Pricing
Three tiers, sized to the frameworks you actually face.
$2K / $8K / $20K per month. Each tier expands the framework coverage, the reviewer rotation, and the number of entities in your evidence graph. Pick by the first framework your auditor names in fieldwork — the matrix below shows exactly what each tier covers and which buyer archetype it was built for.
HIPAA · SOC 2 · PCI DSS · GDPR · HITRUST · ISO 27001 · 50-state privacy
Tier 01 · Foundation
$2K / month
Single framework, single entity
HIPAA or GDPR coverage with continuous evidence collection.
Built for HIPAA-only telehealth · <250 employees
- One framework: HIPAA or GDPR
- Continuous evidence collection across contracts, HR policies, vendor agreements
- Daily rule-change radar with drafted remediation plan
- Quarterly reviewer briefing by a former Big-Four auditor
- BAA + DPA signed within one business day
Tier 02 · Multi-framework
$8K / month
Stacked frameworks, one entity
HIPAA + SOC 2 + GDPR + state privacy, pre-packaged for fieldwork.
Built for HIPAA + SOC 2 healthtech · 250–1,500 employees
- Up to four frameworks: HIPAA, SOC 2, GDPR, and the full US state privacy stack
- Pre-assembled evidence packages ready for fieldwork
- Inline auditor workspace with scoped read-only access
- Same-day reviewer escalation on regulatory radar alerts
- Monthly in-house reviewer review of every recommendation
Tier 03 · Enterprise
$20K / month
Multi-entity, multi-framework
All twelve frameworks — including PCI DSS — across entities.
Built for Multi-framework fintech + healthtech · 1,500+ or multi-entity
- All twelve frameworks: HIPAA, SOC 2, PCI DSS, GDPR, HITRUST, ISO 27001 + 50-state privacy
- PCI DSS Report on Compliance, HIPAA risk assessment, and SOC 2 Type II evidence on demand
- Dedicated reviewer rotation across regulatory domains
- M&A due-diligence mode with bespoke escalation hours
- Multi-entity evidence graph with cross-tenant control inheritance
Every tier includes the daily regulatory radar, a former-Big-Four reviewer rotation, and a BAA/DPA signed within one business day. Pricing excludes annual audit fees — read the procurement FAQ for packaging details.
Framework coverage
Which tier fits the framework your auditor names first.
The matrix is the source of truth: every green cell is an in-scope framework at that monthly price. Tier 3 is the only tier that covers PCI DSS today.
- Tier 1 — HIPAA-only telehealth.Single framework, single entity, <250 employees.
- Tier 2 — HIPAA + SOC 2 healthtech. Stacked frameworks, pre-assembled evidence packages, 250–1,500 employees.
- Tier 3 — multi-framework fintech. Adds PCI DSS, HITRUST, ISO 27001, and the full 50-state privacy stack across entities.
Pick by the first framework your auditor namesTier 1 for HIPAA-only telehealth · Tier 2 for HIPAA + SOC 2 healthtech · Tier 3 for multi-framework fintech.
| Framework | Tier 1Foundation$2K / mo | Tier 2Multi-framework$8K / mo | Tier 3Enterprise$20K / mo |
|---|---|---|---|
| HIPAAHealth Insurance Portability and Accountability Act | Covered | Covered | Covered |
| SOC 2AICPA Service Organization Control 2 | Not in scope | Covered | Covered |
| PCI DSSPayment Card Industry Data Security Standard | Not in scope | Not in scope | Covered |
| GDPREU General Data Protection Regulation | Covered | Covered | Covered |
Free framework checklist | |||
Talk to a reviewer
Send the first framework name; we’ll send a tier recommendation.
Open the MVP to scan a corpus, or email us with the framework your auditor opens on — we’ll pre-build a draft evidence package before the first call.