Scrutineer.ai

Scrutinize any company, including your own

Pricing for Compliance and Vendor Risk, from $599 a month

Map controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collect evidence automatically, monitor continuously, and score every vendor you trust. Every plan is paid. Prices in USD.

Essentials

One framework, continuously compliant

$299 /mo

Billed monthly Billed annually ($3,588/yr), charged once a year

  • One framework (e.g. SOC 2)
  • Continuous compliance & control mapping
  • Automated evidence collection
  • Gap detection & remediation list
  • One audit-ready report
Most popular

Growth

Multi-framework, monitored continuously

$600 /mo

Billed monthly Billed annually ($7,200/yr), charged once a year

  • Multi-framework crosswalk (SOC 2 + ISO 27001 + GDPR…)
  • Continuous control monitoring
  • Security questionnaire automation
  • Audit-ready reports across frameworks
  • Priority support

Risk+ (TPRM)

Everything in Growth, plus third-party risk

$1,250 /mo

Billed monthly Billed annually ($15,000/yr), charged once a year

  • Everything in Growth
  • Unlimited vendor risk scoring
  • Continuous third-party monitoring
  • M&A & diligence reports
  • Vendor questionnaire workflows

Enterprise

Everything in Risk+, for larger organizations

$2,400 /mo

Billed monthly Billed annually ($28,800/yr), charged once a year

  • Everything in Risk+ (TPRM)
  • SSO and SCIM provisioning
  • Custom and bespoke frameworks
  • Priority support with 4-hour response
  • API access
  • Audit-firm collaboration

No per-questionnaire fees. An accredited auditor still issues your attestation; Scrutineer gets you ready and keeps you ready. Prices in USD, every plan paid, no free tier. Pick a plan and we set up your account with you. See every feature or how it works.

No free plan. See what the report looks like on the interactive Scrutiny Desk first.

Pick a framework, or a vendor, and watch Scrutineer build the report on a sample company. You see the readiness ring, the control statuses and the risk score for yourself, so you know exactly what you would be paying for. Scrutinizing your own controls and your real vendors is what a paid plan does.

What manual GRC really costs

Manual compliance and vendor reviews vs Scrutineer

Doing it by hand means a GRC analyst chasing evidence, questionnaire ping-pong that eats whole weeks, and spreadsheet vendor reviews that go stale the day they finish. A flat monthly plan turns all of that into a live, monitored posture.

A GRC analyst

$120k+ / yr

A full-time headcount chasing screenshots, updating spreadsheets and prepping audits, with the bar drifting between people and projects.

Questionnaire ping-pong

Days per deal

Security questionnaires answered by hand for every prospect, slowing deals and pulling engineers off their real work.

Scrutineer

$599-$2,500/mo flat

Controls mapped, evidence collected and monitored, questionnaires auto-answered, and vendors scored continuously. A flat monthly fee, the same posture every day.

Staying compliant Manual or point tools Scrutineer
Control mapping Per-framework spreadsheets One crosswalk across SOC 2, ISO 27001, HIPAA, GDPR, PCI
Evidence Chased manually before audit Collected automatically and kept current
Monitoring Point-in-time, goes stale Continuous, drift flagged as it happens
Questionnaires Answered by hand per deal Auto-answered from your evidence
Vendor risk Stale spreadsheet reviews Scored and monitored continuously

Swipe to see the full comparison →

Managing many vendors? See third-party risk management or vendor risk management.

On every plan

Every plan keeps you audit-ready

No matter which plan you pick, Scrutineer maps controls, collects evidence and flags gaps, and you stay in control of the decision. You only size up for more frameworks, vendor risk and scale.

Control mapping

Your existing controls mapped to the framework requirements, on every plan.

Evidence you can defend

Each control links to the current evidence that proves it, so audits hold up.

You stay in control

Scrutineer is decision-support. Your accredited auditor issues the attestation.

Your data stays yours

Evidence is yours, never sold and never used to train public models.

Control mapping · automated evidence · continuous monitoring · audit-ready reports

Pricing questions

Quick answers before you pick a plan

No. Every plan is paid, in USD, so the product stays fast and focused on enterprise security teams. The Scrutiny Desk on the homepage is an interactive walkthrough built on a worked example, not an assessment of your own environment: it shows the shape of the report you would get, using sample findings. Connecting your stack and scrutinizing your real controls is what a paid plan does.
Monthly is billed every month. Annual is charged once a year and costs half the monthly price, so you save 50%. Essentials is $299 a month billed annually ($3,588 a year) instead of $599 month to month, and Growth is $600 a month billed annually ($7,200 a year) instead of $1,200.
No. Security questionnaire automation is included on Growth and above with no per-questionnaire charge, and vendor risk scoring on Risk+ is unlimited. You size up by what you need, not by how many questionnaires land in your inbox.
No. Scrutineer is decision-support and audit readiness. It maps controls, collects evidence and flags gaps so you walk into the audit organized, but an accredited, independent auditor still issues your SOC 2, ISO 27001 or HIPAA attestation. Scrutineer gets you ready and keeps you ready.
Enterprise is everything in Risk+ (TPRM) plus SSO and SCIM provisioning, custom and bespoke frameworks, priority support with a 4-hour response, API access and audit-firm collaboration. It costs $4,800 a month, or $2,400 a month billed annually ($28,800 a year, save 50%), and you buy it by card from this page like every other plan.
Subscriptions renew automatically, monthly or annually depending on the term you choose. You can cancel at any time and move between plans as your framework and vendor count changes.

Scrutinize any company, including your own

Get started and connect your stack. Scrutineer maps controls to every framework, collects evidence automatically, monitors continuously, and scores every vendor. An accredited auditor still issues your attestation.

Compare plans

USD · Every plan paid · No per-questionnaire fees