The Trust Operations Platform — compliance automation that doesn’t stop at SOC 2. See how it opens deals →
Home  /  Pricing
● One platform · priced to your size

The whole platform. Priced to fit your size.

Every plan is the Trust Operations Platform — compliance automation, vendor risk, privacy operations, and a customer-facing Trust Center on one data model. Plans differ by the depth of modules and the level of support, not by which part of the platform you get.

Growth
For mid-market teams standing up SOC 2 readiness and a trust program for the first time.
Talk to us
Scales with your portfolio
  • SOC 2 Type II readiness engagement
  • LiveThreat scorecards & continuous monitoring
  • QFX assessments with auto-scoring
  • Cross-framework propagation
  • TrustMark+ Trust Center, live day one
  • Employee & vendor self-service portals
Get started →
Scale
For growing teams running compliance, privacy, and vendor risk as one program.
Talk to us
Scales with your portfolio
  • Everything in Growth, plus:
  • Internal Controls Assessment (ICA)
  • Policy management & workforce training
  • Diligence Certificates & Audit Packet
  • Full PrivacyOps: DSAR, RoPA, CookiePLUS consent
  • Breach Watch & Outlook vendor-risk cards
  • API, outbound connectors, Compliance Pack export
Get started →
Enterprise
For regulated organizations that need enterprise identity, scale, and dedicated support.
Talk to us
Tailored to your environment
  • Everything in Scale, plus:
  • Enterprise Risk Management (KRI, risk appetite, 3 lines)
  • M&A cyber diligence & watermarked deal rooms
  • Enterprise SSO + SCIM & Conditional Access
  • SBOM ingestion & supply-chain monitoring
  • Power BI, SharePoint, ServiceNow module routing
  • Dedicated support & custom integrations
Contact sales →

Every plan onboards in under 12 hours — no professional-services contract, no consultant hand-holding. Want to try it first? Start free, no credit card →

One platform vs. a stack of point tools

The capabilities that only line up on one data model.

To match Verisq, most teams buy a compliance tool and a privacy tool — then pay to stitch them together, and still can't unify the audit trail. Here's where the lines actually fall.

Capability Verisq AITrust Operations Platform Compliance-onlySOC 2 / framework tools Privacy-onlyConsent / DSAR tools
Compliance & audit readiness
SOC 2 Type II readiness with three-tier ownership (Control / Evidence / Task)
Pre-seeded Trust Service Criteria catalog with auditor read-only accessVaries
Cross-framework propagation — one evidence item satisfies many frameworksVaries
Internal Controls Assessment (SOX-style quarterly attestation, COSO/ITGC)Rare
Per-control walkthrough notes, sample selection & test resultsVaries
Auto-issued Diligence Certificates with embedded framework mappings
One-PDF Audit Packet — certificates, coverage matrix, evidence indexPartial
Per-framework coverage matrix with gap analysis & remediation pathsVaries
Vendor & supply-chain risk
TPRM register with QFX assessments & AI auto-scoringAdd-on
Live breach intelligence — vendor breaches surfaced as they happen
SBOM ingestion & continuous CVE matchingRare
Automated SOC 2 / CUEC extraction from vendor reportsRare
Branded vendor portal with digital-signature submissionVaries
Multi-cloud config scanning (AWS / Azure / GCP / OCI)Varies
Fourth-party / sub-contractor nested risk mapping
Privacy operations
End-to-end DSAR fulfillment with SLA tracking & vendor sub-requests
No-account public privacy center (regulator-aligned intake)Varies
Article 30 RoPA generation from a live datastore catalogVaries
CookiePLUS consent with hash-chained, tamper-evident receiptsLogs only
IAB TCF 2.3, GPC & GPP signal handling
Consent & DSAR share one backend — single chain of custodyStitched
Compliant marketing list scrubbing with per-removal audit trailRare
Data Protection Impact Assessments (DPIA) via employee portalVaries
Enterprise risk & deals
Enterprise Risk Management — all risk signals land natively, not via integration
Continuous risk telemetry — inherent scores move with the threat landscape
KRI framework with thresholds & three-lines-of-defence roles
M&A cyber diligence workspace with NIST CSF maturity scoring
Watermarked Data Room with scoped external access & audit trail
Risk-acceptance gates with expiry & board-level approval workflowRare
Workforce & policy
Versioned policy library with binding, re-triggered acknowledgementsAdd-on
Workforce awareness training tied directly to the audit packetAdd-on
Policy-to-course mapping with coverage reportingRare
Role-based training tracks (HIPAA, AI, privacy-by-design)VariesVaries
Integrations & enterprise controls
Teams Adaptive Cards & Outlook vendor-risk cards in emailRare
ServiceNow risk-type routing (AVR / SIR / GRC modules)Varies
Jira, GitHub Issues & PagerDuty finding routingVaries
Power Platform connector & Power BI risk dashboards
HMAC-signed webhooks to SIEM (Sentinel, Splunk, QRadar)Varies
Azure AD SSO + SCIM provisioning & Conditional AccessVaries
Five-layer multi-tenant isolation with per-tenant encryption keysVariesVaries
Proof & foundation
Customer-facing Trust Center, live on day oneAdd-on
QFX universal assessment engine — any subject type, any framework
Onboarded in under 12 hours — no professional-services contractVariesVaries
One data model & one audit trail across every programStitchedStitched
Frameworks supported — every tier

SOC 2 (TSC) · ISO 27001:2022 · NIST CSF 2.0 · NIST SP 800-218 (SSDF) · GDPR / UK GDPR · HIPAA Security Rule · HITRUST CSF · PCI DSS 4.0 · DORA · SWIFT CSP · OCC Third-Party Risk · FCA Outsourcing · SIG · plus custom AI-authored frameworks.

Not sure which plan is right? Talk to our team.

We'll give you a recommendation based on your compliance requirements, vendor count, and the frameworks your customers expect.