One price. Everything included.
Two frameworks, the full platform, and our team doing the implementation with you. No separate consultant. No surprise line items.
Get a free snapshot of where you stand on SOC 2 and ISO 27001. No cost, no commitment.
Three plans, one offer
Every plan includes the full platform, implementation by our team, and audit support.
Starter
Up to 25 people
$2,699per year
2 frameworks included- The full platform
- Implementation by our team
- Audit support
Growth
Most popular26 to 100 people
$3,699per year
2 frameworks included- The full platform
- Implementation by our team
- Audit support
Scale
101 to 250 people
$3,999per year
3 frameworks included- The full platform
- Implementation by our team
- Audit support
Nothing is locked behind a higher tier. Price is based on team size only.
Prices shown in US dollars.
More than 250 people? Talk to us.
You won't need a consultant
Most compliance platforms hand you a dashboard and a list of gaps. Then you hire someone to actually close them. That consultant usually costs more than the software did.
We don't work that way. Our team writes your policies, builds your controls, prepares your evidence, and stays with you through the audit. Same price either way.
The usual way
Two vendors to manage- Compliance platformSoftware vendor
- Policy writingConsultant
- Control implementationConsultant
- Evidence preparationConsultant
- Audit preparationConsultant
- External audit feeYour auditor
A platform contract, a consultant contract, and your auditor.
With Viglyn
One vendor to manage- Compliance platformViglyn
- Policy writingViglyn
- Control implementationViglyn
- Evidence preparationViglyn
- Audit preparationViglyn
- External audit feeYour auditor
One contract, at the price on the card above, and your auditor.
One vendor. One price. Done.

The people who close the gaps, not just the tool that finds them
Compliance practitioners work inside your workspace, scoping frameworks, closing gaps, and preparing for the audit. They are in the price of every plan, not a line item beside it.
Two frameworks, not one
Most platforms charge you for one framework, then charge again for the next. Your evidence maps across all of them anyway, so we include two from the start.
SOC 2 and ISO 27001 together, or whichever two you need. GDPR, HIPAA, PCI DSS and more are available too.
Everything in the platform, in every plan
No module is reserved for a higher tier. Starter runs the same product Scale does.
Evidence Automation
Connects to your cloud, identity, HR and code systems and collects audit evidence on its own.
Continuous Control Monitoring
Every control checked around the clock, not just at audit time.
Multi-Framework Mapping
One evidence set maps across every framework you run.
Risk Management
Full risk register, inherent and residual scoring, treatment plans, owner acceptance and review cycles.
Vendor and Third-Party Risk
Vendor inventory, risk assessments, questionnaires, materiality and lifecycle tracking.
Policy Management
Policy library, versioning, and employee acknowledgement with a signed audit trail.
Vulnerability Management
Findings tracked to closure with SLAs.
Auditor Portal
Give your auditor read-only access so evidence review happens in the platform, not over email.
Trust Center
A public page showing your security posture so buyers stop sending you questionnaires.
We don't take shortcuts.
Compliance only means something if the controls are real. Here is what that means in practice.
Evidence comes from your systems, never from us.
Every piece of evidence is pulled from your actual cloud, identity and code systems. We never manufacture, edit or reconstruct it. If something can't be collected, we show it as unresolved rather than passing.
We will tell you when you're not ready.
If a control isn't genuinely in place, we say so. We would rather have an uncomfortable conversation before the audit than a failed one during it.
We don't touch your auditor's fee.
Your external auditor is independent and paid directly by you. We help you choose one and work alongside them, but we take no commission and add no markup.
We build the control, not the checkbox.
Our team implements the actual control and writes the actual policy. A green dashboard over a gap that was never closed helps nobody.
Questions worth asking
What exactly does implementation include?
Is the auditor's fee included?
Which frameworks do you support?
What happens if we need a third framework?
How long does SOC 2 take?
Do you lock features behind higher tiers?
What if we're over 250 people?
Can we start before we're ready?
See where you stand first
Get a free snapshot of where you stand on SOC 2 and ISO 27001. No cost, no commitment.