Simple, transparent pricing
From free diagnostic to full Enterprise with SSO + API. 7-21× cheaper than Vanta/Drata. Billed in EUR.
All plans include: 🇪🇺 EU-only hosting · French + English UI · German coming Q2 2026
Discovery
- Free GRC diagnostic (25 questions, 8 domains)
- Kyrionn Trust Score™
- Basic security scan (SSL, headers, DNS)
- Read-only access to ISO 27001 / NIS2 / GDPR modules
- Community support
Starter
- Everything in Discovery
- 2 AI-generated documents per month
- Policies library (5 templates)
- 1 domain security scan
- Email support 48h
Pro
- Everything in Starter
- 10 AI documents / month
- 25+ policy templates
- Risk register (ISO 27005 / EBIOS RM)
- 3 security scans
- Email support 24h
Compliance
- Everything in Pro
- 25 AI documents / month
- ISO 27001:2022 + ISO 27002 enriched (COFRAC-ready)
- NIS2 + GDPR native + multi-framework mapping
- EBIOS RM v1.5 ANSSI complete
- AI Act module · HDS module
- Incident management (NIS2 72h notification)
- Supplier management + evidence vault
- 5 security scans
- Integrations: GitHub + Google Workspace + M365 + Okta + AWS + Jira + Slack
Expert
- Everything in Compliance
- 50 AI documents / month
- DORA (5 pillars) · SOC 2 Type II
- Public REST API + OpenAPI + Swagger UI
- vCISO multi-organization dashboard
- Custom report builder + C-level dashboard
- Unlimited security scans
- Dedicated senior support 4h response
Frequently Asked Questions
Do you charge in USD?
No. All plans are billed in EUR to avoid currency exposure. Stripe handles conversion for US cards.
Is my data stored in the US?
No. 100% EU. Supabase Frankfurt + Hetzner Germany. GDPR compliant, Schrems II safe. OVH SecNumCloud qualified infrastructure available on Enterprise plan.
Can I get SOC 2 Type II with Kyrionn?
Yes. Expert plan includes the SOC 2 Type II module with 35+ AICPA controls, automatic mapping to ISO 27001, and support for all major CPA audit firms (A-LIGN, Schellman, Prescient, Big 4).
Do you integrate with Okta?
Yes. We also integrate with Microsoft Entra ID (formerly Azure AD), Google Workspace, AWS, GitHub, Jira, and Slack. 32 ISO 27001 controls auto-checked.
What about SAML + SCIM for our IdP?
Included in Enterprise plan. Full SAML 2.0 + SCIM v2 support with documentation for Okta, Entra ID, Google Workspace.
Do you have an API?
Yes. Public REST API v1 with OpenAPI 3.1 spec + Swagger UI. 11 granular scopes. Rate limit 1000-10,000 req/hour. See /docs/api.
How do I cancel?
Self-service from your dashboard anytime. No questions asked. We keep your data for 30 days after cancellation (GDPR-compliant deletion).