Skip to main content

Production adoption

EvalGate is currently offered as a controlled beta. This guide helps a team adopt the verified parts of the platform without treating a beta or experimental surface as a general-availability promise.
EvalGate does not publish a default uptime SLA, SOC 2 certification, universal data-residency commitment, or guaranteed support-response time today. Governance templates are product controls, not certifications. Any negotiated enterprise term must appear in the customer’s signed agreement.

Stage the rollout

Review the public evidence

Before each expansion, review: Source tests, routes, or UI screens are evidence inputs, not availability by themselves. When a public document and the runtime disagree, use the more restrictive behavior and report the mismatch.

Define ownership before a release gate

Assign people or teams for:
  • API-key issuance, scope review, and revocation;
  • repository and baseline approval;
  • provider credentials, data policy, and spend limits;
  • evaluator calibration and failure triage;
  • CI override and production rollback decisions; and
  • incident communication and evidence retention.
EvalGate records decisions and evidence; it does not replace your change management, incident response, or provider contract.

Large organizations

The four public plans remain uncapped at the published overage rate. Organizations with more than 5 million monthly results, multiple business units, procurement or invoicing requirements, or negotiated security and support terms should use the Strategic Enterprise path on the pricing page. Strategic Enterprise is a commercial review path, not a promise that every requested control, certification, region, SSO configuration, SLA, or support tier already exists. The agreed scope, volume schedule, rollout plan, and obligations must be documented before adoption.

Report a gap

Send security and production-adoption questions to team@evalgate.com. Include the organization, surface, exact route or command, timestamp, request ID, and the expected versus observed result. Do not include API keys or provider secrets.