Compliance, identity, signed audit chain, and optional PHI redaction are included on every paid tier — you choose whether to send PHI under your BAA or strip it before it leaves your environment. Tiers package operational capacity (members, runtime, governance, dedicated compliance plane). Variable consumption bills against four meters. The Free Evaluation is the full product on non-PHI data.
Platform plans
Assistant + Studio · For teams
Included on every Platform tier
Assistant chat
Studio app builder
BAA · send PHI under your BAA
Signed audit chain (Ed25519)
Optional pre-model redaction
HIPAA · HITRUST · SOC 2 · GDPR · CCPA
Agent identity layer
BAA-covered inference providers
Email + SSO sign-in
Governed web search and fetch
You're billed for thinking and authorized doing. AI Credits
cover inference and retrieval; Agent Actions are charged only when an agent identity invokes a
tool through the policy gate — pure-inference customers never see an Agent Action charge.
Assistant chat Ask questions, draft documents, summarize records, and run governed tools — all through a conversational interface that logs every turn to your audit chain. For orgs handling PHI, every message is scanned and redacted before it leaves your environment.
Studio app builder Describe the internal tool you need and HASP builds it — schema, UI, permissions, and audit hooks. Publish to your org's subdomain in minutes, not sprints. Every published app inherits the same compliance posture as the rest of your environment.
Compliance & audit
PHI redaction before model For orgs that handle PHI: names, MRNs, dates, addresses, and the other HIPAA Safe Harbor identifiers are detected and redacted inside your environment before a single token reaches the AI provider. Re-identified back to the original values in the response, so the chat still reads naturally.
BAA (Business Associate Agreement) Signed BAA is included on every paid tier — no upcharge, no Enterprise-only gate. Required for HIPAA-covered entities.
Hash-chained audit log When an auditor or regulator asks 'who did what, when, and what data did they touch?' — you have an answer that holds up. Every message, tool call, data access, and auth event lands in a hash-chained, Ed25519-signed log; altering any past entry breaks the chain.
Audit retention How long your signed audit log is retained. Longer retention is required for HITRUST and some state-level HIPAA enforcement interpretations.
7 years
7 years
7 years
Custom (10+ yrs)
Multi-framework compliance One control set satisfies HIPAA, HITRUST, SOC 2, GDPR, CCPA, and PIPEDA simultaneously. You don't need separate tooling per framework.
CSV audit export Download a signed CSV of your audit log from the dashboard. Useful for external auditors or compliance reviews.
—
—
External hash anchoring Even if HASP's infrastructure were fully compromised, your audit history would still be provable. The daily digest of your chain is timestamped by an independent RFC 3161 authority — cryptographic proof of when each entry existed, anchored outside our walls.
IP address logging Records the IP address for every session and access event — part of the audit trail on every paid plan. Device metadata logging is available as an optional add-on on Enterprise.
Identity & access
Email magic-link / Google / Microsoft sign-in Standard sign-in methods available on every plan. No SSO contract required.
Members + roles Invite multiple users to your org, assign them member or admin roles, and manage shared workspace access.
—
Guest access Invite external collaborators (e.g., contractors, clients) who can access specific apps without becoming full org members.
—
SAML SSO Enforce single sign-on through your identity provider (Okta, Azure AD, Google Workspace, etc.) using the SAML 2.0 standard. Users can't log in except via SSO when enforced.
—
—
SCIM group sync Automatically provision and deprovision users and their group memberships from your identity provider. Eliminates manual offboarding steps.
—
—
Workflow runtime
Synchronous agent tool calls Agents can invoke tools (e.g., data lookups, API calls) inline within a single conversation turn. Completes before the response is returned.
Long-running & background agents Agents that run beyond a single request — queued workflows, multi-step pipelines, and background jobs that complete asynchronously. Requires workflow runtime infrastructure.
—
Multi-agent chains Orchestrate multiple specialized agents in supervised pipelines. One agent's output becomes another's input, with the policy gate applied at each step.
—
Governance & analytics
Usage-meter dashboards Real-time view of your AI Credits, App Operations, Storage, and Agent Actions consumption vs. your included allotment.
MAU / DAU / WAU trends Monthly, daily, and weekly active-user trend charts (30, 90, and 365-day windows). Useful for understanding adoption and planning seat expansion.
—
—
Per-user credit limits Org admins can cap how many AI Credits any individual user can consume per billing period — prevents runaway usage from a single account.
—
—
Governance analytics Audit-sourced dashboards for schema changes, publish events, role changes, and access-denial reports. Answers 'who changed what and when' questions without writing queries.
—
—
Infrastructure
Managed subdomain Your apps are published at `[your-org].usehasp.run`. No DNS setup required.
Custom org hostname Publish your apps on your own domain (e.g., tools.yourclinic.com) — bring your own domain via DNS delegation. One hostname per organization.
—
—
1 hostname
1 hostname
Dedicated data plane A per-organization database isolated from all other tenants. Logical row-level-security isolation is replaced with physical database isolation — required for some enterprise security policies.
—
—
—
Custom data residency Negotiate where your data at rest is stored (e.g., US-only, EU). Requires dedicated data plane.
—
—
—
Negotiated
Support
Email support Standard email support with best-effort response time.
Priority support SLA Guaranteed response time SLA with a named support contact who knows your deployment.
—
—
—
Custom DPA / SLA terms Negotiate custom Data Processing Agreement and Service Level Agreement terms into your contract. Required by some large health systems and IDNs.
—
—
—
API plans
Compliant inference + agent identity · For developers
Compliant inference for builders. Send PHI to the model under your BAA or redact it before it
leaves your environment — your choice per request, and every call lands in your signed audit
chain. Works with leading BAA-covered inference providers — same agent identity layer, same
compliance + audit layer, no compliance bolted on after the fact.
Billing period
−15%applied to every self-serve tier
Developer
Production-ready integrations
$212/moSave $444/yr
1.5M AI Credits included
250,000 Agent Actions
All supported AI models — one API, one BAA, one bill
Signed audit chain on every call
Optional PHI redaction when you'd rather not send identifiers at all
Billed in AI Credits — same unit as the platform tier. 1 credit ≈ 1,000 base-model input
tokens. Faster/cheaper models bill at a lower multiplier; larger/heavier models bill higher.
Per-model multipliers are published in the model catalog.
Usage canvas
The shape of your monthly bill.
An estimate for planning — your real mix and traffic decide the bill.
Total credits
3,980,000
Sonnet · 70%
Opus · 20%
Haiku · 5%
Web search · 5%
Monthly requests2M / mo
10K100K1M10M
Tokens per request792 in · 308 out
200100030008000
Web searches20K / mo
off1K50K500K
Agent actions500K / mo
off10K500K5M
Model mix · drag the dividers
70%
20%
10%
Sonnet · 70%Opus · 20%Haiku · 10%
You're on
Growth.
Bill
$899 /mo
DeveloperDev
GrowthGro
ScaleSca
EnterpriseEnt
1.5M cr7.5M cr15M cr∞ cr
1 credit ≈ 1,000 input tokens · each model bills at its own rate · web search +5, fetch +2
The negative space
What we don't bill for.
Six things you'll never see on a HASP invoice.
×
No per-seat pricing.
Active-user counts are capacity guidance, not invoiced.
×
No per-app pricing.
Publish unlimited apps on any tier.
×
No per-agent base pricing.
Agent activity is metered. Agent existence is not.
×
No compliance upcharge.
Signed BAA and tamper-evident audit chain on every paid tier. Send PHI to the model under your BAA, or redact it pre-model — your policy choice, not a paywall.
×
No surface gating by tier inside a plan.
Every Platform tier gets Assistant + Studio. Every API tier gets Public API + Agent SDK. Pick the plan(s) you need; tier differences are operational (limits, governance), never feature locks.
×
No third-party AI gateway.
Direct integration with BAA-covered inference providers under HASP-direct BAAs.
FAQ
Yes — a BAA is included on every paid plan, and you can countersign in-app. There's no procurement back-and-forth and no legal review cycle to start. The BAA is sourced from HHS provisions and posted to our Trust Center. HASP also holds BAAs directly with its inference providers, so one agreement covers the whole path your PHI takes — see what BAA-included AI covers. Until the BAA is countersigned, you can evaluate every surface (chat, documents, API, internal apps) using non-PHI data only.
Yes — the Free Evaluation. It's the full product on non-PHI data, including the integrity-chained audit chain and Agent SDK. Triple-bound by time, AI Credits, and Agent Actions — see the pricing page for current limits. Don't worry — evaluation stays free. Payment info verifies your identity and reduces fraud. You won't be charged unless you upgrade to a paid plan. Real PHI is permitted only after you countersign the BAA in-app.
An Agent Action is a single tool invocation by an agent — an AI acting under delegated human authority — that passes HASP's pre-action authorization gate. The meter captures what HASP adds on each tool call: scope evaluation, an entry in the signed audit chain, delegation tracking, and integrity-chain compute. Pure-inference customers (no agent identity) never see an Agent Action charge. The rule of thumb: thinking is metered everywhere AI runs (AI Credits); doing is metered only when an agent invokes a tool (Agent Actions).
No, no, and no. Active-user counts are capacity guidance, not invoiced. You can publish unlimited apps on any tier — costs only accrue when apps are used (App Operations + Storage meters). And agent existence is free — only authorized doing (Agent Actions) is metered.
The full compliance floor. Compliance posture (HIPAA + HITRUST + SOC 2 + GDPR + CCPA + PIPEDA/CPPA satisfied by one control set), HASP-owned PHI handling, signed audit chain (Ed25519 + RFC 3161 anchoring), agent identity layer, and direct integration with BAA-covered inference providers under HASP-direct BAAs — on every paid tier of both the Platform and API ladders. Within each ladder, every tier gets every surface for that buying motion: Platform tiers get Assistant chat + Studio; API tiers get Public API + Agent SDK. Tier differentiation is operational — seat counts, storage and usage allotments, governance analytics, and dedicated data plane at Enterprise — never compliance-gated.
Yes. Upgrades take effect immediately between Solo / Professional / Business — prorated against your current billing period, no waiting. Downgrades take effect at your next renewal date (no proration) — you keep your current tier's features until then. Upgrades to Enterprise that need a dedicated data plane provision asynchronously: you keep operating on your prior tier until the new plane is ready. Enterprise → lower tier is sales-mediated because the data-plane migration has to be scheduled.
Web search uses 5 credits per search and web fetch uses 2 credits, plus normal credit usage for the content retrieved and added to context. A typical search costs around 6–10 credits total — a small fraction of any plan's included allotment.
Start with a Free Evaluation. Upgrade when you're ready.
Start with a free evaluation — try every surface across both plans against non-PHI data, no
charges until you convert. When you're ready to go live, sign the BAA in-app, pick the
plan(s) you want, and you're done.