Pricing

Priced for the whole team, not per anxious decision.

Access management vendors have spent twenty years charging more for the secure option. We think that gets the incentives exactly backwards, so we don't do it.

Why it costs this little →

Single sign-on is included in every plan, at no extra charge. Entra, Okta, Google — on the $99 tier, on the $999 tier, and on every contact-sales engagement alike. Charging extra for SSO means charging extra for the secure configuration, and then acting surprised when customers don't choose it.

Basic

The whole product at a smaller scale, for teams starting out.

$99 / month
Billed monthly
Join Waitlist

Dedicated & Self-Hosted

Your own stack, run by us or by you. Nothing shared with anyone else, at any layer.

Let's talk
Priced to your environment
Contact Sales

What you get on every plan

The differences between tiers are about isolation and scale. They are not about whether you're allowed to be secure — single sign-on, encrypted credentials, the on-premises agent and every directory integration are on all four.

What happens when Basic reaches 1,000 packages. New requests stop; nothing already granted is affected. Access that exists still expires on schedule, still gets revoked in your directory on schedule, and the audit trail keeps recording all of it. A cap on this product will never stop access from being taken away — a limit that could would quietly turn every temporary grant into a permanent one, which is the opposite of what you bought. Upgrading to Hosted lifts the cap immediately.

Why the second option has no price on it. A dedicated or self-hosted deployment costs what its environment costs, and environments differ by more than any single list price could absorb. Publishing one number would mean picking a figure that is wrong for almost everyone — too high for a small team, too low for a large estate, and impossible to hold once anything needs upgrading. So we ask a few sizing questions first and quote against the answer.

 BasicHostedDedicatedSelf-Hosted
Single sign-on (Entra, Okta, Google)
Time-bound access with automatic revocation
Approval workflows
Full audit trail of every action
Tenant credentials encrypted at rest
On-premises agent for private systems
Bring your own SMTP
Packages delivered1,000UnlimitedUnlimitedUnlimited
Emails per month1,000UnlimitedUnlimitedUnlimited
Webhook notifications per month1,000UnlimitedUnlimitedUnlimited
Audit records retained60 days365 days365 daysYour policy
Dedicated infrastructure
Runs inside your own audit boundary

What customers say

Layout preview. These are illustrative examples, not real customers. They are here to show how the section will look once there are genuine quotes to put in it.
Example

“We went from a two-day turnaround on access requests to about ninety seconds. The part I didn't expect was the quiet — the queue those tickets used to sit in is just empty now.”

Illustrative examplePlatform lead, mid-size fintech
Example

“Our last access review took three weeks and a lot of spreadsheets. This one took an afternoon, because the answer to 'who has what and why' was already written down.”

Illustrative exampleHead of IT, healthcare SaaS
Example

“SSO being included is why we shortlisted them. Every other vendor wanted a tier upgrade for the thing our security team required us to have.”

Illustrative exampleSecurity engineer, logistics

Questions we get asked

Is SSO really included on the $99 plan?

Yes. Entra, Okta and Google on every tier, at no extra cost. Putting single sign-on behind an upgrade means charging a premium for the configuration your security team already requires, and we'd rather not build a business on that.

What counts as a "package delivered"?

One grant of access to one person — provisioned into your directory, tracked, and revoked when its window closes. Revocation and the audit record are part of the same unit, not a separate charge.

What happens if we exceed the email or webhook allowance?

Nothing breaks. Notifications past the month's allowance are not sent — each one is recorded as held back — and access itself is untouched: requests, grants, expiry and revocation all carry on. You can connect your own SMTP credentials on any tier and send email through your own domain, which most teams prefer anyway — approval emails then come from an address their people already recognize, and they no longer count against the allowance. Hosted has no allowance to exceed.

What happens when Basic hits 1,000 packages?

New requests stop until the next billing period or an upgrade; everything already granted carries on exactly as before. Expiry still runs, revocation still reaches your directory, and the audit log still records it. The cap is on creating new access, never on ending it — a limit that could stop revocation would convert every temporary grant you hold into a permanent one, and we will not build one.

Can we move between tiers?

Yes, in both directions. Dedicated and self-hosted run the same product on different infrastructure, so moving is a migration rather than a re-implementation.

Can we run TemprBac inside our own compliance boundary?

Yes. Self-hosting runs the whole product on your infrastructure, inside your network and under your controls, with tenant data never leaving it. We're happy to walk through the architecture and our controls in detail.