Pricing
Honest pricing, stated up front.
One product in a fully isolated AWS account: same features, same FIPS 140-3 Level 3 validated HSMs, same isolation, for every account. You pay for exactly what you run: no tiers, no rounding up to the next bracket, no setup or account fees.
The subscription
$99/month
- Every subscription starts at one key, with 100K crypto operations a month included.
- Additional keys ($12/mo each, each bundling its own 100K ops) and extra ops blocks ($5 per 100K) are added from your console after provisioning, never bought up front - billing for each starts the moment you add it.
- No setup, support or account fees. Cancel from the portal at any time.
Annual billing is chosen at checkout: 12 months for the price of 11, rates locked for your term.
Shared evaluation environment on published demo terms; your demo account is deleted after 14 days.
Every line item, at the published rate
What you can buy and what it costs, stated in full. Your subscription starts at the base row; everything else is added from your console only when you need it.
| Item | Monthly | Yearly | What it does | Requirements |
|---|---|---|---|---|
| Base subscription | $99/mo | $1,089/yr | A dedicated AWS account, 1 key, 100,000 operation units a month, the console, the audit trail and the Keyout right. | None. |
| Additional key | $12/mo | $132/yr | 1 key, plus its own 100,000 operation units. | Base subscription; self-serve cap of 50 keys. |
| Extra 100,000 operation units | $5/mo | $55/yr | Capacity only, no key. | None. |
| Served region | $99/mo | $1,089/yr | A live serving stack in another AWS region. | Bought in the console after signup, not at checkout. |
| Key placed in a region | $12/mo | $132/yr | The same key replicated into a served region, with its own regional operation units. | That region is served. |
| Failover protection | $79/mo | $869/yr | Managed DNS health-check failover for a protected region. | The target region is already served. |
Yearly is 12 months for the price of 11, rates locked for your term.
How operations count: a sign counts as 2 units; every other operation counts as 1.
The free demo isn’t a row here: 14 days in a shared environment, no card, the real product.
What $99 a month buys, before you count a single operation.
Keys and operations are how we count, but they’re not what you’re buying. Everything below ships in the base subscription, for every account, at every size, from day one.
One scope note before the list, since it changes how you’ll integrate: what we ship is the certificate authority itself, not an enrollment ecosystem, so you won’t find ACME, SCEP, EST or a renewal agent here. Renewal automation is your pipeline’s job. Signing, revocation, and revocation truth are ours.
An account with one tenant
Your keys, IAM, quotas, identity pool and audit table live in an AWS account that holds nothing of anyone else’s. Keys are generated inside FIPS 140-3 Level 3 validated HSMs and are non-extractable.
Partitions with group-scoped access
Named compartments for your keys, each backed by its own access group and its own audit trail. A user sees only the partitions they belong to, so payments-prod and ci-signing stay separated.
A certificate authority hierarchy
Roots, intermediates, chaining, CSR import and signing into external chains, issuance and revocation, with public CRL and OCSP endpoints so relying parties can check revocation. Not an add-on and not priced per CA. No enrollment protocols: you drive it from the REST API and the console.
Per-operation audit trail, exportable
Every operation writes a tamper-evident record you can export to your SIEM or hand to an assessor. A gap in the trail raises an alarm rather than passing quietly.
Enforced key lifecycle
Rotation is switched on at creation or the key is deleted and creation fails. A non-rotating key cannot quietly exist in your account.
Console, REST API and the Keyout right
A purpose-built console for people who do not live in the AWS console, one REST API for everything, and a standing published-fee right to take the account and own it outright.
Three steps, fully self-serve
01
Subscribe
Verify your email, check out with Stripe. Card data never touches SanctiKey infrastructure.
02
We forge your vault
A dedicated AWS account is provisioned automatically: HSM-backed keys, API endpoints, audit trail.
03
Call the API
Sign, verify, encrypt and issue certificates over authenticated HTTPS. No tickets, no onboarding calls.
How add-ons actually work
→How mid-cycle additions are billed
Mid-cycle additions are prorated: you pay for the remainder of the current period at the moment you add them, then they join your regular bill.
→Relocation versus placement, and what a placed key does
Relocation (moving a key to a new region) is just the served-region fee; the key exists in one place, so no placement fee. Placed keys are active everywhere they live, not cold standbys. You also get deterministic per-region endpoints, so you choose which region performs a given operation.
Growing past 50 keys? Volume Pricing is a direct quote keyed to usage; accounts that grew with us are quoted more favorably than net-new volume entrants.
Two ways out. Neither requires our permission.
Way out 1 · costs nothing
Cancel and walk
You cancel yourself from the account portal whenever you want, cancelling online isn’t any harder than signing up was, and neither term carries an early-termination fee. The service keeps running to the end of the period you’ve already paid for, and you can ask for your audit trail at any point before then.
→What happens to your data after the account closes
Key material is destroyed by cryptographic erasure, meaning the KMS key is deleted, access to everything it protected is permanently severed, and the deletion event lands in the audit log as the record that it happened. Account and configuration data gets purged within 90 days of closure, and financial records stick around for seven years because tax law says they have to. There is no exit interview and no retention call.
Both commitments are written down where you can check them: cancellation terms and the retention schedule.
Way out 2 · the Keyout, a purchase
Take the whole account with you
Here you’re buying an AWS account and the infrastructure provisioned inside it, so your KMS keys come across intact and operational along with your audit table, and the account is ejected from our Organization into your sole ownership. It’s yours alone to invoke while your subscription is valid and paid up, and we never initiate it.
price = max($2,000, 24 × trailing-12-month average monthly bill)
- Avg $99/mo (1 key, steady)
- $2,376
The price is a published formula, not a negotiation. Worked examples, the three-phase hand-off, and exactly what does and does not transfer.
The fine print, in normal type
→Evaluating first
The shared demo environment lets you explore the console and run real operations before you buy; demo accounts delete automatically after 14 days. Paid subscriptions start with a single key, billed from day one. Add more keys from your console at any time.
→When you grow
Keys and ops scale continuously: your bill is computed directly from what you run, never rounded up to a bracket. At a crypto-ops limit, operations return 429 until you add a prepaid block or your cycle resets, but listing, describing, and managing your keys is never blocked. The API behaviour is documented at rate and quota limits.
→Partitions
Named compartments for your keys inside your account, each backed by its own access group. A user can only see and use keys in partitions they are a member of, so teams and workloads (say, payments-prod versus ci-signing) stay separated with their own audit trail. Every account starts with a default partition.
→Account ownership
The AWS account is SanctiKey-owned and operated inside our Organization; you are its only tenant. Ownership transfers to you whenever you exercise the Keyout above.
→Billing
Handled entirely by Stripe. Your card details never reach a SanctiKey server; see payment security.
Questions people actually ask
The ones that decide whether you buy, answered at length rather than in a sentence. Open any of them; every answer links the page that says it in binding form.
→How many keys do I get at signup?
One. Every subscription starts with a single key and 100K crypto operations a month included, and that single key is what the $99 base subscription covers. Additional keys are add-ons at $12 a month each, each bundling its own 100K operations, and you add them from your console once your account is provisioned rather than choosing a quantity at checkout. A key starts billing the moment you add it, and never before.
This is the reason there are no tiers to compare: you are not picking a bundle that might fit, you are starting at one key and adding exactly what you turn out to need. The subscription block at the top of this page states what the base includes, and the cost model under it shows what an account of any shape works out to at the published rates.
→What happens to my keys if you shut down?
Your key material never depended on us continuing to exist. Keys are generated and held as non-extractable material in AWS KMS inside a dedicated AWS account provisioned for you, which holds nothing belonging to anyone else. Our software is the managed layer on top of that account. It is not the place the keys live.
The mechanism that turns that fact into something you can act on is the Keyout, and it is a standing right rather than a favour we grant case by case. You designate an IAM role in your own separate AWS account, and that role is granted direct AWS KMS access to your keys before our managed layer is decommissioned, so cryptographic access is uninterrupted from the moment you initiate to the moment the account is transferred into your sole ownership. Your audit records come with it.
Exercising the Keyout is not contingent on us ceasing or intending to cease operations. It is available at any time during an active subscription that is valid and paid up, for any reason, and we never initiate it. The price is a published formula rather than a negotiation: see the two ways out above for the worked figure, and the Business Continuity and Keyout Policy for the three-phase hand-off and exactly what does and does not transfer.
→Can I leave, and what does exit cost?
Leaving costs nothing and you do it yourself from the account portal, whenever you want, on either term. No early-termination fee, no exit interview, no retention call, and cancelling online is no harder than signing up was. The service keeps running to the end of the billing period you have already paid for, which on an annual term means the end of the paid annual year, and you can request an export of your audit trail at any point before then. Fees already charged are not refunded - you retain access until the end of the billed period.
If you cancel without executing a Keyout, your access ends when that paid period closes and your key material is destroyed by cryptographic erasure: the KMS key is deleted, access to everything it protected is permanently severed, and the deletion is recorded in the audit log. Worth being exact about the sequence if you are planning a migration around it. Period closure is the moment access stops; the destruction completes after that rather than in the same instant, and the interval between the two is an operational tail on our side for error recovery. It is not a grace period to plan around, and it is not a second chance to exercise the Keyout, which requires a subscription that is still active and paid up. Treat the end of your paid period as the deadline, because that is what it is.
To keep your keys after you leave, execute the Keyout while the subscription is still valid: the two ways out above carries the fee formula, and the Business Continuity and Keyout Policy carries the process. Account and configuration data is purged within 90 days of closure, and financial records are kept for seven years because tax law requires it.
→Can you see or extract my keys?
No, and the reason is structural rather than a policy we promise to keep. Key material is generated inside FIPS 140-3 Level 3 validated HSMs and is flagged non-extractable at creation, so no API call, no support escalation and no internal tool returns the raw private key bytes. That constraint binds you exactly as it binds us: you use a key by asking the platform to sign, verify, encrypt or decrypt with it, never by holding it.
What we can see is metadata, which is to say which key, which operation, when, and by whom, and that is precisely what your audit trail records. We do not retain the plaintext or the ciphertext of the payloads you send. What we cannot see on the security page lists this line by line, and the section above it describes how the non-extractable flag is set.
→What does the demo create, and what happens after 14 days?
The demo is a full SanctiKey environment that we host, running the exact same software a paying customer runs, not a sandbox and not a mockup. Signing up gets you a demo account with everything an engineer or developer would actually touch: the console, the SDK, and a set of shared demo keys ready to sign, verify, encrypt and decrypt with. Two emails arrive, in this order: a console invitation carrying your sign-in URL and a temporary password, then a separate message carrying your API key, so the key never travels in the same email as your login.
What is held back is the administrative side. Demo users share one environment, so the surfaces that manage users, accounts and billing are walled off, and so are creating or deleting keys and running the certificate authority; you work against the shared demo keys that are already provisioned. That was a deliberate trade-off: you evaluate the real product, and nobody’s demo activity leaks into anybody else’s.
Your demo account is deleted 14 days after it is created, as the demo terms state. The clock starts at creation, not at first sign-in, and deletion is permanent and irreversible: the account, its keys, its configuration and its data all go, and nothing lingers. The shared environment keeps running; what is deleted is your account inside it. The demo signup asks for an email address and nothing else.
→What if I want to see the administrative side of the software?
Completely understandable. When you are evaluating custody, you want to see the whole shape of it, including the parts the shared demo walls off. Reach out directly and we will schedule a walkthrough of the administrative backend on our development deployment, with room to ask anything along the way.
→Is there a free trial?
No, and that is deliberate. Rather than a paid plan with the meter switched off for a fortnight, the evaluation path is the free demo: no card, nothing to cancel, and no billing relationship to unwind if you decide against us. What you get is a running environment rather than a guided tour.
Paid subscriptions bill from day one and start at one key. Demo accounts do not convert in place, so subscribing provisions a fresh single-tenant AWS account for you and demo data is not migrated. That is the trade for the demo being shared: the thing you evaluate is real, and the thing you buy is yours alone.
→What happens during an outage?
The commitment is 99% monthly uptime, measured as ((total minutes - downtime minutes) / total minutes) x 100, which allows roughly 7.3 hours of downtime in a calendar month. Scheduled maintenance announced in advance, demo-environment interruptions, and outages caused by your own integration are excluded from the measurement.
Notification is by email to the account contact. We do not publish a status page, so email is the channel rather than a second place to check, and the SLA says so in those words instead of leaving it implied. Issues you raise go to support@sanctikey.com.
A month below 99% earns a service credit of 15% of the monthly fee. You claim it by emailing support@sanctikey.com with the subject line "SLA Credit Request: [Company Name]" within 15 calendar days of the end of the affected month; we evaluate in good faith within 15 business days and approved credits apply to your next invoice. First-response targets are 1, 2 and 3 business days by severity, and those targets are operational goals rather than binding guarantees, so they do not themselves trigger credits. All of it is written out in the service level agreement.
→Do you support invoicing or procurement paperwork?
Card payments through Stripe, today, and that is the whole of the billing path. Checkout is a Stripe session, your card details never reach a SanctiKey server, and there is no invoice-and-net-30 lane, no purchase-order intake and no vendor portal sitting behind it. Everything after that, including cancelling, runs from your account portal.
That reflects where we are rather than a position on how you buy. If your organization cannot put a subscription on a card, or needs paperwork to exist before a payment can, reach out directly and say what your process actually requires. You will be talking to the person who would have to build the answer, not filing a ticket.