Skip to main content
C1.ai logo
Risk & ComplianceNew to marketNewest entrant

C1

Identity platform for the AI era: govern human, non-human, and AI agent identities, enforce agent guardrails, and automate cross-system work.

By C1.ai · HQ San Francisco, US · 4.3/5 Value-Position score (estimate)

Positioning guardrails

Best for

  • Large enterprises consolidating identity governance for human, non-human, and AI agent identities on one platform
  • Security teams moving privileged access to automated, policy-based just-in-time access
  • Organizations rolling out AI agents that need runtime guardrails, MCP governance, and human approval for sensitive changes
  • Enterprises with legacy or on-prem systems that need 400+ prebuilt connectors plus a custom connector builder

Ideal size: 1,000+ employees people · Enterprise with a dedicated identity and security team

Not for

  • Small teams wanting a low-cost, self-serve SSO or password manager
  • Buyers who need published list pricing and instant self-serve signup
  • Companies that only need basic single sign-on, with no access reviews, evidence, or agent controls

Value metrics scorecard

Time-to-Value

Weeks-scale, not months (connector-driven)

~30 days to first production value

Total Cost of Ownership

On request

Two models: SKU-based Platform pricing (scoped by managed identities and product modules) or usage-based Flex pricing billed in C1 Tokens; exact pricing quoted per deal, no published list price.

Implementation Friction

3/5

Engineering + admin effort required

Value-Position score

4.3

out of 5 · model estimate

Full cost breakdown

Mandatory implementation fee

None

Seat tiers

Priced by managed identities (slider shows 100–20,000) and platform level (Pro or Advanced); no seat tiers published.

Add-on costs

  • Flex pricing bills monthly by consumption: billable events draw down C1 Tokens.
  • Platform pricing covers selected product modules (Identity Governance, AI Gateway, Vault, Agents) and requires a scoped quote.

Company & support

Who is behind C1, and how your team gets help once it is live.

Company

Founded
Not recorded
Headquarters
San Francisco, US

How you get support

  • PhoneNot listed
  • EmailNot listed
  • Live chatNot listed
  • Support portal / ticketsNot listed
  • Community forumNot listed
  • Help centre / docsPlan not stated
  • Dedicated account managerNot listed
  • In person / on-siteNot listed
Hours
Not recorded
Response time
Not stated

Contact page routes existing customers to the support channel established for their C1.ai tenant. Public product and developer documentation is available. [email protected] is for vulnerability reports, not product support.

“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.

Market position

Where C1 sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.

Quadrant view

Typical annual cost × Time-to-value

$0/yr$1/yr27d29d30d31d33dAnnual TCO ← betterDays to value better →Quick & CheapQuick & PriceySlow & CheapSlow & PriceyC1Monte CarloLiving SecurityBitsightScytaleEverlaw

The lines cross at the median of the solutions shown, so about half sit on each side of each line.

C1 is outlined. Click any dot to open its dossier.

Companies on the chart 6 / 10

  • C1
  • Monte Carlo
  • Living Security
  • Bitsight
  • Scytale
  • Everlaw
Add or change companies

Up to 10 companies including C1. Listed closest first.

Stack fit signal

Compatibility with standard B2B ecosystems.

MCPNative

Ships an official MCP server. Connects to Claude Code, Claude Desktop, ChatGPT connectors and Cursor out of the box.

SalesforceIntegration
AWSIntegration
SnowflakeIntegration
HubSpotNot supported
Google WorkspaceIntegration
Microsoft 365Integration
SAPIntegration
SlackIntegration

AI & MCP readiness

What C1 ships in AI, and what it asks of your ecosystem.

AI features shipped

AI added to an existing product
Agentic workflowsAI governance tooling

Homepage describes AI-driven lifecycle, access request, review and compliance automation, C1 Agents that complete multi-step jobs with human approval, a guardrailed MCP gateway, and shadow-AI discovery. No vendor page states which models power C1 or whether customer data is used for training.

Your data & models

Trains on your data
Not recorded — ask the vendor
Runs on
Not recorded
AI pricing
Billed by usage or credits

In your ecosystem

AI connection
Official MCP server
Model key
Not recorded
AI usage audit
Not recorded

Compliance attestations

SOC 2 ISO 27001 — not listedGDPR — not listedHIPAA — not listedFedRAMP — not listedCMMC — not listedISO 42001 — not listedIAPP AIGP* — not listed

* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.

Bottom line

C1.ai is an enterprise identity governance and security platform built for the AI era. It governs human, non-human, and AI agent identities from one control plane: lifecycle and access management, access reviews and compliance evidence, just-in-time privileged access, credential vaulting, and shadow-AI discovery. C1 Agents automate multi-step work across connected systems with human approval for sensitive changes, and the MCP Gateway enforces policy on MCP. 400+ prebuilt connectors, REST API, SDKs, and Terraform. SOC 2 Type II audited; pricing quoted per deal.

Frequently asked questions

What does C1.ai actually do?

C1.ai is an identity governance and security platform. It manages lifecycle, access requests, reviews, and compliance evidence for people, non-human identities, and AI agents; enforces runtime guardrails for agents; vaults credentials; discovers shadow AI, agents, and MCP servers; and runs C1 Agents that complete multi-step work across connected systems with human approval for sensitive changes.

How is C1.ai priced?

C1.ai offers two models: Platform pricing, which is SKU-based and scoped by number of managed identities (100–20,000 shown) and selected product modules, and Flex pricing, a usage model where billable events consume C1 Tokens and billing is monthly. Exact prices are not published; the company scopes them with each buyer. Hosting paths include commercial, regional, and federal.

How long does implementation take?

C1.ai ships 400+ prebuilt connectors and lets teams build custom connectors with AI for APIs, databases, or CSV exports, aiming for complete coverage in days or weeks rather than months. Published customer results include onboarding new employees in under an hour and adding 400 entitlements in two days. Enterprise scope, on-prem systems, and governance design still drive the real timeline.

Is C1.ai secure and compliant?

C1.ai's security page states its control domains are reviewed in an annual SOC 2 Type II audit, with TLS 1.2+ in transit, mutual TLS internally, per-tenant encryption and isolation, AWS multi-region redundancy, and annual disaster-recovery dry runs. SOC 2 reports, penetration test results, and subprocessors live in the vendor's Trust Center. The site does not claim ISO 27001 or FedRAMP for the vendor itself.

Does C1.ai support AI agents and MCP?

Yes. C1.ai documents MCP support: C1 MCP Gateway applies identity-aware policy and guardrails to MCP, C1 Agents run multi-step workflows with human approval for sensitive changes, and the platform discovers unsanctioned AI tools, agents, MCP servers, and credentials. Documentation covers using AI tools and MCP clients as an end user.

How do customers get support?

C1.ai's contact page directs existing customers to the support channel established for their C1.ai tenant, so the team can verify organization and account context. Product and developer documentation is public. Security issues go to [email protected]. The site does not publish support hours or a response-time SLA.