The people part

Software sorts the evidence. People answer the strange questions.

Here is the honest limit of every compliance tool, ours included. It can collect evidence, keep the control set straight, and draft your policies. It cannot decide what your scope should be, and it cannot talk you through the auditor's follow-up question at 11pm. That part is people. So every account comes with a shared Slack channel with us and regular check-ins. And when you want us properly involved, we prepare ISO 27001 alongside your team as a separate, scoped engagement.

Included at $250/month: shared Slack channel, regular check-ins, onboarding run by the founding team.

01 / Included

What comes with every account

No support tiers, no premium plan, no per-seat gate on getting help. AuditBadger is $250/month flat, and this is part of it.

A shared Slack channel

You get a channel with the founding team in it. Ask the questions you would rather not ask in front of an auditor. Most of compliance is exactly those questions.

Regular check-ins

We meet periodically to look at where your program actually is, what has stalled, and what to do next. Calendar invites, not a ticket queue.

Onboarding run by the founders

The first weeks decide how the rest of it goes, so the people who built the product run them. Nobody hands you over to a customer success rep.

Answers about the standard, not just the software

What the auditor means by that request. Whether your scope is sane. Whether a control is worth the effort. We have been asked all of it, mostly by ourselves in 2019.

One honest caveat: we are a small team, not a 24/7 support rota. Sometimes you get an answer in ten minutes, sometimes after lunch. If you need a guaranteed response time written into a contract, ask before you buy and we will tell you plainly whether we can sign it.

02 / Deeper help

ISO 27001 preparation, done with you

Some teams want more than answers. They want someone in the room doing the work with them, because nobody there has run an ISMS before and the certification date is already sitting in a customer contract. That is a separate, paid engagement. Here is what it covers.

  • Scoping: what goes inside the ISMS and, more usefully, what stays out
  • Risk assessment and treatment plan, built with your team instead of handed to it
  • Statement of Applicability, with the justifications written down while you still remember them
  • ISMS clauses 4 to 10: context, leadership, planning, support, operation, evaluation, improvement
  • Policies your team will actually follow (AI drafts, we review them together, you approve)
  • One management review and one internal findings round run with you, so the next ones are yours
  • Preparation for the certification body's audit, including the questions they tend to open with
  • ISO 27001 in the 2013 or the 2022 edition, transitions included
Pricing

Quoted per engagement

There is no honest list price for this one. A twelve-person SaaS with a single cloud account is a different job from a forty-person company with three products and a data center contract. So we scope it on a call, tell you what it involves, and quote once. The software stays $250/month either way.

Book a scoping call
03 / Where we stop

The lines we do not cross, on purpose

This is the part most vendors keep vague. Ours is in writing, before you spend anything.

We do not audit you

Certification bodies and CPA firms decide whether you pass. If the people preparing you also graded you, the result would be worth nothing to your customers. We work with a certified ISO 27001 Lead Auditor to keep our own reading of the standard honest, and that stays separate from whoever audits you.

We do not join your team

The engagement has a start and an end. It is not a fractional CISO seat. If what you need is someone embedded for a year, you need a consultant, and we will say so on the call.

The software does not think for you

AI drafts policies, finds gaps, and suggests fixes. Every change waits for your confirmation and lands in the audit trail. Nothing publishes itself, and nothing changes quietly.

We do not call our checks continuous

Automated checks run monthly, some weekly, plus whenever you press the button. Some tools call that continuous monitoring. Your auditor will ask what it actually means, so we say it plainly first.

04 / When not us

When you should hire a proper consultant

Genuinely. Some situations need an experienced advisor with a specialism, and pretending otherwise would cost you more than their invoice.

You are in a heavily regulated corner (banking, insurance, medical devices, defense) where the control set comes with sector rules we do not specialize in.

You need someone on site, in your offices, several days a month.

Your group has multiple legal entities, shared services, and an internal audit function that expects to be coordinated with.

A customer contract names a specific advisory firm, or your board wants a signed opinion from a named consultant.

You need a framework we do not cover. We do SOC 2 and ISO 27001. That is the whole list.

If that is you, hire the consultant. You can still run the program on AuditBadger, and most consultants are relieved to find the evidence already organized and dated. Nothing about the software requires buying our time.

05 / Why us

We have been on both sides of this

In 2019 I took a software company through ISO 27001 certification. It was brutal, mostly because we could not tell which parts actually mattered until we had already spent weeks on the parts that did not. AuditBadger is the tool I wanted that year.

In 2026 we put AuditBadger through its own SOC 2® Type II examination. The observation window ran March 27 to June 27, the whole program ran on AuditBadger, and we used zero external consultants. When we say we know what your next four weeks look like, that is where it comes from.

How we handle your data

Start with the software. Ask for people when you need them.

Most teams need the tool and a Slack channel. Some need us in the room for ISO 27001. Both start with the same conversation, and it is with a founder.