Pay for supervision,
not for tokens.
Agents run on hardware you already own, under your own model keys. Neku holds their risky tool calls and waits for you. Every tier fails closed: a held call denies when the countdown runs out.
billed monthly · cancel any time · [PRICE] per month
Plans
Free
One machine, one person, no card.
free forever · no card required
Get Neku- 1 host · 2 devices
- Session inbox with live states
- Spans: the subagent tree, not noise
- Held-call approvals with a countdown
- Ask-by-default policies
- 7-day session history
- End-to-end encrypted · timeouts deny
Pro
For running five agents at once.
billed monthly · [PRICE] per month
Get Neku- Everything in Free
- 5 hosts · 5 devices
- Full policies: allow, ask or deny by pattern
- Budgets, rate-limit meters and a circuit breaker
- Push to every paired device
- 90-day session history
- Web, iOS and Android apps
Team
Shared hosts, shared policies, one log.
minimum [SEAT MINIMUM] seats · invoiced
Talk to us- Everything in Pro
- Unlimited hosts and devices
- Shared policies across the team
- Audit log of every decision
- 365-day session history
- SSO and per-account isolation
- Priority onboarding
every tier is end-to-end encrypted · code and transcripts stay on your hosts · timeouts deny
Line by line
| Feature | Free | Pro | Team |
|---|---|---|---|
| Supervision | |||
| Session inbox with states | ✓ | ✓ | ✓ |
| Spans (subagent tree) | ✓ | ✓ | ✓ |
| Held-call approvals · hold to approve | ✓ | ✓ | ✓ |
| Timeouts deny | ✓ | ✓ | ✓ |
| Reach | |||
| Hosts | 1 | 5 | Unlimited |
| Paired devices | 2 | 5 | Unlimited |
| Push notifications | ✓ | ✓ | ✓ |
| Policies & control | |||
| Ask-by-default policies | ✓ | ✓ | ✓ |
| Allow / ask / deny by pattern | – | ✓ | ✓ |
| Budgets & rate-limit meters | – | ✓ | ✓ |
| Circuit breaker | – | ✓ | ✓ |
| Shared policies | – | – | ✓ |
| History & audit | |||
| Session history | 7-day | 90-day | 365-day |
| Audit log | – | – | ✓ |
| SSO · per-account isolation | – | – | ✓ |
What counts as a host, and what counts as a device
A host is one machine running the daemon
However many agents it runs. atlas, forge and hearth are three hosts, whether they carry one session or twenty.
A device is anything you paired a key with
Phone, tablet or browser, added with neku pair. Revoke it from Account and its key stops decrypting immediately.
Before you pay
Do you charge for tokens or agent runtime?
No. Agents run on machines you already own, under your own model keys. Neku bills for supervision — the hosts and devices you watch from — never for tokens or compute.
What happens if I go offline or unsubscribed?
Supervision keeps working. The daemon still holds risky calls and denies them on timeout, and terminal, transcripts, diffs and tunnel approvals keep working with no account. Device caps only gate cloud push fan-out; they never enforce entitlements on the daemon.
What happens when I hit a host or device limit?
Existing hosts and devices keep supervising. Adding one past your tier prompts an upgrade — nothing already paired stops working, and no held call is ever left un-denied.
Can I cancel or downgrade?
Yes, any time. On downgrade you keep supervising within the lower tier's limits; history beyond the new window is no longer retained.
Is my data ever sent to Neku's servers?
No. Code, transcripts and terminal output stay on your hosts. The account server holds only entitlements and paired device public keys. See the security overview.
Start on Free. Upgrade when the second host appears.
Install the daemon, pair a phone, and watch the first session land in the inbox.
runs on your machines · end-to-end encrypted · timeouts deny