Skip to content
EveryBill

Product — Sovereign

Your AWS account. Your keys. We operate it for you.

Sovereign puts the AWS account and the KMS encryption keys in your name. EveryBill runs the platform inside that account through cross-account IAM, under a management agreement — but you hold root.

Starts at $6,000/mo + AWS costs

Sovereign is priced and structured as a deliberate, heavyweight commitment. It is not the default recommendation — it is the answer to a specific question.

The question Sovereign answers is concentration risk: what happens to your customers’ data and your payment operations if EveryBill is acquired, wound down, or breached. On Core and Silo, EveryBill owns the AWS account and the KMS keys that protect your data, however isolated that account is. On Sovereign, you own both.

EveryBill continues to run the platform — deployments, patching, monitoring, support — but it does so as an operator acting inside your account under cross-account IAM roles defined in a management agreement, not as the account’s owner. If the relationship with EveryBill ends for any reason, you already hold the account, the data, and the keys that protect it.

Who this is for

Sovereign is typically evaluated by General Counsel, a CFO, or a board — not by the office manager running day-to-day operations.

If your organization is asking “what is our exposure if a vendor we depend on has another security incident, gets acquired by a company we do not want handling this data, or simply stops operating,” Sovereign is built to answer that question at the account-ownership level, not just the contractual level.

What Sovereign is built on

The same platform and the same security baseline as Silo, running in an account you own.

  • You hold the AWS account root and the customer-managed KMS keys with per-domain separation. EveryBill never holds a copy.
  • EveryBill operates the account through scoped cross-account IAM roles under a management agreement, not through account ownership.
  • The account carries the same baseline as Silo: organization CloudTrail with log-file validation, AWS Config with 538 rules, Security Hub with CIS AWS Foundations Benchmark v5.0, AWS Foundational Security Best Practices, and PCI DSS v4.0.1, plus GuardDuty, Inspector2, and IAM Access Analyzer.
  • You can read every one of those controls natively, at any time, because it is your account — not an access grant from EveryBill.

What buying Sovereign actually involves

Be direct with your team about the shape of this commitment before you start.

    This is a procurement event

    Standing up a Sovereign deployment means creating and configuring a new AWS account in your organization, establishing the cross-account IAM trust relationship, and executing a management agreement. Expect a longer onboarding than Core or Silo, closer to a vendor procurement process than a signup.

    You take on AWS billing directly

    AWS costs for your account are billed to you, not bundled into the EveryBill subscription. The $6,000/mo starting price covers EveryBill’s operation of the platform; your AWS invoice is separate and variable with usage.

Talk to sales about Sovereign

This is a longer conversation by design — account structure, the management agreement, and how AWS billing splits from your EveryBill subscription.