Transparent & flat

Pay per company, not per vendor.

Every serious TPRM tool starts at $5,000–$16,500/yr and bills you more for each vendor you add. Covenant publishes its prices and never charges a per-vendor surcharge.

Free

$0 forever
  • Up to 10 vendors
  • Full HIPAA BAA tracking + reminders
  • §164.504(e) clause gap-check + executed-BAA expiry
  • SMB Lite + HIPAA questionnaires
  • Tokenized vendor portal (no-account, reminder cadence)
  • Live email-auth scan (SPF/DMARC) + explainable scores
  • Evidence attachments, vendor-ledger heatmap, CSV export
Start free

Team

$1490 /mo
  • Unlimited vendors
  • Everything in Pro
  • Daily scanning + auto-discovery
  • Custom roles / granular RBAC, SSO
  • Slack / Teams alerts
  • Sightline / Bastion evidence sync
Get started

MSP

$599 /client/mo
  • Team features × N client tenants
  • Cross-client portfolio console
  • White-label vendor portal
  • Consolidated billing
  • Volume discounts at 10+/25+ clients
Talk to us
vs. the incumbents · feature by feature

More vendor-risk program, for a fraction of the price

Every serious TPRM platform starts in the five figures, hides its pricing behind a sales call, and bills you again for each vendor you add. Here is the honest, line-by-line comparison — entry price, per-vendor surcharge, and the capabilities that actually matter to an SMB or MSP.

Capability Covenant$0–$1490/mo flat UpGuard~$19.2k/yr Starter SecurityScorecard~$16.5k/yr WhisticQuote-only (enterprise) Vanta VRM$5k–$15k/yr add-on OneTrust TPRM$10k/yr floor
Pricing & access
Public, flat pricingYes — on this pagePartialNo (opaque)No (quote)No (quote)No (quote)
Per-vendor surchargeNone$79/mo each$1,500–$2,000/yr eachTiered by volumeBy tierBy tier
Unlimited vendors at top tierYes — $1490/moNoNoNoNoNo
Free tier10 vendors + BAA, forever5 vendors, cappedNoNoNoNo
Self-serve, no sales callYes — no cardSelf-serve to a pointSales-ledSales-ledBundled w/ VantaSales-led
HIPAA / BAA — the wedge
Native HIPAA BAA lifecycleYes — freeNoNoNoNoPrivacy module add-on
§164.504(e) clause gap-check11 clauses checkedNoNoNoNoNo
Subcontractor flow-down chainYesNoNoNoNoManual
BAA renewal / overdue reminders90/60/30-dayNoNoNoNoGeneric tasks
Assessment & scoring
SIG & CAIQ questionnaire librariesIncludedYesYesYesYesYes
No-account vendor portal (magic link)Signed, expiring link + remindersAccount often requiredAccount often requiredTrust ExchangeAccount requiredAccount required
Evidence attachments + executed-BAA trackingSOC 2 / ISO / pen-test + BAA, with expiryDoc storeDoc storeYesWithin platformWithin platform
Explainable, itemized scoresEvery delta shownMethodology opaqueUnexplained changesLimitedLimitedLimited
External scanning & AI
Explainable external scanningEmail-auth live; TLS/headers/breach via runner — each finding shows its evidenceInternet-wide ratingsLetter-grade ratingsBreach detectionLimitedAdd-on
AI questionnaire / evidence assistBYO-key, no markupGatedGatedIncluded (higher tier)Paid AI tierAdd-on
Suite evidence graph (NIST SR / SOC 2 / ISO)Native syncNoNoNoWithin Vanta onlyWithin OneTrust only
Typical first-year cost — 30-vendor clinic $8149.80/yr ~$5,000+/yr ~$16,500/yr 5-figure quote $5k–$15k add-on $10,000/yr floor

Competitor figures from public pricing pages and third-party quotes (UpGuard, SecurityScorecard, Whistic, Vanta, OneTrust), 2025–2026; "Partial" denotes available but gated, tier-limited, or quote-dependent. Trademarks belong to their respective owners; Covenant is not affiliated with or endorsed by them.

More, for less

What we include that they charge extra for — or don't offer at all

No per-vendor tax

Grow without watching the meter

UpGuard adds $79/mo for every vendor past five; SecurityScorecard bills $1,500–$2,000 per vendor per year. On Covenant Team, vendor 8 and vendor 800 cost the same flat $1490/mo.

Save thousands as you grow
HIPAA, included free

BAA lifecycle the ratings vendors don't have

BAA library, §164.504(e) gap-check, renewal reminders, and subcontractor flow-down are native and free for 10 vendors. UpGuard and SecurityScorecard simply don't track BAAs; OneTrust gates it behind a privacy module.

A whole product, $0
No five-figure floor

A price you can approve today

OneTrust enforces a $10,000/yr minimum; SecurityScorecard quotes ~$16,500 just to start; Vanta's VRM is a $5k–$15k add-on you can only buy if you already own Vanta. Covenant Team is $15,198/yr, unlimited vendors, no add-on stack.

Undercuts the entry band
No AI surcharge

BYO-key AI, zero markup

Vanta and Secureframe gate AI questionnaire review behind higher tiers. Covenant's summarization, evidence extraction, and risk narratives run on your own LLM key — same capability, no inference cost passed through.

Pay the model, not us