Zimac Enterprise
Self-hosted · White-label · Unlimited seats

Give every team an AI staff.
Keep the control plane in your AWS.

Zimac Enterprise combines a governed model gateway, company identity, optional team services, and a white-label desktop app — deployed around your environment instead of asking your company to move into ours.

  • Flat annual bands from $15,000, with no per-seat license fee
  • Your provider key and self-hosted service data stay in your AWS account; employee memory stays on their devices
  • A separately built Mac or Windows app carries your company’s name

Plan your deployment

Tell us what must stay governed. We’ll reply with the right deployment path, price band, and next technical step.

We use these details only to respond to your Enterprise inquiry. See our Privacy Policy.

Existing customers

Deploy an authorized release

Use the separate administrator key from your welcome package to open the verified AWS deployment form. Prospective customers should plan a deployment first.

Use the separate d1 admin key from your welcome package. Your runtime site entitlement is entered only in AWS and is never put in a browser URL. Need access? →

Installed with a form, not a terminal

The launch link opens a plain-English form in your AWS console. Paste the two credentials from your welcome package, answer the setup questions, click Create, and a build robot in your account does the rest.

1

Click the launch link

Sign in to your company AWS account. You'll land on a pre-filled setup form.

2

Complete the masked form

Choose the app name, paste the separate deployment and runtime keys, add your provider key, and select your company’s Route53 domain for working HTTPS sign-in.

3

Click “Create stack”

About 30 minutes. A progress link shows the install running; green means done.

4

Open your results

Your service addresses, bootstrap token, and branding.conf, which IT uses to build YourName.app/YourName.dmg on macOS or YourName.exe/YourName-Setup.exe on Windows.

Employee onboarding stays inside your cloud

After the stack completes, its private results folder contains service URLs, a bootstrap token, README-FIRST.txt, and branding.conf. IT then builds, signs, hosts, and distributes the branded Mac or Windows app through its normal deployment path. Employees sign in against your directory; the public Zimac Hub is not involved.

1

Admin opens the private results

Open the private results folder, copy the service and registration URLs, and retrieve branding.conf.

2

Employee registers in-cloud

The registration callback stays on your deployment. app.zimac.ai/https://zimac.ai/portal is only for Zimac’s hosted service.

3

MDM installs your build

Distribute the branded, site-licensed app and its baked-in endpoints through your normal device-management path.

Sovereign by construction

This isn't a tenant on our cloud with your logo on it. It's the platform itself, running where your data already lives.

Runs in your account

  • The LLM proxy — your provider key, held server-side, never on laptops
  • Sign-in & seats — one-click setup provisions Cognito; the hands-on installer can use Okta, Entra, or Keycloak over OIDC
  • Secure device sync — end-to-end encrypted, relayed by your servers
  • An ops dashboard for your platform team
  • Self-hosted service updates on your schedule: re-run the installer when we ship

Runtime data boundary

  • Your provider key; model prompts and responses go only to the provider you configure
  • Your employees' memories, notes, and messages
  • Your user list — we can't see who works for you
  • Runtime usage data — the deployed services have no telemetry phone-home to Zimac
  • Administrator-started installer builds contact Zimac for release authorization. Unless IT bakes in a private update feed or employees disable automatic checks, branded desktops also poll Zimac’s public update feed after launch and about daily; those requests carry normal connection metadata, not app content.

One price. Every seat.

A flat annual license per company — unlimited employees, your branding, updates and support included. The app runs on that yearly license and renews to stay active after its documented grace period; only an explicitly perpetual entitlement does not expire. Model usage runs on your own provider account, so there's no per-token markup and no per-seat meter.

Up to 250 employees$15,000/yr
251–1,000 employees$30,000/yr
1,000+ employees$60,000/yr or custom

Every band: unlimited seats, white-label included, runs in your AWS on your provider key.

Plan your deployment →