Transparent pricing for regulated organizations.
Three tiers designed around compliance maturity. Every plan includes customer-hosted Azure deployment: your data never leaves your environment.
Basic
Replace spreadsheet-driven audit prep with continuous evidence collection. One framework to start, expand when you are ready.
Pays for itself when you replace one consultant engagement or one full-quarter readiness sprint.
- 1 framework (NIST CSF, SOC 2, or ISO)
- Core control library + evidence mapping
- Microsoft Entra + Defender integration
- Quarterly posture reports
- Self-serve + email support
- Deployed in your Azure tenant
Foundational
Run continuous compliance across all frameworks. Evidence collected automatically from your Microsoft security stack.
Pays for itself when you compress one cross-framework audit cycle or recover two questionnaire-driven deal slips.
- All frameworks
- Full Microsoft Security integration
- Continuous evidence collection + validation
- Sensei AI Advisor assistance
- Vendor risk management module
- NIST AI RMF + EU AI Act readiness basics
- Monthly executive reports + risk dashboards
- Dedicated CSM + quarterly business reviews
Enterprise
For multi-entity, multi-framework enterprises requiring full AI governance, ISO 42001 implementation, and external-proof capabilities.
Pays for itself when one regulatory finding is avoided or one major customer's procurement timeline is compressed by a quarter.
- Unlimited frameworks + full AI governance
- Multi-entity / multi-subsidiary support
- Insurer + auditor evidence packs
- Board-ready risk quantification dashboards
- Full ISO 42001 + EU AI Act conformity
- MSSP/partner white-label option
- Premium SLA + named engineer
- Custom integrations + API access
Everything included at a glance.
| Feature | Basic | Foundational | Enterprise |
|---|---|---|---|
| Frameworks | 1 | All frameworks | Unlimited |
| Custom controls | |||
| Microsoft integrations | Entra + Defender | Full stack + AWS, GCP | Full stack + custom |
| Evidence collection | Manual + guided | Continuous automated | Continuous automated |
| Sensei AI Advisor | Limited | ||
| AI governance | NIST AI RMF basics | Full: NIST AI RMF, EU AI Act, ISO 42001 | |
| Risk management | Basic | ||
| Vendor risk management | Basic | ||
| Trust Center | |||
| Multi-entity support | Limited | ||
| Reporting | Quarterly | Monthly | Real-time dashboards |
| Support | Self-serve + email | Dedicated CSM | Premium SLA + named engineer |
| Deployment | Your Azure tenant | Your Azure tenant | Your Azure tenant |
How Kyūdō compares to the status quo.
Ranges sourced from publicly available pricing and industry benchmarks. Use the ROI calculator for your own numbers.
| Alternative | Annual cost | Tradeoff |
|---|---|---|
| Big-4 SOC 2 + ISO 27001 prep | $80K–$150K/yr | Time-bounded, no continuous coverage |
| GRC (SaaS) Platforms | $60K–$90K/yr | Multi-tenant SaaS, your data leaves your tenant |
| In-house GRC analyst (1 FTE) | $90K–$140K/yr | Headcount scales linearly with framework count |
| Kyūdō Foundational tier | — | Customer-hosted Azure. All frameworks. Continuous. |
Frequently asked.
Kyūdō uses a simple, all-inclusive commercial model. Every module (GRC, evidence, third-party and vendor risk, risk management, AI governance, policy, and the Trust Center) is included together rather than sold as separate SKUs or gated behind higher tiers. Pricing does not depend on the number of users, and there is no per-framework charge or cap on how many of the 80+ supported frameworks you activate. For figures matched to your deployment scope, contact the Kyūdō team.
All modules are included. GRC and controls, evidence automation, third-party and vendor risk management, enterprise risk management, AI governance, policy management, and the Trust Center come together in one platform, not as add-ons or premium tiers. This is deliberate: because everything runs on one Compliance Graph, separating capabilities into SKUs would break the shared context that makes the platform work. You get the full system from the start.
No. Kyūdō does not charge per user or per seat, so adding people to the platform does not increase the price. Your entire compliance, security, audit, and risk team can use Kyūdō, along with stakeholders who only need reporting or Trust Center access, without seat-based cost. This reflects the platform's purpose: compliance is an organization-wide responsibility, and pricing that penalized participation would work against continuous, shared readiness.
No. Kyūdō does not charge per framework and does not cap how many you can use. You can activate as many of the 80+ supported frameworks as you need at no additional per-framework cost. This follows directly from the architecture: controls are defined once and mapped across frameworks through the Secure Controls Framework crosswalk, so adding a framework reuses existing controls and evidence rather than creating separate work to bill for.
Kyūdō's model is structurally different from compliance tools that charge per seat and per framework. Where those models raise the price as you add users or turn on more frameworks, Kyūdō includes all modules and all activated frameworks under one charge, with no per-seat fee. The difference comes from architecture: one control set mapped across frameworks via the Secure Controls Framework crosswalk means more frameworks reuse the same work, so charging incrementally for them would contradict how the platform operates.
Because Kyūdō deploys through the Azure Managed Application model inside your tenant, it is designed to align with Azure-native procurement. Whether Kyūdō billing can count toward your Microsoft Azure Consumption Commitment (MACC) depends on the listing and contract path, which the Kyūdō team confirms directly. If MACC drawdown matters to your procurement, raise it during the architecture briefing so the right purchasing route is set up.
Kyūdō is delivered as an annual engagement, reflecting that customer-hosted deployment provisions dedicated infrastructure in your Azure tenant and that compliance is a continuous, year-round program rather than a one-time project. Specific contract terms and minimums are confirmed with the Kyūdō team for your scope, and your controls and evidence remain inside your tenant throughout.
Ready to see governance that runs continuously?
Deploy Kyūdō inside your Azure tenant. See your first compliance report in 24 hours.
