On this page
Strike Graph is compliance software that collects evidence and uses Verify AI to check uploaded files against evidence descriptions you write. It fits a team that already runs its security controls and wants help reviewing the records they produce. Skip it if your custom systems need the REST Evidence API, which is listed only on the Enterprise plan, and Enterprise is out of budget. Your independent CPA still decides whether the evidence is sufficient.
Compare with: our Vanta review for connected-system testing and auditor population views, our Secureframe review for guided first-audit preparation, or our Thoropass review for a connected software-and-audit purchase.
Pros
- Checks attachments against your own evidence descriptions
- Reuses controls and evidence across frameworks
- Supports an auditor role and audit-workbook export
- Publishes Scale and Enterprise starting prices
Cons
- Evidence API is listed under Enterprise
- Free signup caps attachments at 15
- Certify has no published base price
- Evidence history and auditor permissions need proof
Strike Graph’s LinkedIn page describes a privately held company founded in 2020 and based in Seattle (checked September 29, 2026). Press coverage reports a $3.9M seed round in October 2020, and Strike Graph and Corporate Compliance Insights reported an $8.5M round led by BAMCAP in December 2023. Its software profile holds the company and product facts. Verify AI is the platform’s evidence-validation feature; check that your quoted plan includes the collection and validation features you need. Where Strike Graph sits among other platforms is in our SOC 2 software guide.
We have not tested Strike Graph’s connectors or Verify AI in a live environment or interviewed its users.
What does Strike Graph’s AI check about your evidence?
Verify AI checks attachments against the evidence descriptions your team supplies. It can help review policies, screenshots and exports, provided your descriptions ask for the right proof. Your CPA must still assess whether the evidence shows that a control operated throughout the SOC 2 audit period.
The Verify AI product page describes validation of new and updated files and lets customers enable it for individual evidence items. The integrations page describes collection on a schedule you define. Those are different jobs: collecting a newer document, checking its content, and retaining the evidence a CPA needs.
| Work you need done | What Strike Graph describes | What to check in the demo |
|---|---|---|
| Collect records from an existing tool | Basic (e.g. AWS, Google Drive, Microsoft 365) and Advanced (e.g. GitHub, GitLab, Azure AD) groups; plan gating for Advanced is not shown. Scheduled collection. | Each system's group and plan inclusion; the exact record, permissions and refresh schedule; whether required fields are collected. |
| Bring in evidence from a custom system | Two routes: AI Security Assistant generates integration configurations or API calls, and a REST Evidence API is listed under Enterprise. | Which route is in the order, who reviews and maintains generated code, and what happens when the source API changes. |
| Check an attachment | Verify AI compares it with your evidence description; you can enable it for individual items. | Whether an incomplete or out-of-period file is flagged, and whether the explanation identifies what is missing. |
| Support the CPA's examination | An auditor role and full audit-workbook export are listed. | Access to definitions, populations, attachment versions and timestamps for the agreed period, including after the contract ends. |
Sources: Strike Graph's integration routes, Verify AI description and paid-plan cards, checked October 4 and 5, 2026. The last column is our proposed acceptance test, not a report of successful product testing.
The Enterprise gate applies to one of those two custom-source routes. Strike Graph’s integrations page describes the Evidence API as the way to push records from custom applications, legacy systems and high-scale deployments, and describes generated configurations as the way to build custom connections. The pricing page lists AI Security Assistant on the Certify card (Basic) and the Scale card (Advanced), so the generated route is not an Enterprise feature. Test it against your source before treating Enterprise as required, and price the maintenance of any code it produces. If the source needs the REST API and your contract excludes it, you are left with generated code or manual uploads.
Strike Graph’s reusable controls and cross-framework mappings may save work when you add ISO 27001 to an existing SOC 2 program. Ask the assessor which records you can reuse and which need more work. A mapping only helps where the evidence meets both frameworks’ requirements.
The evidence description shapes the check. For a quarterly access review, “a list of users” asks for less than “the complete in-scope user population, reviewer approval, review date and resolved exceptions for this quarter.” Test both descriptions against the same incomplete file to see how Verify AI responds.
How should you test Strike Graph before buying?
Test one control you already operate in the plan you intend to buy. A quarterly access review lets you check population completeness, approval, dates and exceptions. Save the results with the proposal.
- Connect the systems you use. Include a representative source from each system you cannot replace: cloud, identity, code repository and endpoint management where applicable. Ask which of them sit in the Advanced group and whether your plan includes it. Retrieve the required fields and a dated artifact. For a custom source, confirm whether you need generated integration code or the Enterprise Evidence API. Have the implementer show the permissions and name who maintains the connection.
- Challenge the evidence description. Prepare a complete review file, a copy missing reviewer approval, and a copy from the wrong quarter. Use the same precise description for all three. Record which files Verify AI accepts or flags and the explanation it gives; have your CPA assess whether the distinction is useful. Confirm which evidence items have validation enabled and how checks consume the quoted allowance.
- Check a failed connection. Revoke a test connection’s permission, then restore it. Save the failure notice, last successful collection time and recovered record. Check whether the screen distinguishes an old artifact from current evidence. Include a departed user or unmanaged device when testing identity or endpoint collection.
- Give your CPA a past-quarter request. Invite the intended CPA using the proposed auditor role. Ask for a past-quarter sample after uploading a newer file. Export the workbook and associated evidence, including versions, dates, approvals and comments. Have the CPA identify what they can retrieve independently and what your team must send separately.
- Confirm the contract and exit terms. Get the Evidence API, Verify AI allowance, implementation help and its duration, auditor seats, renewal terms, and bulk export after cancellation in writing. Open a sample archive outside Strike Graph to check that it is usable, and name an owner for any custom code.
Ask to run these checks in a Strike Graph demo before signing. Clean sample files and an overall G2 rating tell you little about missing evidence or a failed connection. The separate free signup has a smaller scope, described below.
What do Strike Graph reviews and complaints establish?
Customer reviews can help you assess usability and support, but do not measure Verify AI’s accuracy or audit outcomes. Strike Graph’s G2 rating was 4.6/5 across 196 reviews on September 29, 2026. This is G2’s overall software rating, not our rating or a score for Verify AI.
Capterra’s Strike Graph page showed 4.7/5 from nine reviews when checked October 5, 2026. Although the page says it was updated October 1, the visible reviews date from May 2023 to April 2024. Seven are marked vendor-referred with an incentive; two are non-incentivized. This is a small historical software-and-services sample, not a current Verify AI evaluation.
The reviews repeatedly praise human support. A July 2023 CTO valued the account manager and templates but found few integrations useful for that company’s needs. A May 2023 administrative-services manager described a Google Drive sync problem resolved with support. Use those accounts to ask who will help when collection fails and what support your contract includes. They describe those customers’ experience in 2023, so confirm the current integration coverage in your demo.
Glassdoor’s Strike Graph reviews cover employment, not the compliance product.
What does a Strike Graph quote need to include?
Strike Graph does not publish a Certify base price; Scale starts at $21,500/year and Enterprise at $35,000/year. Certify offers a free trial. The separate free-signup page describes up to 15 attachments, a risk assessment, Office 365 and Google Drive connections, and expert support. Treat these as limited ways to try the product; neither promises a complete, permanently free SOC 2 program.
| Plan | Listed starting price | Annual total: plan alone to plan + Verify AI Pro | Listed features that set the tier |
|---|---|---|---|
| Certify | Not published; free trial | No figure to add; Verify AI is listed from Scale | One Tier 1 framework, unlimited risks, controls and evidence, role management, audit-workbook export |
| Scale | $21,500 | $21,500 to $31,500 | One framework from any tier, Verify AI, advanced AI and readiness tools |
| Enterprise | $35,000 | $35,000 to $45,000 | Everything in Scale plus Evidence API, custom frameworks, enterprise workspaces, multi-domain reporting |
Checked October 5, 2026 against the pricing page. Verify AI consumption add-ons are listed at $4,250 (Starter, 350 credits per month), $6,500 (Standard, 750) and $10,000 (Pro, 1,000). The top of each range adds Pro; Standard would give $28,000 on Scale and $41,500 on Enterprise. The bottom assumes the plan's own allowance covers your use, and the pages do not say what the base plan includes. These sums are our arithmetic on listed figures, not quotes. Starting prices are floors that exclude additional frameworks and services, the trial duration is not specified, and Launch, a plan listed in late September, no longer appears.
The $13,500 gap between the Scale and Enterprise starting prices is the listed cost of reaching the Evidence API, and it also buys custom frameworks, enterprise workspaces and multi-domain reporting. If the API is the only Enterprise feature you need, test generated integrations first. The audit is a separate cost, covered below.
Ask for a quote covering your frameworks, collection method, implementation work, validation usage and CPA fees. Before estimating the cost of checks, ask what allowance the base plan includes and what consumes a credit. A plan card that lists Verify AI does not promise unlimited use.
Can you keep your own CPA with Strike Graph?
Strike Graph says you can bring an independent auditor. Its pricing FAQ also offers introductions through its network. Your chosen CPA performs the examination and issues the SOC 2 report. Strike Graph’s “AI internal auditor” is its evidence-checking software.
Attestation-capable CPA firms in our directory whose records list Strike Graph: 1. For comparison, 41 list Vanta and 13 list Secureframe. The listing does not confirm a native integration or a completed Strike Graph engagement, and the count covers our directory, not the vendor’s partner network. If your CPA is already chosen, ask whether it has received a Strike Graph export before you sign. Compare independent SOC 2 audit firms and ask each candidate to complete the export test above.
Get the audit quote from the firm that will sign the report. Strike Graph’s pricing FAQ says independent auditors set their own prices. It separately gives a $4,000–$8,000 annual range for assessment and audit services for approved certifications. Confirm which certification that fee covers; it is not a universal SOC 2 price. Get the SOC 2 report issuer, examination scope and fee in writing.
When should Strike Graph stay on your shortlist?
Keep Strike Graph on the shortlist if it can collect the records you need and its evidence checks reduce your review work. Use the incomplete-file test and your CPA’s past-quarter export request to make that decision. Confirm the required features in the proposal.
| Buying situation | Shortlist direction | Reason |
|---|---|---|
| You already run controls and need to review attachments for several frameworks | Strike Graph, subject to the evidence test | Your own evidence descriptions guide validation. Confirm whether standard connections cover your sources. |
| A custom or legacy system must push records by REST API, and Enterprise is not in budget | Skip, unless generated integrations pass your demo | The Evidence API is listed only on Enterprise. The generated route needs a code owner on your side. |
| You need the software to tell you which controls and evidence a first SOC 2 requires | Secureframe for preparation guidance | Verify AI checks files against descriptions you write. It does not decide what the descriptions should ask for, and implementation help is unconfirmed. |
| Procurement needs a published base price before the first call | Skip Certify until you have a quote | Certify lists no base price. Scale and Enterprise publish starting prices, which are floors. |
| Your CPA wants connected-system populations in a documented audit workflow | Vanta review | Vanta documents full and controlled auditor population views. Strike Graph lists an auditor role and workbook export; a request-list workflow is not established. |
| You want software and an audit bought together | Thoropass for its affiliated audit route | Preparation help and an audit cover different work. Confirm who implements controls and who issues the opinion. |
These are buying options to investigate, not a claim that every competitor has every feature. Use each linked review to check the package details and evidence limits.
For Strike Graph vs Vanta, test what each does with your evidence. Strike Graph describes checking attachments against your evidence definitions; Vanta combines connected tests with customer-controlled auditor views. Run the same missing-approval test and past-quarter request in both to compare how much work each leaves your team.
Save the accepted and rejected sample files, the export your CPA reviewed, and the proposal naming the collection method and validation allowance. For more platforms, use our SOC 2 software comparison or browse the software directory.
More in Compliance Tools