# Evidr: compliance automation > Evidr is an AI-powered compliance automation platform by Evidr LLC (San Francisco, CA). It gets companies audit-ready in weeks across SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, FedRAMP and 14 frameworks in all: evidence collection with AI review, policy generation, continuous monitoring, vendor risk management and an auditor portal. Site: https://evidr.com | Console: https://console.evidr.com | Contact: https://evidr.com/contact | Email: support@evidr.com ## What Evidr does - AI onboarding: a conversation profiles the business across 60+ risk signals, recommends frameworks and generates controls. https://evidr.com/resources/ai-onboarding - Evidence collection: upload once; AI reviews every file with a confidence score, detects credentials and sensitive data, maps it to controls across frameworks, keeps version history. https://evidr.com/product/evidence-collection - Policy generation: policies drafted for the company, approval workflow, employee signatures stored as evidence, PDF export. https://evidr.com/product/policy-generation - Continuous monitoring: evidence expiry tracking, infrastructure scans (AWS, Azure, GCP, Microsoft 365 and more, 80+ checks), a Mac and Windows device agent. https://evidr.com/product/continuous-monitoring - Vendor risk: 230+ pre-loaded vendors, AI risk scoring, alerts on breaches, CVEs and regulatory action, daily digest. https://evidr.com/product/vendor-risk - Auditor access: read-only portal scoped to the audit, showing approved evidence and policies only; every auditor action logged. https://evidr.com/product/auditor-access - Integrations (22, read-only, official APIs): AWS, Google Cloud, Microsoft Azure, Cloudflare, GitHub, GitLab, Bitbucket, Google Workspace, Microsoft 365, Okta, Dashlane, Bitdefender, Jira, Linear, Asana, Notion, Slack, Salesforce, Sentry, Grafana, Stripe, Mercury; plus the Evidr device agent. https://evidr.com/product/integrations - Also included: risk register (5x5), access reviews, personnel checklists, policy signatures, code scanning, code stack monitoring, trust page, audit trail. https://evidr.com/product ## Frameworks (all included on every plan) SOC 2 Type I and II, ISO 27001, HIPAA, GDPR, PCI DSS, FedRAMP, HITRUST, CCPA, ISO 42001, NIST AI RMF, EU AI Act, CMMC, NIST 800-171, StateRAMP, plus custom frameworks. One guide per framework at https://evidr.com/frameworks/ (soc-2, iso-27001, hipaa, gdpr, pci-dss, fedramp, hitrust, ccpa, iso-42001, nist-ai-rmf, eu-ai-act, cmmc, nist-800-171, stateramp). ## Pricing (https://evidr.com/pricing) - Starter: free, no card, no expiry (created in the console). - Growth: $499 a month, $5,988 billed annually. 5 team members and auditors, 10 devices, 50 policy documents a month, 1 connection per platform. - Professional: $899 a month, $10,788 billed annually. 10 team members, 25 devices, 200 documents a month, 5 connections per platform, 20 custom vendors. - Enterprise: $1,199 a month, $14,388 billed annually. 2 workspaces, 50 team members, unlimited devices, 500 documents a month, 10 connections per platform, 100 custom vendors, dedicated support, audit retention up to 7 years. - Custom: unlimited workspaces and members, custom SLAs, dedicated support engineer. - AI usage is metered separately: $0.20 per 1M input tokens, $0.60 per 1M output tokens, $1.00 minimum in months with usage. No per-framework charges. 14-day money-back guarantee. ## Solutions Startups https://evidr.com/solutions/startups | Small businesses https://evidr.com/solutions/small-businesses | Mid-market https://evidr.com/solutions/midmarket | Enterprise https://evidr.com/solutions/enterprise | Healthcare https://evidr.com/solutions/healthcare | Government contractors https://evidr.com/solutions/government ## Guides (https://evidr.com/blog) Long-form, vendor-neutral guides written for engineers and founders. Facts come from the standards themselves (AICPA Trust Services Criteria, ISO/IEC 27001:2022, 45 CFR Parts 160 and 164). - SOC 2 compliance: the five Trust Services Criteria, Type I vs Type II, the evidence auditors request, timeline and cost. https://evidr.com/blog/soc-2-compliance - SOC 2 audit, what to know before hiring an auditor: choosing a CPA firm, an interactive pre-engagement checklist, the prep timeline, how sampling works, what an exception means. https://evidr.com/blog/soc-2-audit - ISO 27001 certification: the ISMS and Clauses 4-10, the 93 Annex A controls by theme, the Statement of Applicability, Stage 1 and Stage 2, the three-year surveillance cycle. https://evidr.com/blog/iso-27001-certification - HIPAA compliance checklist: an interactive checklist covering all four HIPAA rules with CFR citations, every safeguard marked required or addressable, plus Privacy, Breach Notification and the six-year retention rule. https://evidr.com/blog/hipaa-compliance-checklist - Best SOC 2 compliance software for 2027: a side-by-side comparison of Evidr, Vanta, Drata, Secureframe and Sprinto on pricing model, framework economics, support and automation. https://evidr.com/blog/best-soc-2-compliance-software - GRC software: the difference between enterprise GRC platforms and compliance automation, and how to tell which you need. https://evidr.com/blog/grc-software - Vanta vs Drata: a comparison framework, including the fact that neither publishes pricing, and where Evidr fits. https://evidr.com/blog/vanta-vs-drata - HIPAA compliance software: what it does and cannot do, mapped to 45 CFR Part 164, why HHS recognises no HIPAA certification, why the vendor is usually a business associate, and the free HHS Security Risk Assessment Tool. https://evidr.com/blog/hipaa-compliance-software - Vendor risk management software: the vendor requirements in SOC 2 CC9.2, ISO 27001 A.5.19 to A.5.22 and HIPAA 164.308(b)(1), the five-stage life cycle from the 2023 interagency guidance, vendor tiering, and what no tool can do. https://evidr.com/blog/vendor-risk-management-software ## Company and security Security: https://evidr.com/security (AES-256 at rest, TLS in transit, AWS us-east-1, read-only integrations, responsible disclosure at security@evidr.com). About: https://evidr.com/about. Careers: https://evidr.com/careers. Privacy: https://evidr.com/privacy. Terms: https://evidr.com/terms. Compliance checklist guide: https://evidr.com/resources/compliance-checklist. Okta setup guide: https://evidr.com/integrations/okta.