What is Dust? Pricing, EU Residency, and Best Alternatives in 2026
Dust is a Paris-based platform for building AI agents on a company's own tools and documents, and it is the price anchor of this field: it publishes a per-seat figure while Glean and Guru publish none. A Pro seat is $30 per seat per month billed monthly, or $24 billed annually; a Max seat is $150 or $120, both marked "Excluding VAT". It also offers EU data residency on that self-serve plan, so EU hosting is not a point of difference against Dust. The narrow gap is contractual: its DPA is Enterprise-only.
Last updated: 2026-09-06. Every figure on this page was fetched from the vendor on 2026-09-06 and is quoted with its source.
Quick Decision Guide
Dust fits a team that wants to build its own agents over its own documents, wants to know the price before it books a call, and is comfortable declaring access inside Dust rather than inheriting it from the source system. It is a poor fit if you need a signed processor agreement without an Enterprise contract, if your work arrives by telephone, or if your month-to-month volume swings and you need a flat cost.
| If you need... | Dust fits | Better alternative |
|---|---|---|
| Build custom AI agents over your own documents and tools | Yes | - |
| A per-seat price you can budget from before talking to sales | Yes | - |
| EU-hosted data on a self-serve plan, no Enterprise contract | Yes | - |
| A signed data processing agreement on the self-serve plan | No, Enterprise only | Ask every vendor in writing |
| SCIM, audit logs or single-tenant deployment | Enterprise only | - |
| Per-user source permissions mirrored at query time | Not documented | - |
| A flat monthly cost when usage swings | No, credits do not roll over | - |
| Voice or phone-channel AI for inbound or outbound calls | No | Ainora |
| Small EU languages (LT, LV, ET) as a first-class channel | Not stated | Ainora |
How Dust Rates
A six-axis scorecard in the format used across our provider pages. Every note below is traceable to a page fetched on 2026-09-06.
| Axis | Rating | Notes |
|---|---|---|
| Pricing transparency | Strong | The only vendor in this set that publishes a per-seat price with a stated metering model. Pro seat $30 monthly or $24 annual; Max seat $150 or $120. Marked "Excluding VAT". |
| EU data residency | Strong | Feature matrix reads Data residency "US / EU" for Business and Enterprise. The security page: "Host in the EU or US to meet your regulatory needs." eu.dust.tt returned HTTP 200 on 2026-09-06. |
| Contract terms for smaller buyers | Weak | "Custom legal terms (MSA, DPA)" is marked false for Business and true for Enterprise in the pricing feature matrix. A Business-plan EU buyer cannot get a signed DPA on standard terms. |
| Permission model | Mixed | Access is re-declared in Dust-native spaces after ingestion. No per-user source-ACL mirroring is documented. Permissions are additive, so a mis-scoped group only ever widens access. |
| Cost predictability | Mixed | Seats are metered in credits. Docs: "Unused credits do not carry over to the following month." A quiet month buys nothing back; a busy month can exhaust the allowance. |
| Channel coverage | Weak | Slack, Notion, GitHub, Drive and further tools via MCP. No phone or voice channel on any published plan. |
What is Dust?
Dust (dust.tt) is a French company selling a workspace in which administrators connect company systems, organise the ingested content into spaces, and build agents that answer questions and run multi-step workflows over it. Its own pricing page describes the Business plan as "For teams up to 100 people" and lists its highlights as "20+ frontier models", "Custom agents with your skills, knowledge & tools", "Multi-agent workflows on schedules & triggers", "Connect Slack, Notion, GitHub, Drive + 20 more - or any tool via MCP", "SSO with Okta, Entra ID & Jumpcloud" and "US & EU data residency".
A note on how these figures were obtained, because it matters for checking them. Both dust.tt/home/pricing and dust.tt/home/security return an application shell with no body text to a plain fetch. The figures below therefore come from the pricing page's own JavaScript bundle, which is the data the page renders rather than a screenshot of it. On 2026-09-06 that bundle was served at /_next/static/chunks/pages/home/pricing-74a822db81f1ce0b.js. The hash changes on every deploy, so anyone re-checking this should read the current script src list on the pricing page rather than reusing that URL. Every seat figure was independently corroborated against the server-rendered Dust credits documentation.
The product sits in the same category as Glean, Guru and Sana, but with a different commercial shape. Glean has not published a price since January 2023. Guru publishes none at all and sells a bundled services engagement instead. Sana's enterprise tier is now attached to a Workday subscription. Dust is the one vendor here that lets a buyer size the deal before booking a call, and that is a real, checkable advantage which we say plainly rather than talking around.
Dust Features
Three surfaces, each described in Dust's own documentation:
Connections. The admin governance docs describe them as "fully managed integrations that automatically sync data from external platforms (like Slack, Notion, Google Drive) to Dust, with granular admin control over what specific content is accessible to the workspace". The Business plan highlight names Slack, Notion, GitHub and Drive plus roughly twenty more, with anything else reachable through MCP; Enterprise adds "Unlimited connectors & MCP servers".
Spaces. The unit of access control. Same page, verbatim: "Spaces are containers in Dust that let admins organize and control access to data, coming in two types: open spaces accessible to all workspace members and restricted spaces limited to designated users." And the consequence: "users can create agents based on the data of the spaces they have access to", and "users can interact with agents created with the data of the spaces users are a member of".
Agents and workflows. Custom agents built on a workspace's skills, knowledge and tools, with multi-agent workflows that run on schedules and triggers. Credits are the meter: the docs state that "Token credits are proportional to the amount of AI processing involved in generating a response" and that "More complex queries, longer contexts, and more capable models consume more token credits."
There is no phone or voice channel on any published Dust plan. That is not a criticism of the product, which is not sold as one; it is the boundary of the category, and it is the reason a company whose work arrives by telephone ends up buying two things.
How much does Dust cost?
Two plans, Business and Enterprise, with three seat types inside Business. All figures are in US dollars, read from the pricing page's own data on 2026-09-06, and marked on the page itself as "Excluding VAT". Prices move; re-check them before you budget from them.
| Plan / seat | What it covers | Price, fetched 2026-09-06 |
|---|---|---|
| Business, Free seat | 500 credits, described as "Lifetime" | $0 |
| Business, Pro seat | 8,000 credits per seat per month | $30 per seat per month, or $24 annual, excluding VAT |
| Business, Max seat | 40,000 credits per seat per month | $150 per seat per month, or $120 annual, excluding VAT |
| Enterprise | Unlimited connectors and MCP servers, workspace-pooled credits, SCIM, audit logs, custom data retention, single-tenant deployment, MSA and DPA | Quote-based. The page CTA reads "Talk to sales" |
| Ainora | Multi-channel AI teammate: phone, Slack, Microsoft Teams, email | Individual pricing |
The pricing page also carries the string "$0.01 / credit", which is what makes the seat allowances legible: a Pro seat's 8,000 monthly credits and a Max seat's 40,000 are the metered budget, not an unlimited licence. The credits documentation is explicit about what happens to an unused allowance: "Individual seat credits reset monthly, on the anniversary of your subscription start date. Unused credits do not carry over to the following month." Enterprise pools credits across the workspace and adds volume pricing.
Bundle first and meter later is the pattern across this whole field, and Dust is at least honest about it up front: the meter is on the pricing page rather than in a mid-contract change notice.
Does Dust offer EU data residency, and is that enough?
Yes, and on the self-serve tier. We state this plainly because the opposite would be easy to imply and wrong. Dust's pricing feature matrix lists Data residency: "US / EU" for Business and for Enterprise. Its security page says "Host in the EU or US to meet your regulatory needs" and "GDPR compliant, SOC2 Type II certified, HIPAA-ready. Dust prioritizes your data security with encryption, regional hosting, role-based access, and zero model training." And the EU instance is not aspirational: https://eu.dust.tt/ returned HTTP 200 when we checked it on 2026-09-06.
So against Dust, "we host in the EU" is not a differentiator, and we do not present it as one. Dust is a European company selling EU residency on a plan you can buy with a card.
The real gap is contractual, and it is narrow. The same feature matrix marks "Custom legal terms (MSA, DPA)" as available on Enterprise and not on Business. For a smaller EU buyer, that is the constraint that bites: Article 28 of the GDPR requires processing by a processor to be governed by a contract binding the processor, and a Business-plan customer cannot obtain a signed DPA on standard terms. Hosting location and processor contract are two different obligations, and only one of them is solved on the self-serve plan.
The practical move is unglamorous: ask, in writing, at what plan and price a signed processor agreement becomes available, and get the answer before the pilot rather than during procurement. That question is worth asking of every vendor on this page, including us.
Feature and compliance matrix
Dust columns are quoted from its pricing feature matrix as served on 2026-09-06. The Ainora column is filled in honestly, including where we are behind.
| Capability | Dust Business | Dust Enterprise | Ainora |
|---|---|---|---|
| SOC 2 Type II | Yes | Yes | No |
| ISO 27001 | Not claimed on the security or pricing pages | Not claimed on the security or pricing pages | No |
| Data residency | US / EU | US / EU | EU-native by design |
| SSO (Okta, Entra ID, Jumpcloud) | 5+ seats on demand | Yes | Not published |
| SCIM provisioning | No | Yes | Not published |
| Audit logs and advanced security controls | No | Yes | Not published |
| Single-tenant deployment | No | Yes | Not published |
| Custom legal terms (MSA, DPA) | No | Yes | Not published |
| Phone or voice channel | No | No | Yes |
| Published price | Yes | No, quote-based | Individual pricing |
Ainora holds no SOC 2 report and no ISO certification. Dust holds SOC 2 Type II and we do not. A comparison a reader can catch out is worth nothing, so the row says so.
On ISO 27001, the precise statement is: ISO 27001 is not claimed on Dust's security page bundle or its pricing feature matrix. The grep pattern run across both artefacts on 2026-09-06 was SOC|ISO|GDPR|HIPAA|42001|27001, and the only certification strings returned were SOC 2 Type II, GDPR and HIPAA. Dust's trust portal could not be read by fetch, so this is evidence about those two surfaces, not proof that no certificate exists. We do not write that Dust has no ISO 27001, because we did not establish it.
How does Dust decide who sees what?
Access in Dust is re-declared after ingestion rather than mirrored from the source system per user at query time. Content syncs into Dust, an admin places it in a space, and membership of that space governs who can build on it and who can talk to the agents built from it. Nothing in Dust's admin documentation describes consulting a source system's per-user access control list when a question is asked.
That absence has a method behind it, which is the only thing that makes it worth stating. We read the full Dust documentation sitemap (354 URLs on 2026-09-06) and grepped the URL list for secur|privac|region|resid|retent|train|gdpr|data|permission|space|plan|pricing|credit|seats|eu|legal|trust|sso|enterprise. No page describing source-permission mirroring, data residency or retention appears in it. Documentation sites can be incomplete, so this is a statement about what is published, not about what the software does internally.
The design detail worth carrying into a security review is on the workspace governance page, verbatim: "Permissions are granted to groups rather than directly to individual people. To grant a permission to one person, create a manual group, add that person to it, and grant the permission to the group." And then: "Permissions are additive. If a person belongs to several groups, they receive the combined permissions granted by those groups. A group grant adds access and does not remove access granted elsewhere."
Additive-only means there is no deny rule. A group added to solve one team's access problem widens every member's reach and nothing narrows it back. This is a structural property of the model rather than a defect, and it is the same class of problem every assistant in this category has: what the assistant surfaces is what somebody could already technically reach, not what they were meant to see.
On retention, Dust publishes an Enterprise highlight reading "SCIM, audit logs & custom data retention". No default retention period is published for the Business plan, and no retention page exists in the documentation sitemap under the pattern above. We therefore state the absence and no number.
Dust Pros and Cons
Pros
- Publishes a per-seat price with a stated metering model. The only vendor in this comparison set that does.
- EU data residency on the self-serve Business plan, from a European company, with a live EU instance at eu.dust.tt.
- SOC 2 Type II on both Business and Enterprise, per the pricing feature matrix.
- States plainly that customer data is not used to train models and that no data is stored by third-party model providers.
- Model choice is not locked: the Business highlight reads "20+ frontier models", and any further tool can be attached over MCP.
- Self-serve entry. A team can start without a procurement cycle.
Cons
- The DPA is Enterprise-only. A Business-plan EU controller cannot get a signed Article 28 processor agreement on standard terms.
- SCIM, audit logs and single-tenant deployment are all Enterprise-gated.
- Credits do not roll over, so an unused allowance is lost and a busy month can exhaust the seat.
- Permissions are Dust-native and additive. No per-user source-ACL mirroring is documented, and no rule narrows access once granted.
- No default retention period is published for the Business plan.
- No phone or voice channel on any published plan.
- The public security assertions sit on a marketing page, not in a readable contract. The contractual version lives in the Enterprise-gated DPA.
Verdict: Who Should Use Dust?
Dust is the right choice for a team of up to about a hundred people that wants to build its own agents over its own systems, values knowing the price before the first call, and can live with declaring access inside Dust. Its EU story on the self-serve plan is genuinely good and we will not pretend otherwise. Look elsewhere if your legal team requires a signed processor agreement and your budget does not reach Enterprise, if you need SCIM or audit logs without an Enterprise contract, or if a meaningful share of the work you want automated arrives on the telephone and in a language a US-built or English-first platform does not handle well. Those last two are where Ainora is a different product rather than a cheaper one.
Best Dust Alternatives in 2026
1. Ainora
"Dust builds agents over your documents. Ainora answers the phone in your customer's language and then updates the systems those documents live in."
Ainora is a multi-channel AI teammate built EU-native by design. The overlap with Dust is real on the integration side and the difference is the channel: Ainora picks up inbound calls, joins Slack and Microsoft Teams when a colleague mentions it, and executes work across CRM, calendar and ticketing. One memory, one thread per customer, across every channel. Dust has no phone channel on any published plan, so for a company whose bottleneck is the ringing telephone the two products are complements rather than substitutes.
The other structural difference is language. Ainora ships multilingual, including small EU languages that platforms built for the English-speaking market do not cover, with mid-conversation switching. Deployment is measured in days rather than quarters, and the service runs at 99.9% uptime. Ainora holds no SOC 2 report and no ISO certification, which is why that row in the table above says so.
Pricing is individual and scoped to the work rather than sold by the seat. Hear it running in production before you talk to anyone: +1 (218) 636-0234 (English) and +370 5 200 2620 (Lithuanian).
2. Glean
Enterprise search first, agents layered on top, and the deepest connector estate in the category. It publishes no price: its pricing URL now returns a 301 to the homepage and no pricing page appears in its sitemap, checked 2026-09-06. Right answer when the problem is genuinely "nobody can find anything" across hundreds of systems and the budget is enterprise-scale.
3. Guru
Now sold as a platform plus a services engagement rather than a per-seat tool, with knowledge architecture design and solution engineers bundled in. Publishes no price. It offers no customer-selectable EU hosting region and states that EU and EEA personal data is transferred to the United States, which rules it out for buyers with an in-region storage policy.
4. Sana
Acquired by Workday for approximately $1.1 billion, closed 4 November 2025. Its enterprise tier is now sold with Workday HCM or Workday Financial Management through Flex Credits, so it is effectively unavailable on those terms to a company that does not run Workday. A residual $30 per user per month Team tier remains on sanalabs.com and its future is undeclared.
5. Lindy
Self-serve US agent platform, Slack-first, English-first, US data residency. The closest competitor to Dust on buying experience, and the furthest from it on European data policy.
6. Relevance AI
Build-your-own agents with a self-serve interface. Sydney and San Francisco. The nearest no-code analogue if the appeal of Dust is agent-building rather than knowledge retrieval.
Frequently Asked Questions
Dust (dust.tt) is a Paris-based platform for building AI agents on a company's own tools and documents. Its Business plan highlights, taken from the pricing page's own data on 2026-09-06, read: "20+ frontier models", "Custom agents with your skills, knowledge & tools", "Multi-agent workflows on schedules & triggers", "Connect Slack, Notion, GitHub, Drive + 20 more - or any tool via MCP", and "US & EU data residency". Enterprise adds unlimited connectors, SCIM, audit logs, single-tenant deployment and custom legal terms.
Dust publishes seat prices. On the Business plan a Pro seat is $30 per seat per month billed monthly, or $24 per seat per month billed annually; a Max seat is $150 monthly or $120 annual. Both are marked "Excluding VAT". A Free seat carries 500 lifetime credits. Enterprise is quote-based ("Talk to sales"). Figures read from the pricing page's own JavaScript bundle on 2026-09-06 and corroborated against docs.dust.tt.
Yes, and on the self-serve tier. The pricing feature matrix lists Data residency as "US / EU" for both Business and Enterprise, the security page states "Host in the EU or US to meet your regulatory needs", and https://eu.dust.tt/ returned HTTP 200 when checked on 2026-09-06. EU hosting is therefore not a point of difference against Dust, and we do not claim it as one.
Not on standard self-serve terms. The pricing page feature matrix marks "Custom legal terms (MSA, DPA)" as false for Business and true for Enterprise, read from the page's own data on 2026-09-06. For an EU controller that needs a signed Article 28 processor agreement, that is the practical constraint on the Business plan, not the hosting location.
Dust claims SOC 2 Type II, GDPR compliance and HIPAA-readiness. ISO 27001 is not claimed on its security page bundle or its pricing feature matrix: a grep for ISO and 27001 across both artefacts on 2026-09-06 returned zero matches. That is a statement about those two surfaces only. Dust's trust portal could not be read, so the absence of a certificate is not established and we do not assert one. Ainora holds neither SOC 2 nor any ISO certification.
Access is re-declared inside Dust after ingestion rather than mirrored per user from the source system. The docs describe Spaces as "containers in Dust that let admins organize and control access to data", permissions granted "to groups rather than directly to individual people", and state that "Permissions are additive. If a person belongs to several groups, they receive the combined permissions granted by those groups. A group grant adds access and does not remove access granted elsewhere." Additive-only means a mis-scoped group widens access and nothing narrows it back.
No. Dust is a text and workflow product across its web app, Slack, and connected tools via MCP. There is no phone channel. If the work you need automated arrives by telephone, that is the structural gap, and it is the one Ainora is built around.
Founder & CEO, AInora
Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.
View all articles