| Published price | Not published | Not published |
|---|
| Plans published | Compliance Automation Foundation, GRC Advanced, GRC Enterprise | Not published |
|---|
| Entry plan | Compliance Automation Foundation | No plan published |
|---|
| Stated limits | Up to 50 FTEs; 1 pre-mapped framework: SOC 2, ISO 27001, Cyber Essentials, HIPAA or GDPR | Not published |
|---|
| Questionnaires per year | Not published | Not published |
|---|
| Expert services | Via partners | In-house auditor support |
|---|
| Audit path | Auditors are part of the partner network. Audit inclusion by plan is not published. | Automation and audit from the same company; the audit and assessment offering is led by an audit partner. |
|---|
| Penetration test | Not listed on the plans page. | Penetration testing and vulnerability scanning are part of the platform (PCI DSS work includes certified ASV scans). |
|---|
| Integrations stated | Not published (the integrations page says "hundreds of tools") | Not published (integrations are described as vetted and approved by auditors) |
|---|
| Frameworks stated | 30+ pre-built frameworks | No total count published; lists SOC 1, SOC 2, ISO 27001, GDPR, PCI DSS, HITRUST e1/i1/r2, HIPAA, CMMC L1, NIST CSF 2.0, Cyber Essentials |
|---|