Built to fit, priced by conversation
Enterprise is the same platform on a plan shaped to your organisation. This page describes only what Enterprise customers get today — no badge-shaped claims, no line an evaluation could not verify.
Who it's for
Three reasons this conversation starts
Enterprise exists for organisations the published grid cannot describe — by size, by shape, or by the review that precedes the purchase.
-
Organisations beyond the Business plan
Seats, storage or audit history past what the published plans carry. An Enterprise plan is configured for your organisation rather than picked off a grid.
-
Organisations made of organisations
Programs, agencies, branches or partners as child organisations under one tree — with sharing across organisations and privileges that flow down the tree, never up.
-
Buyers who review before they buy
If your procurement runs a security review, this is the tier where it is answered directly — in writing, with the mechanism.
The offer
What Enterprise adds over Business
The pricing page carries the summary; this is what each line means in practice.
-
Everything in Business
The whole platform: the builder and logic engine, workflows, documents and e-signatures, payments, integrations and webhooks, AI agents and the MCP server, email-to-form, child organisations and cross-org sharing.
-
Single sign-on with your identity provider
OIDC against the provider you already operate, configured with you during onboarding. Sessions your provider opens are scoped to your organisation and its descendants.
-
Custom limits, seats and plans
Your plan is configured directly — seats, storage, email and AI allowances, audit retention set to your policy. And as on every plan, submissions are never metered or throttled: the people filling your forms are never the number you buy.
-
Annual invoicing
Priced in conversation, agreed in writing, invoiced annually. No card form.
-
Priority support and onboarding help
A direct line to the people who built the platform, and help shaping your folders, forms and workflows when you arrive.
-
Security reviews answered directly
Send the questionnaire. Answers come back in writing, in the same register as the security page: the mechanism, not an adjective.
Architecture
The security case is already public
Nothing on this page is claimed for Enterprise alone — the mechanisms below hold on every plan, are stated publicly, and are what your security review's answers will cite.
-
Tenant isolation, enforced by the database
Row-level security in PostgreSQL, matched against the organisation on your verified token. A query that loses tenant context returns nothing rather than everything.
-
An append-only audit log
The audit table refuses updates and deletes at the database-permission level, and every change a person can trigger writes an entry.
-
Retention on a schedule, provable in the log
Set a form’s retention and its records are deleted on schedule — and every deletion writes an audit entry, so deletion-on-schedule is a checkable claim, not a policy statement.
-
Every claim on this site is checkable
The mechanisms behind the platform — server-owned computation, immutable versions, closed evaluators — are stated publicly so you can verify them in the product’s behaviour.
Single sign-on
Your identity provider opens the door
Single sign-on is the Enterprise capability, and it is deliberately conservative: deny-by-default configuration, sessions bounded to your own tree, and membership that stays invitation-governed.
-
Your identity provider, by OIDC
Sign-in runs against the provider you already operate. Your side lives in your settings; Faldaro’s side — a deny-by-default allow-list of identity-provider hosts — is configured for you during onboarding.
-
Sessions scoped to your organisation
A session your provider opens reaches your organisation and its descendants, and nothing sideways — another organisation’s provider can never open yours.
-
Membership stays yours to grant
Signing in through your provider never creates an account by itself. People join by invitation, so your member list is a decision, not a side effect of your directory.
How buying works
Priced by conversation, in practice
No card form and no quote widget — a short, honest process that ends in a plan configured for you.
-
1 Write to us
Email sales@faldaro.com with what you run and roughly who is involved — the process, the entities, the identity provider if there is one.
-
2 A conversation, not a card form
We talk through limits, seats and entities and recommend honestly — including a smaller plan, or a different tool, when that is the right answer.
-
3 Your security review, answered
Send the questionnaire whenever you are ready. Written answers, each naming the mechanism.
-
4 A plan shaped to you
Your plan is configured, single sign-on is set up with your identity provider, and an annual invoice closes it out.
The first step is just an email: sales@faldaro.com. We reply in the same register as this page.
Questions
Enterprise, plainly
What the conversation usually covers, answered before it starts.
How is Enterprise priced?
By conversation, after we understand your scope — seats, entities, storage and history. The agreement is annual and invoiced; there is no self-serve Enterprise checkout.
Can we start on Business and move up later?
Yes. Plans change in place — your folders, forms, submissions and history stay exactly where they are. Many Enterprise conversations start as a Business organisation reaching its limits.
What does “custom limits” actually mean?
Your plan’s seats and allowances are configured for your organisation rather than picked from the published grid. One thing never changes: submissions are never metered or throttled on any plan, so the people filling your forms are never the number you buy.
How does single sign-on onboarding work?
You tell us your identity provider; we allow its host on our side and hand you the callback URL to register with it. You finish in your settings with your provider’s details, and from then on sign-in runs through your provider, scoped to your organisation.
What do we get for our security review?
Written answers, directly from the people who built the platform, in the same register as our security page: the mechanism rather than the adjective. The architecture — database-enforced tenant isolation, an append-only audit log, server-owned computation — is public and checkable before you ever send a questionnaire.
Start the conversation
Tell us what you run and who is involved — we will answer with mechanisms, a recommendation, and a plan shaped to fit.