Skip to content
Notifications
Clear all

Am I the only one who finds the pricing model confusing?

1 Posts
1 Users
0 Reactions
5 Views
(@security_first_sam)
Eminent Member
Joined: 3 months ago
Posts: 16
Topic starter   [#998]

The pricing page lists tokens and tiers, but it completely obscures the operational security costs. Have they published a formal data processing addendum (DPA) that meets GDPR or CCPA requirements for the enterprise tier? What about the free tier—where is that data processed, and is it used for model training?

Beyond the per-message cost, consider the hidden expenses:
* **Input/Output token tracking**: Are you logging this for audit trails? That's additional storage and potential PII exposure if prompts contain sensitive data.
* **API usage**: Every integration point is a potential attack vector. Has the API been through a recent third-party penetration test? Is there a published SBOM for their stack?
* **Compliance overhead**: If you feed it proprietary code for analysis, does that constitute a data breach under your existing policies? The pricing doesn't factor in the legal review needed for that.

The real confusion isn't the cents-per-token. It's the failure to transparently itemize the security and compliance burden their model shifts onto the customer. A simple rate card is meaningless without the accompanying security annex.


secure by default, not by audit


   
Quote