Pricing

Infrastructure that asks
before it destroys anything.

CloudEntail generates real Terraform from plain-language prompts — with a plan gate that blocks destructive changes until a human approves them, on every plan tier.

Plans

Pick a plan, not a compromise

Every tier includes the guardrails and plan gate. Higher tiers add scale, integrations, and control.

Billed monthly. Annual billing available — talk to sales.

$ cloudentail plan --tier=starter
Starter
For a small team standing up its first guarded IaC workflow.
$799/ month
billed monthly · one cloud provider
  • + AI-generated Terraform from plain-language prompts
  • + Guardrails & plan gate on every apply
  • + Scheduled drift detection
  • + Import existing infrastructure
  • + 1 cloud provider (AWS, GCP, or Azure)
  • + Community support
Get started
$ cloudentail plan --tier=enterprise
Enterprise
For organizations with compliance and key-ownership requirements.
$3,500/ month
billed monthly · everything in Team, plus:
  • + Full security & compliance scanning (infra + repos)
  • + Bring-your-own-key encryption (BYOK / KMS)
  • + SSO with approval-gated org access
  • + Custom LLM governance policy
  • + Dedicated onboarding & support
Talk to sales
Nothing destructive happens without approval — on every plan. A destroy request needs a reason and an admin's sign-off before terraform destroy ever runs, whichever tier you're on.
How the guardrails work →
Compare

Full feature breakdown

Feature Starter Team Enterprise
Generation & safety
AI-generated Terraform
Plan gate on every apply
Destroy approval workflow
Drift detection
Import existing infrastructure
Scale & integrations
Cloud providers1AWS + GCP + AzureAWS + GCP + Azure
Kubernetes
Environment promotion
GitHub PR automation
Jira pipeline
Alert channelsEmailSlack, Teams, PagerDuty, EmailSlack, Teams, PagerDuty, Email
Security & governance
Security & compliance scanning
Bring-your-own-key (BYOK)
SSO & approval-gated orgs
Custom LLM governance policy
Support
SupportCommunityPriorityDedicated
Questions

Frequently asked

No. Any apply that would destroy or replace a resource is blocked server-side until an admin explicitly approves a destroy request with a stated reason. This isn't a checkbox in the UI you can skip — it's enforced on every apply, regardless of plan tier.
Pick AWS, GCP, or Azure when you set up your first credential. You can generate and manage as much infrastructure as you need within that one provider. Multi-cloud (managing all three at once) is a Team and Enterprise feature.
Yes, at any time. Upgrading takes effect immediately; your existing stacks, state, and drift history carry over — nothing is re-provisioned or interrupted when you change tiers.
Yes — every tier encrypts stored credentials and sensitive configuration at rest with a dedicated, tenant-scoped key that CloudEntail manages. Enterprise's bring-your-own-key (BYOK) option lets you supply and control that key yourself; it doesn't change whether encryption happens, only who holds the key.
No. Everything CloudEntail generates or imports runs in your own AWS, GCP, or Azure account, using standard Terraform. CloudEntail holds your encrypted credentials and state; it doesn't proxy or host your workloads.
Start on Starter or Team and evaluate CloudEntail against your own infrastructure before committing. For Enterprise, talk to sales about a pilot scoped to your compliance requirements.

Generate your first stack in minutes.

No infrastructure changes without your approval — from the first prompt.