Free to try. Priced by who keeps the list current.
Eight documents free, no account. Solo for the compliance or ISMS manager keeping one document set current. Team for the function that keeps several entities current and has to show what changed since the last audit.
Free
- Up to eight documents per paste; the specimen runs in full
- Each classified to its type and family, with its review state, or marked unrecognised
- Every finding named, including what is expected and not listed; the clauses, owner, cadence and templates on your own list open on Solo
Solo
- Every document registered, no cap
- The requiring clauses per regime on every line, each with what it expects the document to contain
- The expected owner and the review cadence on every line, with the due date
- The gap list with the clause that expects each document and the template to start from
- One-page auditor summary, the owner and cadence sheet, the requiring-clause matrix
- CSV export of the register and the gap list
- One saved register, re-run as the list changes
Team
- Everything in Solo, unlimited registers
- Change log when the list is pasted again: every document added, removed or retitled, every change of owner or review date, every gap closed or opened, timestamped and attributed
- Change log export for the audit file
- One account for every entity in the group, one billing portal
One click to checkout: card, Apple Pay or Google Pay, and your account is created from the email you give there, no sign-up form and no link to wait for. Prices in US dollars; VAT or GST added where it applies. Cancel any time from the billing portal; refunds on request within 30 days. On every plan the register runs in your browser; a saved register is the only thing stored.
Questions the pricing page gets
Which regimes are covered? ISO/IEC 27001:2022 with the ISO/IEC 27002:2022 guidance beside each control, ISO/IEC 27701:2025, ISO/IEC 42001:2023, ISO 22301:2019, DORA, the NIS2 Directive and GDPR, from a human-verified compliance corpus under licence. SOC 2 CC1 and CC5 and PCI DSS Requirement 12 name the same documents; they are named here and not quoted.
Does the register read my documents? No. It reads the titles on the list, says which clause requires a document of that kind and what the clause expects it to contain, and names the documents the regimes expect that the list does not carry. Whether a document meets its clause is the reader's judgement.
Where do the templates come from? The policy-templates library on the compliance platform; a type with no template says so.