Transparent pricing

Pricing that scales with your risk,not your headcount.

A full-time CISO costs $300k–$500k per year. ROS delivers the same judgment-layer at a fraction of that — with agents running continuously, not just during business hours.

All tiers operate read-only. No production access, ever.

Growth
$990/month

Up to ~500 employees

The judgment of a CISO for organizations that are scaling security without scaling headcount.

  • Continuous risk assessment
  • Core integrations (AWS, Azure, GCP, Okta)
  • SOC 2 & HIPAA compliance mapping
  • Automatic evidence collection
  • Business-impact prioritization
  • Board-ready reports (quarterly)
  • Email support
Most popular
Enterprise
$2,990/month

Up to ~5,000 employees

Full CISO coverage at enterprise depth — all integrations, AI governance, and priority access to our team.

  • Everything in Growth
  • All integrations (SaaS, SIEM, endpoint, IaC)
  • AI Governance module (NIST AI RMF)
  • SSO / SAML enterprise authentication
  • Custom compliance frameworks
  • Board-ready reports (monthly + on-demand)
  • Priority support with named response SLA
  • Quarterly CISO advisory session
Government & Defense
Custom/ annual contract

Agencies & regulated contractors

Purpose-built for public-sector missions — CMMC, HITRUST, and GovCloud-aligned CISO oversight.

  • Everything in Enterprise
  • CMMC Level 2 & 3 assessment paths
  • HITRUST CSF mapping
  • GovCloud deployment path (FedRAMP-aligned, in progress)
  • Dedicated CISO oversight lead
  • Air-gap and FIPS 140-2 roadmap
  • Annual contract with optional multi-year pricing
  • On-site executive briefing available

All prices shown in USD. Annual prepay available at a discount — ask our team. Pricing above reflects our current design-partner period and may change when we exit early access.

AI Governance module

Govern the AI you build and the AI you buy.

Included in Enterprise and Government tiers. Available as an add-on for Growth customers. Maps your AI systems against the NIST AI RMF — tracking bias risk, data lineage, model provenance, and accountability controls. Delivers an AI-specific risk narrative your board can understand and your legal team can defend.

  • NIST AI RMF alignment (Govern / Map / Measure / Manage)
  • Inventory of AI systems with risk classification
  • Bias, drift, and data lineage monitoring stubs
  • AI-specific board narrative template

A note on design-partner pricing

Sapien9 ROS is in active design-partner conversations with regional healthcare and public-sector organizations. The prices above reflect our current early-access period. Design partners receive locked-in rates for the duration of their initial contract, direct input into the product roadmap, and a named point of contact with our founding team.

We will not inflate numbers or invent customer logos to look bigger than we are. What we offer is the judgment of an operator who has done this job for real — encoded into software that runs continuously. If that resonates, we want to talk.

hello@sapien9.com
FAQ

Common questions

Does ROS store or modify any of my production data?

No. ROS uses least-privilege, read-only API access (and non-intrusive external-surface probes) with a full audit trail — it assesses, advises, and reports, and never writes to your environment or touches production. The read-only credentials you connect are encrypted at rest (AES-256-GCM) and used only to run assessments. See our Trust Center for specifics.

What compliance frameworks does ROS cover today?

Current coverage includes NIST CSF 2.0, SOC 2 Type II (in progress, see our transparency note), HIPAA, and CMMC Level 2. The NIST AI RMF module is included in Enterprise and Government tiers. Additional frameworks are added on a roadmap basis.

How long does the initial integration take?

Most core integrations complete in a matter of hours via OAuth and read-only API keys. A full-scope baseline assessment across your cloud, identity, and compliance stack typically completes within one to three business days.

Is ROS itself SOC 2 certified?

Sapien9 is currently pursuing SOC 2 Type II certification — we list it as 'in progress' to be accurate. We can share our current security posture documentation and evidence package with qualified prospects under NDA.

Get the CISO your organization could never hire.

A focused walkthrough with our team, tailored to your environment, your frameworks, and the risks that keep you up at night.

Built on the methodology of the former CISO of the City of San José

Sapien9 ROS — Risk Operating System