Enterprise

Frontier AI coding, inside your perimeter.

Your models. Your GPUs. Your keys. Ship faster without your code, prompts, or IP ever leaving your control.

SOC 2 Type II (in progress)ISO 27001 (in progress)GDPR • HIPAAZero Data Retention30M+ DevelopersFortune 500 Trusted
Trusted at scale

Already shipping at scale.

30M+

developers worldwide

4.2M

VS Code installs

4hr

critical incident response

Trusted across regulated industries

Deloitte
Microsoft
Intel
Accenture
Apple
Amazon
Salesforce
Google
Infosys
Oracle
Capgemini
GitHub
ByteDance
Cisco
PwC
SAP
Cognizant
Why Enterprise

Frontier speed. Sovereign control.

Dedicated GPU Compute

Reserved hardware, your weights

Your models run on hardware reserved for you — not shared inference pools. Pin the region, scale capacity, and run frontier, open-source, or your own weights without noisy neighbors or rate-limit contention.

  • Reserved GPU pools
  • Frontier, OSS, or BYO model weights
  • Regional pinning & dedicated capacity

Isolated Sandboxes

Single-tenant execution

Every agent run, code execution, and tool call happens in single-tenant sandboxes provisioned per workspace. No cross-customer process, network, or filesystem access — ever.

  • Per-workspace agent sandboxes
  • Zero cross-tenant access
  • Network & filesystem isolation

End-to-End Encryption

Zero-knowledge architecture

Encrypted from your IDE to inference and back. Customer-managed keys, per-tenant encryption, and encrypted memory mean not even Blackbox can read your prompts, completions, or code.

  • Customer-managed keys (BYOK)
  • Per-tenant encryption at rest
  • Encrypted prompts & memory

Fully Customizable

Configure every layer

Bring your own models, IdP, git, observability stack, DLP rules, and deployment target. Every policy and integration is configurable per workspace to fit your security model and your stack.

  • SAML/SCIM/RBAC with your IdP
  • Model allow-lists & content policies
  • Audit streams to your SIEM

Zero Data Retention

Nothing logged, nothing trained

Prompts and completions are discarded after every response. Abuse monitoring off, no human review, no side-channel collection. Your code never trains a model — yours or anyone else's.

  • No prompt or completion logging
  • Abuse monitoring disabled
  • Excluded from all training pipelines

Flexible Deployment

Your cloud, your datacenter

Run on our hardened multi-tenant SaaS, a dedicated VPC in AWS/Azure/GCP, on-premise inside your datacenter, or fully air-gapped with no outbound internet. Regional residency in US or EU on every mode.

  • Multi-tenant SaaS or dedicated VPC
  • On-prem & air-gapped installs
  • US / EU regional pinning
Deployment

Your boundary. Your rules.

SharedSovereign

Tier 01 · Shared

Multi-tenant SaaS

The fastest path to production — our hardened cloud with SSO, SCIM, RBAC, audit logs, and Zero Data Retention enabled by default on Pro and above.

  • Hardened multi-tenant cloud
  • Zero Data Retention on Pro and above
  • Ships in hours, not weeks
Capability Matrix

Every category. Every tier.

CapabilityWhat You GetIncluded In
Security & Compliance
Zero Data RetentionPrompts and completions discarded after every responsePro & above
Abuse Monitoring OFFNo human review, no prompt logging, no side-channel collectionEnterprise ZDR
End-to-End EncryptionZero-knowledge chat — not even Blackbox can read your contentEnterprise
SOC 2 Type IIAudit in progress — interim letter available under NDAIn progress
ISO 27001Certification in progress — current scope available under NDAIn progress
HIPAA BAABusiness Associate Agreements for healthcare customersEnterprise
GDPR & CCPADPA signed — data subject rights fully honoredAll Plans
Identity & Access
SAML 2.0 SSOOkta, Azure AD / Entra ID, Google Workspace, OneLoginEnterprise
SCIM 2.0 ProvisioningAutomated user and group lifecycle from your IdPEnterprise
Fine-grained RBACControl access to repos, models, and agent capabilities per roleEnterprise
Audit Logs → SIEMStreaming to Splunk, Datadog, Sumo Logic, Elastic via webhook or S3Enterprise
Session & Device PolicyIP allow-listing, session timeouts, enforced MFAEnterprise
Deployment & Data Residency
Dedicated GPU PoolReserved GPU capacity for your models — no shared inference, no rate-limit contentionEnterprise
Single-tenant SandboxesPer-workspace isolated execution for agents, code runs, and toolsEnterprise
Multi-tenant SaaSFastest path to production on our hardened cloudAll Plans
Dedicated VPCSingle-tenant cloud deployment in AWS / Azure / GCPEnterprise
On-PremiseDeploy inside your own datacenter with our install packageEnterprise
Air-gappedNo outbound internet required — fully sovereign installEnterprise
Regional ResidencyPin to US or EU regions — data never leaves the regionEnterprise
Customer-managed KeysBYOK / CMK for full cryptographic controlEnterprise
Models & Integrations
Frontier + OSS ModelsClaude, GPT, Gemini, Grok, Llama, Mistral, DeepSeek, Qwen — one key, every model, automatic failoverAll Plans
BYO Model EndpointsRoute to private models on your preferred hyperscaler or any OpenAI-compatible endpoint you hostEnterprise
Self-hosted GitGitHub Enterprise Server, GitLab Self-Managed, Bitbucket Data CenterEnterprise
Custom IntegrationsJira, Slack, Teams, Linear, and custom webhooksEnterprise
Unified APIOpenAI-compatible — one key across every modelAll Plans
Governance & Admin
Workspace IsolationPer-tenant encryption keys, no cross-tenant accessEnterprise
Usage QuotasPer-user and per-team spend limits with real-time alertsEnterprise
Model Allow-listingRestrict which models can be used per team or projectEnterprise
Content Policy ControlsCustom DLP rules, prompt filters, and redaction policiesEnterprise
Admin DashboardsUsage, spend, and activity across every workspaceEnterprise
Support & SLA
99.9% Uptime SLAContractual uptime guarantee with service creditsEnterprise
24/7 Priority SupportResponse times as fast as 4 hours for critical incidentsEnterprise
Dedicated CSMA named Customer Success Manager assigned to your accountEnterprise
Named Slack ChannelShared Slack or Teams channel with our engineering teamEnterprise
Custom OnboardingWhite-glove rollout, training, and SSO / deployment setupEnterprise
FAQ

Common questions. Plain answers.

How do we start an enterprise pilot or POC?

Reach out to enterprise@blackbox.ai with a short description of your use case, team size, and any compliance requirements. We'll scope an evaluation that fits — including trial credits, a security review, and a path from pilot to production.

Can we sign a custom MSA, DPA, and BAA?

Yes. We sign custom Master Service Agreements, Data Processing Addenda, and HIPAA Business Associate Agreements. A standard DPA is available for GDPR customers, and our legal team is fast — most redlines turn around in 48 hours.

What deployment options do you support?

Multi-tenant SaaS, dedicated VPC in AWS / Azure / GCP, on-premise inside your own datacenter, and fully air-gapped installs with no outbound internet. Regional data residency in US and EU is available on every deployment mode.

Do you offer volume discounts and custom pricing?

Yes. Volume discounts start at 10+ seats. Enterprise contracts include custom token pricing, annual commitments with rollover, and usage-based billing at the workspace or department level. Net-30 and Net-60 payment terms are available.

What does onboarding look like?

Enterprise onboarding covers SSO / SAML configuration, SCIM setup, RBAC design, repository integration, model allow-listing, and admin training. We scope the timeline with your team based on environment complexity and compliance requirements.

Can Blackbox be deployed without outbound internet access?

Yes. Our air-gapped install ships with a curated set of open-source model weights (Llama-family, Mistral, DeepSeek, Qwen) that run fully offline inside your perimeter. For online deployments, frontier models (Claude, GPT, Gemini, Grok) are routed through the customer's preferred cloud with automatic failover across providers. The air-gapped mode is used by regulated industries with strict network egress policies.

What support and SLA do enterprise customers get?

Enterprise contracts include an uptime SLA with service credits, priority support with defined response times, and a named point of contact for ongoing account management. Specific SLA targets, response windows, and review cadences are negotiated as part of the contract.

Ready to deploy Blackbox in your perimeter?

Tell us about your security and deployment requirements — we'll scope a pilot that fits.