Cost control

The compute lands on your bill. That is the whole pricing model.

Kapten invoices you for the control plane. AWS invoices you for the infrastructure, directly, at the rates you already negotiated. Nothing passes through us, so there is nothing for us to mark up.

Kapten bills
The control plane
AWS bills
Your infrastructure, directly
Markup
None — nothing is resold
Commitments
Savings Plans and RIs still apply

One role assumption crosses the boundary. Nothing else does.

The billing argument and the security argument are the same argument: your resources are created by a role you own, in an account we never hold a credential for.

KAPTEN CONTROL PLANEGitHub Apppush → build queuedDeploy orchestratordrives the in-cluster agentMetadata storedeploy state · log indexSTORESdeploy metadata, build status,log index, service topology.Never your data, never your keys.sts:AssumeRolerole/KaptenControlPlanesession 900sYour AWS account · 918273644021AWSVPC vpc-0a91c4f2 · eu-west-3PRIVATE SUBNETS · 3 AZKubernetesmanaged · 3 AZYour workloadsapi · web · workerIngress + LBstatic IP · TLSManaged Postgresfrom your blueprintObservabilityGrafana + LGTM stackKapten agentegress onlyYour VPC · no peeringStandard KubernetesYours if we vanishegress only · no inbound path from Kapten · CloudTrail logs every call
01

git push

Commit 4f2a9c1 lands on main. Kapten's webhook receiver queues a build and resolves the target environment. Nothing has touched your AWS account yet.

Where the money goes

A bill you can already audit.

BYOC is usually sold on sovereignty. The part teams notice first is duller and lands sooner: the infrastructure line on the invoice is one they already know how to read.

  • No resale margin

    Kapten never sits between you and AWS on the invoice. The compute transaction is one we do not see, cannot mark up, and have no reason to grow.

  • Your commitments still count

    Savings Plans, Reserved Instances and any negotiated discount apply to Kapten-provisioned capacity, because it is ordinary capacity in your own account rather than a slice of ours.

  • Cost per service, per environment

    Resources are tagged as they are created, so the breakdown arrives in the tool your finance team already reads instead of in a dashboard only we can show you.

  • Idle is a setting, not a surprise

    Environments that are not serving traffic can sleep. A preview environment costs what it costs while its pull request is open, and nothing once it closes.

  • Leave and keep the cluster

    There is no proprietary runtime to unwind. Stop paying Kapten and the infrastructure keeps serving traffic — you already hold every key to it.

  • Every action is attributable

    Provisioning runs through a published, versioned IAM policy. Anything that appears on your bill can be traced back to something Kapten was explicitly allowed to do.

Ready when you are

Your cloud. Our ergonomics.

Connect a cloud account and watch a production-grade environment come up in your own VPC. If it isn’t serving traffic in fifteen minutes, we want to hear why.