Choose the evidence depth the decision requires.
Enterprise POC is the primary path for consequential AI decisions. Standard Validation supports builders and technical teams; Assurance Firms can bring HAIEC evidence into their professional workflow.
Self-Service Platform
For teams that operate HAIEC themselves. SCAN, DEFEND, and ASSURE — start with visibility and move to evidence-bound assurance when ready.
Enterprise Assurance POC
For organizations with consequential AI systems and complex evidence sources. A founder-led, bounded engagement — not a subscription tier.
Assurance Firms
For audit, compliance, and assurance firms. Reviewer flows, evidence handoff, and API access where supported for your practice.
Founder-led Enterprise Assurance POC
A founder-led, bounded engagement for organizations with consequential AI systems and complex evidence sources. Not a self-service subscription upgrade.
$25K–$75K
Typical scoped range, depending on complexity and evidence-source coverage. Typical duration scoped per engagement (commonly 4–8 weeks for the initial evaluation).
Start focused. Establish what the evidence supports. Expand from there.
The scope can expand to additional systems, action surfaces, evidence sources, or environments when the initial evaluation supports deeper work. Expansion is evidence-bound and mutual — not automatic.
FIRM — Custom
For audit, compliance, and assurance firms. Reviewer flows, evidence handoff, framework mapping where supported, and API access where enabled for your assurance practice.
Talk to HAIECPlatform vs Enterprise
Self-service platform and enterprise engagement are different motions, not ascending tiers. Choose by evidence complexity and system consequence.
| Dimension | Self-Service Platform | Enterprise Assurance POC |
|---|---|---|
| Starting motion | Self-service checkout. Start with SCAN ($99/mo) and upgrade as needed. | Founder-led scoping call. Start with one consequential AI system and one priority question. |
| System boundary | Customer operates HAIEC against their own repositories and endpoints. | HAIEC team helps define the evidence boundary and scope explicitly with your team. |
| Evidence access | Customer connects source repositories, runtime endpoints, and assets directly. | Private/restricted evidence sources, sandbox environments, and custom integrations where needed. |
| Integrations | Standard GitHub, CI/CD, SARIF import, and supported framework mappings. | Custom integrations for consequential systems where the evidence path requires it. |
| Operating Envelope | Customer authors and approves Operating Envelopes in System Workspace. | HAIEC helps establish the authority configuration and policy boundary for the scoped system. |
| Acceptance criteria | Customer defines their own assurance thresholds and review workflow. | Mutual success criteria defined at engagement start. Decision-ready evidence package. |
| Readout | Dashboard, reports, Decision Receipts, and Executive Reports. | Founder-led technical and executive decision readout with explicit gaps and UNKNOWN states. |
| Commercial model | Monthly or annual subscription. Cancel anytime. 14-day free trial on SCAN. | Scoped engagement, typically $25K–$75K. No checkout. No cancellation — engagement-bound. |
Self-Service Platform
For teams that operate HAIEC themselves. Start with visibility and move to evidence-bound assurance when ready.
SCAN
Discover AI action surface and collect source evidence
14-day free trial
Visibility into your AI security and compliance risks. Source evidence, action/access baseline, and initial evidence collection.
Start Free 14 DaysWhat's Included
DEFEND
Add security validation, engineering controls, and evidence workflows
Engineering validation, runtime/security testing where supported, exports, CI/CD, and evidence workflows.
Start DefendingWhat's Included
ASSURE
Build evidence-bound assurance packages, decisions, and receipts
Decision-ready evidence, assurance packages, reports, and receipt-oriented workflows where implemented.
Start Building AssuranceWhat's Included
Which Path Is Right?
Three buying motions, not four ascending tiers. Choose by capability and complexity.
Individual / builder / small technical team
Start with SCAN.
Visibility into your AI security and compliance risks.
Engineering or security team
DEFEND.
Deeper security validation, exports, and engineering workflows where supported.
Organization building evidence-bound assurance workflows
ASSURE.
Evidence-bound assurance packages, decisions, and receipts.
Enterprise consequential AI system
Enterprise Assurance POC.
Complex evidence sources, founder-led scoped engagement.
Audit / compliance / assurance firm
FIRM.
Reviewer flows, evidence handoff, and API access where supported for your assurance practice.
Self-Service Comparison
Hover over abbreviations to see full terms. Enterprise and FIRM are separate engagement motions — not self-service tiers.
| Feature | SCAN $99/mo | DEFEND $349/mo | ASSURE $999/mo |
|---|---|---|---|
| Pipeline & Automation | |||
Pipelines (Pipelines (Compliance Workflows)) | 10 | 50 | 200 |
Execs (Monthly Executions) | 500 | 2,000 | 10,000 |
CI/CD (CI/CD Integration) | |||
Cron (Scheduled Monitoring) | |||
| AI Security Scanner | |||
SAST (Static Analysis (121 rules)) | |||
Runtime (Runtime Testing (14 categories)) | |||
PDF (PDF Report Export) | |||
SARIF (SARIF Export (CI/CD Format)) | |||
| Scan History Retention | 30 days | 90 days | Unlimited |
| Governance & Evidence | |||
AI Inventory (AI Systems in Inventory) | 10 | 50 | Unlimited |
SDK (Kill Switch SDK) | |||
CT (Compliance Twin) | |||
Vault (Evidence Vault) | |||
MARPP (MARPP Evidence Package) | |||
| Regulatory Alerts | |||
| Compliance Assessments | |||
SOC 2 (SOC 2 Attestation Readiness) | |||
GDPR (GDPR Evidence Mapping) | |||
HIPAA (HIPAA Evaluation & Readiness) | |||
ISO (ISO 27001 / 42001 Readiness) | |||
NIST (NIST AI RMF Alignment) | |||
EU (EU AI Act Evidence) | |||
CCA (Colorado AI Act) | |||
| Full Board Reports | |||
| Full Audit Logs (Exportable) | |||
| Team & Support | |||
| Team Seats | 1 | 3 | 10 |
| Support Channel | Email + Call | ||
Frequently Asked Questions
What's the difference between SCAN, DEFEND, and ASSURE?
Self-service tiers differ by capability access, pipeline capacity, execution limits, exports, runtime testing, evidence/assurance features, and support. SCAN ($99) is for teams exploring (10 pipelines, 500 executions/mo, web-view only). DEFEND ($349) adds exports, CI/CD, and runtime testing (50 pipelines, 2,000 executions/mo). ASSURE ($999) adds cryptographic evidence, assurance packages, and full governance (200 pipelines, 10,000 executions/mo).
What about Enterprise or Assurance Firms?
Enterprise Assurance POC is a founder-led engagement (typically $25K–$75K) for organizations with consequential AI systems — not a self-service tier. FIRM is for audit, compliance, and assurance firms — custom-priced with reviewer flows and API access where supported. Both are engagement-led, not checkout-based.
What's the "14-day free trial" for SCAN?
Payment method required at checkout. No charge during the 14-day trial; billing begins after the trial unless canceled. After the trial, the SCAN plan renews monthly at the selected billing cycle.
What are "Pipelines" and "Executions"?
A Pipeline is a compliance assessment workflow (e.g., "Run GDPR assessment on our hiring process"). An Execution is one run of that pipeline. SCAN allows up to 10 pipelines and 500 total executions/month. When you hit your limit, you can upgrade or wait until the next month.
What is Runtime Testing?
Adversarial attack testing across 14 categories (prompt injection, jailbreak, data exfiltration, etc.) that tests your AI system against real-world exploitation techniques where supported. SCAN does not include runtime testing. DEFEND and ASSURE do.
What is MARPP?
MARPP is the Metadata-Anchored Retention & Proof Protocol. It produces a tamper-evident evidence package using SHA-256 integrity where supported. Auditors can compare hashes to detect changes. Available in ASSURE only.
What is the Kill Switch SDK?
A 5-layer emergency shutdown system you embed in your AI apps. It lets you instantly halt AI inference at the model, API, orchestration, data, or network layer — critical for high-risk AI compliance. Available in ASSURE only.
Can I upgrade or downgrade?
Yes. Upgrades take effect immediately. Downgrades take effect at the end of your current billing period.
Do you offer annual pricing?
Yes — annual billing saves 20% on all self-service tiers. Use the toggle above the pricing cards to see the per-month rate when billed annually.
Do you conduct audits or certify compliance?
No. HAIEC provides tools and infrastructure to help you prepare for audits. Final compliance determination is made by your independent auditor. We do not conduct audits or issue certifications.
Secure & Trusted Platform
Start Your Assurance Journey Today
Start SCAN with a 14-day trial. Payment method required at checkout. No charge during the trial; billing begins after the trial unless canceled.