30-day trial, no card taken · macOS
Pricing
All prices in USD, billed annually, exclusive of tax. Annual terms only: there is no monthly price, because there is no monthly plan.
Pro
One developer
$70/ user / year
Team
Two or more, with shared repositories
$140/ user / year
Enterprise
Procurement, security review, SSO
Custom
Annual only. Nothing can be bought yet.
Nothing here can be bought yet. There is no checkout and no payment provider. The prices are the terms that have been set, published so you can plan around them.
After the trial
Three plans
Every plan carries every capability. What separates them is how many people, how much of the pooled resources, and what an organisation needs on paper.
Pro
Most chosenOne developer, every capability, with the whole recovery history kept.
$70per user / year
Billed annually, excluding tax.
- Every everyday Git operation: staging, branches, merges, rebases, worktrees, stashes, submodules and LFS
- Operation Preview before anything dangerous, showing the exact commands
- A recovery capsule before every risky operation, kept until you remove it
- Lost Work across the reflog, the stash reflog, refs/aegis/ and a bounded git fsck
- Safe Mode, the Operation Journal and Doctor's full repair set
- Email support, first response within two business days
Team
A team that needs the same rules to apply to everyone, and evidence that they did.
$140per user / year
Billed annually, minimum 2 seats.
- Everything in Pro, for two or more people
- Seats are assigned to people, not machines
- Shared repositories: give somebody the files they need, not the whole history
- Larger monthly pools for syncing and AI, counted per seat
- Email support, first response within one business day
Enterprise
An organisation with a procurement process and a security review.
Custom
Written to sales@gitaegis.com.
- Everything in Team, with the largest pools and seat counts
- Single sign-on and directory-managed accounts
- A negotiated agreement, a named contact and a security review
- Managed updates on a schedule you set
- Priority support with an agreed response target
All prices in USD, billed annually, exclusive of tax. Annual terms only: there is no monthly price, because there is no monthly plan.
Or buy it once
The complete local application, owned outright, with no subscription and no renewal.
Lifetime
$299once
Every desktop capability Pro has, on two computers, for as long as GitAegis operates this software. Updates included for that whole time. No renewal, no expiry, and no account needed to open a repository.
500 licences in the first run, then it closes. A promise with no end date is priced against a cost that never ends, so the number sold is fixed in advance rather than discovered later.
Nothing can be bought yet: there is no checkout anywhere in this product. The terms are published so they can be judged before they can be paid.
What it includes
- Every everyday Git operation, and every desktop capability Pro has
- Recovery capsules kept until you remove them, with no ceiling on how many
- Flight Recorder history kept for 90 days, the same as Pro
- Deep Lost Work: a bounded git fsck, capsule bundles, sibling worktree HEADs and Flight Recorder “before” oids
- Doctor’s full repair set
- Semantic Composer, reviewed before anything is applied
- Two computers signed in at once, the same as Pro
- Every update for as long as the software is operated
What it does not include, and why
- AI explanations
- Every explanation is inference somebody pays for at the moment it runs.
- Cloud capsule backup
- Stored bytes cost money every month they stay stored.
- Shared repositories
- A served repository uses storage and bandwidth continuously.
- Organization features and seats
- Policies, the audit trail and shared workspaces are a running service, and seats are how several people are paid for.
Each of those runs on a service that costs money every month it keeps running. One payment cannot fund a cost that never stops, so they belong to the subscriptions rather than to this. A lifetime licence and a subscription can be held at the same time.
Add-ons
Extend a plan's capabilities without a full upgrade. Each add-on is an annual grant to an organisation.
Shared Repositories
Price not yet set · per organisation / year
Unlock shared repositories for an organisation on any plan, without upgrading to Team.
Nothing can be bought yet: there is no checkout anywhere in this product. The terms are published so they can be judged before they can be paid.
What it unlocks
- 50 shared repositories at once
- 10 people per shared repository
- 1,000 syncs a month
- 10 branches per shared repository, including the primary
- GitLab and GitHub as push destinations for served branches
What it requires
- An organisation: shared repositories are organisation features and belong to the org, not to a person
- At least one member with a Pro or Team seat to push from the shared repository
What every plan shares, and what no plan can take away
Recovery is not held hostage. A capsule is taken before a risky operation on Pro exactly as it is on Enterprise, the operation is refused if the capsule cannot be written, and when a subscription ends your repositories still open: history, undo, capsule restore and export never stop.
What GitAegis can put back
- If a recovery capsule was taken, you can roll the operation back.
- If a Flight Recorder event captured a state hash, you can roll back to that state.
- If any reflog entry, ref, branch, stash, or capsule references a commit, Lost Work can recover it.
- Outside those, it cannot, and GitAegis says so instead of pretending otherwise.

Limits that apply on every plan
- Rebase state is not restored from a capsule.
- Configuration is not restored from a capsule. It is kept as evidence only.
- .gitattributes content filters cannot be wholesale disabled.
- Bisect and a conflicted stash apply have no generic resume.
And on every plan, GitAegis asks before deleting a capsule. Retention governs what it marks as expired and offers to clean up; it never governs what it removes without your say-so.
Every capability, across every plan
Each row is a capability that ships today, scored against the desktop application rather than against a plan document.
| Capability | Pro | Team | Enterprise |
|---|---|---|---|
| Everyday Git | |||
| Repository catalogue and discovery across a folder tree | Included | Included | Included |
| Status: staged, unstaged, untracked, conflicts | Included | Included | Included |
| Hunk-level and line-level staging | Included | Included | Included |
| Commit, with amend safety and signing pass-through | Included | Included | Included |
| Branches, tags, remotes, refs, reflog | Included | Included | Included |
| File history, blame, commit graph, compare, search | Included | Included | Included |
| Bisect | Included | Included | Included |
| Fetch, pull, push, force-push-with-lease, publish, prune | Included | Included | Included |
| Merge, rebase, cherry-pick, revert, reset, restore, clean | Included | Included | Included |
| Conflict detection, stage-1/2/3 read, resolution | Included | Included | Included |
| Sequencer continue / skip / abort | Included | Included | Included |
| Worktrees: create, lock, unlock, prune, open | Included | Included | Included |
| Stashes: create, apply, drop, branch, clear | Included | Included | Included |
| Submodules: init, update, recursive, sync, deinit | Included | Included | Included |
| Git LFS: status, missing-object accounting, locks (read-only), fetch | Included | Included | Included |
| Clone with streamed, cancellable progress | Included | Included | Included |
| Five modes: Home, Work, History, Review, Doctor | Included | Included | Included |
| Command palette ⌘K over real intents | Included | Included | Included |
| UI scale 80–200%, light / dark / system theme | Included | Included | Included |
| Private repositories | Included | Included | Included |
| Commercial use | Included | Included | Included |
| The recovery layer | |||
| Recovery capsule taken before every risky operation | Included | Included | Included |
| Six capsule domains: refs, index, staged, working, untracked, operation state | Included | Included | Included |
| Operation refused if the capsule cannot be taken | Included | Included | Included |
| Restore per domain, or all domains | Included | Included | Included |
| Capsule retention | Until removed | Until removed | Until removed |
| Capsule browser and manual capsule capture | Included | Included | Included |
| Flight Recorder timeline | Full history | Full history | Full history |
| Filesystem watcher: records changes GitAegis did not cause | Included | Included | Included |
| Roll back to a Flight Recorder event that captured a state hash | Included | Included | Included |
| Lost Work: reflog, stash reflog, refs/aegis/ recovery refs | Included | Included | Included |
| Lost Work: bounded git fsck --unreachable --dangling | Included | Included | Included |
| Lost Work: capsule bundles, sibling worktree HEADs, Flight Recorder “before” oids | Included | Included | Included |
| Safe Mode: mutating controls lock out, core.hooksPath pinned to /dev/null | Included | Included | Included |
| Operation Journal: intent, commands, checkpoint, outcome | Included | Included | Included |
| Reconciliation of an incomplete operation after a crash | Included | Included | Included |
| Doctor: scan, with the evidence behind each finding | Included | Included | Included |
| Doctor: core repairs, each preceded by a capsule | Included | Included | Included |
| Doctor: full repair set | Included | Included | Included |
| Doctor: plain and technical report export, optional path redaction | Included | Included | Included |
| Never runs gc, prune, or reflog expiry | Included | Included | Included |
| Support bundle: written locally, secret-scanned, path-redactable | Included | Included | Included |
| Working faster | |||
| Semantic Composer: proposed commit groupings, applied through the orchestrator | Included | Included | Included |
| Plan terms | |||
| Account required | Included | Included | Included |
| Network required for local Git operations | Never | Never | Never |
| Minimum seats | 1 | 2 | Negotiated |
| Billing | Annual | Annual | Annual, negotiated |
| Email support first-response target | 2 business days | 1 business day | Agreed target |
A tick means the capability is in the shipped build for that plan. A dash means it is not. There is no third state and no footnote doing quiet work.
How much of each, on each plan
The capability table above says whether something exists. This one says how much of it you get, in the numbers the service itself refuses against.
| Limit | Pro | Team | Enterprise |
|---|---|---|---|
Computers signed in at once Sign a computer out to make room for another. Nobody is signed out when a plan changes. | 2 computers | 5 computers | 10 computers |
Seats A seat belongs to a person, not a machine. Team and Enterprise are sold by the seat. | 1 seat | 50 seats | 500 seats |
AI explanations Counted per person, starting again on the first of the month. | 300 explanations a month | 500 explanations a month, per seat | 2,000 explanations a month, per seat |
Cloud capsule backup What your account keeps in cloud backup at any one time. | 10 GB | 25 GB, per seat | Unlimited |
Shared repositories Held at once. Retiring one frees its place immediately. | 50 shared repositories | 100 shared repositories | 200 shared repositories |
People per shared repository Everyone a single repository is served to, invitations included. | 10 people | 25 people | 250 people |
Syncs A pass that brings a shared repository up to date, counted for the whole organization. | 1,000 syncs a month | 500 syncs a month, per seat | 1,000 syncs a month, per seat |
These are the numbers the product enforces, read from the same table the service refuses against. Everyone is warned at four fifths of a limit, and reaching one stops new use of that capability only: nothing already made stops working, and undo, restore, export and revoke are never blocked.
What the paid plans do not include today
These are the capabilities the plan ladder is designed around. Each one is stated here rather than shown as a filled cell in the table above, because none of them runs.
Not built, not running, or not reachable
- Cloud capsule backup and multi-device restore
- No capsule storage service is running. Capsules stay on your disk, and there is nothing to upload them to.
- GitHub and GitLab in the client
- The read-oriented GitHub and GitLab connector foundation exists, including self-hosted PAT connections. Its production registrations, live end-to-end qualification and public rollout are not complete; provider writes and webhook-backed freshness also remain planned.
- AI assist beyond the commit report
- The AI commit report ships, needs a signed-in account, and is not a paid capability: usage is counted and rate-limited, and there is no plan quota because there is nothing to buy. Commit-message drafting, conflict explanation and Doctor summaries are bound to no provider and do not run.
- Shared workspaces, Change Sets, branch leases, and an organisation audit trail
- These exist as an undeployed prototype, not as a service anyone can sign in to.
- Org policy as a trust boundary
- Policy documents are signed with a symmetric key that every member of the organisation can read, so a member could mint one.
- SSO, SCIM, regional data residency, audit retention controls, and legal hold
- None of these is implemented.
- Staged rollout and rollback of updates
- Updates ship to everyone at once. The updater checks one manifest, verifies the archive's signature against a key built into the application, and installs when you press Restart to update. What is absent is the staged percentage rollout, the kill switch and the forced downgrade: a bad release is withdrawn by repointing the manifest, which protects installs that have not updated yet and does nothing for one that already has.
The local edition never depended on any of it. Every local operation, every capsule, and every restore works on a machine that has never been on a network: there is no licence check and no server in the path of any of it.
Terms
| Term | Detail |
|---|---|
| Currency | USD. Every price on this page is USD and excludes tax. |
| Billing period | Annual. Monthly billing is not sold, and no page on this site quotes a monthly-equivalent price, because you could not buy one. |
| Tax | Prices exclude sales tax, VAT, and GST. |
| Minimum seats | 1 on Pro. 2 on Team: a one-person team is a Pro subscription. Negotiated on Enterprise. |
| Trial | 30 days of Pro, with no card taken. No card is taken, so nothing is charged and nothing renews by itself. When it ends, GitAegis keeps opening your repositories: history, undo, capsule restore and export never stop. What waits for a subscription is making new work. |
| Money back | 30 days from the first charge, in full, no reason required. |
| Payment methods | None. No payment provider is integrated, so there is no card, wallet, bank transfer or invoice path to describe. |
| Where the numbers can change | Here, and on the changelog. A price on any other page of this site would be a copy of this one, so there are none. |
Prices appear on this page and nowhere else on this site. If you find one somewhere else, it is a copy, and copies go stale.
Pricing questions
Commercial terms: sales@gitaegis.com. Security questionnaires: security@gitaegis.com.
30-day trial · No card required
A recovery capsule before every risky Git operation.
You see the exact commands before they run, and the operation is refused if the capsule cannot be written.
Requires Git 2.38.0 or newer, already installed.
Every risky operation, in this order
- Previewthe exact commands, shown before anything runs
- Capsulerefs, index, staged and working changes, untracked files, operation state: written to disk first
- Executethe commands as shown, or not at all
- Journalplan, commands, capsule id, outcome