Or we can just run it for you.
Most organizations our size do not fail compliance because they lack software. They fail because nobody has the hours. So every module can be bought as a tool you run, or as an outcome we deliver.
Pick how much of it you want to do yourself.
Tool only
You get the software and run it. Published price by population, unlimited users, setup and training included. Best if you have someone whose job this can be.
See the price list →Managed Most chosen
We run it. You get the scans, the fixes, the reports and the reminders, on a schedule, without assigning anyone to it. One flat annual fee, no hourly meter.
What that includes →Project work
A defined piece of work with a start and an end — an audit readiness assessment, a vendor review programme, a full policy set written from nothing. Fixed fee.
See the project list →Everything below is a flat fee. You will never get an invoice with hours on it, and you will never be asked to approve a change order to finish something we quoted.
Stay compliant without touching it.
A consultant charges five figures for an audit that tells you what is broken and then leaves. We find it, write the fixes, hand them to whoever maintains your site, check the work, and produce the dated conformance report — every quarter, for less than that one audit cost.
What we do for you, every quarter
- Full crawl and scan of your public site against all 86 WCAG criteria
- We triage the findings — you never see a raw list of 800 issues
- A prioritized fix list, with the corrected markup, for your web team or vendor
- We review the human-judgement items ourselves rather than leaving them to you
- Re-scan to confirm the fixes actually landed
- A dated conformance report for your file, and a one-page summary for your council
- We tell you when something new on the site breaks compliance, between scans
| Population | Tool only | Managed |
|---|---|---|
| Under 10,000 | $1,200–2,400 | $4,800 $400/mo |
| 10,000 – 50,000 | $3,600–4,800 | $9,600 $800/mo |
| 50,000 – 150,000 | $9,600 | $19,200 $1,600/mo |
| Over 150,000 | See pricing | Let's talk |
Why this is the one most people take
The April 2027 deadline is not a one-time job. Your site changes every week, and every change can break it again. Managed is the only version of this that is still true a year from now.
You are responsible for your vendors. Almost nobody checks them.
A typical city has somewhere between fifty and two hundred vendors touching its systems or its residents' data. CJIS expects you to assess them. IRS Publication 1075 expects it. Your cyber insurance renewal asks about it. Most organizations answer honestly and hope the question moves on.
What an assessment covers
- What data the vendor actually touches, and how it reaches them
- Their security posture — certifications, audit reports, breach history
- The contract terms that matter: breach notification, data ownership, right to audit, what happens at termination
- Where they fall short, written plainly, with what to ask them for
- A risk rating you can defend to an auditor, recorded in Census against that vendor
- Re-assessment on a schedule, so it stays current rather than becoming a stale PDF
| Assessment | Fee |
|---|---|
| Standard vendor Limited or no access to resident data | $750 |
| Critical vendor Holds resident data or has system access | $1,500–2,500 |
| Annual programme 20 vendors assessed, tracked and re-reviewed | $12,000–18,000 per year |
| One-time inventory Find and rank every vendor you actually have | $3,500 |
Start with the inventory
Most organizations cannot name their vendors, let alone rank them. The one-time inventory tells you who you are actually exposed to, and usually finds three or four nobody remembered.
The audit is coming either way.
CJIS, IRS Publication 1075, HIPAA, PCI, state information security reviews. The finding is rarely that you were insecure. It is that you could not produce evidence of what you were doing. We prepare you, sit with you through it, and leave the system behind so the next one is easier.
| Engagement | Fee |
|---|---|
| Readiness assessment CJIS, IRS 1075, HIPAA or state review. Where you stand and what to fix first | $8,000–15,000 |
| Full audit support Preparation, evidence, responses, and we are on the calls with you | $15,000–30,000 |
| Annual compliance programme Continuous. Controls attested, issues closed, always audit-ready | $18,000–36,000 per year |
| Incident response retainer A number to call at 2am, and someone who answers | $6,000–18,000 per year |
What makes this different from a consultant
A consulting engagement ends with a document. Six months later the document is out of date and the work has to be paid for again.
Everything we do lands inside Verifort instead: the controls, the evidence, the issues, the owners, the dates. When the next audit comes, the answers are already there and already current. You are paying once to build something, not repeatedly to describe it.
The software is included for the length of any annual programme.
Policies nobody has time to write.
Most organizations have a policy folder that is either empty or fifteen years old. Both answer an auditor the same way.
| Engagement | Fee |
|---|---|
| Full policy set Written from nothing, for your organization, adopted and in force | $6,000–12,000 |
| Review and refresh Your existing policies brought current and gaps filled | $3,500 |
| Annual maintenance Reviewed every year, updated when the rules change | $2,400 per year |
| Incident response plan Written, and tested with your staff in a tabletop exercise | $4,500 |
| Security strategic plan A multi-year plan you can put in front of a council | $5,000–9,000 |
Written to be read
Policies get ignored because they are written for lawyers. Ours are written so the person who has to follow them can understand them in one pass — plain English, short, and specific to how your organization actually works.
Delivered inside Katalogo, so they are searchable, version-tracked and set for annual review from day one.
Founding customers
The first ten organizations to come aboard get 40% off every price on this site, locked for three years — software and services both. In return we ask to use your name as a reference once you are happy. That is the whole deal, and it closes when the ten are taken.
Not sure which of these you need?
Most people are not. Tell us what is worrying you — a deadline, an audit letter, an insurance questionnaire you cannot answer — and we will tell you honestly what would actually help, including when the answer is that you do not need us.
Start there