For teams · Cinctus Business

Your agents work.

Getting them past a security review is the problem.

Pilots don't stall because the model is bad. They stall because nobody can say who approved what, which key the agent used, or what it did at 3am on a Sunday. Cinctus Business is the identity, policy and audit layer that answers those questions — self-hosted, on your infrastructure, priced per agent.

Segment: for my team — already selected

No demo call. No sales qualification. Self-serve with a card when it ships.

Self-hosted on your infrastructure · SSO against your IdP · Priced per managed agent

cinctus.internal/fleet
CINCTUS
cinctus.internal · self-hosted
Overview
Fleet 12
Policies v14
Users 6
Audit
Settings
policy v14 · enforcing on 12/12
sso · connected to your IdP
audit · retention 365 d
Fleet / all agents
policy v14 enforcing
SL security-lead · via SSO
09:12
CENTRAL POLICY · APPLIES TO EVERY AGENT
baseline-policy v14 · enforcing
v14 · edited by security-lead · 2 days ago · v13 → v14 diff in history
egress deny-all approvals: spend · mail · repo keys via vault only retention 365 d
Fleet 12 agents · 4 teams
live
openclaw-ci platform-team v14 running
hermes-support support-team v14 running
claude-code-dev dev-tools v14 running
openclaw-research data-team v13 update queued
hermes-billing finance v14 running
+ 7 more · one policy, one history — no config files on laptops
Users via your IdP · SSO
SL security-lead admin
PT platform-team operator
AU auditor read-only
Audit Export evidence pack
09:04 policy v14 applied · 11/12 agents
08:51 openclaw-ci · egress blocked
08:47 sso login · auditor · read-only
08:31 audit export · CSV · by auditor

01 — WHERE PILOTS ACTUALLY DIE

The blocker is never the agent. It's the paperwork the agent can't produce.

The vast majority of enterprise agentic pilots never reach production. Not for lack of capability — they reach the point where someone asks for identity, access control and an audit trail, and the answer is a config file on somebody's laptop.

[SOURCE: IDC]
BLOCKER
WHAT CINCTUS BUSINESS GIVES YOU

Who is this agent acting as?

Real identity per agent. SSO against your existing IdP, roles that decide which humans can change which agent's rules.

Who allowed it to do that?

Central policy per agent, versioned. Not a config file per machine — one place, one history, one answer.

Prove what happened.

Every run, read, outbound call and cost in an exportable audit trail, with retention you set and compliance reports you can hand over.

02 — THE REPUTATION FEED

Every install makes the next one safer.

A skill or MCP server is only as trustworthy as the last person who audited it. Cinctus ships a reputation feed built the way antivirus signatures were: every install that scans a skill contributes back, and every install benefits from what the others found.

341

Malicious skills, one sweep

One marketplace audit found 341 malicious skills in a single sweep; later scans found hundreds more. Nobody audits that by hand, and no single team's allowlist keeps up.

Koi Security, Feb 2026
This is the part that does not fork. The code is open — copy it. The feed is what makes the code useful, and it grows with every deployment.

03 — WHAT YOU ACTUALLY BUY

Business, in full.

Multiple users, SSO, roles (RBAC)

Your IdP, your groups. No second directory to maintain.

Central policy per agent

Write the rule once, it applies everywhere, and the change is in the history.

Exportable audit and log retention

The format your auditors already accept, kept as long as your policy says.

Compliance reports

The evidence pack, generated, not assembled by hand the week before.

The reputation feed

With the rule updates that come with it.

Everything in the free core

Sandbox, egress control, vault, approvals, audit timeline.

04 — PRICING

From €99 a month. Priced per managed agent.

€99 / month and up · per managed agent

You pay for agents under management, so the bill follows your adoption instead of a seat count you negotiate once a year. Card, not a sales call: you can start without talking to us, and you can leave without asking us.

THE LINE THAT DOES NOT MOVE

Everything one person needs to secure their own agents is free forever, in the open-source core. You start paying when there is an organisation to run — more users, SSO, central policy, exportable evidence. Not before.

05 — THE CAVEATS

What this does not do.

Same honesty as the home page. You are going to put this in front of a security review; you deserve the caveats before the pitch.

It does not stop prompt injection.

Nobody's product does. Cinctus assumes the agent will eventually be talked into something stupid and makes that survivable.

It does not police what the agent is allowed to think.

Inside the permissions you granted, an agent can still do a bad job. That is your call to make, not ours.

It is not a managed service.

Nothing runs in our cloud. If your box is down, Cinctus is down, and that is the trade you came here for.

It is not a compliance certificate.

Cinctus produces the evidence; your auditor still decides what it's worth.

It does not exist yet.

This is a waitlist, not a download. First build lands late September 2026 — and if it slips, you get the email that says so.

06 — WHY SELF-HOSTED IS THE POINT

Your agents' traffic never leaves your perimeter.

An agent sees your source, your tickets, your customer data. A managed control plane would see all of it too. Cinctus runs on your infrastructure — the only thing that leaves is the reputation feed lookup, and you can run that air-gapped if your policy demands it.

And it stays agent-agnostic: OpenClaw, Hermes, Claude Code, anything that speaks MCP. If the framework you standardised on hardens its own core next quarter, or you replace it entirely, your policies, your audit history and your evidence pack survive the migration.

Get one email when Business ships.

We're building this in the open, and the waitlist decides what gets built first. Tell us you're a team and you'll get the Business build, not the hobby one.

Stored on our own box in Germany. Never sold, never shared.