Skip to main content

Pricing

For accredited educational institutions

Academic Plans

The 3-Year and 5-Year discounts require paying the whole term up front. Institutions that need to pay each year choose the Annual plan.

Annual

$175,000per year
How you payOne invoice each year

~$15/researcher/month at 1,000 researchers.

  • Unlimited users
  • Up to 2,048 compute cores
  • Platform & security updates
  • Installation, setup & training
  • Direct engineering support
  • NIST/CMMC SSP guides
  • tiCrypt Knowledge Share

3-YearPrepaid

$472,500total for 3 years, paid up front
How you payOne invoice for all 3 years

Works out to $157,500 a year over 3 years. Equivalent to ~$13/researcher/month at 1,000 researchers.

  • Same features as Annual
  • 10% off the Annual rate, in return for paying all 3 years up front

5-YearPrepaid

$700,000total for 5 years, paid up front
How you payOne invoice for all 5 years

Works out to $140,000 a year over 5 years. Equivalent to ~$12/researcher/month at 1,000 researchers.

  • Same features as Annual
  • 20% off the Annual rate, in return for paying all 5 years up front

Additional Options

Multi-CampusTwo or more campuses under a single governing body with shared hardware and network resources
+$80,000 / yr per campus+1,000 additional cores per campus
See a 3-campus pricing example

Annual: $175,000 base + 2 additional campuses ($160,000) = $335,000 / yr with 4,048 cores

5-Year: $700,000 base + 2 additional campuses ($800,000) = $1,500,000 paid up front for 5 years with 4,048 cores (works out to $300,000 a year)

Multi-year discounts apply to the base license only. Per-campus fees are $80,000 / yr regardless of term.

Scaling Beyond 2,048 CoresFlexible per-core pricing for deployments that need more compute capacity
Contact us for pricing

Frequently Asked Questions

Do multi-year plans have to be paid up front?

Yes. The 10% discount on the 3-Year plan and the 20% discount on the 5-Year plan are for prepaying the full term, so the whole amount is invoiced at the start rather than spread across the years. The "works out to" figure on each card is that total divided by the number of years, for comparison only; it is not an annual payment. If your institution needs to pay each year, choose the Annual plan.

What infrastructure do we need to get started?

tiCrypt runs on any modern Linux-based server with hardware-assisted virtualization (Intel VT-x or AMD-V). Most deployments start with as few as two nodes using hardware your institution likely already has. We handle installation and configuration alongside your IT staff. See the full installation checklist →

How quickly can we go from purchase to researchers using the system?

Most institutions are production-ready within 5 to 10 weeks. Our team works alongside yours through server setup, initial data migration, MFA and identity provider integration (SAML 2.0 or LDAP), user onboarding, and hands-on training for administrators and researchers.

What compliance frameworks does tiCrypt support?

tiCrypt is built to satisfy NIST SP 800-171, CMMC Level 2, ITAR/EAR, HIPAA, and FERPA requirements out of the box. Every deployment includes templated System Security Plans (SSPs) that map tiCrypt controls to each framework, reducing the documentation burden on your compliance team.

How does this compare to building a secure enclave ourselves?

In-house solutions typically require 12 to 18 months of engineering, ongoing maintenance staff, and separate compliance documentation efforts. tiCrypt delivers a production-ready, independently assessed platform in weeks, with compliance documentation included and security updates handled by our team.

What federal grants require a secure enclave?

A growing number of DoD, NIH, and DOE solicitations now mandate CMMC Level 2, NIST SP 800-171, or equivalent controls. Without a compliant enclave, your institution cannot compete for these awards. See which funding requires compliance →

How does tiCrypt satisfy Data Use Agreement obligations?

Most DUAs require access controls, audit trails, and data destruction guarantees that general-purpose IT cannot structurally enforce. tiCrypt satisfies these obligations clause by clause through its architecture rather than through policy alone. Read the DUA analysis →

Can researchers run HPC batch jobs inside the secure enclave?

Yes. tiCrypt integrates with Slurm so researchers submit jobs from their secure VM. Worker nodes are provisioned, network-isolated, and destroyed automatically when the job completes. Learn about secure HPC →

What does the cloud shared responsibility model actually leave to us?

Cloud-hosted enclaves still leave the majority of NIST SP 800-171 controls to the customer. tiCrypt closes that gap so your team owns fewer residual controls and less compliance documentation. See the control-by-control breakdown →

Do we need dedicated storage hardware for CUI?

No. tiCrypt uses client-side encryption and per-user key isolation so you can run a CUI enclave on your existing shared filesystem without physically segregating storage. Read about cryptographic isolation →