Start free, get audit-ready on Essentials, run a full programme on Complete. Yearly billing saves roughly 17%.
$0/yr billed yearly
Evaluate — or very small teams & solo operators
$250/yr billed yearly
SMB starter — one framework, light cadence
$2,500/yr billed yearly
Full SMB GRC programme
Mid-market & regulated enterprise
| Feature | Free | Essentials | Complete | Enterprise |
|---|---|---|---|---|
| AI Sidekick — your built-in AI vCISO | ||||
| AI vCISO assistant (chat, guidance, drafting) | 5-credit trial | |||
| AI personas | 2 (Compliance, Analyst) | 5 (CISO, Compliance, Analyst, IR, Pentester) | 5 | |
| Hosted AI credits / month | 5 (signup trial) | 25 | 250 | Unlimited |
| Top-up credits | ||||
| AI propose / approve loop on evidence & controls | Basic | |||
| AI risk derivation from compliance gaps | Preview | |||
| Scheduled AI workflows (gap review, assessment cadence) | Monthly only | |||
| Bring your own agent (your model & key) — all tiers | ||||
| Native MCP server — connect Claude, Copilot or Cursor | ||||
| MCP tools (read + human-approved actions) | 34 | 34 | 34 | 34 |
| Agentic API keys (OAuth 2.1 or scoped) | ||||
| Safe actions — human-approved, scope-gated tools | ||||
| Compliance & Standards | ||||
| Standards available | 1 — NIST CSF 2.0 (read-only) | 2 active baselines | All 17 | All 17 + unlimited custom |
| Control ↔ requirement mapping (bidirectional) | ||||
| Cross-framework derivation (NIST CSF hub) | ||||
| Custom framework builder (template, from scratch, CSV import) | ||||
| Assessments & evidence | ||||
| Onboarding wizard | ||||
| Assessment runs | 1 (read-only) | Unlimited | Unlimited | Unlimited |
| Control state machine (claimed → validated → gap → managed) | View only | |||
| Coverage / maturity / gap analytics | Basic snapshot | |||
| Manual evidence upload | Up to 1 GB | Up to 25 GB | Unlimited | |
| Evidence expiry tracking + reminders | ||||
| Risk management | ||||
| Org-level risk appetite | Preview | |||
| Risk register | Preview | |||
| 5×5 inherent / residual scoring | Preview | |||
| SCF threat catalogue (41 threats / 39 risk statements) | Preview | |||
| Risk heatmap | Preview | |||
| Risk treatment plans linked to controls | Preview | |||
| Materiality flag | Preview | |||
| Remediation actions inbox (gap → action, auto-close on fix) | Preview | |||
| CTEM — Continuous Threat Exposure Management | ||||
| Attack-surface scans | Passive only | Passive + light active | Deep, active, passive & custom | All + custom modules |
| Manual scans / month | 5 | 25 | Unlimited | Unlimited |
| Scheduled scans | Daily / weekly / monthly | Daily / weekly / monthly | Continuous + SLA | |
| Monitored domains | 3 | 10 | 25 | Unlimited |
| Tracked assets | 50 | 200 | 500 | Unlimited |
| Asset types (domain, host, IP, cert, identity, data, app, device…) | 9 | 9 | 9 | 9 + custom |
| Live scan feed | ||||
| Vulnerability triage with audit events | Read-only | |||
| CVE enrichment | ||||
| EPSS / KEV vulnerability enrichment | ||||
| Exposure scoring & CTEM prioritisation | Preview | |||
| Identity exposure & dark-web monitoring | ||||
| Dark-web & breach monitoring cadence | On-demand | Monthly | Weekly | Daily |
| Leaked / breached credential findings | ||||
| Breach timelines & first-seen history | ||||
| Domain-ownership verification (DNS-TXT) | ||||
| Reveal leaked credential (audited) | ||||
| Cloud & SaaS connectors — Configuration Posture (CSPM) | ||||
| Cloud & SaaS connectors | Preview | 1 connector (Microsoft 365) | Up to 3 connectors | Unlimited connectors + custom |
| Scheduled connector sync (identities, devices, vulnerabilities) | ||||
| Native configuration-posture checks (MFA, admin governance, device compliance…) | Preview | |||
| Posture mapped to NIST CSF → auto-evidence | Preview | |||
| Failing checks become tracked remediation actions (auto-close on fix) | ||||
| Policies & governance | ||||
| Starter catalogue of policy, procedure & playbook templates | ||||
| Author, version & restore (full change history) | ||||
| Generate polished documents & reports | ||||
| Dashboards & analytics | ||||
| Real-data dashboards (assets, scans, findings) | Preview | |||
| GRC dashboard (compliance + risk posture) | Preview | |||
| Attack-surface graph view | Preview | |||
| Time-bucketed trend analytics | Preview | |||
| Reporting & exports | ||||
| Compliance report (executive summary, coverage, gaps, risk) | Preview | |||
| Findings report (evidence, screenshots, editable draft) | Preview | |||
| HTML reports (browser print) | Preview | |||
| Data export | Preview | CSV only | CSV + JSON | CSV + JSON + bulk |
| Collaboration | ||||
| Collaboration & project sharing (internal + third-party) | ||||
| Email notifications (scan events, digests, alerts) | Basic | |||
| Activity feed | ||||
| Shared AI Sidekick team memory | ||||
| Gamification & engagement | ||||
| Maturity achievement badges | Preview | |||
| Maturity progress & path-to-baseline | Preview | |||
| Risk-treated-over-time streaks | Preview | |||
| Identity, access & audit | ||||
| OIDC single sign-on (Microsoft 365 & email) | ||||
| Built-in roles (Main Admin / Admin / User / Reader) | ||||
| MFA (via identity provider) | ||||
| Audit log (typed events) | Last 7 days | Read by admin | Read + export | Read + export |
| Platform & support | ||||
| Projects | 1 | 2 | Unlimited | Unlimited |
| Users | 1 | 3 | 10 | Unlimited |
| Data retention | 7 days | 30 days | 90 days | 365 days (configurable) |
| Public REST API access | ||||
| Support | Community | Email (business hours) | Priority email + chat | Dedicated CSM, 24×7 |
| Onboarding | Self-serve | Self-serve + docs | Onboarding call | Tailored training |
NIST CSF 2.0 is the core spine every account runs; Complete unlocks all of the below.
All prices in USD. During preview, capabilities marked “Preview” are available on all plans, including Free — plan limits for these are being introduced as the platform exits preview. Enterprise plans add unlimited scale, public API access and dedicated support — talk to sales for design-partner pricing. Yearly billing saves roughly 17% versus monthly. Registered users can preview what we are building next on our roadmap.