One control set for SOC 2 and ISO 27001.
Build your SOC 2 and ISO 27001 program in one place.
Turn your company context into a prioritized roadmap, mapped policies, and evidence-backed readiness without duplicating work across frameworks.
14 days free. No credit card. No mandatory sales call.- SOC 2 criteria
- 61
- ISO 27001 controls
- 93
- live connectors
- 10
- shared control set
- 1
A real vCISO.ai program dashboard
From gaps to audit-ready work
See what matters, produce the work, and keep the proof connected. Your team stays in control of every approval.
Know what is missing
Your company, stack, and goals become a gap analysis and phased roadmap with owners and due dates.
Produce the work
Draft policies in your context, mapped to the controls they cover. Your team reviews, edits, and approves.
Keep evidence current
Connect systems or upload artifacts, map proof to controls, and track validity windows for Type II.
From assessment to evidence-backed readiness
The platform drafts and organizes the program. Your team reviews, approves, and owns the decisions.
- 01
Tell us about your company
A short onboarding covers your stack, team, and goals. Your AI vCISO turns it into a gap analysis and phased roadmap.
- 02
Review and approve the work
Review drafted policies and tasks, assign owners, and approve what becomes part of your program.
- 03
Prove what is ready
See which controls have current policy and evidence, and which gaps remain before either audit.
Cross-framework by design
Do the security work once. Reuse it across both audits.
SOC 2 criteria and ISO 27001 controls map into one shared control library. Approve a policy or attach evidence once, and it supports every mapped requirement where it applies.
- SOC 2
- Type I and Type II
- ISO 27001
- 2022 revision
Ten evidence connectors available today
Run scheduled, read-only checks against the systems you use. Manual upload with AI-assisted mapping covers everything else.
Account access, audit logging, threat detection, storage, databases, and network exposure.
Public IAM bindings and data access audit logging.
Defender for Cloud and activity-log export.
Organization access, repository controls, and high-risk dependency-alert coverage.
Paginated users and required authenticator enrollment.
User and administrator inventory for access reviews.
Also available: GitLab, Jira Cloud, Vercel, and Supabase.
Choose how much help you want
Start with the real platform for free, then choose software alone or add a practitioner review. Every price is published and locked for 24 months.
Build a real roadmap and test the workflow before you buy.
- 14 days, no credit card
- SOC 2 and ISO 27001 cross mapping
- 100 vCISO chat messages
- 5 policy or evidence generations
The complete compliance operating system, without framework or seat fees.
Billed $2,988 yearly · Save $600
- SOC 2 Type I and Type II
- ISO 27001:2022 and Statement of Applicability
- Unlimited users and frameworks
- All available integrations; no connector-count fees
Platform plus a practitioner who reviews the program and unblocks the team.
Billed $9,990 yearly · Save $1,998
- Everything in Platform
- Monthly 60-minute practitioner review
- 2 asynchronous advisory requests monthly
- 2-business-day response target
Your signup price is your renewal price for 24 months under our Terms. If our list prices go up, yours does not.
See full pricing and plan detailsFrequently asked questions
Quick answers about the product, frameworks, and getting started.
Product
Getting started
Did not find what you were looking for? Talk to us.
See your security gaps before you buy.
Answer a few questions and get a free, personalized gap analysis and roadmap. No credit card or mandatory sales call.