Start free.
Scale when you need it.
Open-source core covers 95% of teams. @lua-ai-global/governance-enterprise adds fleet analytics, RBAC, and multi-tenancy for regulated industries.
npm i governance-sdk- Core policy engine— 13 condition types
- Before-action enforcement
- HMAC audit trail— hash-chained, tamper-evident
- 7-dimension scoring
- Kill switch— priority 999
- Injection detection— 64+ patterns
- EU AI Act mapping— 6 articles
- 20 framework adapters— Mastra, Vercel AI, LangChain, OpenAI + 16 more
- PostgreSQL + in-memory storage
- 945+ tests, 0 deps
- RBAC
- Multi-tenant isolation
- Fleet analytics
- Policy templates
- Priority support
per registered agent · billed monthly
- Everything in Open Source
- RBAC— role-based access control
- Multi-tenant isolation— namespace-isolated per tenant
- Fleet analytics— enforcement rates, score trends
- Policy templates— fintech, healthcare, SaaS presets
- Policy suggestion engine— agent-type-aware recommendations
- Org management
- Slack alerts— enforcement events + kill switch
- Priority support— < 24h response
- Unlimited saved policies
- 90-day audit retention
- Compliance reports
- On-premise deployment
- Dedicated CSM
- SLA
- Everything in Pro
- Unlimited agents
- On-premise deployment— air-gapped environments
- Compliance reports— EU AI Act audit export
- Custom policy conditions— extend the engine
- Dedicated CSM
- 99.9% SLA
- SOC 2 compliance docs
- SSO / SAML
- Security review
- Training & onboarding
- Custom integrations
All tiers include the full open-source SDK. @lua-ai-global/governance-enterprise is a separate package — no forking, no lock-in.
Common questions
Is the core SDK really free forever?
Yes. governance-sdk core is MIT licensed and will always be free and open source. @lua-ai-global/governance-enterprise is a separate package that adds team features (RBAC, multi-tenancy, analytics) on top of the open core.
What counts as an 'agent'?
Any registered agent in your fleet — a unique gov.register() call with a distinct name and owner. Static scripts that don't call gov.register() don't count.
Do I need Pro for EU AI Act compliance?
No. The free tier includes all 6 EU AI Act article mappings (Articles 9, 11, 12, 14, 15, 50), HMAC audit trails (Article 12), policy enforcement (Articles 9/15), and human oversight gates (Article 14). Pro adds compliance report exports.
Can I self-host Pro?
The enterprise module code ships in the npm package. Pro and Enterprise are licensing and support tiers — you deploy your own infrastructure. No SaaS lock-in.
What frameworks are supported?
20 adapters: Mastra, Vercel AI, LangChain, OpenAI Agents, Anthropic, MCP, CrewAI, Bedrock, Genkit, Semantic Kernel, AutoGen, A2A, LlamaIndex, Cloudflare AI, Deno, Mistral, Ollama, E2B, Composio, and more. Rolling your own takes under 50 lines.
Start governed in 5 minutes
Open-source core. No account, no API key, no lock-in.
npm i governance-sdk