Overview
Stop Security Compliance Nightmares with Scytale:
Manage compliance in one hub, automate evidence collection, cross-map controls, and get real-time alerts with 24/7 continuous monitoring.
Scytale is the global leader in compliance automation serving customers worldwide to get and stay compliant with frameworks like SOC 2, ISO 27001 and GDPR. With every security and compliance workflow managed inside Scytale, every requirement relating to your GRC program is centralized in one hub, your complete security and compliance solution.
Selected by G2 as Best Seller 2025 and trusted by thousands of customers worldwide.
- Streamlines frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, POPIA, (and many more).
- Platform enables automated evidence collection, continuous control monitoring, vendor risk management, automated user access reviews and many more key features.
- Reduces time to compliance by up to 90% with 24/7 continuous monitoring.
- Secured, in-house GRC expert services offer dedicated and tailored guidance from start to finish of your compliance journey, leading you through each compliance requirement and getting you audit-ready with confidence.
- Seamless integration into 30+ AWS (e.g., Security Hub, Config, CloudTrail) and over 100 cloud integrations.
In addition, Scytale offers other core solutions including Penetration Testing and AI Security Questionnaires, as well as Trust Center solutions.
Highlights
- Cut your audit preparation time in half through continuous monitoring with automated evidence collection, auditor-approved policy templates and more.
- Dedicated GRC experts, guiding customers throughout the audit-readiness process, the external audit and beyond. Exclusive discount on AWS Marketplace Private Offers available - Reach out to find out more.
- Trust Center solutions, Penetration Testing, AI Security Questionnaires and other core security solutions, making Scytale your only complete security and compliance platform.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(1)

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Software Platform - Security Compliance Automation Hub | Software Access & 1 framework - Starting price (per org size, get quote) | $7,500.00 |
Service Package - Additional Platform Framework (i.e. SOC2, ISO 27001, PCI DSS) | One framework automation & support - starting price (get quote) | $2,100.00 |
Service Package - Framework Consulting | Dedicated compliance expert support - starting price (get quote) | $4,000.00 |
Service Package - Offensive Security (PT) | Advanced security penetration testing - starting price (get quote) | $4,500.00 |
Service Package - Virtual Compliance | Personal vGRC/vDPO expert full support - starting price (get quote) | $36,000.00 |
Service Package - Security Questionnaires | Security Questionnaires with AI and expert review - starting price (get quote) | $12,000.00 |
Service Package - 3rd Party Audit | 3rd Party Audit Services offered. | $4,200.00 |
- | - | $0.00 |
Vendor refund policy
100% refund for first 7 days
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Sudden access suspension has disrupted compliance work and raises serious trust concerns
What is our primary use case?
My usual use case for Scytale is for ISO 27001 compliance.
What is most valuable?
The inbuilt framework was reasonable on 27001, and the policy support was reasonable. Scytale's customizable policy framework seems acceptable.
What needs improvement?
Scytale unilaterally suspended access because in their opinion, I don't know why they did that. I'm assuming they think that we're competitive, which we're not. They sold us the system and sent a contract to us in full knowledge of what we do as a business. Compliance is a very broad word; we provide compliance into nonprofits, housing associations, markets that these guys do not serve. Somebody inside Scytale likely thought, "Oh my God, these guys must be competitive, so let's just cut them off." I'm assuming that's what happened, but there was no explanation, nothing.
Scytale did not help me streamline my compliance processes. It didn't really identify gaps. There was no gap analysis in there that we could see. I didn't really get that far to use the effectiveness of Scytale's real-time insights in identifying potential compliance issues. All my experiences with Scytale have been negative. We haven't used the automated evidence collection of Scytale. Scytale has not helped me allocate resources more efficiently for compliance; it's been the opposite experience. We have put six months of effort into looking at the controls on 27001, talking about auditors, getting audit-ready, and so forth. But we've invested significant time, which has now been a complete waste of time.
Scytale is not only unreliable, considering they can suspend access without any notice or formal reason, but this lack of stability results in serious concerns about their dependability as a partner. If they can do that without explanation, my fear is that even if they switch it on again, who's to know in three months' time that the same thing couldn't happen again?
For how long have I used the solution?
I have been working with Scytale for about six months.
What do I think about the stability of the solution?
Scytale is not reliable at all; not stable. You would be unwise to put a mission-critical function like ISO 27001 on Scytale. From one to ten, I would rate the stability and reliability of Scytale as a one.
How are customer service and support?
We have communicated with the technical support and customer service of Scytale. My experience with them is that the response time is very slow from Scytale. You get a ticket, and maybe a couple of days later, people might get back to you. When we asked Scytale for an explanation as to why they did what they did, there was no response—either direct LinkedIn messages out to their CEO and senior management team or in-app messages to their customer support service—just no response. I thought they'd gone out of business; that was my assumption when we couldn't access the system. Based on my experience with the technical support, I would definitely rate them a one.
Which solution did I use previously and why did I switch?
We did not use a different solution for these use cases before Scytale.
How was the initial setup?
Initially, I participated in the setup and deployment of Scytale, but then it was passed on to a staff member.
The processes I participated in during the setup of Scytale were straightforward; it was acceptable and fine.
Which other solutions did I evaluate?
We did evaluate other options and vendors before choosing Scytale; we looked at Vanta and Drata . We decided to go with Scytale over Drata or Vanta because we thought the interface was a bit nicer, and we thought that maybe they were a smaller company that we would get better support from as opposed to Vanta.
What other advice do I have?
We're going to sue Scytale, and we're going to sue Amazon as well because they're technically the people we're paying.
My feedback on Scytale is that it's terrible.
Currently, it's actually useless to us. When we were using it, it was good.
We used elements of integration into our core subsystems.
We were working with it and building it up; we had spent probably about a man-month in that six months, which has now been a wasted effort.
We've had a month of a man-month of effort, and now we have to go back to square one, go to Vanta or go to Drata or one of the other competitors, and that's what we're going to do next.
Scytale unilaterally suspended access because we have a subscription through Amazon marketplace, paying monthly, and we're not direct competitors with Scytale. We provide compliance services into specific vertical markets like credit unions and financial institutions. We don't do security compliance, which is their bread and butter or their primary market.
We went back because we were using Scytale for ISO 27001 certification and had put about six months' work into it. There was no formal reason, no notice, nothing. We just tried to log in one day and couldn't, and then reached out; a junior customer service representative said, "Oh, no, it's with our legal department," and provided no explanation.
I rate this review overall as a one out of ten.