Pricing
Simple to start. Powerful at scale.
Five plans, from solo vendors to large regulated accounts. Priced per team: add as many users as you need.
4 plans, 62 features compared line by line. Public prices, no mandatory sales call.
Small business · vendor
Free
The essentials to answer your customers’ assessments.
€0/ year
Free forever
1 team
- 5 vendors · 3 business activities
- Public Trust page
- Basic SecOps score
- Receive assessments
Small security team
Starter
AI Chat and a risk matrix to start a structured programme.
€900/ year
excl. VAT · 2 months free
3 teams
- AI Chat · 10M tokens/month
- 4×4 risk matrix
- 25 vendors
- 20 monitored assets
Structured GRC programme
Pro
ISO 27001, AI-generated policies and custom questionnaires.
€4,900/ year
excl. VAT · 2 months free
8 teams
- ISO 27001 & frameworks
- AI document generation (5/yr)
- 50 monitored assets
- 50 vendors
Large regulated account
Enterprise
Hybrid deployment, 99.9%+ SLA, bespoke integrations.
Custom
Large regulated account
Unlimited
- Hybrid deployment on demand
- 99.9% SLA + contractual 4h
- Dedicated CSM + DPA
- Bespoke SIEM integrations
Prices excl. VAT. Regulatory modules enabled à la carte. Hosted in Europe.
Which plan fits your situation?
Answer the questions: the recommendation follows your strongest requirement, and you immediately see the time and money you get back.
Answer the questions
A first suggestion appears after your first answer. Refine it by completing the questions.
0 / 3
Plan by plan
What each plan adds over the one below it, then everything it includes.
Structured GRC programme
Pro
ISO 27001, AI-generated policies and custom questionnaires.
€4,900/ year
excl. VAT · 2 months free
- Scope
- 8 teams
- Features included
- 54
Everything in Starter, plus:
- Vendors · 50
- Business activities (scopes) · 50
- Internal projects · 10
- Vendor compare wizard
- Exemption register
- Assessments sent / year · 100
- Active campaigns · 15
- Custom questionnaires · 5
- Auto-generated gap analyses · Advanced + project
- AI Chat / RAG on your documents · 50M tokens/mois
- AI Excel import (questionnaire auto-answer) · 25/an
- AI doc gen — section refinement · 25/mois
- AI doc gen — full generation (NIS2, ISO, GDPR) · 5/an
- GDPR (registers, DPIA, 72h breach) · Full
- Frameworks (ISO 27001, etc.)
- Internal policies · 50
- Global requirement library · + custom
- Monitored assets · 50
- On-demand discovery scans · 20/mois
- Manual SecOps scans · 250/mois
- Typosquat monitoring (DNSTwist) · 3 domains
- Vulnerability scans (Nuclei) · 10/mois
- Granular per-customer sharing
- File storage with folders · 5 GB
- Signed download links (expiring)
- Incident propagation (cross-org)
- Projects · 20
- Tickets · 1 500
- MFA (TOTP / email / SMS) · + org policy
- Audit logs · Extended
- Hybrid deployment · On request
- Contractual 99.9%+ SLA · On request
- Custom DPA & terms · On request
- Dedicated CSM · On request
- Custom integrations (SIEM, API…) · On request
- Channel · Email + chat
- Response SLA · 24h
- Onboarding · Self + 2h included
Everything included
Vendor & GRC core
- Vendors · 50
- Business activities (scopes) · 50
- Internal projects · 10
- Vendor compare wizard
- Vendor map
- Dependency map
- Risk matrix (4×4 heatmap)
- Risk register
- Exemption register
Assessments & questionnaires
- Assessments sent / year · 100
- Active campaigns · 15
- Preconfigured questionnaires · All
- Custom questionnaires · 5
- Receive assessments (vendor side)
- Auto-generated gap analyses · Advanced + project
AI suite
- AI Chat / RAG on your documents · 50M tokens/mois
- AI Excel import (questionnaire auto-answer) · 25/an
- AI doc gen — section refinement · 25/mois
- AI doc gen — full generation (NIS2, ISO, GDPR) · 5/an
Compliance (per-framework modules)
- GDPR (registers, DPIA, 72h breach) · Full
- Frameworks (ISO 27001, etc.)
- Internal policies · 50
- Global requirement library · + custom
My exposure
- SecOps score (SSL/DNS/Email/Headers) · Full
- Attack surface perimeters · Unlimited
- Monitored assets · 50
- On-demand discovery scans · 20/mois
- Manual SecOps scans · 250/mois
- Scheduled SecOps scans
- Typosquat monitoring (DNSTwist) · 3 domains
- Vulnerability scans (Nuclei) · 10/mois
- My Customers (score sharing) · Unlimited
- Granular per-customer sharing
- Public Trust page · With CISAPP badge
- Public sub-processor register · With CISAPP badge
Document management
- File storage with folders · 5 GB
- Tags + ACL
- TLP marking (classification)
- Signed download links (expiring)
Incident & crisis management
- Incident register
- Incident propagation (cross-org)
Projects
- Projects · 20
- Tickets · 1 500
Admin & security
- Google / Microsoft SSO
- MFA (TOTP / email / SMS) · + org policy
- Audit logs · Extended
Enterprise gates
- Hybrid deployment · On request
- Contractual 99.9%+ SLA · On request
- Custom DPA & terms · On request
- Dedicated CSM · On request
- Custom integrations (SIEM, API…) · On request
Support
- Channel · Email + chat
- Response SLA · 24h
- Onboarding · Self + 2h included
All features
11 categories, 62 rows. Click a category to expand it.
Showing 62 of 62 rows
| Feature | Free €0 / year | Starter €900 / year | Pro €4,900 / year | Enterprise Custom |
|---|---|---|---|---|
| Vendors | 5 | 25 | 50 | Unlimited |
| Business activities (scopes) | 3 | 10 | 50 | Unlimited |
| Internal projects | 1 | 3 | 10 | Unlimited |
| Partners, subsidiaries, applications | — | — | — | ✓ |
| Vendor compare wizard | — | — | ✓ | ✓ |
| Vendor map | — | ✓ | ✓ | ✓ |
| Dependency map | — | ✓ | ✓ | ✓ |
| Risk matrix (4×4 heatmap) | — | ✓ | ✓ | ✓ |
| Risk register | — | ✓ | ✓ | ✓ |
| Exemption register | — | — | ✓ | ✓ |
| Assessments sent / year | 5 | 30 | 100 | Unlimited |
| Active campaigns | — | 3 | 15 | Unlimited |
| Preconfigured questionnaires | All | All | All | All |
| Custom questionnaires | — | — | 5 | Unlimited |
| Receive assessments (vendor side) | ✓ | ✓ | ✓ | ✓ |
| Auto-generated gap analyses | Basic | Advanced | Advanced + project | Advanced + project |
| AI Chat / RAG on your documents | — | 10M tokens/mois | 50M tokens/mois | Unlimited |
| AI Excel import (questionnaire auto-answer) | — | 5/an | 25/an | Unlimited |
| AI doc gen — section refinement | — | 3/mois | 25/mois | Unlimited |
| AI doc gen — full generation (NIS2, ISO, GDPR) | — | — | 5/an | Unlimited |
| GDPR (registers, DPIA, 72h breach) | Essential | Register & processors | Full | Full |
| NIS2 (Art. 21, supply chain, ANSSI export) | — | — | — | ✓ |
| AI Act (AI systems, FRIA) | — | — | — | Unlimited |
| DORA (CTPP, TLPT, ICT incidents) | — | — | — | ✓ |
| Frameworks (ISO 27001, etc.) | — | — | ✓ | ✓ |
| Internal policies | 3 | 10 | 50 | Unlimited |
| Global requirement library | ✓ | ✓ | + custom | + custom |
| SecOps score (SSL/DNS/Email/Headers) | Basic | Full | Full | Full |
| Attack surface perimeters | Unlimited | Unlimited | Unlimited | Unlimited |
| Monitored assets | — | 20 | 50 | Unlimited |
| On-demand discovery scans | — | 2/mois | 20/mois | Unlimited |
| Manual SecOps scans | 5/mois | 50/mois | 250/mois | Unlimited |
| Scheduled SecOps scans | — | ✓ | ✓ | ✓ |
| Typosquat monitoring (DNSTwist) | — | 1 domain | 3 domains | Unlimited |
| Vulnerability scans (Nuclei) | — | 1/mois | 10/mois | Unlimited |
| My Customers (score sharing) | Unlimited | Unlimited | Unlimited | Unlimited |
| Granular per-customer sharing | — | — | ✓ | ✓ |
| Public Trust page | With CISAPP badge | With CISAPP badge | With CISAPP badge | White-label |
| Public sub-processor register | With CISAPP badge | With CISAPP badge | With CISAPP badge | White-label |
| File storage with folders | 500 MB | 1 GB | 5 GB | Unlimited |
| Tags + ACL | ✓ | ✓ | ✓ | ✓ |
| TLP marking (classification) | ✓ | ✓ | ✓ | ✓ |
| Signed download links (expiring) | — | — | ✓ | ✓ |
| Incident register | — | ✓ | ✓ | ✓ |
| Incident propagation (cross-org) | — | — | ✓ | ✓ |
| Crisis war-room | — | — | — | ✓ |
| Crisis cells + channels + messaging | — | — | — | Multi-cell |
| Projects | 1 | 5 | 20 | Unlimited |
| Tickets | 50 | 300 | 1 500 | Unlimited |
| Google / Microsoft SSO | ✓ | ✓ | ✓ | ✓ |
| Enterprise SSO (OIDC, SAML 2.0) | — | — | — | Unlimited |
| MFA (TOTP / email / SMS) | Per user | Per user | + org policy | + org policy |
| IP restriction (CIDR) | — | — | — | Unlimited |
| Audit logs | — | Standard | Extended | Extended |
| Hybrid deployment | — | — | Build on demand | |
| Contractual 99.9%+ SLA | — | — | ✓ | |
| Custom DPA & terms | — | — | ✓ | |
| Dedicated CSM | — | — | ✓ | |
| Custom integrations (SIEM, API…) | — | — | Bespoke | |
| Channel | Community | Email + chat | CSM + phone | |
| Response SLA | — | 48h | 24h | 4h contractual |
| Onboarding | Self-service | Self-service | Self + 2h included | Custom programme |
| Start for free | Choose Starter | Choose Pro | Contact sales | |
Pricing questions
Billing, limits, changing plans.
No. It is per team: each plan includes a number of teams (1 on Free, 3 on Starter, 8 on Pro, unlimited on Enterprise) and you add as many users as you need inside each one, at no extra cost.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours