Pricing

Priced by frameworks and seats. Nothing else.

No per-integration fees, no evidence-volume pricing, no charge to export your own data. Every plan is the full self-hosted platform.

Starter

1 framework
Up to 10 seats

Everything you need to run a serious ISO 27001 ISMS.

  • ISO 27001:2022 — all 93 Annex A controls
  • Risk register, SoA, incidents & audits
  • Evidence, documents & CAPA workflows
  • Email support
Most popular

Professional

10 frameworks
Up to 50 seats

Multi-framework programs with control reuse built in.

  • Everything in Starter
  • SOC 2, GDPR, CIS v8, ISO 9001/45001 & more
  • Cross-framework control sync
  • Automation, integrations & scheduled sync
  • Priority support

Enterprise

All 35 frameworks
Unlimited seats

The full catalog, unlimited people, complete control.

  • Everything in Professional
  • ISO 42001, 22301, NIST, PCI DSS, HIPAA & more
  • Self-hosted with full data sovereignty
  • SSO / SAML, MFA & custom RBAC
  • Dedicated success manager
What's included StarterProfessionalEnterprise
Compliance frameworks 1 (ISO 27001) 10 All 35
Seats 10 50 Unlimited
Risk, SoA, incidents, audits, evidence
Document control & CAPA workflows
Cross-framework control sync
Automation, integrations & scheduled sync
AI assistant, policy drafting & CCM
SSO / SAML, MFA & custom RBAC
Support Email Priority Dedicated manager

Every framework, by plan

All 35 frameworks ship in the product — your license decides which ones activate.

Framework Controls StarterProfessionalEnterprise
ISO 27001
Information Security Management System
93
ISO 42001
Artificial Intelligence Management System
39
ISO 22301
Business Continuity Management System
44
ISO 45001
Occupational Health & Safety
54
ISO 9001
Quality Management System
51
SOC 2
Trust Services Criteria
61
GDPR
EU Data Protection
54
UK GDPR
UK Data Protection
38
PCI DSS
Payment Card Industry
63
NIST CSF
Cybersecurity Framework
22
HIPAA
US Healthcare Privacy
54
HITRUST
Healthcare Security Framework
49
CCPA
California Privacy
37
NIST 800-53
Security & Privacy Controls
848
ISO 27701
Privacy Information Management
26
CMMC
Cybersecurity Maturity Model
136
NIST 800-171
Controlled Unclassified Information
110
CIS v8
CIS Critical Security Controls
153
DORA
Digital Operational Resilience
45
NIS2
EU Network & Information Security
12
CSA STAR
Cloud Controls Matrix
197
FedRAMP
US Federal Cloud Authorization
421
SOX ITGC
Sarbanes-Oxley IT Controls
50
TISAX
Automotive Industry Security
53
ISO 14001
Environmental Management
45
ISO 31000
Risk Management
28
COBIT
IT Governance
40
ISO 20000
IT Service Management
38
Cyber Essentials
UK Cyber Essentials
28
LGPD
Brazilian Data Protection
32
IEC 62443
Industrial Automation Security
52
SOC 1
Internal Controls over Financial Reporting
35
ISO 27017/18
Cloud Security & Privacy
62
NIST AI RMF
AI Risk Management Framework
72
DPDP Act
India Digital Personal Data Protection
46

Need hands-on help with ISO 27001 or DPDPA compliance?

ISO 27001 implementation, DPDPA assessments, 24×7 SOC and security testing — delivered as fixed-price professional services.

View services pricing

Frequently asked questions

Is it really self-hosted? +

Yes. The platform runs on your own infrastructure (Node.js + PostgreSQL). Your risks, documents and evidence never leave servers you control — the license key is the only thing that talks to us.

How does license activation work? +

Enter your signed license key during the setup wizard or later under Settings → License & Plan. Keys validate against our license server and keep working offline with a grace period, so an internet blip never locks your ISMS.

What counts as a seat? +

Any active user account in the platform. Seat usage syncs automatically as you invite people, and user creation is blocked — never silently billed — when you reach your plan's limit.

Can I upgrade later? +

Any time. Activate a higher-tier key and the additional frameworks and seats unlock instantly — no reinstall, no migration, and everything you've already built carries over.

Do you also help with implementation? +

Yes — we offer ISO 27001 implementation, DPDPA assessments, managed SOC and security testing as professional services with transparent fixed pricing.