PLANS

Continuous Compliance Built to Scale

Start with the compliance foundation you need today, then expand across frameworks, systems, and properties as your organization grows.

OBRYN GUARD combines continuous control monitoring, evidence management, findings, remediation, and readiness workflows in one platform.

Hospitality-aware architecture Readiness-focused Built for continuous monitoring

Choose your operating model

One platform. Three levels of scale.

Every plan preserves the core monitoring, findings, remediation, retesting, and evidence workflow.

ESSENTIAL

Starter

Establish the foundation for continuous compliance with core monitoring, findings, and evidence management for one site.

Best for

Smaller single-site hotels and organizations focused on one primary compliance framework.

What’s included

  • 1 site / property
  • Choose 1 readiness framework
  • PCI DSS, SOC 2, or ISO 27001
  • For hotels, OBRYN GUARD recommends starting with PCI DSS readiness.
  • Up to 50 monitored identities
  • 1 identity provider
  • Core Continuous Control Monitoring
  • Automated control testing
  • Automated evidence collection
  • Manual evidence collection
  • Automated findings
  • Remediation tracking
  • Automatic retesting
  • Historical evidence timeline
  • Standard readiness dashboard
  • Basic risk register
  • Basic vendor register
  • Access tracking
  • Incident register
  • Standard onboarding

ENTERPRISE

Scale

Centralize continuous compliance, risk, and evidence governance across a multi-property or multi-site organization.

Best for

Hotel groups, ownership groups, management companies, and complex multi-site organizations.

What’s included

  • Multiple sites / properties
  • Custom monitored identity volume
  • Multiple identity providers
  • Multiple Microsoft / Google / supported identity tenants
  • Portfolio-wide dashboards
  • Centralized compliance governance
  • Property-level readiness views
  • Cross-property findings
  • Cross-property risk trends
  • Shared corporate controls
  • Property-specific controls
  • Centralized evidence management
  • Custom evidence retention
  • Enterprise RBAC
  • Property-level permissions
  • Custom controls
  • Custom framework mappings
  • Custom reporting
  • Bulk evidence export
  • Custom integrations when contracted
  • Enterprise SSO when available
  • API / webhooks when available
  • Dedicated implementation
  • Priority security/compliance support
  • Executive reviews
  • Custom support / SLA options
Growth+ enterprise acceleration

Launch a production baseline or pilot cohort, then expand across properties through controlled rollout waves.

Platform principle

The Core CCM Loop Is Included in Every Plan

OBRYN GUARD does not weaken the monitoring engine between plans. Plans scale by framework breadth, integrations, governance, reporting, implementation support, and organizational complexity.

  1. Connect
  2. Monitor
  3. Detect
  4. Remediate
  5. Verify
  6. Preserve evidence

Every OBRYN GUARD plan retains the core continuous-control-monitoring workflow.

Full plan comparison

Compare scope, capabilities, and support

Expand a category, then scroll horizontally on smaller screens. “When available” labels identify capabilities that should not be treated as currently released.

Swipe to compare all plans

Commercial scope
Commercial scope comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
Sites / properties 1 1 Multiple / custom
Monitored identities Up to 50 Up to 200 Custom
Framework scope 1 selected framework PCI DSS + SOC 2 + ISO 27001 Custom / contracted
Growth+ Included Enterprise-tailored
Continuous control monitoring
Continuous control monitoring comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
Continuous Control Monitoring Included Included Included
Automated control testing Core standard library Full standard library Full + enterprise/custom
Automated evidence collection Included Included Included
Manual evidence collection Included Included Included
PASS / FAIL / WARNING / ERROR Included Included Included
Automated findings Included Included Included
Finding assignment Included Included Included
Remediation tracking Included Included Included
Automatic retesting Included Included Included
Manual sync / recheck Included Included Included
Historical evidence timeline Included Included Included
Frameworks
Frameworks comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
PCI DSS Readiness Select as your framework Included Included
SOC 2 Readiness Select as your framework Included Included
ISO 27001 Readiness Select as your framework Included Included
Hotel-first starting point PCI DSS recommended PCI DSS included Portfolio scoped
Multi-framework shared controls Included Included
Shared evidence across frameworks Included Included
Custom controls Limited / approved Scoped
Custom framework mappings Scoped
Enterprise governance Included
Identity & evidence connectors
Identity & evidence connectors comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
Identity provider allowance 1 Standard supported providers Multiple providers + tenants
Microsoft Entra / M365 Choose Microsoft or Google Included Included
Google Workspace When available When available When available
Okta Future When supported When supported
Multiple identity providers Included Included
Multiple identity tenants Included
MDM / EDR / SIEM / cloud Add-on as released Scoped as released
Custom integrations Scoped separately
Evidence & reporting
Evidence & reporting comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
Historical evidence Included Included Included
Evidence expiry / renewal tracking Basic Advanced Advanced / portfolio
Readiness dashboard Standard Advanced Portfolio / executive
Framework readiness view Single framework Multi-framework Custom
Executive reporting Basic Advanced Portfolio / custom
Evidence export Standard Advanced Enterprise / bulk
Property comparison & cross-property findings Included
Evidence retention 12 months 24 months Custom / multi-year
Risk & operational management
Risk & operational management comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
Risk register Basic Advanced Enterprise / portfolio
Risk ownership & treatment Basic Included Included
Vendor governance Basic register Vendor risk tracking Centralized portfolio
Access tracking Core Advanced Cross-property oversight
Staff training & attestations Core Advanced Enterprise oversight
Incident management Incident register Included Portfolio visibility
Administration & governance
Administration & governance comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
Standard RBAC Included Included Included
Advanced RBAC Included Included
Property-level permissions Included
Centralized portfolio governance Included
Custom roles When available
Enterprise SSO When available / contracted
API / webhooks When available / contracted
Services & support
Services & support comparison for Starter, Growth, and Scale
Capability Starter Growth Recommended Scale
Customer kickoff Included Included Included
Solution Specialist onboarding Standard Dedicated Growth+ Dedicated enterprise
Environment discovery Standard Enhanced Enterprise / multi-site
Security / compliance scoping Standard Enhanced Enterprise
Initial readiness review Included Enhanced Enterprise
Growth+ 4 weeks included Enterprise-tailored
Customer reviews Quarterly Custom cadence
Support Standard Priority Enterprise priority
Security specialist involvement Escalation Material findings / priority Priority / governance
Dedicated account governance Included
Custom SLA Available

Growth+

From Contract to Continuous Monitoring in Four Structured Weeks

A guided implementation path designed to establish a defensible initial operating baseline—without promising certification or pretending every remediation can be completed in four weeks.

  1. 01

    Scope & Configure

    Kickoff, environment discovery, framework scope, connector planning, and evidence requirements.

  2. 02

    Connect & Assess

    Connect supported systems, run initial CCM tests, collect evidence, and establish initial findings.

  3. 03

    Prioritize & Remediate

    Prioritize findings, assign owners, establish due dates, track remediation, and retest controls.

  4. 04

    Verify & Launch

    Verify fixes, review manual evidence, establish the initial readiness baseline, and begin ongoing monitoring.

Why OBRYN GUARD

One continuous system of record

01

One Control Engine

Evidence from Microsoft, Google, and future supported systems feeds one OBRYN control architecture rather than separate compliance engines.

02

One Finding, Not Three

A single real-world control failure can map across PCI DSS, SOC 2, and ISO 27001 without creating duplicate remediation work.

03

Automated + Manual Evidence

Technical integrations monitor what can be verified automatically, while structured workflows cover operational and manual controls.

04

Built for Continuous Readiness

Findings, remediation, retesting, evidence history, and readiness workflows remain connected over time.

Built for hospitality

Start With Hotels. Scale Across the Organization.

OBRYN GUARD is initially designed around hotel environments—payment systems, staff access, vendors, evidence, and distributed operations—while the platform architecture supports expansion into other multi-site organizations.

Organization Portfolio governance
Site / Property Readiness scope
Department Operational ownership
Users Systems Controls Evidence and monitoring

Readiness, Monitoring & Evidence Management

OBRYN GUARD supports PCI DSS readiness and continuous monitoring, SOC 2 readiness and control monitoring, and ISO 27001 readiness and control monitoring. Formal certification, attestation, or validation requirements may require an appropriately authorized independent assessor, certification body, CPA firm, or QSA organization.

Plan your next step

Find the Right OBRYN GUARD Plan

See how OBRYN GUARD can support your organization’s compliance, evidence, risk, and continuous-monitoring requirements.