Start free. Upgrade when you need verified evidence and board reports. No credit card required.
SOLO
R0/month
Forever free
Solo founders getting started with POPIA
PRO
R999/month
Billed annually (R11,988/year)
Businesses preparing for audit, insurance, or enterprise clients
ENTERPRISE
Custom pricing
Consultancies and large organisations
Already doing POPIA? Your existing work covers up to 40% of ISO 27001 requirements. Pro subscribers get full access to the ISO 27001 Hub with mandatory clause tracking and ISMS document generation.
90-day compliance deployment. We engineer your complete POPIA compliance system — not a document pack that sits on a shelf.
R29,500 (50% upfront, 50% on completion)
Includes 12 months KomplyZA Pro (R11,988 value)
What you get
Target outcome: 70%+ verified POPIA score with signed compliance pack within 90 days.
That's the evidence-verified score — independently proven, not self-graded. The threshold for a POPIA Framework Alignment Attestation.
After 90 days, your compliance system runs itself. No consultants to re-engage. No binders on shelves. A living, monitored, evidence-backed compliance posture.
Timeline — 12 weeks, 6 phases
Phase 1 · Weeks 1–2
Discovery & baseline
Kick-off, 14-step assessment, risk register, POPIA Hub setup
Phase 2 · Weeks 3–4
Governance & policies
IO appointment, core policies drafted and reviewed with legal
Phase 3 · Weeks 5–6
Email & technical controls
DMARC/SPF/DKIM, evidence vault, security baselines
Phase 4 · Weeks 7–8
Vendors & breach readiness
Operator agreements, breach notification procedure, tabletop
Phase 5 · Weeks 9–10
Remediation sprint
Close critical gaps, Jira-tracked tasks, weekly check-ins
Phase 6 · Weeks 11–12
Audit pack delivery
Board compliance pack, King IV report, handover to your team
Full feature breakdown by tier
| Feature | Solo | Pro | Enterprise |
|---|---|---|---|
| Assessment | |||
| 14-step security baseline | ✅ | ✅ | ✅ |
| Risk register with heatmap | ✅ | ✅ | ✅ |
| Risks identified | Up to 17 | Unlimited | Unlimited |
| POPIA Hub (8 conditions) | ✅ | ✅ | ✅ |
| POPIA score tracking | ✅ | ✅ | ✅ |
| Breach Clock (dual 72hr) | ✅ | ✅ | ✅ |
| 90-day compliance plan | ✅ | ✅ | ✅ |
| Public DMARC scanner | 1/day | Unlimited | Unlimited |
| Tabletop exercises | 5/year | Unlimited | Unlimited |
| Full assessments per year | 3 | Unlimited | Unlimited |
| Policies | |||
| SA policy library (24 templates) | ✅ | ✅ | ✅ |
| AI policy generation | 3/month | Unlimited | Unlimited |
| Policy adoption workflow | ✅ | ✅ | ✅ |
| ROPA generator | ❌ | ✅ | ✅ |
| PAIA Manual generation | ✅ | ✅ | ✅ |
| Unwatermarked PDF exports | ❌ | ✅ | ✅ |
| Evidence & Verification | |||
| Evidence checklist (in-app) | ✅ | ✅ | ✅ |
| SHA-256 evidence vault | ❌ | ✅ | ✅ |
| File uploads | ❌ | ✅ | ✅ |
| KMS encrypted storage (af-south-1) | ❌ | ✅ | ✅ |
| Legal partner verification portal | ❌ | ✅ | ✅ |
| Technical partner verification portal | ❌ | ✅ | ✅ |
| Dedicated legal partner | ❌ | ❌ | ✅ |
| Reporting | |||
| Watermarked PDF exports | 1/module/yr | ❌ | ❌ |
| Board-ready compliance pack | ❌ | ✅ | ✅ |
| King IV board report | ❌ | ✅ | ✅ |
| External report sharing | ❌ | ✅ | ✅ |
| White-label reports | ❌ | ❌ | ✅ |
| Frameworks | |||
| POPIA (mandatory) | ✅ | ✅ | ✅ |
| Cybercrimes Act | ✅ | ✅ | ✅ |
| FSCA Joint Standard (financial) | ✅ | ✅ | ✅ |
| ISO 27001 readiness hub + gap analysis | ❌ | ✅ | ✅ |
| Custom framework mapping | ❌ | ❌ | ✅ |
| Integrations | |||
| Jira remediation sync | ❌ | ✅ | ✅ |
| GitHub issues sync | ❌ | ✅ | ✅ |
| Linear sync | ❌ | ✅ | ✅ |
| SSO (SAML/OIDC) | ❌ | ❌ | ✅ |
| Support & Scale | |||
| Users | 1 | Up to 10 | Unlimited |
| vCISO multi-tenant portal | ❌ | ❌ | ✅ |
| Multi-organisation clients | ❌ | ❌ | ✅ |
| Priority support + SLA | ❌ | ❌ | ✅ |
14-step security baseline
Solo
✅
Pro
✅
Enterprise
✅
Risk register with heatmap
Solo
✅
Pro
✅
Enterprise
✅
Risks identified
Solo
Up to 17
Pro
Unlimited
Enterprise
Unlimited
POPIA Hub (8 conditions)
Solo
✅
Pro
✅
Enterprise
✅
POPIA score tracking
Solo
✅
Pro
✅
Enterprise
✅
Breach Clock (dual 72hr)
Solo
✅
Pro
✅
Enterprise
✅
90-day compliance plan
Solo
✅
Pro
✅
Enterprise
✅
Public DMARC scanner
Solo
1/day
Pro
Unlimited
Enterprise
Unlimited
Tabletop exercises
Solo
5/year
Pro
Unlimited
Enterprise
Unlimited
Full assessments per year
Solo
3
Pro
Unlimited
Enterprise
Unlimited
SA policy library (24 templates)
Solo
✅
Pro
✅
Enterprise
✅
AI policy generation
Solo
3/month
Pro
Unlimited
Enterprise
Unlimited
Policy adoption workflow
Solo
✅
Pro
✅
Enterprise
✅
ROPA generator
Solo
❌
Pro
✅
Enterprise
✅
PAIA Manual generation
Solo
✅
Pro
✅
Enterprise
✅
Unwatermarked PDF exports
Solo
❌
Pro
✅
Enterprise
✅
Evidence checklist (in-app)
Solo
✅
Pro
✅
Enterprise
✅
SHA-256 evidence vault
Solo
❌
Pro
✅
Enterprise
✅
File uploads
Solo
❌
Pro
✅
Enterprise
✅
KMS encrypted storage (af-south-1)
Solo
❌
Pro
✅
Enterprise
✅
Legal partner verification portal
Solo
❌
Pro
✅
Enterprise
✅
Technical partner verification portal
Solo
❌
Pro
✅
Enterprise
✅
Dedicated legal partner
Solo
❌
Pro
❌
Enterprise
✅
Watermarked PDF exports
Solo
1/module/yr
Pro
❌
Enterprise
❌
Board-ready compliance pack
Solo
❌
Pro
✅
Enterprise
✅
King IV board report
Solo
❌
Pro
✅
Enterprise
✅
External report sharing
Solo
❌
Pro
✅
Enterprise
✅
White-label reports
Solo
❌
Pro
❌
Enterprise
✅
POPIA (mandatory)
Solo
✅
Pro
✅
Enterprise
✅
Cybercrimes Act
Solo
✅
Pro
✅
Enterprise
✅
FSCA Joint Standard (financial)
Solo
✅
Pro
✅
Enterprise
✅
ISO 27001 readiness hub + gap analysis
Solo
❌
Pro
✅
Enterprise
✅
Custom framework mapping
Solo
❌
Pro
❌
Enterprise
✅
Jira remediation sync
Solo
❌
Pro
✅
Enterprise
✅
GitHub issues sync
Solo
❌
Pro
✅
Enterprise
✅
Linear sync
Solo
❌
Pro
✅
Enterprise
✅
SSO (SAML/OIDC)
Solo
❌
Pro
❌
Enterprise
✅
Users
Solo
1
Pro
Up to 10
Enterprise
Unlimited
vCISO multi-tenant portal
Solo
❌
Pro
❌
Enterprise
✅
Multi-organisation clients
Solo
❌
Pro
❌
Enterprise
✅
Priority support + SLA
Solo
❌
Pro
❌
Enterprise
✅
Yes. Solo is R0/month forever for a single user. No credit card required at signup. Annual quotas reset on your signup anniversary.
Yes. Your organisation data, risks, policies, and POPIA scores carry over when you upgrade to Pro or Enterprise.
Paystack for South African cards and recurring billing. Annual Pro plans can also be paid by EFT — contact us for an invoice.
Founding members get 50% off the first year of Pro. Contact [email protected] with your company details.
Yes. Application data and evidence files are hosted in AWS af-south-1 (Cape Town) with KMS encryption. Authentication services use Supabase (EU) covered by a Section 72 Transfer Agreement. All evidence uploads are stored on South African soil.