Product — Sovereign
Your AWS account. Your keys. We operate it for you.
Sovereign puts the AWS account and the KMS encryption keys in your name. EveryBill runs the platform inside that account through cross-account IAM, under a management agreement — but you hold root.
Starts at $6,000/mo + AWS costs
Sovereign is priced and structured as a deliberate, heavyweight commitment. It is not the default recommendation — it is the answer to a specific question.
The question Sovereign answers is concentration risk: what happens to your customers’ data and your payment operations if EveryBill is acquired, wound down, or breached. On Core and Silo, EveryBill owns the AWS account and the KMS keys that protect your data, however isolated that account is. On Sovereign, you own both.
EveryBill continues to run the platform — deployments, patching, monitoring, support — but it does so as an operator acting inside your account under cross-account IAM roles defined in a management agreement, not as the account’s owner. If the relationship with EveryBill ends for any reason, you already hold the account, the data, and the keys that protect it.
Who this is for
Sovereign is typically evaluated by General Counsel, a CFO, or a board — not by the office manager running day-to-day operations.
If your organization is asking “what is our exposure if a vendor we depend on has another security incident, gets acquired by a company we do not want handling this data, or simply stops operating,” Sovereign is built to answer that question at the account-ownership level, not just the contractual level.
What Sovereign is built on
The same platform and the same security baseline as Silo, running in an account you own.
- You hold the AWS account root and the customer-managed
KMSkeys with per-domain separation. EveryBill never holds a copy. - EveryBill operates the account through scoped cross-account IAM roles under a management agreement, not through account ownership.
- The account carries the same baseline as Silo: organization
CloudTrailwith log-file validation,AWS Configwith 538 rules,Security Hubwith CIS AWS Foundations Benchmark v5.0, AWS Foundational Security Best Practices, and PCI DSS v4.0.1, plusGuardDuty,Inspector2, andIAM Access Analyzer. - You can read every one of those controls natively, at any time, because it is your account — not an access grant from EveryBill.
What buying Sovereign actually involves
Be direct with your team about the shape of this commitment before you start.
This is a procurement event
You take on AWS billing directly
Compare Sovereign with Core and Silo
The platform is identical across all three. What changes is who holds the account and the keys.
Talk to sales about Sovereign
This is a longer conversation by design — account structure, the management agreement, and how AWS billing splits from your EveryBill subscription.