diff --git a/bots.mdx b/bots.mdx
index 49b03d98..48440ddd 100644
--- a/bots.mdx
+++ b/bots.mdx
@@ -1,5 +1,6 @@
---
-title: "Bots and agents"
+title: "KERNEL Bots and Agents"
+sidebarTitle: "Verify KERNEL Traffic"
description: "Kernel's bots and agents, their purposes, and how to verify them with Web Bot Auth"
---
diff --git a/docs.json b/docs.json
index 9d7946df..f184da18 100644
--- a/docs.json
+++ b/docs.json
@@ -268,39 +268,49 @@
]
},
{
- "group": "Working with your browser",
+ "group": "Partnering with KERNEL",
"pages": [
{
- "group": "Intermediate",
- "expanded": true,
+ "group": "Plans and Billing",
"pages": [
- {
- "group": "Bot Anti-Detection",
- "pages": [
- "bots"
- ]
- }
+ "info/pricing",
+ "info/spending-caps",
+ "info/mpp"
+ ]
+ },
+ {
+ "group": "Security and Trust",
+ "pages": [
+ "shared-responsibility-model",
+ "info/trust-center",
+ "security-vulnerability-reporting",
+ "bots"
+ ]
+ },
+ {
+ "group": "Enterprise",
+ "pages": [
+ "info/enterprise",
+ "info/hipaa",
+ "info/zero-data-retention",
+ "info/contact-sales"
+ ]
+ },
+ {
+ "group": "Support and Community",
+ "pages": [
+ "info/support",
+ "community/discord",
+ "community/github"
]
}
]
},
- {
- "group": "Community",
- "pages": [
- "community/github",
- "community/discord"
- ]
- },
{
"group": "Info",
"pages": [
"info/concepts",
- "info/zero-data-retention",
- "info/pricing",
- "info/spending-caps",
- "info/support",
- "info/unikernels",
- "info/mpp"
+ "info/unikernels"
]
}
]
diff --git a/info/contact-sales.mdx b/info/contact-sales.mdx
new file mode 100644
index 00000000..1e2f1269
--- /dev/null
+++ b/info/contact-sales.mdx
@@ -0,0 +1,18 @@
+---
+title: "Contact Sales"
+description: "Talk to Kernel about an enterprise plan, custom limits, or a pilot"
+---
+
+**[Book a call](https://calendly.com/d/d3tn-5kp-5yt).**
+
+Worth reaching out when:
+
+- You need **custom concurrency or create-rate limits** beyond the published plans — see [concurrency and limits](/browsers/concurrency-and-limits).
+- You need a **BAA, zero data retention, or continuous audit log export** — see [Enterprise](/info/enterprise).
+- You're **migrating a fleet** and want help choosing between browser pools, on-demand browsers, and the [code execution platform](/apps/develop).
+- You're running **thousands of end-user identities** and want the project and profile layout reviewed.
+- Your target sites have **aggressive bot detection** and you want them tested before you commit.
+
+Bring the sites you need to automate, your expected concurrency, and how the automation is triggered. That's usually enough to scope pricing and the right architecture on the first call.
+
+Already a customer with a support question? Use [support](/info/support) instead.
diff --git a/info/enterprise.mdx b/info/enterprise.mdx
new file mode 100644
index 00000000..7cd3be14
--- /dev/null
+++ b/info/enterprise.mdx
@@ -0,0 +1,39 @@
+---
+title: "Enterprise Overview"
+sidebarTitle: "Overview"
+description: "HIPAA, zero data retention, custom limits, and support on KERNEL's Enterprise plan"
+---
+
+What changes on the Enterprise plan.
+
+## HIPAA
+
+KERNEL signs a BAA on the Enterprise plan. See [HIPAA](/info/hipaa) for what KERNEL provides and what you're responsible for.
+
+## Zero data retention
+
+[Zero data retention](/info/zero-data-retention) is Enterprise-only and configured per organization. With it enabled, session recordings, live view streams, and telemetry aren't retained after the browser terminates.
+
+## What else the Enterprise plan includes
+
+| | Enterprise |
+| --- | --- |
+| Concurrency and rate limits | Custom limits for concurrency and browser creation. See [concurrency and limits](/browsers/concurrency-and-limits). |
+| Audit logs | [Continuous export to S3](/info/audit-logs#continuous-s3-export), in addition to search and download |
+| Replay retention | Custom [replay](/browsers/replays) retention |
+| [Support](/info/support) | A shared Slack channel, with tiered response times |
+| Data processing | [DPA](/dpa) |
+
+The full plan comparison is on [pricing](/info/pricing). For KERNEL's security program, compliance reports, and the shared responsibility model, see [security practices](/security) and the [trust center](/info/trust-center).
+
+## Legal
+
+- [Terms of service](/tos)
+- [Privacy policy](/privacy)
+- [Acceptable use policy](/acceptable-use)
+- [Data processing addendum](/dpa)
+- [Vulnerability reporting](/security-vulnerability-reporting)
+
+## Talk to us
+
+Scoping an enterprise deployment, a BAA, or zero data retention starts with a conversation: [contact sales](/info/contact-sales).
diff --git a/info/hipaa.mdx b/info/hipaa.mdx
new file mode 100644
index 00000000..0656bf21
--- /dev/null
+++ b/info/hipaa.mdx
@@ -0,0 +1,16 @@
+---
+title: "HIPAA"
+description: "Run browser workflows that handle protected health information on KERNEL's Enterprise plan"
+---
+
+KERNEL supports HIPAA compliance for workflows that handle protected health information (PHI), and signs a business associate agreement (BAA) on the Enterprise plan.
+
+## What KERNEL provides
+
+- **A BAA.** KERNEL signs a BAA with Enterprise customers. [Contact sales](/info/contact-sales) to start one.
+- **Isolation per browser.** Each browser runs in its own VM with its own kernel and filesystem, isolated from other sessions at the hypervisor.
+- **Zero data retention.** With [zero data retention](/info/zero-data-retention), session recordings, live view streams, and telemetry aren't retained after a browser terminates. Turn it on if PHI must not persist after a session ends.
+
+## What you're responsible for
+
+HIPAA compliance is shared. KERNEL secures the platform; you're responsible for how your agents use it, such as which sites they access, what data they extract, and where that data goes. See the [shared responsibility model](/shared-responsibility-model) for the full split, and [security practices](/security) for KERNEL's program and current compliance status.
diff --git a/info/pricing.mdx b/info/pricing.mdx
index 69b7e5c1..fe834374 100644
--- a/info/pricing.mdx
+++ b/info/pricing.mdx
@@ -1,8 +1,9 @@
---
-title: "Pricing & Limits"
+title: "Pricing"
+sidebarTitle: "Plans and Pricing"
---
-With Kernel, you only pay for what you use and nothing more. You don't pay for idle time thanks to [Standby Mode](/browsers/standby), idle browsers in a browser pool incur no usage charges, and you're never charged for proxies.
+With Kernel, you only pay for what you use and nothing more. You don't pay for idle time thanks to [Standby Mode](/browsers/standby), and idle browsers in a browser pool incur no usage charges.
## Plan Pricing
| Plan | Monthly cost | Included Credits / mo
@@ -55,69 +56,47 @@ import { PricingCalculator } from '/snippets/calculator.jsx';
| HIPAA compliance (BAA) | ❌ | ❌ | ❌ | ✅ |
-## Concurrency limits
+
+
+
+## Limits
-Kernel enforces a single concurrency limit covering all browsers you run at once—whether created on demand with `browsers.create()` or reserved in a [browser pool](/browsers/pools/overview). Your full limit is available to either API in any mix.
+Concurrency, rate limits, and per-browser resources for each plan are on [concurrency and limits](/browsers/concurrency-and-limits).
-| Feature | Developer | Hobbyist | Start-Up | Enterprise |
-| --- | --- | --- | --- | --- |
-| Concurrent browsers | 5 | 10 | 150 | Custom |
-| App invocations | 5 | 10 | 50 | Custom |
-| App invocations (per-app) | 5 | 10 | 20 | Custom |
-| Managed auth health check interval | 6 hours minimum | 1 hour minimum | 20 minutes minimum | Custom |
-
-#### Notes
-- Reserved capacity in a [browser pool](/browsers/pools/overview) counts toward your concurrency limit whether or not the browsers are currently acquired—a pool sized to 40 browsers uses 40 of your limit.
-- Browsers in [Standby Mode](/browsers/standby) count against your concurrency limit.
-- Limits are org-wide by default unless stated otherwise.
-
-
-## Rate limiting
-
-Kernel enforces per-organization rate limits on API requests. When you exceed the rate limit, the API returns a `429 Too Many Requests` response with a `Retry-After` header indicating how many seconds to wait before retrying.
-
-Rate-limited endpoints include these headers on every response:
-
-| Header | Description |
-| --- | --- |
-| `X-RateLimit-Limit` | Maximum requests allowed per minute |
-| `X-RateLimit-Remaining` | Requests remaining in the current window |
-| `Retry-After` | Seconds to wait before retrying (only on `429` responses) |
-
-All Kernel SDKs automatically retry `429` responses up to 2 times, respecting the `Retry-After` header for delay timing. If retries are exhausted, the SDK throws a typed `RateLimitError` with the response headers accessible for custom backoff logic.
+## Other ways to pay
-If you need higher rate limits, [contact us](https://calendly.com/d/d3tn-5kp-5yt).
+Agents can buy a single browser without a KERNEL account or API key through the [machine payments protocol (MPP)](/info/mpp). One stealth, headful browser for 30 minutes costs \$0.50, paid with a Link payment. See [buy a browser with MPP](/info/mpp) for the payment flow.
## FAQ
-
Enterprise pricing is custom, with custom concurrency, rate limits, support, and compliance terms.
+Contact the KERNEL team for a quote.
+