Enterprise
Controls your security team
will actually accept.
Everything an engineering organisation needs to roll Goatfied out without a six-month review — and the option to run the whole thing inside your own network if the review says so anyway.
SSO · SCIM · Audit export · Self-hosted inference
Identity & access
Access that follows the directory.
Nobody should be maintaining a second list of who works here. Goatfied reads the one you already keep.
Single sign-on
SAML and OIDC against Okta, Entra ID, Google Workspace or whichever identity provider you already run. People sign in the way they sign in to everything else.
SCIM provisioning
Seats follow the directory. Someone joins a team and gets access; someone leaves and loses it the same day, without anyone remembering to do it.
Scoped credentials
An agent is issued a short-lived token narrowed to the repositories you named. There is no organisation-wide token to leak and nothing standing to revoke.
Governance
What was said, what was changed, what it cost.
An assistant with write access to your repositories has to be answerable for it. These are the answers, kept by default.
Privacy, enforced org-wide
No training on your code and no retention of prompts or completions. Set once for the organisation rather than left to each engineer to remember.
- Applies to every seat, including new ones
- Cannot be turned off per-user
- Covers agents as well as chat and completions
Audit you can export
Every prompt, completion, tool call, diff and command is recorded and exportable to your SIEM. Long output is kept rather than truncated.
Org-wide policy
Model allow-lists, redaction rules and repository-scoped MCP servers, so the tools an agent can reach are the ones you decided it should.
Spend you can see
Per-workspace budgets and per-seat usage, visible while it is being spent rather than reconciled from an invoice at the end of the month.
Replayable runs
Open an agent run months later and read exactly what it read, what it changed and why. The trace outlives the session.
Data processing
A DPA and a current sub-processor list, available on request. SOC 2 Type II is in progress.
Deployment
Our infrastructure, or none of it.
Some organisations cannot send code anywhere, and that is a reasonable position rather than an edge case. Goatfied runs entirely inside your network if it has to.
Self-hosted inference
Run the inference plane on your own Kubernetes with your own GPU pools. Air-gapped if that is what your review requires — nothing leaves the network.
- Your GPUs, your scheduler, your quotas
- Or bring your own provider keys and pay them directly
Your control plane
The coordination layer can sit inside your network too, so session data and repository metadata never leave infrastructure you administer.
Managed, if you would rather
Most organisations start on our infrastructure and move later, or never. The product is the same either way; only the address changes.
Getting started
A pilot, then a decision.
Enterprise is priced per seat against the size and shape of your organisation. Pilots usually start with twenty-five to fifty engineers over thirty days.
- 1
We wire identity
SSO and SCIM against your provider, with the policy defaults your security review asks for.
- 2
We deploy what needs deploying
Nothing, if you are happy on our infrastructure. The inference plane and control plane inside your network if you are not.
- 3
Your team uses it for a month
With usage and spend visible throughout, so the decision at the end is made against numbers rather than impressions.
Tell us your stack.
Email us with your organisation size and where your code lives, and we will tell you what a pilot would look like.