Transparent pricing for compliance teams

Built for mid-market SaaS — not enterprise procurement, not startup starter plans.

Growth
For teams pursuing their first SOC 2 Type II
$1,200/mo
$990/mo billed annually
Up to 5 integrations · 1 framework (SOC 2 or ISO 27001) · 3 team members
  • Continuous 15-min control polling
  • SOC 2 or ISO 27001 (not both)
  • 5 integrations
  • Automated evidence packages
  • Email + Slack drift alerts
  • Standard audit-prep export
  • Email support
Request access
Enterprise
For complex compliance environments
Custom
Contact us for pricing
Unlimited integrations · Unlimited frameworks · Unlimited team members
  • Everything in Scale
  • Custom integrations via API
  • NIST CSF + additional frameworks (roadmap)
  • Dedicated customer success manager
  • Custom evidence templates
  • SSO + custom RBAC
  • MSA + BAA available
  • SLA negotiated per contract
Contact us

Common questions

No. Tenurex only stores control state metadata — the result of a control test (pass/fail) plus the timestamp and source system identifier. We do not store the underlying business data, PII, or system content. API tokens we use are scoped read-only and cannot access the actual data your systems process.
During onboarding, we provide instructions for generating read-only API tokens for each integration (e.g., AWS IAM with a custom policy granting only get/list permissions). Tenurex uses these tokens to query system state — checking things like whether MFA is enabled, who has admin access, or whether branch protection rules are configured. We never request write permissions.
Yes — the Scale plan and above supports simultaneous SOC 2 + ISO 27001 monitoring with shared evidence collection for common controls. This significantly reduces duplication: a single access review can satisfy both CC6.1 (SOC 2) and control 5.15 (ISO 27001) from one evidence record.
Most teams complete initial integration setup in 2–4 hours. We provide step-by-step integration guides for each connector. Your first control scan runs automatically after your first integration is connected. Full baseline evidence collection typically completes within 24–48 hours of connecting all integrations.
You can add integrations up to your plan's limit at any time. If you need more, contact us — we can upgrade your plan mid-cycle with prorated billing. Integration requests for systems not yet on our connector list can be submitted via the integrations page; we build common connectors on a rolling basis.