Skip to content
AuditFetch

Pick the frameworks you need.

Every plan runs on your own infrastructure. Evidence and credentials stay in your environment. Plans differ only in which frameworks they cover.

Local Team

The default install. Start with one owner, then optionally add members with their own roles. Use HTTPS before sharing it across your network.

Local Single User

The explicit lightweight option for one administrator account on a machine you control. Sign-in uses a password you hold.

Hosted

Run by us instead, if you would rather not operate it. Ask us.

Priced per organization, billed monthly in USD until canceled. Cancel future renewals online through the Stripe customer portal, or by emailing info@auditfetch.com; access continues through the paid billing period. Charges already incurred are non-refundable except where required by law or described in our Subscription Policy.

2 months free

Compliance Core

$99/mo

$990/yr billed annually

Getting SOC 2 evidence under control

  • SOC 2 evidence collection, readiness tracking, review, and export
  • Read-only collectors for GitHub, AWS, Okta, Google Workspace, Jira, Linear, Datadog, and WorkOS
  • Continuous collection — no evidence limits
  • Local Team by default — unlimited members with no per-seat pricing
  • 10 years of evidence history
  • Gap analysis, reviewer workflow, and drift alerts
  • Custom evidence automations
  • PDF / ZIP / CSV auditor packets
  • AI summaries, including local models
  • Email support

Compliance Pro

Most popular
$149/mo

$1,490/yr billed annually

Running SOC 2 and HIPAA together

  • Everything in Core, plus HIPAA readiness
  • Evidence collected once is reused across both frameworks automatically
  • Read-only collectors for GitHub, AWS, Okta, Google Workspace, Jira, Linear, Datadog, and WorkOS
  • Continuous collection — no evidence limits
  • Local Team by default — unlimited members with no per-seat pricing
  • 10 years of evidence history
  • Gap analysis, reviewer workflow, and drift alerts
  • Custom evidence automations
  • PDF / ZIP / CSV auditor packets
  • AI summaries, including local models
  • Email support

Compliance Advanced

$299/mo

$2,990/yr billed annually

Preparing for ISO 27001 certification

  • Everything in Pro, plus ISO 27001 readiness
  • Statement of Applicability lifecycle with approved snapshot pinning
  • Risk references and separation-of-duties approval
  • ISO audit packets
  • Read-only collectors for GitHub, AWS, Okta, Google Workspace, Jira, Linear, Datadog, and WorkOS
  • Continuous collection — no evidence limits
  • Local Team by default — unlimited members with no per-seat pricing
  • 10 years of evidence history
  • Gap analysis, reviewer workflow, and drift alerts
  • Custom evidence automations
  • PDF / ZIP / CSV auditor packets
  • AI summaries, including local models
  • Email support

ISO 27001 readiness and evidence workflows. AuditFetch does not issue certifications.

Prices cover the AuditFetch software only. They exclude your auditor and certification fees, the infrastructure you run AuditFetch on, and any consulting or advisory work. AuditFetch collects and organizes evidence — it does not certify compliance or guarantee auditor acceptance.

Questions

Is AuditFetch a replacement for Vanta or Drata?

No. AuditFetch is designed to complement tools like Vanta and Drata. It focuses on collecting, validating, packaging, and syncing evidence.

Where is evidence stored?

With AuditFetch Local, evidence is stored in your environment by default. AuditFetch Cloud is used for licensing, updates, connector templates, optional telemetry, and future optional collaboration services.

Does AuditFetch certify SOC 2 or HIPAA compliance?

No. AuditFetch helps collect and organize evidence. It does not provide legal advice, guarantee auditor acceptance, or certify compliance.

Why local-first?

Audit evidence often includes sensitive security configuration, access lists, and screenshots. Local-first deployment keeps evidence and credentials under your control.

Can AuditFetch reach internal systems?

Yes, when deployed locally, AuditFetch can collect evidence from systems that are not publicly accessible.

Do we need to give AuditFetch write access?

No. AuditFetch should use read-only scopes by default. It is designed to collect evidence, not modify infrastructure.

Is Custom Evidence Automation included in every plan?

Yes. Custom Evidence Automation is included in Compliance Core, Compliance Pro, and Compliance Advanced. Plans differ by framework coverage, not by access to this capability.

How do the Compliance plans differ?

Compliance Core covers SOC 2, Compliance Pro adds HIPAA, and Compliance Advanced adds ISO 27001 readiness. All three include Custom Evidence Automation.

What can we customize?

Today, reviewed templates are available for AWS and GitHub. AuditFetch does not support arbitrary API requests or write actions.

Can we use AI locally?

AuditFetch can support local AI providers for privacy-sensitive deployments. AI-generated summaries are reviewable drafts.

When will AuditFetch Cloud be available?

AuditFetch Cloud is invitation-only today while we expand the managed platform. Contact us at info@auditfetch.com to discuss your requirements.

Want AuditFetch Cloud?

We're currently onboarding cloud customers selectively while we expand the managed platform. Contact us to discuss your requirements.

Ready to stop chasing audit screenshots?

See AuditFetch pricing and get started with local-first evidence automation for SOC 2, HIPAA, and ISO 27001.

Get product updates instead: