The agent is free. Pay for the fleet.

The Medusa agent is open source and runs standalone at no cost. These plans cover the cloud dashboard — shared policy, telemetry, and alerting across every endpoint you run.

01 // FREE

Free

$0/mo

Individual developers and lab environments.

  • 3 endpoints
  • Full on-device DLP (9 categories)
  • 30-day event retention
  • Single dashboard user
Get Started Free
02 // STARTER

Starter

$15/mo

Small teams securing their MCP infrastructure.

  • 5 endpoints
  • 90-day event retention
  • OAuth SSO (Google / GitHub)
  • Slack / webhook alerting
  • Saved policy templates
  • Email support
Get Starter
Best Value
03 // PRO

Pro

$35/mo

Growing organizations with compliance needs.

  • 25 endpoints
  • 1-year event retention
  • Multi-user + RBAC
  • Compliance audit export
  • Alerting + policy templates
  • Priority email support
Get Pro
04 // ENTERPRISE

Enterprise

Custom

Unlimited scale, SAML, and self-hosting.

  • Unlimited endpoints
  • Unlimited retention
  • SAML / OIDC SSO
  • Self-hosted or air-gapped deployment
  • Multi-tenant (MSSP) mode
  • SLA + priority support
Contact Sales

All plans include the open-source agent — install it with pipx install medusa-mcp.

Plan Comparison

Detailed breakout of capabilities by plan.

FeatureFreeStarterProEnterprise
Endpoints3525Unlimited
On-device DLP9 categories9 categories9 categories9 categories + custom
Event retention30 days90 days1 yearUnlimited
Dashboard users1TeamTeam + RBACTeam + RBAC
SSOOAuthOAuthSAML / OIDC
AlertingSlack / webhookSlack / webhookSlack / webhook
Audit exportCSVCSV
DeploymentHostedHostedHostedHosted or self-hosted
SupportCommunityEmailPriority emailSLA + priority

FAQ

[Q1]Wait — what's free, exactly?

The Medusa agent — the thing that runs on each machine and does the actual DLP enforcement — is free and open source (Apache 2.0). It works fully standalone with no account. Pricing here is for the cloud dashboard that manages a fleet of agents: shared policy, telemetry aggregation, and alerting.

[Q2]What counts as an endpoint?

An endpoint is any machine running the Medusa agent connected to your dashboard. Each agent protects the MCP servers on that machine.

[Q3]Can I upgrade or downgrade anytime?

Yes. Switch plans anytime from Settings → Billing. Changes take effect immediately and billing is prorated.

[Q4]Can I self-host the dashboard?

Yes, on the Enterprise tier. The dashboard ships as a Docker image with a signed license key you verify offline — no data leaves your infrastructure. See our self-hosting guide.

[Q5]Do I need the dashboard at all?

No. The open-source agent enforces DLP locally on its own. The dashboard becomes worth it once you're running Medusa on more than one or two machines and want fleet-wide policy and visibility.

Ready to secure your
MCP infrastructure?