Enforce and prove.
Not observe and alert.
Most tools in this space watch agents and raise a flag after something has already happened — and they sell that to the enterprise through a quote. P1 Halo is different in kind: it's the runtime boundary your agent executes inside. It contains the run, holds the keys outside the box, and can kill it on command — then signs the whole thing into evidence you re-verify yourself. And you can start today, from $29.
An alert tells you. A boundary stops it.
The market splits into observe-and-alert tools, heavyweight governance suites, and rolling your own. Here is the honest line each draws — and where the enforcing runtime sits.
Enforce at runtime
Observability and detection tools sit beside the agent and tell you after the fact. Halo is the layer the agent runs inside — no route off the sandbox, no key in the box, a kill switch outside it. The control is enforced below the agent, so it can't be talked around.
CONTAIN · NOT WATCHEvidence you own
A dashboard shows you a vendor's view of what happened. Halo gives you an Ed25519-signed, hash-chained log you export and re-verify offline, on your own machine, with a standalone verifier. Proof you hold — not a screen you have to trust.
RE-VERIFY · OFFLINEIndependent & neutral
The thing being governed shouldn't be the thing that governs it. Halo is vendor-neutral and BYOK — bring a key from any supported provider, including OpenAI-compatible endpoints. You're never locked to one cloud or one model to keep your guardrails.
BYOK · ANY MODELWhere the categories stop.
Four axes that matter when an autonomous agent has your repo, your shell and your keys. We describe the category honestly — not by name.
Enforce at runtime, not observe and alert CONTAINMENT
Observability and detection tools instrument the agent and tell you what it did — useful, but the action has already happened. Halo is the boundary the run executes inside: an internal-only sandbox with no route out, a sole-egress broker as the only door, and a host-authoritative kill switch the agent can't reach. The control fires before the leak, not after.
Evidence you re-verify and own, not a vendor dashboard PROOF
Most platforms render their own view of events into a console you have to take on faith. Halo signs every prompt, tool call, output, routing decision and kill with Ed25519, hash-chains them, and lets you export the run and re-verify each event offline with a standalone tool. Tamper one byte and verification fails. You hold the proof; we can't quietly rewrite it.
Independent and vendor-neutral, not locked to one cloud or model BYOK
Governance baked into a single model cloud means the vendor grades its own homework, and your guardrails move only where they want to sell. Halo is BYOK and provider-agnostic — bring a key from any supported provider or OpenAI-compatible endpoint. The key lives in a libsodium-encrypted vault, never enters the container, and the broker injects it for exactly one policy-checked call.
Self-serve from $29, not enterprise “contact sales” FLAT PRICING
Enterprise governance suites are sales-led: a demo, a quote, a procurement cycle. Halo is flat and self-serve — Solo $29, Team $544, Business $1,779 per month, BYOK so you only ever pay your provider for tokens and we never mark them up. Sign in, bring a key, and run a governed agent today. Team and Business add RBAC, separation of duties, one org-wide signed chain, and re-verifiable OSCAL / eMASS export with NIST 800-171 mapping.
An alert is a story about something that already happened. A boundary is the reason it didn’t. We’d rather hand you the thing you can check than the thing you have to believe.
We say what's real, and what's roadmap.
Honesty is a feature. The live container path enforces real controls today; where something is targeted rather than shipped, we put it in writing.
What's enforced today
No-route sandbox, sole-egress broker, BYOK libsodium vault, per-run and per-tenant cost caps, a host-authoritative kill switch, multi-agent collaboration, and an Ed25519-signed, hash-chained audit you re-verify offline. Team adds RBAC and one actor-stamped org chain. Business adds NIST 800-171 / CMMC mapping and OSCAL / eMASS export.
What we don't claim
CMMC alignment is self-assessed and a SOC 2 Type II audit is targeted for Q3 2026 — not attested yet. We don't sell threat detection or monitoring, we aren't an MSSP, and live billing is in test today. We name the roadmap as roadmap, so the parts you trust are the parts you can verify.
Stop watching agents.
Start governing them.
Spin up a sandbox, point an agent at a real task, and watch it work behind the broker — then export the proof and re-verify it offline. Solo $29 · Team $544 · Business $1,779.