Skip to main content
GhostStack
Menu
pricing
Two products

Two SaaS products. Honest pricing when there is something to charge for.

Prospector and Vault are both coming-soon. Plan shapes are final; prices are held until there is a working product to bill against. Every CTA on this page routes to Contact until launch.

01 / Prospector

Prospector pricing

Free
Contact us

Free while Prospector is in coming-soon

Evaluate Prospector on a small set of real jobs. Limited ingestion and one outbound proposal at a time.

  • Single-platform ingestion
  • Baseline scoring model
  • Single active proposal
  • Manual delivery tracking
Pro
Recommended
Contact us

Pricing finalizes before public launch

For a working freelancer. Full ingestion, auto-scoring, AI-drafted proposals with operator approval, and delivery tracking.

  • Single-platform ingestion
  • Full-platform ingestion
  • Baseline scoring model
  • Signal-based auto-scoring
  • Single active proposal
  • AI-drafted proposals with operator approval
  • Manual delivery tracking
  • Tracked delivery with stage history
Power
Contact us

Pricing finalizes before public launch

For high-volume operators. Adds multi-source ingestion, per-platform scoring tuning, parallel proposals, and signed delivery receipts.

  • Single-platform ingestion
  • Full-platform ingestion
  • Multi-source ingestion
  • Baseline scoring model
  • Signal-based auto-scoring
  • Per-platform scoring tuning
  • Single active proposal
  • AI-drafted proposals with operator approval
  • Parallel proposal drafting
  • Manual delivery tracking
  • Tracked delivery with stage history
  • Signed delivery receipts
Enterprise
Contact us

Contact us for enterprise terms

Agency-scale Prospector with managed onboarding, SSO, per-user policy, and signed audit trails across every delivery.

  • Single-platform ingestion
  • Full-platform ingestion
  • Multi-source ingestion
  • Baseline scoring model
  • Signal-based auto-scoring
  • Per-platform scoring tuning
  • Single active proposal
  • AI-drafted proposals with operator approval
  • Parallel proposal drafting
  • Manual delivery tracking
  • Tracked delivery with stage history
  • Signed delivery receipts
  • SSO and per-user policy
  • Exportable audit trail
Prospector feature matrix
04 plans / 14 features
Prospector feature availability by plan
Feature Free Pro Power Enterprise
Ingestion
Single-platform ingestion Included Included Included Included
Full-platform ingestion Not included Included Included Included
Multi-source ingestion Not included Not included Included Included
Scoring
Baseline scoring model Included Included Included Included
Signal-based auto-scoring Not included Included Included Included
Per-platform scoring tuning Not included Not included Included Included
Proposals
Single active proposal Included Included Included Included
AI-drafted proposals with operator approval Not included Included Included Included
Parallel proposal drafting Not included Not included Included Included
Delivery
Manual delivery tracking Included Included Included Included
Tracked delivery with stage history Not included Included Included Included
Signed delivery receipts Not included Not included Included Included
SSO and per-user policy Not included Not included Not included Included
Exportable audit trail Not included Not included Not included Included
Prospector FAQ
07 questions
  • 01 When do prices go live?
    Prospector is coming-soon. Every plan on this page shows "Contact us" until the backend is ready for paying customers. Pricing tiers are designed, but not priced, until there is a working product to bill against.
  • 02 Is there a refund policy?
    Yes. If Prospector does not solve your workflow in the first 30 days, email hello@ghoststack.app and the subscription is refunded in full. That policy will be in the terms of service when Prospector launches.
  • 03 What does the Free plan actually let me do?
    The Free plan is for evaluating Prospector on a small number of real jobs. Limited ingestion, baseline scoring, and one active proposal at a time. It is enough to judge whether Prospector is worth paying for without committing money.
  • 04 Can a team share a Prospector workspace?
    Team features are part of the Enterprise plan. The Pro and Power plans are single-operator by design. If you need multi-seat with SSO and per-user policy, the Enterprise tier is the starting point.
  • 05 Monthly or annual billing?
    Monthly at launch. Annual billing with a clear discount will follow. The rate of that discount is not invented until there is revenue data to back it.
  • 06 Can I upgrade or downgrade later?
    Yes. Plan changes take effect at the end of the current billing period. No data is lost on downgrade. Features above the new plan tier are disabled but your job history stays intact.
  • 07 Can I export my data if I leave?
    Yes. Job history, proposals, and delivery records export as JSON on demand. This is a baseline for every plan, not an upsell.

02 / Vault

Vault pricing

Free
$0 / month

Forever-free for personal use. Sized for solo developers and side projects; upgrade when you hit a cap.

Personal credential vault for solo use. 25 credentials, 1,000 leases per month, 7-day audit retention. Single user, single tenant.

  • API keys
  • OAuth tokens
  • Service tokens
  • Local agent access
  • MCP server access
  • Scoped leases with per-agent policy
  • Envelope encryption
Pro
Recommended
$12/mo / month

$120/yr (save 17%). Individual paid; sized to cover a working developer with multiple projects and vendors.

250 credentials, 10,000 leases per month, 90-day audit retention. Adds audit export, broader credential types (databases, webhooks, OAuth clients).

  • API keys
  • OAuth tokens
  • Service tokens
  • Database credentials
  • Webhook signing secrets
  • Local agent access
  • MCP server access
  • Scoped leases with per-agent policy
  • Envelope encryption
  • Immutable audit log
  • Audit log export
Team
$24/seat/mo / month

3-seat minimum (so $72/mo entry). Sized for the 5-20 engineer team that needs shared credentials with per-member RBAC.

2,500 credentials, 100,000 leases per month, 1-year audit retention (SOC 2 default). Unlimited seats. Every lease attributed; per-credential ACLs.

  • API keys
  • OAuth tokens
  • Service tokens
  • Database credentials
  • Webhook signing secrets
  • Local agent access
  • MCP server access
  • Scoped leases with per-agent policy
  • Shared vaults
  • Per-member ACLs
  • Per-lease attribution
  • Envelope encryption
  • Immutable audit log
  • Audit log export
Enterprise
Contract / month

Custom pricing. Sold by direct contract; suited to regulated industries (HIPAA, PCI-DSS, financial services).

Unlimited credentials and leases, 7-year audit retention (regulated-industries default). SAML SSO, customer-held KMS (BYOK), SIEM streaming, SOC 2 attestation, custom security review.

  • API keys
  • OAuth tokens
  • Service tokens
  • Database credentials
  • Webhook signing secrets
  • Local agent access
  • MCP server access
  • Scoped leases with per-agent policy
  • Shared vaults
  • Per-member ACLs
  • Per-lease attribution
  • Envelope encryption
  • Immutable audit log
  • Audit log export
  • Customer-managed keys
  • SSO
  • SOC 2 attestation
Vault feature matrix
04 plans / 17 features
Vault feature availability by plan
Feature Free Pro Team Enterprise
Credential types
API keys Included Included Included Included
OAuth tokens Included Included Included Included
Service tokens Included Included Included Included
Database credentials Not included Included Included Included
Webhook signing secrets Not included Included Included Included
Agent integration
Local agent access Included Included Included Included
MCP server access Included Included Included Included
Scoped leases with per-agent policy Included Included Included Included
Team features
Shared vaults Not included Not included Included Included
Per-member ACLs Not included Not included Included Included
Per-lease attribution Not included Not included Included Included
Security
Envelope encryption Included Included Included Included
Immutable audit log Not included Included Included Included
Customer-managed keys Not included Not included Not included Included
SSO Not included Not included Not included Included
SOC 2 attestation Not included Not included Not included Included
Audit log export Not included Included Included Included
Vault FAQ
10 questions
  • 01 When do prices go live?
    Vault is coming-soon. Every tier shows "Contact us" until the product is open to paying customers. Plan shapes and feature envelopes are final, but numbers will be set with real cost data before public launch.
  • 02 Which credential types does Vault support?
    API keys, OAuth tokens, service tokens, database credentials, and webhook signing secrets are in scope for launch. Every credential is encrypted with envelope encryption under a per-tenant data key.
  • 03 How does the MCP server work?
    Vault exposes an MCP (Model Context Protocol) server that coding agents connect to. When an agent needs a credential, it requests a scoped, time-bound lease through MCP. The vault owner approves the policy once; the agent leases under that policy on demand. Agents never see the raw credential outside the lease window.
  • 04 What is the encryption model?
    Envelope encryption. Every secret is encrypted with a per-record data key; data keys are wrapped by a per-tenant key encryption key held in a KMS. Enterprise customers can bring their own KMS key (customer managed keys). Decrypted values never hit durable storage.
  • 05 What about compliance and SOC 2?
    The Enterprise plan is the tier that carries SOC 2 attestation and an exportable audit log. The Free, Pro, and Team plans inherit the same encryption and audit pipeline, but formal attestation and audit export are Enterprise-only.
  • 06 Where is credential data stored?
    US region at launch. EU region follows when there is enough demand to justify a separate data plane. Residency guarantees for Enterprise customers are in the contract, not a toggle.
  • 07 Is agent lease volume capped per plan?
    Free has a small daily lease quota. Pro and Team have generous quotas sized for active coding workflows. Enterprise is unbounded under contract. Exact caps will be listed once there is real workload data to tune against.
  • 08 What is the difference between Team and Enterprise?
    Team is shared vaults with per-member ACLs and per-lease attribution for a small-to-medium team. Enterprise adds customer-managed keys, SSO, SOC 2 attestation, and exportable audit log for organizations that need to prove control and trace every credential decision.
  • 09 What happens if I lose access?
    Every account has a recovery path that does not involve our team reading your vault. The recovery key is generated at signup and is never stored by us. Lose the recovery key and your vault is gone; this is the price of end-to-end encryption.
  • 10 How is this different from 1Password or Bitwarden?
    Vault is built for agents and humans alike, with the lease model as the thing that sets it apart. Humans store and share credentials the way they would in 1Password or Bitwarden. Agents request scoped, time-bound credential access through MCP, and the operator approves a policy once rather than approving every call. The same vault serves both populations under one audit log.

Contact

Enterprise contact

Enterprise inquiry
Prospector / Vault / both

Enterprise terms for Prospector or Vault are drawn up by hand. Tell us the shape of the engagement and we will respond with pricing, SSO setup, and the relevant security review process.

Ready when you are
Two products

Pick your entry point.

Prospector and Vault share one operator, one brand, and one audit discipline. Start with whichever fits your work first. The other is one Contact away.