Skip to content
FAQ

Questions, answered

The things teams ask us most about getting and staying compliant.

General

About the platform

How long until we're audit-ready?
Weeks, not quarters — you start from pre-built content and a guided path. (It depends on your starting point.)
How do you protect my compliance data?
Data is encrypted in transit and at rest, access is scoped by role, and audit trails record sensitive actions. You can export your data at any time.
Do we need a compliance team to use it?
No. It's designed for lean teams and even a single owner, with automation doing the heavy lifting.
Will it work with our stack?
It's built to integrate and automate, including with AI agents.
What frameworks does it support?
SOC 2 first, with the ability to add and map many more — ISO 27001, HIPAA, CCPA, NIS 2, GDPR, DORA, ISO 27701, ISO 42001, 21 CFR Part 11, HDS — or build your own custom framework.
Can customers see our security posture?
Yes — publish a branded trust center with NDA-gated documents on your own domain.
Where does my data live?
On our secure cloud. Enterprise customers can discuss private cloud hosting and data-residency options.
Does it replace our auditor?
No — it gets you and your evidence audit-ready; your auditor still issues the report.
Can our auditor work with us in SOC2Start?
Yes. Pro includes an auditor workspace and access so your auditor can review the evidence and controls you prepare in the platform.
Can we migrate from Vanta?
Talk to us about your current program and exports. We will scope a migration plan around the controls, evidence and framework data you already have rather than promise a one-size-fits-all import.

Pricing

About pricing

How does per-framework pricing work?
You pay for the frameworks you actively manage — SOC 2, ISO 27001, HIPAA, GDPR, NIS 2, DORA and more, or a custom framework — priced to be affordable for small companies. Add frameworks as you grow.
Is there a genuinely free option?
Yes. The Free plan remains available for 1 framework and 1 user. Every signup starts with 30 days of Pro features, then returns to the Free plan unless you upgrade.
What's the difference between Free and Pro?
Free includes 1 framework and 1 user. Pro adds continuous monitoring, the trust center, SSO and more; each framework you actively manage is billed separately.
Do you punish early-stage teams on price?
No. Transparent pricing that doesn't punish you for being early — that's the whole point.

Get audit-ready. Stay in control.

Start with one framework and one user free. Every signup includes 30 days of Pro features.

FAQ · SOC2Start.io