Start free, pick any two modules on Starter, get audit-ready on Essentials, run a full programme on Complete. Yearly billing saves roughly 17%.
SPECIAL: 50% off annual plans for Start-up, Health, EDU and NFPs. T&Cs apply.
$990/yr billed yearly
Small teams that need just one or two capabilities
$3,600/yr billed yearly
SMB starter — one framework, light cadence
$9,990/yr billed yearly
Full SMB GRC programme
Mid-market & regulated enterprise
| Feature | Free | Starter | Essentials | Complete | Enterprise |
|---|---|---|---|---|---|
| AI Sidekick — your built-in AI vCISO | |||||
| AI vCISO assistant (chat, guidance, drafting) | 5-credit trial | ||||
| AI personas | 2 (Compliance, Analyst) | 2 (Compliance, Analyst) | 5 (CISO, Compliance, Analyst, IR, Pentester) | 5 | |
| Hosted AI credits / month | 5 (signup trial) | 10 | 25 | 250 | Unlimited |
| Top-up credits | |||||
| AI propose / approve loop on evidence & controls | Basic | Basic | |||
| AI risk derivation from compliance gaps | Preview | ||||
| Scheduled AI workflows (gap review, assessment cadence) | Monthly only | Monthly only | |||
| Bring your own agent (your model & key) — all tiers | |||||
| Native MCP server — connect Claude, Copilot or Cursor | |||||
| MCP tools (read + human-approved actions) | 34 | 34 | 34 | 34 | 34 |
| Agentic API keys (OAuth 2.1 or scoped) | |||||
| Safe actions — human-approved, scope-gated tools | |||||
| Content modules | |||||
| Modules included | Any 2 of 4 | Any 2 of 4 | All 4 | All 4 | All 4 |
| GRC / compliance | Selectable | Selectable | |||
| Attack surface (CTEM) | Selectable | Selectable | |||
| Identity exposure & dark-web monitoring | Selectable | Selectable | |||
| Cloud posture (CSPM) | Selectable | Selectable | |||
| Compliance & Standards | |||||
| Standards available | 1 — NIST CSF 2.0 (read-only) | 2 active baselines | 2 active baselines | All 17 | All 17 + unlimited custom |
| Control ↔ requirement mapping (bidirectional) | |||||
| Cross-framework derivation (NIST CSF hub) | |||||
| Custom framework builder (template, from scratch, CSV import) | |||||
| Assessments & evidence | |||||
| Onboarding wizard | |||||
| Assessment runs | 1 (read-only) | Unlimited | Unlimited | Unlimited | Unlimited |
| Control state machine (claimed → validated → gap → managed) | View only | ||||
| Coverage / maturity / gap analytics | Basic snapshot | ||||
| Manual evidence upload | Up to 0.5 GB | Up to 1 GB | Up to 2 GB | Unlimited | |
| Evidence expiry tracking + reminders | |||||
| Risk management | |||||
| Org-level risk appetite | Preview | ||||
| Risk register | Preview | ||||
| 5×5 inherent / residual scoring | Preview | ||||
| Threat-informed risk statements | Preview | ||||
| Risk heatmap | Preview | ||||
| Risk treatment plans linked to controls | Preview | ||||
| Threat-informed minimum baseline | Preview | ||||
| Remediation actions inbox (gap → action, auto-close on fix) | Preview | ||||
| CTEM — Continuous Threat Exposure Management | |||||
| Attack-surface scans | Passive only | Passive + light active | Passive + light active | Deep, active, passive & custom | All + custom modules |
| Manual scans / month | 5 | 10 | 25 | Unlimited | Unlimited |
| Scheduled scans | Monthly | Weekly / monthly | Daily / weekly / monthly | Continuous + SLA | |
| Monitored domains | 1 | 3 | 10 | 25 | Unlimited |
| Tracked assets | 50 | 200 | 500 | 1,000 | Unlimited |
| Asset types (domain, host, IP, cert, identity, data, app, device…) | 9 | 9 | 9 | 9 | 9 + custom |
| Live scan feed | |||||
| Vulnerability triage with audit events | Read-only | ||||
| CVE enrichment | |||||
| EPSS / KEV vulnerability enrichment | |||||
| Exposure scoring & CTEM prioritisation | Preview | ||||
| Identity exposure & dark-web monitoring | |||||
| Dark-web & breach monitoring cadence | On-demand | Monthly | Monthly | Weekly | Daily |
| Leaked / breached credential findings | |||||
| Breach timelines & first-seen history | |||||
| Domain-ownership verification (DNS-TXT) | |||||
| Reveal leaked credential (audited) | |||||
| Cloud & SaaS connectors — Configuration Posture (CSPM) | |||||
| Cloud & SaaS connectors | Preview | 1 connector (Microsoft 365) | 1 connector (Microsoft 365) | Up to 3 connectors | Unlimited connectors + custom |
| Scheduled connector sync (identities, devices, vulnerabilities) | |||||
| Native configuration-posture checks (MFA, admin governance, device compliance…) | Preview | ||||
| Posture mapped to NIST CSF → auto-evidence | Preview | ||||
| Failing checks become tracked remediation actions (auto-close on fix) | |||||
| Policies & governance | |||||
| Starter catalogue of policy, procedure & playbook templates | |||||
| Author, version & restore (full change history) | |||||
| Generate polished documents & reports | |||||
| Dashboards & analytics | |||||
| Real-data dashboards (assets, scans, findings) | Preview | ||||
| GRC dashboard (compliance + risk posture) | Preview | ||||
| Attack-surface graph view | Preview | ||||
| Time-bucketed trend analytics | Preview | ||||
| Reporting & exports | |||||
| Compliance report (executive summary, coverage, gaps, risk) | Preview | ||||
| Findings report (evidence, screenshots, editable draft) | Preview | ||||
| HTML reports (browser print) | Preview | ||||
| Data export | CSV | CSV | CSV | CSV + JSON | CSV + JSON + bulk |
| Collaboration | |||||
| Collaboration & project sharing (internal + third-party) | |||||
| Email notifications (scan events, digests, alerts) | Basic | ||||
| Activity feed | |||||
| Shared AI Sidekick team memory | |||||
| Gamification & engagement | |||||
| Maturity achievement badges | Preview | ||||
| Maturity progress & path-to-baseline | Preview | ||||
| Risk-treated-over-time streaks | Preview | ||||
| Identity, access & audit | |||||
| OIDC single sign-on (Microsoft 365 & email) | |||||
| Built-in roles (Main Admin / Admin / User / Reader) | |||||
| MFA (via identity provider) | |||||
| Audit log (typed events) — read + export | |||||
| Platform & support | |||||
| Projects | 1 | 2 | 4 | Unlimited | Unlimited |
| Users | 1 | 2 | 3 | 10 | Unlimited |
| Data retention | 7 days | 14 days | 30 days | 90 days | 365 days (configurable) |
| Public REST API access | |||||
| Support | Community | Email (business hours) | Email (business hours) | Priority email + chat | Dedicated CSM, 24×7 |
| Onboarding | Self-serve | Self-serve + docs | Self-serve + docs | Onboarding call | Tailored training |
NIST CSF 2.0 is the core spine every account runs; Complete unlocks all of the below.
All prices in USD. Starter is à la carte — a flat price for any 2 of the 4 content modules; enabling a third moves you to Essentials. During preview, capabilities marked “Preview” are available on all plans, including Free — plan limits for these are being introduced as the platform exits preview. Enterprise plans add unlimited scale and dedicated support — talk to sales for design-partner pricing. Yearly billing saves roughly 17% versus monthly. Registered users can preview what we are building next on our roadmap.