One control set for SOC 2 and ISO 27001.

Build your SOC 2 and ISO 27001 program in one place.

Turn your company context into a prioritized roadmap, mapped policies, and evidence-backed readiness without duplicating work across frameworks.

14 days free. No credit card. No mandatory sales call.
SOC 2 criteria
61
ISO 27001 controls
93
live connectors
10
shared control set
1

A real vCISO.ai program dashboard

From gaps to audit-ready work

See what matters, produce the work, and keep the proof connected. Your team stays in control of every approval.

Know what is missing

Your company, stack, and goals become a gap analysis and phased roadmap with owners and due dates.

Produce the work

Draft policies in your context, mapped to the controls they cover. Your team reviews, edits, and approves.

Keep evidence current

Connect systems or upload artifacts, map proof to controls, and track validity windows for Type II.

From assessment to evidence-backed readiness

The platform drafts and organizes the program. Your team reviews, approves, and owns the decisions.

  1. 01

    Tell us about your company

    A short onboarding covers your stack, team, and goals. Your AI vCISO turns it into a gap analysis and phased roadmap.

  2. 02

    Review and approve the work

    Review drafted policies and tasks, assign owners, and approve what becomes part of your program.

  3. 03

    Prove what is ready

    See which controls have current policy and evidence, and which gaps remain before either audit.

Cross-framework by design

Do the security work once. Reuse it across both audits.

SOC 2 criteria and ISO 27001 controls map into one shared control library. Approve a policy or attach evidence once, and it supports every mapped requirement where it applies.

SOC 2
Type I and Type II
ISO 27001
2022 revision
Compare SOC 2 and ISO 27001

Ten evidence connectors available today

Run scheduled, read-only checks against the systems you use. Manual upload with AI-assisted mapping covers everything else.

AWS

Account access, audit logging, threat detection, storage, databases, and network exposure.

Google Cloud

Google Cloud

Public IAM bindings and data access audit logging.

Defender for Cloud and activity-log export.

GitHub

GitHub

Organization access, repository controls, and high-risk dependency-alert coverage.

Okta

Okta

Paginated users and required authenticator enrollment.

Slack

User and administrator inventory for access reviews.

Also available: GitLab, Jira Cloud, Vercel, and Supabase.

Choose how much help you want

Start with the real platform for free, then choose software alone or add a practitioner review. Every price is published and locked for 24 months.

Trial

Build a real roadmap and test the workflow before you buy.

$0 for 14 days
  • 14 days, no credit card
  • SOC 2 and ISO 27001 cross mapping
  • 100 vCISO chat messages
  • 5 policy or evidence generations
Run my free gap analysis
Platform

The complete compliance operating system, without framework or seat fees.

$249 /month equivalent

Billed $2,988 yearly · Save $600

  • SOC 2 Type I and Type II
  • ISO 27001:2022 and Statement of Applicability
  • Unlimited users and frameworks
  • All available integrations; no connector-count fees
Start with Platform
Advisor

Platform plus a practitioner who reviews the program and unblocks the team.

$833 /month equivalent

Billed $9,990 yearly · Save $1,998

  • Everything in Platform
  • Monthly 60-minute practitioner review
  • 2 asynchronous advisory requests monthly
  • 2-business-day response target
Start with Advisor

Your signup price is your renewal price for 24 months under our Terms. If our list prices go up, yours does not.

See full pricing and plan details

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

Product

Getting started

Did not find what you were looking for? Talk to us.

See your security gaps before you buy.

Answer a few questions and get a free, personalized gap analysis and roadmap. No credit card or mandatory sales call.