How do plans and billing work?
Enforgate has three plans: Free, Pro, and Scale. The differences are your monthly token allowance, team/resource limits, and a handful of capabilities like webhooks and standing grants. Here's exactly what each tier unlocks and how upgrading, downgrading, and cancellation actually behave.
The three plans
- Free ($0): 10,000 tokens a month (about 1,000 guarded calls), 1 team member, 2 API keys, 2 connected tools, 3 policies, email approval alerts, 7-day audit history.
- Pro ($29/month): 500,000 tokens a month (about 50,000 guarded calls), 5 team members, 20 keys and connected tools, unlimited policies, Slack/Teams/Telegram notifications, custom SMTP, standing grants, webhooks, authenticated approvals with reversal, 90-day audit retention.
- Scale ($199/month): 10,000,000 tokens a month (about 1,000,000 guarded calls), unlimited members, keys, connected tools and policies, white-label branding with a custom domain, audit export, and 1-year audit retention, plus everything in Pro.
Both paid plans are also available yearly, priced as 10 months for the price of 12, two months free versus paying monthly: Pro is $290/year (instead of $348) and Scale is $1,990/year (instead of $2,388). Switch between monthly and yearly with the toggle on the Plans page.
How tokens work
Usage is metered in tokens, one shared monthly pool per org. It's the unit the Usage page meter shows. The conversion is fixed and simple:
- An allowed guarded call costs 10 tokens.
- A call held for human approval costs 30 tokens (the extra covers the wait plus multi-channel notification fan-out). A call that is denied or that times out waiting for approval costs nothing.
- AI features (the policy assistant, the dashboard chat, DLP-pattern drafting) draw from the same pool at their real model token count.
So Free's 10,000 tokens is roughly 1,000 plain allowed calls, Pro's 500,000 is roughly 50,000, and Scale's 10,000,000 is roughly 1,000,000, before any approvals or AI usage.
What's actually enforced
Two different kinds of limit, and they fail differently:
- Resource counts (seats, API keys, connected tools, policies) are hard caps. Creating one more than your plan allows returns an error at creation time, not a warning after the fact.
- The monthly token allowance is a hard cap.Once your org reaches its plan's token limit, further chargeable usage is blocked until the next billing cycle or an upgrade. The Usage page shows an over-limit banner well before you hit it.
- Pay-as-you-go overage (optional). If you enable the wallet, usage beyond your monthly allowance draws from your prepaid balance at $0.001 per token (so about $0.01 for a typical allowed call) instead of being blocked, until the balance runs out, at which point the hard cap applies again. The wallet is off by default.
Capability gates (custom SMTP, multi-channel notifications, standing grants, webhooks, white-label branding, audit export) check your plan the moment you try to use them and return a plan-upgrade error if you're not entitled, rather than silently no-op'ing. Audit retention works as a read boundary: you can search and export history back to your plan's retention window, not further, on Free that's 7 days back.
Checkout, upgrades, and downgrades
Upgrading opens an inline Paddle checkout right on the /dashboard/plans page. Paddle (not Enforgate) is the merchant of record and handles the card details directly, Enforgate never sees or stores a card number. Once Paddle confirms payment, a webhook flips your org onto the new plan, usually within a couple seconds of the success screen.
Switching plans while already subscribed reuses the same checkout flow. Canceling takes effect at the end of the current billing period, you keep paid-plan access through the period you already paid for, and your org reverts to Free automatically once it ends. There's no immediate-cutoff cancellation.
The Manage subscriptionbutton opens Paddle's self-serve customer portal (payment method, invoice history, cancellation) in a new tab, pre-authenticated so you don't need a separate Paddle login.
Promo codes
A promo code redeemed on the Plans page comps your org onto a higher plan for a fixed number of days, no card required. It's independent of your actual subscription state, a comped org can still be on Free underneath; the comp just raises the effective plan until it expires.
Refunds
Refunds are handled manually, by design, not as a self-service button. Submitting a refund request (admin-only) requires the transaction ID from your receipt and a description of at least 30 characters, and acknowledging the refund policy. The request is logged for a human to review; Paddle, as merchant of record, issues any actual refund.
