Pricing

Simple, transparent pricing for compliance automation.

Every plan includes all 14 compliance frameworks, vendor risk management and continuous monitoring. AI usage follows each plan's feature gates and is billed separately as pay-as-you-go. No hidden fees. No per-framework charges. Start free and scale as your programme grows.

Growth

$499/ mo, billed annually

For small teams getting serious about compliance. Evidence collection, policy automation, continuous monitoring, and device security, all included.

Get started

Every framework and every tool, including:

  • All frameworks, including custom
  • Evidence collection and AI review
  • Screenshots, in-browser capture
  • AI Assistant (Ask Sam)
  • Policy generation, 50 docs / mo
  • Continuous monitoring, AWS, Azure, GCP, M365, GitHub +14 more
  • Device monitoring, 10 devices
  • Code Stack, AI ecosystem vuln monitoring
  • Penetration test evidence tracker
  • Access reviews with AI risk analysis
  • Vendor risk management with AI scoring
  • Up to 5 team members & auditors
  • Custom domain trust page
  • IP allowlisting, audit export

Professional

$899/ mo, billed annually

For teams actively pursuing SOC 2, ISO 27001, or HIPAA certification with full evidence collection, policy automation, and infrastructure monitoring.

Get started

Everything in Growth, plus:

  • Policy generation, 200 docs / mo
  • Continuous monitoring, 5 connections per platform
  • Device monitoring, 25 devices
  • Evidence uploads, 25 MB max
  • Up to 10 team members & auditors
  • Up to 20 custom vendors
  • Higher AI vendor assessment limit

Enterprise

$1,199/ mo, billed annually

For organizations managing multiple compliance frameworks at scale with dedicated support, unlimited device monitoring, and continuous infrastructure scanning.

Get started

Everything in Professional, plus:

  • 2 compliance workspaces
  • Policy generation, 500 docs / mo
  • Continuous monitoring, 10 connections per platform
  • Device monitoring, unlimited devices
  • Evidence uploads, 50 MB max
  • Up to 100 custom vendors
  • Up to 50 team members & auditors
  • Custom audit retention up to 7 years
  • Dedicated support

Custom

For several workspaces, higher limits or your own SLA.

Need more workspaces, higher limits, dedicated support, or custom SLAs? We build plans around your requirements.

Prices in USD, billed annually, with no contract and no per-framework charges. AI usage is metered separately as pay-as-you-go. There is a 14-day money-back guarantee, and you can cancel from the billing screen.Compare every feature

01AI usage

AI is metered, not bundled.

AI features follow your plan. The tokens they use are billed separately, only in months you use them.

Pay as you go

AI usage calculator

Evidence review, policy generation, evidence documents and the assistant are billed on tokens used, separately from the plan. No usage, no charge. A $1.00 minimum applies to months with usage.

Estimated monthly$2.317.0M tokens
Input
$0.20/1M
Output
$0.60/1M
Evidence reviewsAI-powered evidence review with confidence scoring · ~40-page evidence PDF
20$1.40/mo
Policy generationGenerate full compliance policies from framework requirements · 1 policy document
5$0.27/mo
Evidence generationGenerate evidence documents and audit artifacts · 1 evidence document
10$0.35/mo
Access reviewsAI risk analysis on user access and entitlements · 1 access review batch
5$0.11/mo
Remediation guidanceAI-guided remediation steps for failing security checks · 1 remediation session
10$0.05/mo
Chat messagesAsk Sam compliance questions, get guidance, or summaries · 1 message + response
100$0.13/mo

02Included in every plan

All frameworks. Full coverage.

From SOC 2 and ISO 27001 to HIPAA, GDPR, PCI DSS, FedRAMP and the EU AI Act. No per-framework charges.

Security & Trust

  • SOC 2 Type IPoint-in-time security controls assessment
  • SOC 2 Type IIContinuous security controls over a defined period
  • HIPAAProtected health information safeguards
  • PCI DSSPayment card data protection standard

International Standards

  • ISO 27001Information security management system
  • ISO 42001Artificial intelligence management system
  • GDPREuropean data protection regulation
  • CCPACalifornia consumer privacy rights

Government & AI Governance

  • FedRAMPU.S. federal cloud security authorization
  • HITRUSTHealthcare information trust certification
  • NIST AI RMFAI risk management framework
  • EU AI ActEuropean AI regulatory compliance

03Plan details

Compare every feature.

FeatureGrowthProfessionalEnterpriseCustom
SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, FedRAMP, HITRUST, CCPA, ISO 42001, NIST AI RMF, EU AI Act, and custom frameworksEvidr ships with pre-built control mappings for every major compliance framework. Each framework comes with its own checklist of requirements, mapped controls, and evidence expectations. You can also create fully custom frameworks for internal standards or niche regulations specific to your industry or region.
AI-driven framework selection based on your risk profileDuring onboarding, Evidr analyzes your industry, geography, data types, and customer base to recommend the exact frameworks you need. No more guessing whether you need SOC 2 or ISO 27001 first, the system prioritizes based on your actual risk exposure and business requirements.
Auto-generated control checklists mapped to each frameworkFor every framework you activate, Evidr automatically generates a structured checklist of controls you need to satisfy. Each control is mapped to specific requirements within the framework, so you always know exactly what evidence and policies are needed to pass an audit.
Real-time readiness scoring per frameworkA live percentage score tracks how close you are to full compliance for each framework. The score updates in real-time as you upload evidence, approve policies, and complete controls, giving you an honest snapshot of audit readiness at any moment.
Instant audit-ready detection across your entire programEvidr continuously evaluates your compliance posture across all active frameworks. The moment every control is satisfied, evidence uploaded, policies approved, risks addressed, the system flags your program as audit-ready so you can confidently engage your auditor.
Custom frameworks for regional and industry-specific regulationsBuild your own framework from scratch with custom categories, controls, and evidence requirements. This is ideal for internal security policies, industry-specific regulations (e.g. DORA, NIS2), or contractual obligations from enterprise customers that don't map to a standard framework.
Isolated compliance workspacesEach workspace is a completely separate compliance environment with its own frameworks, evidence, policies, vendors, and team members. Enterprise plans include 2 workspaces, ideal for organizations managing compliance across multiple business units, subsidiaries, or product lines.112Custom
Conversational setup that learns your business in minutesInstead of filling out static forms, Evidr uses a conversational AI flow that asks intelligent follow-up questions to understand your business. It adapts in real-time based on your answers, covering your industry, data handling practices, team size, and regulatory landscape in under 5 minutes.
Deep-dive profiling across 60+ risk and regulatory signalsThe onboarding process evaluates over 60 distinct signals including your industry vertical, geographic footprint, data classification levels, customer types (B2B vs B2C), payment processing, healthcare data handling, cloud infrastructure, and more, building a comprehensive risk profile that drives every recommendation.
Automated company profile generationBased on your onboarding conversation, Evidr generates a complete company profile that includes your industry classification, compliance scope, data handling practices, infrastructure overview, and organizational risk appetite. This profile informs AI recommendations throughout the platform.
Tailored framework recommendations from day oneThe AI analyzes your company profile and risk signals to recommend exactly which compliance frameworks to pursue and in what order. Recommendations are prioritized by business impact, for example, suggesting SOC 2 first if you're selling to enterprise customers, or HIPAA if you handle protected health information.
Natural language compliance guidanceAsk Sam, Evidr's AI compliance assistant, any compliance question in plain English. It understands the nuances of SOC 2, ISO 27001, HIPAA, and other frameworks, and responds with actionable guidance specific to your situation, no need to parse dense regulatory documents yourself.
Evidence upload recommendations per controlFor every control in your checklist, Sam can explain exactly what type of evidence an auditor expects to see, provide examples of acceptable documents, and suggest the fastest way to obtain that evidence from your existing tools and processes.
On-demand compliance posture summariesAsk Sam for a summary of where you stand. It analyzes your current evidence, policies, and open gaps across all frameworks and generates a clear, executive-ready overview of your compliance posture, including what's complete, what's at risk, and what to prioritize next.
Personalized answers informed by your company profile and frameworksSam doesn't give generic answers. Every response is informed by your specific company profile, active frameworks, uploaded evidence, and compliance history. When you ask "What do I need for access control?", Sam answers based on your actual framework requirements and what you've already done.
Prioritized next steps to close compliance gapsSam identifies your most critical open gaps across all frameworks and generates a prioritized action list. It considers control dependencies, audit timelines, and effort level to recommend the most impactful actions you can take right now to move the needle on readiness.
Sam daily messagesEvery plan includes generous daily messaging with Sam, Evidr's AI compliance assistant.
AI-generated evidence documents with conversational context gatheringTell Sam what you need, for example, "Generate an incident response plan", and it asks targeted follow-up questions about your team structure, escalation paths, and tools. Then it produces a complete, audit-ready document tailored to your organization, ready for review and approval.
Conversation memory with NLP-powered context recallSam remembers previous conversations and can recall context from past interactions. If you discussed your backup strategy last week, Sam can reference that conversation when you ask about disaster recovery, maintaining continuity across sessions instead of starting from scratch.
AI-powered evidence review with confidence scoringWhen you upload evidence, Evidr's AI reviews the document against the specific control requirement it's mapped to. It provides a confidence score (0-100%) indicating how well the evidence satisfies the control, flags potential issues, and explains its reasoning, so you know before your auditor does.
AI evidence reviews per monthThe monthly cap on automated AI evidence reviews. Current standard plans with evidence collection have no monthly hard cap for evidence review.
Automated sensitive data and credential detectionEvery uploaded file is automatically scanned for sensitive data including API keys, passwords, private keys, access tokens, and personally identifiable information. If detected, the upload is flagged immediately, preventing accidental exposure of credentials in your compliance evidence.
One-click evidence approval workflowsTeam members can upload evidence, and workspace owners or designated reviewers can approve or reject it with a single click. Rejected evidence includes review notes explaining what needs to change, creating a clear feedback loop that accelerates the evidence collection process.
Complete version history with per-requirement audit trailEvery evidence upload, approval, rejection, and replacement is logged with timestamps, user attribution, and version numbers. For each control requirement, you can see the complete history of evidence changes, exactly what auditors need to verify the integrity of your compliance program.
AI-generated review notes on every submissionWhen evidence is uploaded, the AI automatically generates detailed review notes summarizing what the document contains, how it maps to the control, and any potential concerns. These notes help reviewers make faster, more informed approval decisions without reading every document end-to-end.
AI evidence documents per monthThe monthly cap on AI-generated evidence documents. Current standard plans with evidence collection have no monthly hard cap for evidence document generation.
Automatic document classification and taggingEvidr's AI automatically classifies uploaded documents by type (policy, screenshot, configuration export, report, etc.) and applies relevant tags. This makes evidence searchable and organized without manual effort, and helps auditors quickly find what they need during review.
Malware scanning and file integrity validationEvery uploaded file undergoes malware scanning before being stored. Files are validated for integrity to ensure they haven't been tampered with. This security layer protects your compliance repository from compromised files and satisfies security controls around data integrity.
Evidence uploads per monthUpload evidence files to your compliance controls each month. All paid plans include generous upload limits.
Max file size per uploadThe maximum size for a single evidence file upload. Growth plans support files up to 20 MB, Professional supports 25 MB, and Enterprise supports 50 MB.20 MB25 MB50 MBCustom

04Questions

Common questions.

Ready to scale your compliance programme?

Talk to our team about Enterprise deployment, custom frameworks and dedicated support.