---
title: "Enterprise · Caveman"
description: "The things we run for you. Covered public-catalog spend in, eval-gated changes"
canonical: https://caveman.so/enterprise
last-updated: 2026-10-08
---

# Enterprise · Caveman

The things we run for you. Covered public-catalog spend in, eval-gated changes
out, and a causal-cache verified ledger that starts at the honest zero.

Caveman Cloud is in private development. Book a call: https://cal.com/caveman/chat

## The managed plane

1. **Compression, every method** — nine compressors for JSON, logs, code, tables, diffs, search results and bulk context. Originals are always recoverable.
2. **Every dollar explains itself** — who spent it, through which key, on which model, and why it burned. Twenty detectors file each dollar under a cause.
3. **Cave Plan** — ranked moves with a dollar figure on each, read from your own traffic. Per-day rates, inferred until proven.
4. **Model routing** — the cheapest model in your pool that passes your evals, or traffic stays put. In development; savings stay inferred until provider-causal.
5. **Eval-gated rollout** — record → replay → shadow → canary → active, with a gate at every stage and automatic rollback on regression.
6. **Caching, done for you** — provider-native cache hints added upstream only. Model-visible bytes untouched. Today's only verified dollars.
7. **Runs where your prompts live** — hosted (managed gateway, BYOK, never resold), your cloud (Helm-deployed in your VPC), or on-prem (your datacenter). In your cloud account, request content and operational telemetry stay in your deployment's configured storage. Caveman's operational and support access is defined in your agreement. Separate CLI usage telemetry can be turned off; your chosen model providers still receive requests. On hosted Enterprise, request bodies are stored by default like on every plan, redacted and encrypted. An admin can switch storage off to keep metadata only, any request can send `x-cave-retention: zdr`, and Enterprise traffic is never used to train Caveman's models.

## Governance

SSO via SAML and OIDC, five-role RBAC, row-level organization isolation, an
append-only audit log, and Ed25519-signed receipts (manual export today).

Scoped access tokens narrow an integration to a subset of the caller's role
permissions; authorization is the intersection of role and scope, so a scope
never grants authority the role lacks. The scope catalogue is published in the
[OpenAPI specification](https://caveman.so/openapi.json).

## How a number becomes a number

Spend is priced from provider-reported usage multiplied by the public model
catalog. Unknown models stay unpriced. Verified savings start at $0.00 and move
only on provider-causal evidence: measured at the gateway, planned in dollars,
fixed by a Cave Agent pull request you review, verified on your live traffic.
Nothing is claimed on a projection.

## Talk to us

[Book a conversation](https://caveman.so/enterprise) ·
[contact@caveman.so](mailto:contact@caveman.so)
