LeanCTX Enterprise

Run agents like infrastructure.

In 2026, every developer runs coding agents; by 2027 it’s fleets. Agents that touch production code and customer data need real governance — not dashboards. The Enterprise tier gives you full control: deploy in our cloud or your own infrastructure.

The Context Plane

Govern what your agents see, use and remember.

One local binary per machine, one policy surface for the fleet. Every read, command and output passes through the same context engineering layer first. Everything below ships in the open-source core today.

See

PathJail confines file access to allowed roots. Secrets are redacted before any model sees them. Prompt-injection screening checks untrusted content, OWASP-aligned.

Use

The shell allowlist blocks dangerous commands before execution. Per-role token budgets cap spend. The MCP gateway routes external tools through one governed entry point.

Remember

Session memory and the knowledge store are local, inspectable files. You decide what persists, what syncs and what gets purged.

Prove

An Ed25519-signed, hash-chained ledger records reads, commands and savings. Verify integrity with one command; export for audit and finance.

Your agents touch production code. Govern them like infrastructure.

Live demo

Don't take our word for it — watch it run.

A real gateway instance is running at demo.leanctx.com: real open-source-model inference, real wire compression, real per-person metering — synthetic identities, measured numbers. Sign in with the published demo credentials and inspect everything.

Access tokens for the console and the /me view are published on demo.leanctx.com — the admin API is read-only, and inference endpoints are not exposed on the public instance. Every number you see is metered from real requests through the unmodified product path — no mock data.

Enterprise plane

Everything in the core, plus fleet control.

The open-source core stays free forever, enforced by a public CI gate. Enterprise adds the plane that lets platform and security teams operate hundreds of agents.

SSO & SCIM

SAML/OIDC sign-on and automated seat provisioning: agents and humans under the same identity plane.

Fleet policies

Centrally managed PathJail roots, allowlists, budgets and persona policies, versioned, reviewed and rolled out like code.

Compliance exports

Signed, aggregated audit and savings reports across the fleet: numbers finance and auditors can verify themselves.

Cloud or self-hosted

Your choice: use our managed cloud, or deploy lean-ctx in your own Azure, on-prem, or air-gapped environment. Same features, your infrastructure.

The open-source core stays free forever. Enterprise adds governance, compliance and dedicated support. See the full tier comparison →

How you pay

Fair pricing, aligned incentives.

No surprise bills, no hidden upsells. Three components, each optional or negotiated to your situation.

Platform Fee

Per-seat license covering governance, support, updates and SLA. Negotiated to your org size — contact sales for a quote.

Guided Onboarding

A 2–4 week fixed-price package: deployment, IdP integration, policy setup, admin training and a developer workshop. One-time, not recurring.

Success Fee (optional)

Pay a capped share of the savings we cryptographically prove. Floor equals your platform fee, cap at 50% of your actual bill reduction. You verify every number offline.

Regulated? Audited?

Frameworks mapped, evidence verifiable.

The context plane answers compliance questions with enforced controls and offline-verifiable evidence — and is explicit about what stays an organisational duty.

Built on open standards: the Context Governance Benchmark defines the controls, the Open Context Protocol defines the wire format — both citable, both vendor-neutral.

"What leaves the machine?"

Nothing. verify it. LeanCTX runs locally with zero telemetry. The ledger, cache and knowledge store are local files. Network egress happens only where your configuration sends it, and the audit trail records it.

Read the full security model

What buyers ask first.

Pilot theContext Plane.

Two weeks, your repos, your policies, and a signed report of what your agents read, ran and saved.

Support this project