Skip to content
New · Ask Viglyn, your AI compliance copilot. Ask your program anything.See it
Pricing

One price. Everything included.

Two frameworks, the full platform, and our team doing the implementation with you. No separate consultant. No surprise line items.

Get a free snapshot of where you stand on SOC 2 and ISO 27001. No cost, no commitment.

Plans

Three plans, one offer

Every plan includes the full platform, implementation by our team, and audit support.

Starter

Up to 25 people

$2,699per year

2 frameworks included
  • The full platform
  • Implementation by our team
  • Audit support

Scale

101 to 250 people

$3,999per year

3 frameworks included
  • The full platform
  • Implementation by our team
  • Audit support

Nothing is locked behind a higher tier. Price is based on team size only.

Prices shown in US dollars.

More than 250 people? Talk to us.

Implementation included

You won't need a consultant

Most compliance platforms hand you a dashboard and a list of gaps. Then you hire someone to actually close them. That consultant usually costs more than the software did.

We don't work that way. Our team writes your policies, builds your controls, prepares your evidence, and stays with you through the audit. Same price either way.

The usual way

Two vendors to manage
  • Compliance platformSoftware vendor
  • Policy writingConsultant
  • Control implementationConsultant
  • Evidence preparationConsultant
  • Audit preparationConsultant
  • External audit feeYour auditor

A platform contract, a consultant contract, and your auditor.

With Viglyn

One vendor to manage
  • Compliance platformViglyn
  • Policy writingViglyn
  • Control implementationViglyn
  • Evidence preparationViglyn
  • Audit preparationViglyn
  • External audit feeYour auditor

One contract, at the price on the card above, and your auditor.

One vendor. One price. Done.

A team of four working together at a shared desk with laptops and notebooks.
Who does the work

The people who close the gaps, not just the tool that finds them

Compliance practitioners work inside your workspace, scoping frameworks, closing gaps, and preparing for the audit. They are in the price of every plan, not a line item beside it.

Frameworks

Two frameworks, not one

Most platforms charge you for one framework, then charge again for the next. Your evidence maps across all of them anyway, so we include two from the start.

SOC 2 and ISO 27001 together, or whichever two you need. GDPR, HIPAA, PCI DSS and more are available too.

SOC 2ISO 27001GDPRHIPAAPCI DSSand more
The platform

Everything in the platform, in every plan

No module is reserved for a higher tier. Starter runs the same product Scale does.

Evidence Automation

Connects to your cloud, identity, HR and code systems and collects audit evidence on its own.

Continuous Control Monitoring

Every control checked around the clock, not just at audit time.

Multi-Framework Mapping

One evidence set maps across every framework you run.

Risk Management

Full risk register, inherent and residual scoring, treatment plans, owner acceptance and review cycles.

Vendor and Third-Party Risk

Vendor inventory, risk assessments, questionnaires, materiality and lifecycle tracking.

Policy Management

Policy library, versioning, and employee acknowledgement with a signed audit trail.

Vulnerability Management

Findings tracked to closure with SLAs.

Auditor Portal

Give your auditor read-only access so evidence review happens in the platform, not over email.

Trust Center

A public page showing your security posture so buyers stop sending you questionnaires.

How we work

We don't take shortcuts.

Compliance only means something if the controls are real. Here is what that means in practice.

  1. Evidence comes from your systems, never from us.

    Every piece of evidence is pulled from your actual cloud, identity and code systems. We never manufacture, edit or reconstruct it. If something can't be collected, we show it as unresolved rather than passing.

  2. We will tell you when you're not ready.

    If a control isn't genuinely in place, we say so. We would rather have an uncomfortable conversation before the audit than a failed one during it.

  3. We don't touch your auditor's fee.

    Your external auditor is independent and paid directly by you. We help you choose one and work alongside them, but we take no commission and add no markup.

  4. We build the control, not the checkbox.

    Our team implements the actual control and writes the actual policy. A green dashboard over a gap that was never closed helps nobody.

FAQ

Questions worth asking

What exactly does implementation include?
Our team connects your systems, writes your policies, builds your controls, prepares your evidence, and stays with you through the audit. You get compliance practitioners working inside your workspace, not a dashboard and a list of gaps handed back to you. It is included in every tier at no extra cost.
Is the auditor's fee included?
No. Your external auditor is independent and you pay them directly. We take no commission and add no markup on their fee. We will help you choose an auditor and work alongside them through the examination, but the opinion is theirs alone.
Which frameworks do you support?
SOC 2 and ISO 27001 are the core, and the same evidence base covers GDPR, HIPAA, PCI DSS, ISO 27701, ISO 22301, NIST CSF and more. Your plan includes two of them, three on Scale, and you choose which ones.
What happens if we need a third framework?
Tell us and we will add it. Your evidence already maps across frameworks, so an added framework reuses work you have done rather than starting a second project, and it costs far less than the first one did. Scale includes three from the start.
How long does SOC 2 take?
A Type I report is achievable in weeks, depending on how much is already in place. A Type II cannot be compressed the same way: it reports on how your controls operate over a period, and that observation window is typically three months or more. We will tell you the real timeline for your starting point before you commit, not after.
Do you lock features behind higher tiers?
No. Every module, every integration and the same implementation team come with every plan. Price is based on team size only. The one thing that changes between tiers is how many frameworks are included: two on Starter and Growth, three on Scale.
What if we're over 250 people?
Talk to us. The published tiers stop at 250 people because above that, scope matters more than headcount. The model does not change: one price, with the platform and the implementation included.
Can we start before we're ready?
Yes, and most teams do. Not being ready is the normal starting point, and closing that gap is the work we are here for. Start with a free snapshot: we will tell you where you actually stand and what to close first, before you commit to anything.

See where you stand first

Get a free snapshot of where you stand on SOC 2 and ISO 27001. No cost, no commitment.