Strike Graph SOC 2 compliance software
We previously described Strike Graph as the only platform in our set with published pricing and a free tier; the published-numbers part still holds as of 2026-07-24 (Certify $10,000/yr, Scale $21,500/yr, Enterprise $35,000/yr, all confirmed on the live pricing page).
By Peter Korpak, Lead Editor · independently researched · Methodology
- Pricing
- Published, $10K–$35K/yr
- Source-checked frameworks
- 8
- Integrations
- 300+
- G2 (2026-07-24)
- 4.7 · 193 reviews
The "free tier" framing needs softening: the free option is a separate, lead-form-gated signup (strikegraph.com/start-for-free) capped at 15 evidence attachments and two integrations (Office 365, Google Drive), not a persistent free plan inside the Certify/Scale/Enterprise comparison table -- it reads more like a limited trial/lead magnet than a standing freemium tier of the actual compliance product. Framework add-on pricing is granular and can add up fast: a Certify customer adding ISO 27001 plus an internal audit and a penetration test could add $20K+/yr on top of the $10,000 base. The August 31 pricing recheck lists Evidence API under Enterprise; do not imply it is included at the Certify starting price.
Strike Graph has raised at least $20.4M across primary-sourced rounds: a $3.9M seed (TechCrunch, Oct 5, 2020), an $8M Series A led by Information Venture Partners (Strike Graph company blog, 2021), and an $8.5M round led by BAMCAP with Madrona and Information Venture Partners (Strike Graph company blog and Corporate Compliance Insights, both reporting the close around Dec 2023). A third-party aggregator (startupintros.com) reports a higher cumulative total of $29.5M across 5 rounds that we could not independently reconcile against primary press -- see openQuestions.
Strike Graph publishes a price.
You can read the numbers without a sales call, which is uncommon in this category and worth weighing on its own.
- Disclosure model
- Published, $10K–$35K/yr
- Sourced annual range
- USD 10,000–35,000 / year
- Basis
- Confirmed, 2026-08-11
Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.
What Strike Graph does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Vendor claims automated evidence collection from 300+ systems and 50,000+ data points, with scheduled refresh and an Evidence API for custom sources. Source |
| Auditor workspace | Yes | Pricing/comparison table lists a dedicated "Auditor Role" permission and full audit-workbook export across all plans; vendor states the platform works with any independent auditor the customer chooses. Source |
| Trust center | Yes | "Trust Center" and "Trust asset library" are listed as plan features; also a dedicated nav item (strikegraph.com/trust-chain area). Source |
| Security questionnaire answering | Yes | "Questionnaires" (AI-assisted response generation from implemented controls) is a paid add-on on the Certify plan and included from Scale up. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Partial | Current pricing confirms Role Management from Certify, SSO on Scale and Enterprise, and Enterprise Workspaces on Enterprise. The current SCIM evidence confirms deactivation, reactivation, and IdP role mapping but does not establish account creation, so the roll-up remains partial. Source |
| SCIM 2.0 provisioning | Not established | Strike Graph's current product-update log confirms SCIM user deactivation, reactivation, and role mapping from the identity provider, but it does not establish creation of new accounts. Full lifecycle provisioning and tier inclusion remain unknown. Source |
| Continuous control testing | Yes | "Control monitoring" and "Automated Collection" are listed as included features across all three plans, and the integrations page describes evidence updating on a defined schedule rather than only at audit time. Source |
| Native multi-framework support | Partial | Vendor's own language: "New frameworks are automatically mapped to your existing controls" and the pricing page sells "Cross-framework mappings" as a named feature -- this is explicitly a crosswalk-mapping model, not independently built native control sets per framework. Source |
8 frameworks checked individually, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Listed as a Tier 1 framework on the current pricing page; also has a dedicated SOC 2 solution page (strikegraph.com/soc2). Source |
| ISO 27001 | Vendor-claimed | Tier 2 framework; add-on pricing shown ($5k-$8k/yr depending on plan). Source |
| HIPAA | Vendor-claimed | Tier 1 framework; HIPAA certification add-on priced separately ($4k-$5k/yr). Source |
| GDPR | Vendor-claimed | Tier 1 framework. Source |
| ISO 27701 | Vendor-claimed | Tier 1 framework, pre-seeded alongside SOC 2/HIPAA/GDPR. Source |
| PCI DSS | Vendor-claimed | Tier 2 framework. Source |
| NIST 800-171 | Vendor-claimed | Tier 3 framework. Source |
| CCPA | Vendor-claimed | Tier 1 framework. Source |
Who actually issues the report.
Strike Graph is compliance software, not a CPA firm, and does not issue the SOC 2 report itself. The platform states it is compatible with any independent auditor the customer already uses, and separately offers to connect customers with vetted independent auditors through its own partner network if they don't have one; audit/assessment services through that network are priced separately ($4K-$8K/yr per the pricing FAQ).
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Strike Graph is for, and who it is not.
Good fit
A company that wants to see real dollar figures before a sales call: Strike Graph is one of the few vendors in this set that puts specific starting prices ($10,000 / $21,500 / $35,000 per year) and most framework add-on costs directly on its public pricing page.
Poor fit
A pre-revenue or bootstrapped startup with no live deal forcing SOC 2 right now should not commit to a paid plan yet -- the cheapest published tier (Certify) still starts at $10,000/year, and several core AI/questionnaire features are reserved for the $21,500/year Scale tier and above.
Typical buyer: Growth-stage SaaS/tech companies that need SOC 2 plus one or more adjacent frameworks (HIPAA, ISO 27001, GDPR) and want a single platform with published, plan-based pricing..
Compare Strike Graph with three alternatives.
- Comp AI Sponsored
An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.
-
A lean first SOC 2 program needs a public platform price.
-
Published plans and bundled advisory support fit a budget-conscious buyer.
Where every figure on this page came from.
9 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.
- Current pricing: Certify $10,000/year, Scale $21,500/year, Enterprise $35,000/year; Role Management from Certify, SSO on Scale and Enterprise, and Enterprise Workspaces on Enterprise. https://www.strikegraph.com/pricing
- Current product-update log confirms SCIM deactivation, reactivation, and identity-provider role mapping. https://help.strikegraph.com/en/articles/15635088-strike-graph-product-updates
- Details of the free signup: capped at 15 attachments, risk assessment, Office 365/Google Drive integrations, expert support -- a lead-gated limited account rather than a listed plan tier. https://www.strikegraph.com/start-for-free
- 300+ systems/tools and 50,000+ data points for automated evidence collection; Evidence API option. https://www.strikegraph.com/integrations
- "Strike Graph has been rated 4.7 stars by 193 verified reviews on G2" (per Google/Serper cached snippet; direct G2 page fetch was blocked by DataDome anti-bot protection). https://www.g2.com/sellers/strike-graph
- $3.9M seed round, Oct 2020, led by Madrona Venture Group. https://techcrunch.com/2020/10/05/strike-graph-raises-3-9-million-to-help-automate-security-audits
- 2023 funding round (reported as $7M by GeekWire vs $8.5M in the vendor's own release) and a cumulative total of $18.9M reported at that time. https://www.geekwire.com/2023/compliance-automation-startup-strike-graph-lands-7m-to-expand-certification-offerings
- $8.5M funding round led by BAMCAP with Madrona and Information Venture Partners, Dec 2023; Jim Sheward (BAMCAP) joined the board. https://www.corporatecomplianceinsights.com/strike-graph-funding-2023
- Scoped plan recheck: annual starting prices remain Certify $10,000, Scale $21,500 and Enterprise $35,000. Evidence API is listed under Enterprise. Customer Support is listed, but the page does not establish self-service onboarding or a dedicated consultant. https://www.strikegraph.com/pricing
1 fact on this page we could not establish.
Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Strike Graph, send us the sources and we will fill them.
Verification is free and always will be. It does not change where Strike Graph appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.