For early-stage teams running their first framework. No card, no time limit.
Get started- 1 framework
- Up to 5 users
- 1 evidence connector
- Community support
SentinelPanda pricing depends on your framework set, scale, and whether you run on our cloud or your own infrastructure. We quote it directly so the number matches the program, not a list price. The full 1,330-control library and cross-framework mapping are included on every plan — including Free.
For early-stage teams running their first framework. No card, no time limit.
Get startedFor small teams preparing for their first SOC 2 or ISO 27001 audit.
Talk to usFor multi-framework programs with internal auditors and continuous evidence.
Talk to usLevel 1 ROC programs where your QSA works inside the platform, multi-tenant assessment firms, and regulated industries.
Contact salesStartups and qualified open-source projects: mention either when you book the call — see FAQ below for current discounts.
| Feature | Free | Starter | Growth | Enterprise |
|---|---|---|---|---|
| Frameworks | 1 | 2 | 5 | Unlimited |
| Workspace users | 5 | 25 | 100 | Unlimited |
| Evidence connectors | 1 | 5 | 12 (all) | 12 (all) |
| 1,330 controls library | ||||
| Cross-framework mapping | ||||
| Three-role review workflow | ||||
| Immutable audit log | ||||
| Risk register + heatmap | ||||
| Statement of Applicability | ||||
| OIDC single sign-on | ||||
| Custom roles | ||||
| PCI ROC / AOC export | ||||
| Public REST API | ||||
| Outbound event webhooks | Roadmap | Roadmap | Roadmap | Roadmap |
| QSA + external auditor seats | ||||
| Multi-tenant for QSA firms | ||||
| Dedicated customer success | ||||
| Custom SLA | ||||
| Support | Community | Priority | 24/7 + CSM |
Pricing depends on your framework set, team size, and whether the engagement is self-assessed or QSA-led. We quote it directly so you get a number that fits the actual scope of your program, not a list price you then have to negotiate down.
Yes — that is the most common way teams use SentinelPanda. Level 2, 3, and 4 merchants and most service providers below the Level 1 threshold can self-attest via the appropriate SAQ; the workspace walks the scope, the SAQ type, the requirements, the quarterly ASV scan attestations, and produces the signed AOC for your acquirer. A QSA is only required for the ROC path (typically Level 1).
Yes — the platform is designed for this. Your QSA gets their own seats inside your tenant on the Growth and Enterprise tiers, with auditor-layer access (review, approve, request more info) and full audit trail on every action. The QSA-led ROC workflow uses the same evidence library you populated for your SAQ work, so nothing has to be re-gathered.
Yes — no card, no time limit. It is capped to 1 framework, 5 users, and 1 evidence connector. Plenty to run a first ISO 27001 or SOC 2 readiness pass, or a small-merchant PCI SAQ A.
Any human with login access to the workspace, regardless of role (auditee, auditor, or support). External auditor seats during an active engagement do not count toward the limit.
No. Plans bundle a number of frameworks, and the full 1,330-control library plus cross-framework mapping is included on every plan — including Free.
Yes — upgrade or downgrade at any time. The product never deletes anything when you downgrade; frameworks above the new limit go read-only until you upgrade again or remove them yourself.
Yes — we have a startup credit for the first year and a free Growth tier for qualified open-source projects. Mention either when you book the call.
The marketing site walks through every feature: workflow, evidence, registers, reports, and the per-framework pages. The fastest tour is a 20-minute demo.