Pricing

Controlled pilot pricing, scoped per engagement

RiskAlign is quote-led. Every engagement is a controlled pilot, named, scoped and contracted directly with the founder so that what is delivered matches what your security and legal teams have reviewed. Pricing is set against engagement scope and whether you take RiskAlign alone or as part of the combined RegAlign and RiskAlign offering. A maximum of two founding-customer slots is available across RegAlign and RiskAlign combined, subject to fit and the approved portfolio authority.

Controlled pilot engagement

One regulated firm, up to three legal entities

Scoped per engagement
Fixed-term, invoiced on agreed milestones
  • Full operator console — risk, controls, KRIs, appetite, audit trail
  • Named user allowance agreed at scoping
  • Founder-led onboarding and cadence calls
  • Trust Centre artefacts issued per engagement, in their current published or on-request status
  • Vulnerability disclosure and security.txt covered by the same agreement

RegAlign + RiskAlign — founding/launch package

Firms scoping both compliance operations (RegAlign) and enterprise risk intelligence (RiskAlign)

Combined commercial offering, quote on request
Single invoice via RegAlign Limited (Jersey company no. 165263)
  • Both products delivered as a combined commercial offering; the consoles remain separate
  • Governed CSV bridge between RegAlign obligations and RiskAlign risks; a unified operator console is not implied
  • One contract, one DPA, one invoicing rail — no Stripe, no card on file
  • Trigger-tied external assurance roadmap (see Security Roadmap)

What is not included today

  • · SOC 2 or ISO 27001 attestation (trigger-tied — see Security Roadmap)
  • · Completed independent penetration test report (scope prepared; not yet contracted)
  • · Application-layer envelope encryption / customer-managed keys
  • · Self-serve provisioning, card-on-file billing, or Stripe checkout

Trust Centre documents are listed with their current status (public, on request or draft). Only artefacts marked as available should be relied on; nothing above is presented as independently verified unless the Trust Centre entry says so explicitly.

Want to inspect the security posture first? Start with the Trust Centre, the CAIQ v4 (197 controls), and the operational metrics.