Where to start
Not sure where to begin?
Start where you actually are.
A stage-by-stage roadmap showing what most companies need at each phase — from your first policy to a full risk program. No sales call. No pressure to over-buy.
Stage 1
Just Founded
1–10 people · Pre-seed to Seed
You're building product and closing first customers. Compliance isn't the priority yet — but you can't answer basic security questions from prospects either.
What you usually need
- Foundational policies (Acceptable Use, InfoSec, Data Handling)
- A basic security posture snapshot
- Something to send when a prospect asks 'are you SOC 2?'
Scarlet Go — $25/moSee planStage 2
Early Traction
10–25 people · Seed to Series A
First real enterprise deals are showing up. Security questionnaires are landing in your inbox. You need to show buyers you take risk seriously — without hiring a CISO.
What you usually need
- Vendor risk tracking as your stack grows
- Answering security questionnaires without stalling deals
- Basic incident response plan on file
- Board-ready posture summary each quarter
Scarlet Pro — $99/moSee planStage 3
Getting Serious
25–75 people · Series A to B
Deals are gated on SOC 2 or HIPAA. You need real readiness — not just paperwork — before spending on a full GRC automation platform.
What you usually need
- SOC 2 / HIPAA / PCI readiness assessment
- Continuous world-watch on threats to your industry
- Formal risk register with owners and due dates
- Executive reporting cadence
Scarlet Pro or EliteSee planStage 4
Scaling SMB
75–200 people · Series B+
Multiple frameworks in flight. Real customers, real regulators, real board scrutiny. This is where a dedicated risk program starts to pay for itself.
What you usually need
- Multi-framework program (SOC 2 + HIPAA, or CMMC for defense)
- Deeper vendor risk and fourth-party exposure
- Regulatory tracking across jurisdictions
- Named risk owner (fractional or full-time)
Scarlet Elite — $250/moSee planStage 5
Enterprise-Ready
200+ people
You've outgrown the foundation. Time to layer in dedicated GRC automation (Vanta, Drata) for certification — while keeping Scarlet as your intelligence layer.
What you usually need
- Certification automation platform for continuous audit evidence
- Scarlet stays on as risk intelligence + world monitoring
- Dedicated seats for internal audit, legal, and security teams
- Custom reporting for enterprise buyers
Scarlet Team — $500/moSee plan
Still not sure which stage fits? Run the ROI calculator or try the scoping calculator — both take under two minutes.
Stop guessing.
Start knowing.
AI-powered risk intelligence that shows you exactly where you're exposed — and what to do about it. Live in minutes.
Get started