Foundation
Core
For teams that want to organize controls, evidence, and risks without a program that is difficult to operate.
- GRC Workspace
- Controls and Evidence
- Risk register
- Policies and documents
- Basic Trust Center
- Standard support
ZebraByte Plans
We don’t use generic pricing for organizations with different needs. Choose the capability level and we scope the quote to your company, frameworks, integrations, and service level.
Foundation
For teams that want to organize controls, evidence, and risks without a program that is difficult to operate.
Automation
For growing companies that need automation, integrations, and continuous audit readiness.
Recommended
For organizations running multiple frameworks that want operations, audit, and security in one program.
Custom scope
For complex organizations that need architecture, governance, integration, and support adapted to their environment.
Organisations featured in the platform reference library
Compare capabilities
Exact capabilities and final scope are confirmed in the quote. The table is a commercial guide for choosing the right level.
| Capability | Core Core | Growth Growth | Professional Pro | Enterprise Ent. |
|---|---|---|---|---|
| Compliance workspace | ||||
| Controls, measures and evidence | ||||
| Policies and documents | ||||
| Risk register | ||||
| Asset inventory | Basic | |||
| People & access reviews | — | |||
| Vendor management | — | |||
| Automations and workflows | — |
| Capability | Core Core | Growth Growth | Professional Pro | Enterprise Ent. |
|---|---|---|---|---|
| SOC 2 readiness | ||||
| ISO/IEC 27001 | Optional | |||
| GDPR / Privacy | Optional | |||
| NIS2 | Optional | Optional | ||
| Multiple frameworks | — | Limited | ||
| Audit workspace & findings | — | Basic | ||
| Evidence packages | — | |||
| Trust Center | Basic | Custom |
| Capability | Core Core | Growth Growth | Professional Pro | Enterprise Ent. |
|---|---|---|---|---|
| SaaS / identity integrations | Basic | |||
| Cloud security posture | — | Optional | ||
| Device security | — | Optional | ||
| Security assessments | Optional | Optional | ||
| Penetration testing | Optional | Optional | Optional | |
| API, webhooks and MCP | Basic | |||
| SSO / provisioning | — | — | Optional |
| Capability | Core Core | Growth Growth | Professional Pro | Enterprise Ent. |
|---|---|---|---|---|
| Onboarding ghidat | ||||
| Support | Standard | Prioritar | Prioritar | Dedicat |
| Managed compliance | Optional | Optional | ||
| Coordonare audit | Optional | Optional | ||
| Remediation programme | — | Optional | ||
| Custom SLA | — | — | — | |
| Rollout multi-entity | — | — | — |
Optional modules
Modules are scoped in the same quote, without a separate price catalogue that does not reflect the real scope.
Available in your quote
Ongoing programme operations: controls, evidence, policies, remediation and audit coordination.
Available in your quote
Authorized testing for applications, API s and infrastructure, with findings and a remediation plan.
Available in your quote
Readiness, triage, containment, remediation and recovery for incidents that require a coordinated response.
Available in your quote
Controlled access to documents, NDAs, buyer security review content and trust workflows.
Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.