AZMX AI — The sovereign agent platform.
Every paid surface is gated on top of a Free product that's a complete tool by itself. There's no "trial mode" that hides core features — Free is the floor, not a teaser. Paid tiers add capability above that floor.
| Local terminal + agent | ✓ |
| BYOK any major provider | ✓ |
| Free local models via Ollama | ✓ |
| Per-call agent approval | ✓ |
| Built-in secret-path screen | ✓ |
| Local-only AI lock | ✓ |
| Hash-chained audit log | ✓ |
| Spend tracker (estimated, on-device) | ✓ |
| Encrypted backup + restore | ✓ |
| Memory tree (workspace + global) | ✓ |
| Code-graph index (private, local) | ✓ |
| Skills | ✓ |
| MCP connectors | ✓ |
| No account · No telemetry · Forever | ✓ |
Free is the whole product. The paid tiers add operational and team controls.
Everything in Free, plus:
- Cross-device E2E sync — 2 personal devices, encrypted with your passphrase, our server never sees plaintext.
- Parallel + background agents — run several agents at once; long-running tasks survive window close.
- Agent checkpoint / replay — pause a run, branch from it, replay a failed step.
- Strict / Paranoid approval presets — every tool asks for approval, destructive commands require a typed confirmation.
- Hash-chain audit verify + export to SIEM — Splunk / Datadog / OTel-ready.
- Path deny-list — extend the built-in secret-path screen with your own patterns.
- Private codebase index — semantic index is kept across devices via sync.
- Magic-link Polar checkout · no account · monthly or annual.
Everything in Pro, plus:
- DLP secret-egress guard — block AI requests whose prompt contains a high-confidence secret.
- Provider allowlist — restrict which AI providers the fleet can use.
- Agent capability sandbox — centrally disable shell or sub-agents per seat.
- Org policy file (
~/.azmx/org-policy.json) — MDM-friendly, fail-safe. - SCIM 2.0 provisioning — Okta, Azure AD, Google Workspace.
- RBAC — admin / member / observer roles.
- Local signed audit log — every seat, central console.
- Admin console — seats, members, spend, billing, per-license API tokens.
- Encrypted team registry — share skills, prompts, agents, macros, MCP connectors.
- Per-team spend dashboard with anomaly alerts and webhooks (Slack / Discord / Teams).
Everything in Teams, plus:
- Self-hosted license issuer — your fleet's licenses signed by your own key.
- Customer-rooted trust — verifier accepts customer-issuer-signed tokens, not vendor-rooted.
- FIPS 140-3 allowlist build.
- PIV / CAC smart-card authentication.
- SIEM / OTel structured audit export.
- Compliance bundle — SBOM (CycloneDX 1.5, signed), SOC 2 pack, DPA.
- Air-gapped install + renewal — offline trust evaluator.
- Named support + SLA with air-gapped renewal cycle.
Every new install includes a 14-day Pro trial — endowed progress, no payment, no account. Every paid surface is unlocked while the trial runs. After day 14 your install reverts to Free and your settings stay intact (deny-list, approval policy, audit log all persist).
Full side-by-side feature comparison: azmx.ai/pricing.