Compliance Add-Ons

Compliance, done in weeks. Not months.

We don't sell you software and walk away. SOC 2, HIPAA, ISO 27001, PCI DSS, GDPR and more — wired into the platform we host for you, with our team doing the work. You ship the product. We ship the audit.

Why us, not Vanta

Four reasons we ship audits faster

We do the work

Vanta and Drata sell software and you do the work. We do the work. You get a managed service that delivers your audit, not another SaaS to learn.

Done in weeks, not months

SOC 2 Type I in 4–6 weeks. HIPAA in 3–5. ISO 27001 in 8–12. We've automated the busywork so you spend hours, not weeks, on compliance.

Built into your platform

We host you, we operate you, we make you compliant. One vendor, one contract, one throat to choke when something breaks.

No SaaS lock-in

Evidence lives in your cloud accounts. Policies live in your repo. Cancel any time and walk away with everything — no platform to migrate off.

Most-requested frameworks

Pick a framework, see the plan

Setup gets you to the report. The retainer keeps you compliant year-round.

SOC 2

Service organizations and SaaS

The de facto trust signal for B2B SaaS. We get you from zero to Type II observation period in weeks.

Setup
$15,000
Retainer
$2,500/mo
4–6 weeks to audit-ready
Learn about SOC 2

HIPAA

Health tech, telehealth, digital therapeutics

PHI handling done right. BAA, Security Rule, Privacy Rule, and Breach Notification — all wired up.

Setup
$7,500
Retainer
$1,500/mo
3–5 weeks to BAA-ready
Learn about HIPAA

ISO 27001

Global SaaS and enterprise

The international standard for information security. Required for most EU enterprise deals.

Setup
$20,000
Retainer
$3,500/mo
8–12 weeks to Stage 1 audit
Learn about ISO 27001

PCI DSS

Anyone storing, processing, or transmitting cardholder data

PCI DSS v4.0.1 done right. We scope your CDE narrowly so you don't pay for compliance you don't need.

Setup
$15,000
Retainer
$2,500/mo
6–10 weeks to AOC
Learn about PCI DSS

GDPR

Anyone processing EU/UK personal data

EU/UK personal data protection. ROPA, DPAs, DPIA, breach response — everything Article 30 + 32 requires.

Setup
$7,500
Retainer
$1,250/mo
3–4 weeks to Article 30 ready
Learn about GDPR

What's included

Every add-on ships with the same foundation

Pick a framework above to see what's specific to that one. Below is what comes standard, on every engagement.

Pre-mapped control libraries

Every framework comes with a pre-built control catalog mapped to your specific cloud (AWS, Azure, GCP) and tooling.

Continuous evidence collection

Automated control tests run hourly. Evidence is gathered, tagged, and timestamped — no screenshot scavenger hunts.

All policies drafted for you

Information Security, Acceptable Use, Incident Response, Change Management, BCP/DR — written, version-controlled, and acknowledged.

Quarterly access reviews

Vendor inventory, access reviews, risk assessments — scheduled, assigned, completed, and evidenced.

Auditor portal + intros

We have working relationships with vetted, fixed-fee auditors. They review evidence in our portal — no email back-and-forth.

Drift remediation included

When a control fails, our team fixes it. You don't get an alert and a help article — you get a closed ticket.

Stack frameworks, save money

Your second framework is 60–80% cheaper

Most controls overlap across frameworks. SOC 2 evidence covers most of ISO 27001 (~80%), most of HIPAA (~65%), and a chunk of GDPR (~40%). Once we've built one program for you, adding the next is a fraction of the work and cost.

SOC 2 + ISO 27001 = ~$5K incremental
SOC 2 + HIPAA = ~$3K incremental
ISO 27001 + GDPR = ~$2K incremental
HIPAA + HITRUST = upgrade path

Frequently asked questions

Framework-specific questions live on each sub-page.

Tell us your framework and your timeline.

We'll scope the work, give you a fixed price, and have you audit-ready in weeks. No SaaS demos. No annual contracts.