Conformiti
ProductEditionsPricing ConsultingSelf-hostDocs Security GitHub Book a demo

Editions

The core is yours.

Core is not a trial or a crippled build. It is the entire compliance programme, 217 controls, signed audit packages, single sign-on, vendor risk and the auditor portal, under the MIT licence on your hardware.

Pro and Enterprise are signed licence files that install on top and add nineteen features and 22 framework libraries. Nothing is ever taken out of the free build to create a paid one.

Core v0.9.5j · shipping Pro & Enterprise v1.1.4 · needs Core 0.9.5b or newer
Shipping · v0.9.5jMIT

Core

A team that wants to run its own compliance programme, on its own hardware, without asking anyone's permission.

Free

Free for ever. Not a trial, not a seat count, not a limited edition.

  • 217 controls: SOC 2 (61), ISO/IEC 27001:2022 (93), PCI DSS v4.0.1 (63)
  • Sealed audit packages with Ed25519 signatures and a verifiable manifest
  • Evidence library, folder grants, PBC lists, roll-forward and year-on-year diff
  • Single sign-on: OIDC and SAML 2.0 with step-up, passkeys, TOTP
  • Auditor portal, scoped to one engagement and refused everything else
  • Vendors, assessments, questionnaires by link, shared-responsibility matrices
  • Risk register, access reviews, meeting minutes, RACI, calendar, Jira
  • Slack and Teams notifications, digest email, ClamAV on upload
  • Workspaces, and the whole REST API

No account to create, no key to fetch, no telemetry to switch off. Clone it and run.

Built · v1.1.4

Enterprise

A consultancy, managed service provider or audit firm carrying a book of clients rather than one programme.

Licensed per firm

Then per client workspace. No per-seat metering on your consultants.

Everything in Pro, plus four more
  • Multi-client console: one login across every client, readiness and overdue work rolled up per client, one cross-client queue, search across the whole book, and bulk actions
  • Partner role: an explicit list of client workspaces with its own capability flags, scoped row by row. Cross-workspace access in Core means superuser, which is far too much to hand a new consultant.
  • White-label: logo, wordmark, colours, sign-in page, sender name and subject prefix, report cover and footer, custom domain, and the "powered by" line off
  • TPRM Advanced: questionnaire scoring, portfolio ranking by exposure, concentration and fourth-party analysis, and the DORA register-of-information export

Audit windows can be licensed per engagement rather than per year, when that is the honest shape.

Two promises. The free core stays free: paid features are added on top, never carved out of it. And there is no licence server and no phone-home: a licence is a signed file, and when it expires the paid features go read-only rather than locking anything away.

Pro · the anchor

A copilot that has actually
read your programme.

Every general-purpose assistant writing compliance text is working from whatever it absorbed about the standards. Ours works from the objectives, documents, risks and vendor records already sitting in your installation, and every answer lists the controls, documents, risks and vendors it was drawn from.

Four things it does

  • Drafts a policy from a framework or a set of control objectives, and files it as a draft for a human to approve.
  • Explains a gap: why this control reads as not implemented, what evidence is missing, and what an auditor will actually ask you for.
  • Maps evidence: reads a document you uploaded and proposes the controls it satisfies, with a confidence and the passage it relied on.
  • Answers questions about the programme, citing the control reference and the document by name.

Three rules it cannot break

Enforced in code, not by prompt.

  • It proposes; you commit. It may never approve a document, set a control status, or draw a conclusion.
  • It sees what you see. Retrieval is scoped to the workspace and the reader's own folder grants. Document text is indexed only for folders switched on, one at a time.
  • Your key, your model. Bring your own Anthropic, OpenAI-compatible or local key. Evidence is never proxied through us, because we would rather not be able to read it. A per-workspace daily ceiling bounds what it can spend.

Safe to publish. Conformiti's control objectives are original paraphrases we wrote, not the text of the standards, so the copilot expands our words rather than reproducing AICPA, ISO or PCI copy.

Nineteen features

Everything that is sold,
grouped the way you think about it.

Each one is built, tested and shipping in v1.1.4. None of them replaces anything the free core already does.

Evidence & fieldwork · Pro

Control testing

Test a control over an observation window and produce a workpaper that survives questioning: a population frozen with a digest when drawn, a sample anyone can re-derive from the stored seed, and sign-off by somebody who did not perform the test.

Evidence & fieldwork · Pro

Recurring evidence collection

A standing evidence requirement on a cadence: one task per period, assigned to a named person, chased before it is due and escalated when missed. The coverage grid shows every period, including the empty cells.

Evidence & fieldwork · Pro

SOC 2 Type II testing pack

61 criteria with 305 test procedures, per-criterion population and sampling guidance, common exceptions, and complementary user-entity controls on 42 of them. Read directly by the control-testing runtime rather than sitting in a PDF.

Evidence & fieldwork · Pro

Policy acknowledgement

Ask everyone to read and sign the current version of a policy, pinned to the exact document version and its digest. The record is append-only and carries the typed name, statement, timestamp and address, which is what an auditor asks for.

Evidence & fieldwork · Pro

Security-awareness training

Assign training, track completion, and keep the attestation records auditors ask for under CC1.4, ISO 27001 A.6.3, PCI DSS 12.6, NIST AT-2 and HIPAA §164.308(a)(5). Three starter courses included, or author your own.

Documents · Pro

Personal-data detection

Finds personal data in uploaded evidence: Luhn-checked payment cards, SSN with the invalid-range rules, IBAN mod-97, NINO, SIN, keys and tokens, and flags it. Detect and warn: the original file is never modified.

Documents · Pro

Masked derivatives

Generate a masked copy for the audit package, keeping the original intact and recording honestly in the manifest what was disclosed, so the package is defensible rather than quietly redacted.

Documents · Pro

E-signature

Send a policy for signature; the executed copy and its completion certificate are filed automatically as a new version, which is exactly the evidence an auditor asks for. DocuSign, Dropbox Sign, or a manual flow that needs no vendor contract at all.

Documents · Pro

Contract auto-extract

Upload a signed contract; it proposes the vendor record, the standards the counterparty is held to, and the expiry that feeds the review clock. Nothing is written until a person confirms it, and every field carries the passage it came from.

Governance · Pro

Board and executive reporting

Scheduled reporting packs with the numbers frozen at generation, so a pack re-read next year shows what the board actually saw. Shareable with a director by an expiring, revocable link that reaches nothing but that one pack.

Governance · Pro

Meeting scheduler

Create the real Teams or Google Meet invite from the governance cadence tracker, and reconcile cancellations made in the calendar. Uses the customer's own OAuth application, not ours.

Content · Pro

Policy and register seed pack

30 policies, plans, standards and procedures pre-mapped to every shipped framework, plus 12 registers: risk register, asset and vendor inventories, incident log with the statutory clocks, access-review workbook, control test schedule, DPIA, AI impact assessment, business impact analysis, ISO 27001 Statement of Applicability, GDPR Article 30 records of processing and continuity exercise records. Markdown, CSV, JSON and XLSX.

Content · Pro

Custom framework builder

Define your own controls and categories, import from CSV or XLSX, crosswalk them to the shipped libraries, and export as a portable pack. Everything else (evidence, scoring, packages, the copilot) works on them unchanged.

Multi-client · Enterprise

MSP console and partner role

One login across the whole portfolio, with readiness, overdue reviews, expiring vendor assurance and open evidence requests rolled up per client, plus search and bulk actions across the whole book. Working inside a client's own screens still needs an account on that workspace.

Multi-client · Enterprise

White-label and TPRM Advanced

Your brand on the sign-in page (rendered before anyone has authenticated), the application shell, the sender name and subject line of every message, and the board report packs. TPRM Advanced adds questionnaire scoring, portfolio ranking by exposure, concentration and fourth-party analysis, and the DORA register-of-information export.

Line by line

What each edition adds.

Core is the whole product. The paid rows are additions, never restorations of something removed.

Feature comparison of the Core, Pro and Enterprise editions
  Core
Free · MIT
Pro Enterprise
The programme: free in every edition
SOC 2 · ISO 27001 · PCI DSS libraries (217 controls)
Sealed audit packages, Ed25519 signatures, roll-forward
SSO: OIDC and SAML 2.0 with step-up, passkeys, TOTP
Auditor portal, time-boxed and scoped per package
Vendors, assessments, questionnaires, responsibility matrices
Risk register, access reviews, meetings, RACI, calendar, Jira
Slack and Teams notifications, digest email
Workspaces, and the full REST API
PeopleUnlimitedUnlimitedUnlimited
Pro: fifteen features
AI compliance copilot (bring your own model key)No
Public trust centreNo
Control testing, frozen populations and sign-offNo
Recurring evidence collection and chasingNo
SOC 2 Type II testing pack (305 procedures)No
Policy acknowledgement, pinned to a version digestNo
Security-awareness training and attestationsNo
Personal-data detection, and masked derivativesNo
E-signature for policy attestationNo
Contract auto-extractNo
Board and executive reporting, frozen at generationNo
Meeting scheduler: real Teams and Meet invitesNo
Custom frameworks (authoring, import, crosswalk, export)API only
30 policies and 12 registers, pre-mappedNo
Enterprise: four more
Multi-client console and portfolio rollupsNoNo
Partner role spanning named client workspacesNoNo
White-label: brand, domain, sender, sign-in pageNoNo
TPRM Advanced, scoring, exposure ranking, DORA registerNoNo
Client workspacesUnlimitedYour own orgLicensed per client
Content and support
Compliance packs (22 libraries, 2,158 controls, perpetual)Bought separately, perpetually, per library or as one bundle
Community support: GitHub issues and discussions
Email supportNoNext business dayNext business day
Priority support: private channel, 4 business hoursNoAdd-onIncluded

Would you rather not run the server at all? We will operate it for you, at a price that reflects what that actually costs.

Compliance packs

Three are free.
Twenty-two more, one-time fee.

SOC 2, ISO/IEC 27001:2022 and PCI DSS v4.0.1 ship in the free core, complete, for ever. Every other framework is a pack: control library, categories, crosswalk to what you already run, and testing guidance. 2,158 controls across twenty-two libraries, all built today, not a roadmap.

Packs are perpetual. A pack you buy keeps working for ever; a renewal buys newer builds of it, never continued access.

The 22 compliance packs with control counts and copyright posture
Pack Controls What it covers Copyright posture
NIST SP 800-53 Rev. 5527The catalogue by family, with SP 800-53B baselinesPublic domain
ISO/IEC 27701188Privacy information management extension to 27001Identifiers + our wording
CIS Critical Security Controls v815318 controls with implementation groupsIdentifiers + our own objectives
NIST SP 800-171 Rev. 2 / CMMC L2110All 110 requirements across 14 familiesPublic domain
NIST CSF 2.0106All six functions, including GovernPublic domain
FedRAMP Moderate90The parameter delta overlay on 800-53Public domain
PIPEDA85The ten Schedule 1 principles plus breach dutiesPublic statute (Canada)
FIPPA / MFIPPA83Ontario access and privacy, provincial and municipalPublic statute (Ontario)
HIPAA Security Rule81§164.308-318 plus Breach Notification, Required/Addressable splitPublic domain
CCCS ITSG-3378The Canadian control catalogue with the PBMM profilePublic (Govt of Canada)
DORA73Digital operational resilience for EU financePublic law (EU)
ISO/IEC 4200170AI management system, clauses 4-10 and Annex AIdentifiers + our wording
Quebec Law 2570The modernised Quebec private-sector privacy regimePublic statute (Quebec)
OSFI Guideline B-1362Technology and cyber risk for Canadian FRFIsPublic regulator guidance
GDPR59Controller and processor obligations as testable controlsPublic law (EU)
PHIPA53Ontario personal health information custodian dutiesPublic statute (Ontario)
CCPA / CPRA49Consumer rights, disclosures, service-provider termsPublic law (California)
ISO 2230147Business continuity managementIdentifiers + our wording
ISO/IEC 2701746Cloud services, including all seven CLD controlsIdentifiers + our wording
SOX ITGC45The four classic ITGC domains plus IPE and EUCOriginal work
ISO/IEC 2701843PII in public clouds, for a processorIdentifiers + our wording
NIS240The EU network and information security directivePublic law (EU)

One pack

One library

Installed into your library and crosswalked to the frameworks you already run, so evidence mapped to SOC 2 satisfies the new set without re-uploading a file.

A bundle

A themed bundle

Privacy (GDPR, CCPA/CPRA, ISO 27701), EU resilience (DORA, NIS2, ISO 22301), NIST (800-53 with the FedRAMP overlay), or CSF with CIS.

All twenty-two

All twenty-two

Every library in the build, perpetual, with newer builds for as long as you keep maintenance. 2,158 controls.

The copyright position. Public law and public-sector guidance are rendered faithfully. ISO standards are not redistributed: those packs ship clause identifiers and titles with our own objective wording, and you must hold a licence for the standard itself. CIS is the same, being CC BY-NC-ND.

How the paid editions work

Your licence is a file,
not a login.

There is no licence server, no activation call and no seat check phoning home, because the product promises there is no telemetry and we are not going to break that promise to protect a subscription.

Installing Pro onto an existing checkout
$ python install.py --check --target /srv/conformiti
   493 backend files and 29 SPA files would be copied
   3 SPA anchors found, all unpatched
   compose + environment diff printed
   32 migrations would run · nothing written

$ python install.py --target /srv/conformiti --license acme.json
   archive checksums and Ed25519 signature verified
   installed · pro_doctor: all checks pass

$ python install.py license --show
  /srv/conformiti/pro/license.json
  state   active
  expires 2027-10-01 (379 days)

Licence in force
  -> the licence file on disk
       state   active
       expires 2027-10-01 (379 days)

$ python manage.py pro_license --features
  Licensed to   Northwind Traders Ltd
  Plan          pro
  Workspaces    northwind, northwind-eu
  Expires       2027-10-01
  Features      copilot yes, trust yes, ...
  • Rehearse it first. --check prints the two trees it would copy, the patch state of each anchor with the exact diff, the compose and environment changes as a diff, and the migrations that would run, writing nothing.
  • The package verifies itself. Checksums and an Ed25519 release signature are checked against a pinned key before a single byte is copied.
  • It checks its own work. The install ends by running pro_doctor, which fails loudly rather than leaving a half-installed platform.
  • Deployment state is backed up: the licence, the manifest, the environment shims, the compose override and the pre-patch hashes, which your volume backup cannot see.
  • Upgrades are rehearsable and rollback goes back more than one version.
  • Windows and air-gapped installs are first-class: the installer writes a service script and a Task Scheduler job for Windows hosts, and --offline checks every prerequisite up front.
  • Uninstalling is supported, reverses every patch, and leaves the MIT checkout as it was (only pro/, which holds your licence, is kept): verified by a gate that hashes every file in the core checkout, about 1,500 of them, before and after.

Objections, answered

The awkward questions.

Will you move free features into a paid edition later?

No, and the MIT licence means we could not make it stick if we tried. Everything released under MIT stays MIT. You can fork the last free commit and carry on. Paid features are additions written afterwards, in a separate package that installs on top.

What happens when my licence expires?

The paid features go read-only and Core carries on exactly as before. Nothing is deleted, nothing is locked, and your evidence, packages and signatures are untouched. They are Core data and always were.

Do you see my evidence if I buy Pro?

No. Pro is a package on your server with a signed file next to it. There is no callback, no usage report and no proxy. The copilot talks to your model provider using your key, from your network.

Is the copilot going to write my policies for me?

It writes the draft. It cannot approve one, set a control status, or reach a conclusion: refused at the code level, not by prompt. An auditor asking who owns the policy needs a person's name, and the workflow makes sure there is one.

Why is third-party risk not in the paid tier?

Because vendors, tiering, assurance posture, SOC and ISO tracking with validity windows, responsibility matrices and the questionnaire sent by link are already free in the core. TPRM Advanced is the tier above, scoring, exposure ranking, fourth-party analysis, DORA, and the name says so.

Can I check the licence verifier myself?

Yes. It is a few dozen lines of Ed25519 signature checking against a public key in the build, with no network path in it. That is deliberate: a licence check that phoned home would contradict the promise the product is sold on.

Do I have to buy packs to use Pro?

No. Pro works on the three free libraries, and on any framework you build yourself with the custom framework builder. Packs are separate, perpetual, and bought only when you need that standard.

Can you run the programme for us?

Yes. Our consulting practice builds the whole management system: scope, risk method, Statement of Applicability, policy suite, internal audit and the first management review. We collect the evidence inside your organisation and hand over on an agreed date.

Start with the free one.

Install Core, load your evidence, seal a package and hand it to someone. If it holds up, Pro is a file away, and if it does not, you have lost an afternoon rather than a year of licence fees.

Questions about editions, packs or the partner programme go to sales@conformiti.app.