No per-integration fees, no evidence-volume pricing, no charge to export your own data. Every plan is the full self-hosted platform.
Everything you need to run a serious ISO 27001 ISMS.
Multi-framework programs with control reuse built in.
The full catalog, unlimited people, complete control.
| What's included | Starter | Professional | Enterprise |
|---|---|---|---|
| Compliance frameworks | 1 (ISO 27001) | 10 | All 35 |
| Seats | 10 | 50 | Unlimited |
| Risk, SoA, incidents, audits, evidence | |||
| Document control & CAPA workflows | |||
| Cross-framework control sync | |||
| Automation, integrations & scheduled sync | |||
| AI assistant, policy drafting & CCM | |||
| SSO / SAML, MFA & custom RBAC | |||
| Support | Priority | Dedicated manager |
All 35 frameworks ship in the product — your license decides which ones activate.
| Framework | Controls | Starter | Professional | Enterprise |
|---|---|---|---|---|
| ISO 27001 Information Security Management System | 93 | |||
| ISO 42001 Artificial Intelligence Management System | 39 | |||
| ISO 22301 Business Continuity Management System | 44 | |||
| ISO 45001 Occupational Health & Safety | 54 | |||
| ISO 9001 Quality Management System | 51 | |||
| SOC 2 Trust Services Criteria | 61 | |||
| GDPR EU Data Protection | 54 | |||
| UK GDPR UK Data Protection | 38 | |||
| PCI DSS Payment Card Industry | 63 | |||
| NIST CSF Cybersecurity Framework | 22 | |||
| HIPAA US Healthcare Privacy | 54 | |||
| HITRUST Healthcare Security Framework | 49 | |||
| CCPA California Privacy | 37 | |||
| NIST 800-53 Security & Privacy Controls | 848 | |||
| ISO 27701 Privacy Information Management | 26 | |||
| CMMC Cybersecurity Maturity Model | 136 | |||
| NIST 800-171 Controlled Unclassified Information | 110 | |||
| CIS v8 CIS Critical Security Controls | 153 | |||
| DORA Digital Operational Resilience | 45 | |||
| NIS2 EU Network & Information Security | 12 | |||
| CSA STAR Cloud Controls Matrix | 197 | |||
| FedRAMP US Federal Cloud Authorization | 421 | |||
| SOX ITGC Sarbanes-Oxley IT Controls | 50 | |||
| TISAX Automotive Industry Security | 53 | |||
| ISO 14001 Environmental Management | 45 | |||
| ISO 31000 Risk Management | 28 | |||
| COBIT IT Governance | 40 | |||
| ISO 20000 IT Service Management | 38 | |||
| Cyber Essentials UK Cyber Essentials | 28 | |||
| LGPD Brazilian Data Protection | 32 | |||
| IEC 62443 Industrial Automation Security | 52 | |||
| SOC 1 Internal Controls over Financial Reporting | 35 | |||
| ISO 27017/18 Cloud Security & Privacy | 62 | |||
| NIST AI RMF AI Risk Management Framework | 72 | |||
| DPDP Act India Digital Personal Data Protection | 46 |
ISO 27001 implementation, DPDPA assessments, 24×7 SOC and security testing — delivered as fixed-price professional services.
Yes. The platform runs on your own infrastructure (Node.js + PostgreSQL). Your risks, documents and evidence never leave servers you control — the license key is the only thing that talks to us.
Enter your signed license key during the setup wizard or later under Settings → License & Plan. Keys validate against our license server and keep working offline with a grace period, so an internet blip never locks your ISMS.
Any active user account in the platform. Seat usage syncs automatically as you invite people, and user creation is blocked — never silently billed — when you reach your plan's limit.
Any time. Activate a higher-tier key and the additional frameworks and seats unlock instantly — no reinstall, no migration, and everything you've already built carries over.
Yes — we offer ISO 27001 implementation, DPDPA assessments, managed SOC and security testing as professional services with transparent fixed pricing.