Pricing
Compare plans
Every feature across all four plans, side by side. On a narrow screen, scroll right — the Feature column stays in view while you compare tiers.
| Feature | Free (Scorecard) | Compliance Pack | Ongoing Compliance | Enterprise |
|---|---|---|---|---|
| Self-audit: NDPA/GAID or Cybercrimes Act | One, your choice, freely repeatable | Unlimited, both | Unlimited, both | Unlimited, both |
| Self-audit: the OTHER free framework | Requires upgrade | Yes | Yes | Yes |
| Self-audit: UK GDPR / ISO 27001 | Add-on required | Add-on required | Add-on required | Often bundled |
| Score + gap analysis | Yes | Yes | Yes | Yes |
| Compliance document generation (NDPA only currently) | No | Yes | Yes | Yes |
| Evidence Vault | No | Yes | Yes | Yes |
| Vendor & Third-Party Assessment | No | Yes | Yes | Yes |
| Staff Training tracking | No | (personal) | (full team roster) | Yes |
| Implementation Roadmap | No | Yes | Yes | Yes |
| Audit Log | No | Yes | Yes | Yes |
| My Documents | No | Yes | Yes | Yes |
| Support Tickets | Yes | Yes | Yes | Yes |
| Regulatory update email alerts | No | Yes | (+ full in-app panel) | Yes |
| Compliance Calendar | No | No | Yes | Yes |
| Incident Response workflow | No | No | Yes | Yes |
| Evidence freshness alerts | No | No | Yes | Yes |
| Trust Page + shareable badges | No | No | Yes | Yes |
| Team members | Solo only | Solo only | Up to 3 seats | Beyond 3, negotiated |
| Questionnaire Automation + AI Compliance Assistant | No | Add-on | Add-on | Often bundled |
Compliance Pack vs. Ongoing Compliance
Compliance Pack is a one-time compliance snapshot: your score, your gap list, and the actual documents (privacy policy, DPIA, data register, breach response plan) generated once, for right now. It's built for a single moment — a board update, an investor questionnaire, closing out a specific gap before a deadline.
Ongoing Compliance is built for staying compliant, not just proving it once. It adds the tooling that only matters when compliance is a continuous responsibility: a compliance calendar for recurring deadlines, evidence freshness alerts so stale documentation gets flagged before an auditor finds it, an incident response workflow for when something actually goes wrong, and a shareable Trust Page that stays current automatically. If you're revisiting this every quarter or should be that's the plan built for it, not just a bigger version of the same one-time snapshot.
How add-ons work
Add-ons; UK GDPR framework access, ISO 27001 framework access, and Questionnaire Automation + AI Compliance Assistant are never available on their own. Each one requires an existing Compliance Pack or Ongoing Compliance subscription (or Enterprise) as its base; there's no way to buy an add-on standalone on top of the free Scorecard. Upgrade first, then add what you need.
What "Enterprise, contact sales" actually means
Enterprise isn't a fixed package, it starts from everything in Ongoing Compliance, then gets negotiated per deal: team access beyond 3 seats, which add-ons (if any) are bundled in rather than billed separately, and pricing that reflects your actual usage and team size. There's no self-serve checkout for it; it's set up directly with sales once you've talked through what you actually need.