Pricing

Three tiers, sized to the frameworks you actually face.

$2K / $8K / $20K per month. Each tier expands the framework coverage, the reviewer rotation, and the number of entities in your evidence graph. Pick by the first framework your auditor names in fieldwork — the matrix below shows exactly what each tier covers and which buyer archetype it was built for.

HIPAA · SOC 2 · PCI DSS · GDPR · HITRUST · ISO 27001 · 50-state privacy

Tier 01 · Foundation

$2K / month

Single framework, single entity

HIPAA or GDPR coverage with continuous evidence collection.

Built for HIPAA-only telehealth · <250 employees

  • One framework: HIPAA or GDPR
  • Continuous evidence collection across contracts, HR policies, vendor agreements
  • Daily rule-change radar with drafted remediation plan
  • Quarterly reviewer briefing by a former Big-Four auditor
  • BAA + DPA signed within one business day
Start a Foundation rollout →

Tier 02 · Multi-framework

$8K / month

Stacked frameworks, one entity

HIPAA + SOC 2 + GDPR + state privacy, pre-packaged for fieldwork.

Built for HIPAA + SOC 2 healthtech · 250–1,500 employees

  • Up to four frameworks: HIPAA, SOC 2, GDPR, and the full US state privacy stack
  • Pre-assembled evidence packages ready for fieldwork
  • Inline auditor workspace with scoped read-only access
  • Same-day reviewer escalation on regulatory radar alerts
  • Monthly in-house reviewer review of every recommendation
Start a Multi-framework rollout →
Full-stack

Tier 03 · Enterprise

$20K / month

Multi-entity, multi-framework

All twelve frameworks — including PCI DSS — across entities.

Built for Multi-framework fintech + healthtech · 1,500+ or multi-entity

  • All twelve frameworks: HIPAA, SOC 2, PCI DSS, GDPR, HITRUST, ISO 27001 + 50-state privacy
  • PCI DSS Report on Compliance, HIPAA risk assessment, and SOC 2 Type II evidence on demand
  • Dedicated reviewer rotation across regulatory domains
  • M&A due-diligence mode with bespoke escalation hours
  • Multi-entity evidence graph with cross-tenant control inheritance
Scope an Enterprise rollout →

Every tier includes the daily regulatory radar, a former-Big-Four reviewer rotation, and a BAA/DPA signed within one business day. Pricing excludes annual audit fees — read the procurement FAQ for packaging details.

Framework coverage

Which tier fits the framework your auditor names first.

The matrix is the source of truth: every green cell is an in-scope framework at that monthly price. Tier 3 is the only tier that covers PCI DSS today.

  • Tier 1 — HIPAA-only telehealth.Single framework, single entity, <250 employees.
  • Tier 2 — HIPAA + SOC 2 healthtech. Stacked frameworks, pre-assembled evidence packages, 250–1,500 employees.
  • Tier 3 — multi-framework fintech. Adds PCI DSS, HITRUST, ISO 27001, and the full 50-state privacy stack across entities.

Pick by the first framework your auditor namesTier 1 for HIPAA-only telehealth · Tier 2 for HIPAA + SOC 2 healthtech · Tier 3 for multi-framework fintech.

Framework coverage by tier. Tier 1 Foundation covers HIPAA and GDPR. Tier 2 Multi-framework covers HIPAA, SOC 2, and GDPR. Tier 3 Enterprise covers HIPAA, SOC 2, PCI DSS, and GDPR.
FrameworkTier 1Foundation$2K / moTier 2Multi-framework$8K / moTier 3Enterprise$20K / mo
HIPAAHealth Insurance Portability and Accountability ActCoveredCoveredCovered
SOC 2AICPA Service Organization Control 2Not in scopeCoveredCovered
PCI DSSPayment Card Industry Data Security StandardNot in scopeNot in scopeCovered
GDPREU General Data Protection RegulationCoveredCoveredCovered
Free framework checklist
✓ Covered — in scope at this tierNot in scope — graduate to the next tier

Talk to a reviewer

Send the first framework name; we’ll send a tier recommendation.

Open the MVP to scan a corpus, or email us with the framework your auditor opens on — we’ll pre-build a draft evidence package before the first call.