Production adoption
EvalGate is currently offered as a controlled beta. This guide helps a team
adopt the verified parts of the platform without treating a beta or experimental
surface as a general-availability promise.
EvalGate does not publish a default uptime SLA, SOC 2 certification, universal
data-residency commitment, or guaranteed support-response time today.
Governance templates are product controls, not certifications. Any negotiated
enterprise term must appear in the customer’s signed agreement.
Stage the rollout
Review the public evidence
Before each expansion, review:
Source tests, routes, or UI screens are evidence inputs, not availability by
themselves. When a public document and the runtime disagree, use the more
restrictive behavior and report the mismatch.
Define ownership before a release gate
Assign people or teams for:
- API-key issuance, scope review, and revocation;
- repository and baseline approval;
- provider credentials, data policy, and spend limits;
- evaluator calibration and failure triage;
- CI override and production rollback decisions; and
- incident communication and evidence retention.
EvalGate records decisions and evidence; it does not replace your change
management, incident response, or provider contract.
Large organizations
The four public plans remain uncapped at the published overage rate. Organizations
with more than 5 million monthly results, multiple business units, procurement or
invoicing requirements, or negotiated security and support terms should use the
Strategic Enterprise path on the pricing page.
Strategic Enterprise is a commercial review path, not a promise that every
requested control, certification, region, SSO configuration, SLA, or support tier
already exists. The agreed scope, volume schedule, rollout plan, and obligations
must be documented before adoption.
Report a gap
Send security and production-adoption questions to team@evalgate.com. Include
the organization, surface, exact route or command, timestamp, request ID, and the
expected versus observed result. Do not include API keys or provider secrets.