Application

Sovereign

Dedicated, single-tenant infrastructure.
from$4,999per month
MemoryIndefinite
KeysClient-controlled
InfraDedicated single-tenant
ModelsUp to 70B + custom
  • ·Everything in Executive
  • ·Per-client GCP A3 CC pool
  • ·Client-controlled key material
  • ·Encrypted private RAG
  • ·End-to-end-to-enclave (Phase 2)
  • ·Concierge implementation
  • ·Named engagement engineer
Apply for Sovereign
For organizations

Teams Professional · Teams Executive · Enterprise

 

Teams Professional

Small practices, boutique firms.
$319per seat / mo
5-seat minimum
Memory7–90 days
KeysPlatform-managed
InfraTEE shared pool
Models7B / 8B
  • ·Everything in Professional
  • ·Org admin console
  • ·Centralized billing
  • ·Org-level audit log (metadata)
  • ·BAA workflow
  • ·5-seat minimum
Retain Teams Pro
 

Teams Executive

Hospital departments, mid-size firms.
$959per seat / mo
10-seat minimum
MemoryIndefinite
KeysUser-held + admin policy
InfraTEE shared pool (dedicated opt.)
ModelsUp to 70B
  • ·Everything in Executive
  • ·SSO / SAML (Okta, Entra, Google, Azure)
  • ·Role-based memory policies
  • ·Teams-level attestation reports
  • ·Dedicated Knowledge Pack tuning
  • ·10-seat minimum
Retain Teams Executive
Negotiated

Enterprise

Hospitals, health systems, institutions.
from$1,199per seat / mo
25-seat minimum
MemoryIndefinite
KeysClient-controlled
InfraDedicated single-tenant
ModelsUp to 70B + custom
  • ·Everything in Teams Executive
  • ·Dedicated single-tenant infra
  • ·Custom retention & audit policies
  • ·Dedicated implementation engineer
  • ·Custom MSA / DPA review
  • ·On-call security contact (1-hour SLO)
  • ·25-seat minimum
Apply for Enterprise

Looking for the technical deployment surface? /organizations has the architecture overview, compliance grid, and organizational capability matrix.


What every tier includes.

Privacy is not a pricing lever. Every paid tier carries the same cryptographic floor:

  • Hybrid classical + post-quantum transport
    TLS 1.3 with ML-KEM-768 alongside X25519. Hardens every session against harvest-now-decrypt-later.
  • AES-256-GCM at rest
    Argon2id-derived keys. Data encryption keys wrapped by a platform key that never leaves the HSM.
  • TEE-isolated inference
    NVIDIA H100 Confidential Computing mode, AMD SEV-SNP memory encryption. Attestation verified before every session.
  • Ghost Mode
    Per-session zero-retention toggle. Conversations held only in TEE memory, purged on session close.
  • Signed audit log
    Ed25519-chained entries for every operation. Exportable and verifiable offline. Metadata only — never content.
  • Response signature verification
    Every response chunk is ML-DSA-65-signed. Your client rejects unsigned or tampered output.

Answered straight.

Why is Professional the only tier without TEE today?

Confidential-computing GPUs are materially more expensive than non-TEE GPUs. At the Professional price point the unit economics do not carry TEE on every session. Professional is still end-to-end encrypted, post-quantum on transit, and zero-retention by default — and it upgrades to Executive the day your work requires it.

What is the pilot and who is it for?

Executive opens with a 30-day pilot at a contracted rate, billed today and non-refundable, which auto-converts to the standard fee on day 31. The pilot is for founders, executives, and principals who need proof the vault performs on their actual workflow before committing to the standard fee.

What does Sovereign add that Executive does not have?

Sovereign customers receive a dedicated, single-tenant GCP A3 CC pool — infrastructure that no other client shares. Sovereign is also the tier with end-to-end-to-enclave key exchange, meaning the application server is cryptographically excluded from the plaintext path. ArcaKey cannot read Sovereign content by construction, not by policy.

Does cancelling the pilot refund the pilot charge?

No. The pilot charge is billed day one and is non-refundable; you acknowledge this explicitly at checkout. Cancelling before day 31 ends the subscription after the pilot window.

Do you sell to Ontario government entities?

Not at this time. Arca · Key is on a prospecting exclusion list for Ontario Health, OHTs, Ontario-funded hospitals, Public Health Ontario, and Ontario ministries during an active consulting engagement separation window.

Can I bring my own compliance framework (HIPAA / PHIPA / GDPR)?

Yes. HIPAA with BAA is available on Healthcare deployments. PHIPA alignment is supported via the northamerica-northeast1 (Montréal) GCP region. GDPR, SOC 2 roadmap, and custom DPA terms are handled on Teams Executive and Enterprise.


The conversations that cannot live on anyone else’s server.

Start an Executive pilot today, or request a Sovereign call.

Request AccessSecurity overview