Logo Menu

Strike Graph SOC 2 compliance software

SOC 2 / multi-framework compliance automation platform Last updated

We previously described Strike Graph as the only platform in our set with published pricing and a free tier; the published-numbers part still holds as of 2026-07-24 (Certify $10,000/yr, Scale $21,500/yr, Enterprise $35,000/yr, all confirmed on the live pricing page).

By , Lead Editor · independently researched · Methodology

Pricing
Published, $10K–$35K/yr
Source-checked frameworks
8
Integrations
300+
G2 (2026-07-24)
4.7 · 193 reviews
What the evidence says

The "free tier" framing needs softening: the free option is a separate, lead-form-gated signup (strikegraph.com/start-for-free) capped at 15 evidence attachments and two integrations (Office 365, Google Drive), not a persistent free plan inside the Certify/Scale/Enterprise comparison table -- it reads more like a limited trial/lead magnet than a standing freemium tier of the actual compliance product. Framework add-on pricing is granular and can add up fast: a Certify customer adding ISO 27001 plus an internal audit and a penetration test could add $20K+/yr on top of the $10,000 base. The August 31 pricing recheck lists Evidence API under Enterprise; do not imply it is included at the Certify starting price.

Company context

Strike Graph has raised at least $20.4M across primary-sourced rounds: a $3.9M seed (TechCrunch, Oct 5, 2020), an $8M Series A led by Information Venture Partners (Strike Graph company blog, 2021), and an $8.5M round led by BAMCAP with Madrona and Information Venture Partners (Strike Graph company blog and Corporate Compliance Insights, both reporting the close around Dec 2023). A third-party aggregator (startupintros.com) reports a higher cumulative total of $29.5M across 5 rounds that we could not independently reconcile against primary press -- see openQuestions.

Pricing

Strike Graph publishes a price.

You can read the numbers without a sales call, which is uncommon in this category and worth weighing on its own.

Disclosure model
Published, $10K–$35K/yr
Sourced annual range
USD 10,000–35,000 / year
Basis
Confirmed, 2026-08-11

Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.

Capabilities

What Strike Graph does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes Vendor claims automated evidence collection from 300+ systems and 50,000+ data points, with scheduled refresh and an Evidence API for custom sources. Source
Auditor workspace Yes Pricing/comparison table lists a dedicated "Auditor Role" permission and full audit-workbook export across all plans; vendor states the platform works with any independent auditor the customer chooses. Source
Trust center Yes "Trust Center" and "Trust asset library" are listed as plan features; also a dedicated nav item (strikegraph.com/trust-chain area). Source
Security questionnaire answering Yes "Questionnaires" (AI-assisted response generation from implemented controls) is a paid add-on on the Certify plan and included from Scale up. Source
Enterprise admin (SSO, SCIM, RBAC) Partial Current pricing confirms Role Management from Certify, SSO on Scale and Enterprise, and Enterprise Workspaces on Enterprise. The current SCIM evidence confirms deactivation, reactivation, and IdP role mapping but does not establish account creation, so the roll-up remains partial. Source
SCIM 2.0 provisioning Not established Strike Graph's current product-update log confirms SCIM user deactivation, reactivation, and role mapping from the identity provider, but it does not establish creation of new accounts. Full lifecycle provisioning and tier inclusion remain unknown. Source
Continuous control testing Yes "Control monitoring" and "Automated Collection" are listed as included features across all three plans, and the integrations page describes evidence updating on a defined schedule rather than only at audit time. Source
Native multi-framework support Partial Vendor's own language: "New frameworks are automatically mapped to your existing controls" and the pricing page sells "Cross-framework mappings" as a named feature -- this is explicitly a crosswalk-mapping model, not independently built native control sets per framework. Source
Source-checked frameworks

8 frameworks checked individually, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Listed as a Tier 1 framework on the current pricing page; also has a dedicated SOC 2 solution page (strikegraph.com/soc2). Source
ISO 27001 Vendor-claimed Tier 2 framework; add-on pricing shown ($5k-$8k/yr depending on plan). Source
HIPAA Vendor-claimed Tier 1 framework; HIPAA certification add-on priced separately ($4k-$5k/yr). Source
GDPR Vendor-claimed Tier 1 framework. Source
ISO 27701 Vendor-claimed Tier 1 framework, pre-seeded alongside SOC 2/HIPAA/GDPR. Source
PCI DSS Vendor-claimed Tier 2 framework. Source
NIST 800-171 Vendor-claimed Tier 3 framework. Source
CCPA Vendor-claimed Tier 1 framework. Source
Auditor handoff

Who actually issues the report.

Strike Graph is compliance software, not a CPA firm, and does not issue the SOC 2 report itself. The platform states it is compatible with any independent auditor the customer already uses, and separately offers to connect customers with vetted independent auditors through its own partner network if they don't have one; audit/assessment services through that network are priced separately ($4K-$8K/yr per the pricing FAQ).

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Strike Graph is for, and who it is not.

Good fit

A company that wants to see real dollar figures before a sales call: Strike Graph is one of the few vendors in this set that puts specific starting prices ($10,000 / $21,500 / $35,000 per year) and most framework add-on costs directly on its public pricing page.

Poor fit

A pre-revenue or bootstrapped startup with no live deal forcing SOC 2 right now should not commit to a paid plan yet -- the cheapest published tier (Certify) still starts at $10,000/year, and several core AI/questionnaire features are reserved for the $21,500/year Scale tier and above.

Typical buyer: Growth-stage SaaS/tech companies that need SOC 2 plus one or more adjacent frameworks (HIPAA, ISO 27001, GDPR) and want a single platform with published, plan-based pricing..

Related profiles

Compare Strike Graph with three alternatives.

  • Comp AI

    An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.

  • A lean first SOC 2 program needs a public platform price.

  • Published plans and bundled advisory support fit a budget-conscious buyer.

Source ledger

Where every figure on this page came from.

9 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

← All SOC 2 compliance software · How we verify

For Strike Graph

1 fact on this page we could not establish.

Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Strike Graph, send us the sources and we will fill them.

Verification is free and always will be. It does not change where Strike Graph appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.

Correct this record