Same engine. Different room.
The open-source core is the whole product, not a funnel into a paid one. What enterprise sells is governance, tuning, and people — the things a large organisation actually cannot self-serve.
Core
Everything that detects, investigates, and deploys. Run it on a laptop or across a cluster, for as long as you like, with no seat count and no expiry.
- Every connector, detector pack, and custom detector tier
- Inquiries, fingerprints, cases, and the Harness AI autopilot
- Desktop app and the Helm chart, both fully featured
- Workspace isolation is in the core and always on
Governed
The core plus the lock on the cabinet, and engineers who learn your domain. Our people work with your team from the first pilot rather than handing over a license key.
- SSO, roles, and per-workspace authorization
- Models tuned on your terminology and languages
- Detectors and sources built for your industry's data
- Architecture reviews, OpenShift, SLA-backed support
The whole comparison
Four of the five groups below are identical between editions.
| Capability | Open source | Enterprise |
|---|---|---|
| DetectionIdentical. The engine is the open-source project. | ||
| Every source connectorDatabases, lakehouses, collaboration tools, storage, streams | ✓ | ✓ |
| Built-in detector packsPII, secrets, code security, threats, content quality | ✓ | ✓ |
| Custom detectorsRegex, entity classification, Hugging Face models, any LLM | ✓ | Built with you |
| Semantic rankingImportance 0–1 with written reasons, not just severity | ✓ | Calibrated to your corpus |
| Detection tuned to your terminologyModels trained so a term means what it means at your company | – | ✓ |
| Multilanguage detection tuning | – | ✓ |
| InvestigationIdentical. Cases are the product, in both editions. | ||
| Findings, inquiries, and fingerprints | ✓ | ✓ |
| Cases, hypotheses, and evidence trails | ✓ | ✓ |
| Harness AI autopilotFive agents working the investigation between scans | ✓ | Tuned to your workflows |
| In-app assistant and MCP serverDrive the whole product from your own AI client | ✓ | ✓ |
| Notifications and data export | ✓ | ✓ |
| DeploymentIdentical. No runtime is held back. | ||
| Desktop appmacOS, Windows, Linux — PostgreSQL embedded | ✓ | ✓ |
| Helm chart on KubernetesScales as far as the estate demands | ✓ | ✓ |
| Workspace isolationOwn schema, evidence, AI memory, and endpoint per workspace | ✓ | ✓ |
| OpenShiftWith upgrade assistance from our engineers | – | ✓ |
| GovernanceThe real difference — the lock on the cabinet. | ||
| Single sign-on (SSO) | – | ✓ |
| Roles and permissions | – | ✓ |
| Per-workspace authorizationAn auditor opens the audit workspace and nothing else | – | ✓ |
| PeopleWhat you get besides software. | ||
| Support | GitHub issues | SLA-backed, named engineers |
| Onboarding | Docs and the demo | Guided pilot, architecture review |
| Roadmap influence | Open issues and PRs | Direct, on your industry's data |
| Price | Free, forever | Talk to us |
Detection
Identical. The engine is the open-source project.
Every source connector
Databases, lakehouses, collaboration tools, storage, streams
- Open source
- ✓
- Enterprise
- ✓
Built-in detector packs
PII, secrets, code security, threats, content quality
- Open source
- ✓
- Enterprise
- ✓
Custom detectors
Regex, entity classification, Hugging Face models, any LLM
- Open source
- ✓
- Enterprise
- Built with you
Semantic ranking
Importance 0–1 with written reasons, not just severity
- Open source
- ✓
- Enterprise
- Calibrated to your corpus
Detection tuned to your terminology
Models trained so a term means what it means at your company
- Open source
- –
- Enterprise
- ✓
Multilanguage detection tuning
- Open source
- –
- Enterprise
- ✓
Investigation
Identical. Cases are the product, in both editions.
Findings, inquiries, and fingerprints
- Open source
- ✓
- Enterprise
- ✓
Cases, hypotheses, and evidence trails
- Open source
- ✓
- Enterprise
- ✓
Harness AI autopilot
Five agents working the investigation between scans
- Open source
- ✓
- Enterprise
- Tuned to your workflows
In-app assistant and MCP server
Drive the whole product from your own AI client
- Open source
- ✓
- Enterprise
- ✓
Notifications and data export
- Open source
- ✓
- Enterprise
- ✓
Deployment
Identical. No runtime is held back.
Desktop app
macOS, Windows, Linux — PostgreSQL embedded
- Open source
- ✓
- Enterprise
- ✓
Helm chart on Kubernetes
Scales as far as the estate demands
- Open source
- ✓
- Enterprise
- ✓
Workspace isolation
Own schema, evidence, AI memory, and endpoint per workspace
- Open source
- ✓
- Enterprise
- ✓
OpenShift
With upgrade assistance from our engineers
- Open source
- –
- Enterprise
- ✓
Governance
The real difference — the lock on the cabinet.
Single sign-on (SSO)
- Open source
- –
- Enterprise
- ✓
Roles and permissions
- Open source
- –
- Enterprise
- ✓
Per-workspace authorization
An auditor opens the audit workspace and nothing else
- Open source
- –
- Enterprise
- ✓
People
What you get besides software.
Support
- Open source
- GitHub issues
- Enterprise
- SLA-backed, named engineers
Onboarding
- Open source
- Docs and the demo
- Enterprise
- Guided pilot, architecture review
Roadmap influence
- Open source
- Open issues and PRs
- Enterprise
- Direct, on your industry's data
Price
- Open source
- Free, forever
- Enterprise
- Talk to us
Workspace isolation lives in the open-source core and is always on — a workspace has its own database schema, evidence, AI memory, and endpoint. Enterprise does not add the wall; it adds the authorization that decides who may open which drawer.
How workspaces workStart free. Call us later.
Almost everyone starts on the open-source core and stays there. The conversation is worth having when SSO, roles, and a tuned model start mattering more than the scan itself.
Or poke at the live demo first