Pricing · Every tier maps to whichever framework your auditor reads

One Snapshot to know where you stand. Five subscription tiers to keep you there.

Every tier maps your controls to whichever framework your auditor reads: SOC 2, PCI DSS v4.0, ISO 27001, NIST CSF, and HIPAA; GDPR and US state privacy by request. What changes across tiers is cadence (monthly to weekly), entity count (one to unlimited), and concierge level (email-only to two named contacts with a dedicated incident-response runbook). Pick the row that fits your scope and pace. Month-to-month, no long-term contract.

Monthly subscription · Annual = 10x monthly (two months free) · Fair-use terms
One-time · No subscription

Multi-Framework Readiness Snapshot™

Where do you actually stand against the framework your auditor reads, today, from your live cloud telemetry? SOC 2, PCI DSS v4.0, ISO 27001, NIST CSF, and HIPAA; GDPR and US state privacy by request. Ten-question intake plus up to five optional read-only connectors (AWS, Azure, Microsoft 365, Okta, CrowdStrike). Per-framework gap matrix PDF in your inbox within hours. $1,995 credits 100% to month-1 of any tier within 30 days.

Run my Snapshot · $1,995 →
$1,995
one-time · delivered within hours

Aegis AI™ vCISO subscription tiers

Five tiers. Same framework scope: SOC 2, PCI DSS v4.0, ISO 27001, NIST CSF, and HIPAA; GDPR and US state privacy by request. Different cadence, entity coverage, and concierge level. The $1,995 Snapshot credits to month 1 of any tier within 30 days. Annual prepay is 10× monthly, two months free.

How to size the ladder: Sentinel and Guardian deliver what most teams assemble from compliance software plus outside consulting hours, done for you, continuously. Vanguard replaces standing up an internal compliance function. Fortress and Sovereign price against headcount, not software: security-office coverage, with your executives making every call.

Sentinel
Single entity. Monthly cycle. Email support.
What it replaces: compliance software your team still has to operate.
$4,500/mo
Annual $45,000 · month-to-month flexibility
  • Map to whichever framework your auditor reads (SOC 2, PCI DSS, ISO 27001, NIST CSF, HIPAA; others by request) every cycle
  • Monthly validation cycle
  • One legal entity
  • Email support, business hours
  • Standard audit-defense exhibits
Subscribe Monthly → Annual $45,000 →
Guardian
Bi-weekly cycle. Email + chat. Quarterly board narrative.
What it replaces: a fractional security consultant’s monthly hours, delivered continuously.
$8,500/mo
Annual $85,000 · month-to-month flexibility
  • Map to whichever framework your auditor reads (SOC 2, PCI DSS, ISO 27001, NIST CSF, HIPAA; others by request) every cycle
  • Bi-weekly validation cycle
  • One legal entity
  • Email + chat support
  • Quarterly board narrative
Subscribe Monthly → Annual $85,000 →
Fortress
Weekly cycle. Up to 10 entities. Concierge SLA.
What it replaces: a full-time security hire plus the tooling around them.
$33,500/mo
Annual $335,000 · month-to-month flexibility
  • Map to whichever framework your auditor reads (SOC 2, PCI DSS, ISO 27001, NIST CSF, HIPAA; others by request), every week
  • Weekly validation cycle
  • Up to 10 legal entities
  • Concierge SLA, 15-min P0 response
  • Named escalation contact
  • Audit-defense exhibit assembly
  • Quarterly board + audit committee narrative
Subscribe Monthly → Annual $335,000 →
Sovereign
Unlimited entities. M&A-grade. Two named contacts.
What it replaces: a multi-entity security leadership layer.
$60,000/mo
Annual $600,000 · month-to-month flexibility
  • Map to whichever framework your auditor reads (SOC 2, PCI DSS, ISO 27001, NIST CSF, HIPAA; others by request), every week
  • Weekly validation cycle
  • Unlimited legal entities
  • Dedicated IR runbook
  • Two named contacts, highest priority queue
  • M&A-grade control mapping
  • Board + audit committee + ad-hoc
Subscribe Monthly → Annual $600,000 →

OFAC and Authorized Signatory certification required at checkout. Service is for organizations not subject to U.S. sanctions and signed by an officer authorized to bind the company. Custom MSA, regulated industry overlays (FedRAMP, IL5+, FINRA, HITRUST inheritance), or scopes beyond unlimited: partners@ai4ciso.ai.

Tier comparison matrix

Feature Sentinel Guardian Vanguard Fortress Sovereign
Price / month$4,500$8,500$17,000$33,500$60,000
Price / year$45,000$85,000$170,000$335,000$600,000
SOC 2 (live)
PCI DSS v4.0 (live)
ISO 27001 (live)
NIST CSF 2.0 (live)
HIPAA (live)
GDPR + US state privacy (by request*)by request*by request*by request*by request*by request*
* Live today at every tier: SOC 2, PCI DSS v4.0, ISO 27001, NIST CSF 2.0, and HIPAA. GDPR and US state privacy mappings are onboarded per engagement. Reply to agents@ai4ciso.ai with your audit timeline and we’ll confirm ETA before you commit.
Validation cycleMonthlyBi-weeklyWeeklyWeeklyWeekly
Legal entities11Up to 3Up to 10Unlimited
Support channelEmailEmail + chatEmail + chat + Slack ConnectConcierge SLAHighest priority queue
P0 response SLASame business daySame business daySame business day15 minutes15 minutes, named backup
Named contact · · Named CSMNamed escalationTwo named contacts
Audit-defense exhibit assemblyStandardStandardEnhanced
Board narrative · QuarterlyMonthlyQuarterly board + audit committeeBoard + audit committee + ad-hoc
M&A-grade control mapping · · · ·
Dedicated IR runbook · · · ·
$1,995 Snapshot credit (30 days)

Month-to-month billing

Subscriptions are monthly (or prepaid annual). Month-to-month, no long-term contract. Full billing mechanics and refund terms on the Refund Policy page.

What every tier includes

Aegis AI™ is not an auditor. SOC 2 attestations come from independent CPA firms; ISO 27001 certifications from accredited certification bodies; HIPAA from your designated assessor; PCI Reports on Compliance from independent QSAs. Aegis AI is the readiness software you use before they arrive. How each framework is covered →