Basic digital safety shouldn’t cost anything. That’s why Digital Gnome is free for individuals and very small businesses. Growing organisations pay when they need continuous monitoring, evidence and assurance.
Registers and standards mapping are part of the subscription. Assurance work is the only thing charged separately - and AI-prepared work is included from Protect upwards.
| FEATURE |
Personal
£0
|
Small business
£0
|
Essentials
£24.99
|
Protect
£99.99
|
Assure
From £199
|
|---|---|---|---|---|---|
| Core protection checks | ✓ | ✓ | ✓ | ✓ | ✓ |
| Continuous monitoring | - | Basic | ✓ | ✓ | ✓ |
| Plain-English fixes with steps | ✓ | ✓ | ✓ | ✓ | ✓ |
| App & account settings checks | ✓ | ✓ | ✓ | ✓ | ✓ |
| Email spoofing checks (SPF, DKIM, DMARC) | - | Basic | ✓ | ✓ | ✓ |
| Web address & certificate monitoring | - | ✓ | ✓ | ✓ | ✓ |
| Device & asset register | Basic | ✓ | ✓ | ✓ | ✓ |
| Backups and restore evidence | Basic | Basic | ✓ | ✓ | ✓ |
| Access reviews and leaver checks | - | Basic | ✓ | ✓ | ✓ |
| Policy pack with version history | - | Basic | ✓ | ✓ | ✓ |
| Staff training records and phishing tests | - | - | Basic | ✓ | ✓ |
| AI register | - | - | ✓ | ✓ | ✓ |
| Records of processing (ROPA) | - | - | Basic | ✓ | ✓ |
| Personal data inventory (PII) | - | - | Basic | ✓ | ✓ |
| DPIA workflow | - | - | - | ✓ | ✓ |
| Supplier and processor register | - | - | ✓ | ✓ | ✓ |
| Risk register with 5×5 matrix | - | - | - | ✓ | ✓ |
| Incident log and rehearsals | - | - | - | ✓ | ✓ |
| Standards mapping - CE, CE Plus, ISO 27001, ISO 42001, PCI DSS, DSPT | - | - | - | ✓ | ✓ |
| Evidence library with timestamps | - | - | ✓ | ✓ | ✓ |
| Customer, tender and insurer reporting | - | Basic | ✓ | ✓ | ✓ |
| Named owners, due dates and escalation | - | - | - | ✓ | ✓ |
| Board and audit committee reporting | - | - | - | Basic | ✓ |
| Multi-site scoping and delegation | - | - | - | - | ✓ |
| Single sign-on (SSO) | - | - | - | - | ✓ |
| Directory sync for joiners and leavers | - | - | - | - | ✓ |
| Evidence log export and API access | - | - | - | - | ✓ |
| Priority support and response SLA | - | - | - | - | ✓ |
| AI-prepared assurance work | - | Pay as needed | Pay as needed | Included | Included |
| Expert-reviewed assurance work | - | Pay as needed | Pay as needed | Pay as needed | Allowance |
| Virtual CISO time | - | Pay as needed | Pay as needed | Pay as needed | Days included |
Your subscription covers everyday protection and every register in the table above. Assurance work is the jobs on top of that - and the price depends on who does it.
Drafted by us from your own evidence: included on Protect. Reviewed or signed off by a security professional: charged, because that is a person’s afternoon.
Upload a customer or supplier questionnaire and we draft the answers from your existing evidence - every answer linked to the check that supports it.
Policies, evidence, security statement and supporting documents assembled for a tender.
Assess a supplier and record the evidence against your own requirements.
Record the system, its data, permissions, risks and the controls it needs - and produce the DPIA if one is required.
A full assessment against Cyber Essentials, with the actions required before you apply.
A security leader for the meetings that need one: client pitches, board and audit committee, insurer and regulator conversations, and the “should we actually do this?” calls. Booked by the hour or the day.
Yes, genuinely, and we mean it in the way people rarely do online. There is no card to enter, no trial countdown ticking away in the corner, and no useful features quietly greyed out to nag you into paying. Individuals, families and any business of up to ten people pay nothing, for as long as you want to use it, with the same core checks, reminders and plain-English guidance everyone else gets. We make our money elsewhere: from larger organisations that need audit-ready evidence packs for contracts and insurers, live website and email monitoring, and hands-on help from an assessor. In other words, the people who set the requirements fund the tool for the people who have to meet them. We would rather earn trust from thousands of small businesses than a few pounds from the ones we set out to protect.
Only read-only configuration, never content. We can see who has accounts, whether two-factor sign-in is switched on, how far behind your devices and software are on updates, and what your public web address and email records say to the rest of the internet. We cannot and do not read the contents of your emails, files, messages, customer records or anything else private, and we never make changes to your systems for you without asking first and showing you exactly what would happen. Everything is built to answer one question, where do we actually stand today, and then to help you close the gaps in your own time. If a check ever needs access we do not have, we tell you what it is, why it helps, and let you decide.
No, and that is rather the point. Every finding is written in plain English, with clear numbered steps, a realistic estimate of how long it takes, and an honest note on whether it is a five-minute job or a proper afternoon. A non-technical owner or manager can work through them at their own pace, one at a time, without needing to understand the jargon underneath. If you would rather not do it yourself, you can book hands-on help at £50 per 30 minutes, in slots that suit you, and you are only charged after the work is actually done, never up front. And if you already have an IT company or a capable person in-house, the findings route straight to them with the supporting evidence attached, so nothing falls between the cracks.
That is exactly how it should be, and nothing here is designed to replace them. Findings route to your IT partner with the evidence already attached, so you stop being the go-between forwarding half-understood emails, and the actual work gets closed off and recorded. Most of our business customers keep their existing IT provider and use us as the layer on top that tracks what needs doing, proves what has been done, and produces the evidence a customer, auditor or insurer will ask for. Your IT company handles the systems; we handle the assurance, the reminders and the paper trail. If anything it makes their job easier, because the priorities and the proof are already in one place instead of scattered across inboxes.
Only when nothing free will genuinely do the job, and even then we say so plainly and give you a realistic price rather than a scary one. In fact, several pages in the product exist specifically to talk you out of spending money: antivirus for a single laptop when the built-in protection is fine, or ISO 27001 for a team of eleven when Cyber Essentials is the sensible, affordable step. We take no commission or referral fees for pointing you at a tool, so there is never a hidden reason to recommend something. The honest answer is very often that you already have what you need and simply have not switched it on. We would far rather keep your trust for years than earn a few pounds steering you wrong once.
Any time, with none of the friction other services bury it under. Monthly plans simply stop at the end of the month you cancel in, with no exit fees, no minimum term, and no retention phone call to sit through. Everything you have built, your evidence, adopted policies, registers and generated reports, exports cleanly with you, so you are never held hostage by your own data. There is no penalty for leaving and coming back later, and your account and history are kept for a while in case you do. Quoted agreements for organisations of 125 people or more run on an annual basis for budgeting reasons, but even those come with a clear reminder well before any renewal, so nothing rolls over by surprise.