Assessment pricing

Choose the assessment depth that matches the decision.

ApertureRisks begins with a defined exposure decision, not an open-ended platform subscription. Select the scope that best reflects the number of questions, operating records, risk categories, jurisdictions, and dependencies involved. Final scope and price are confirmed before payment.

Qualification does not create a contract, authorize payment, or begin the delivery period.

Assessment options

Three assessment scopes. One evidence standard.

Every assessment preserves the same evidence, lineage, human-review, and Not assessed safeguards. The scope changes with the complexity and depth of the decision.

Secure row ingestion creates an evidence-backed baseline for the exposure questions the approved scope covers.

DEFINED ENTRY SCOPE

Essential Exposure Assessment

Fixed price, 1,500 US dollars, one time

Fixed price for the Essential scope below.

Best for one urgent, well-defined exposure decision supported by usable, structured records.

Includes

  • One scoped exposure question
  • One operating context
  • One primary risk category
  • Up to 50 accepted supplier and operating records
  • One approved source file or equivalent structured intake
  • Evidence-backed exposure baseline
  • AR-Score basis when evidence supports assessment
  • Evidence gap and prioritized action register
  • One executive Decision Brief
  • One human review
  • five-business-day delivery target after accepted intake and scope confirmation

Not included

  • Continuous monitoring
  • Live integrations
  • Extensive data cleansing or reconstruction
  • Multi-tier network discovery
  • Custom governance and SSO
  • Legal, customs, insurance, financial, audit, or certification determinations
  • Guaranteed outcomes

CONNECTED EXPOSURE SCOPE

Expanded Exposure Assessment

Starting at 3,500 US dollars. Final price confirmed in the approved written scope

Final price is confirmed in the approved written scope.

Best for connected exposure questions, multiple dependencies, or greater evidence and data complexity.

Includes

  • Up to three connected exposure questions
  • Up to three risk categories
  • Up to 250 accepted supplier and operating records
  • Multiple approved source files
  • Limited connected operating contexts
  • Multiple jurisdictions when bounded in writing
  • Cross-dependency exposure analysis
  • Comparative AR-Score analysis when evidence supports assessment
  • Scenario comparison
  • Expanded evidence gap and action register
  • Executive Decision Brief
  • One executive review session
  • Limited data normalization when expressly included in the written scope
  • seven-to-ten-business-day delivery target after accepted intake and scope confirmation

Not included

  • Live production integrations unless separately approved
  • Unlimited data remediation, cleansing, or source reconstruction
  • Continuous monitoring
  • Custom SSO and custom governance controls
  • Legal, customs, insurance, financial, audit, or certification determinations
  • Guaranteed outcomes

COMPLEX OR GOVERNED SCOPE

Enterprise Exposure Assessment

Custom scope. Price confirmed in writing before payment

Written scope, price, delivery target, security requirements, and governance requirements are confirmed before payment.

Best for multi-business-unit, multi-jurisdiction, multi-tier, integrated, or governance-intensive exposure decisions.

Suitable when the engagement involves

  • More than 250 records
  • Multiple business units, operating regions, or jurisdictions
  • Tier-two or deeper supplier analysis
  • Product, revenue, facility, or lane dependency mapping
  • Material customs or compliance complexity
  • ERP, procurement-system, TMS, SFTP, or API intake
  • Custom security controls and custom data retention
  • SSO requirements and custom governance
  • Board-level and multi-stakeholder reporting requirements
  • Bespoke evidence, validation, and human-review requirements

Not included

  • A published price, because scope determines cost
  • Online purchase without a written scope
  • Legal, customs, insurance, financial, audit, or certification determinations
  • Guaranteed outcomes

What determines assessment scope?

Decision questions

The number of related exposure decisions the engagement must support.

Record volume and condition

The number, structure, completeness, duplication, accessibility, and usability of submitted records.

Risk categories

The number of disruption, compliance, supplier, customs, logistics, financial, or operating categories involved.

Operating complexity

The number of facilities, business units, products, jurisdictions, suppliers, regions, or lanes affected.

Evidence depth

The amount of corroboration, scenario comparison, dependency tracing, validation, and human review required.

Integration and governance

Requirements involving SFTP, ERP, procurement systems, TMS, APIs, SSO, retention, security, or custom controls.

What counts as an accepted record

Accepted records are usable, in-scope records that meet the published intake structure after validation. Data remediation, enrichment, translation, deduplication, or reconstruction may require an Expanded or Enterprise scope.

Which assessment fits?

Choose Essential when

  • One scoped exposure question.
  • Records are already structured and usable.
  • One primary risk category.
  • One operating context.
  • No integration is required.
  • No extensive remediation is required.

Choose Expanded when

  • Questions or dependencies are connected.
  • Several risk categories affect the decision.
  • Multiple source files must be reconciled.
  • Multiple scenarios must be compared.
  • Limited normalization is required.
  • An executive review session is required.
  • The scope remains bounded in writing.

Choose Enterprise when

  • The scope crosses business units.
  • The scope crosses jurisdictions.
  • The scope crosses supplier tiers.
  • The scope crosses operating systems.
  • Integrations are required.
  • Custom security or custom data retention is required.
  • SSO or custom governance is required.
  • The evidence requirements cannot be responsibly bounded by the Expanded scope.

Compare the three assessment scopes

Free tools and post-assessment monitoring are not assessment scopes and are described separately below.

Assessment scope comparison across Essential, Expanded, and Enterprise Exposure Assessments
CapabilityEssential$1,500 one timeExpandedStarting at $3,500EnterpriseCustom scope
Exposure questionsOne scoped exposure questionUp to three connected exposure questionsDefined in the written scope
Accepted recordsUp to 50Up to 250Defined in the written scope
Risk categoriesOne primary risk categoryUp to three risk categoriesDefined in the written scope
Source filesOne approved source file or equivalent structured intakeMultiple approved source filesDefined in the written scope
Business unitsOne operating contextLimited connected operating contextsDefined in the written scope
JurisdictionsOne operating context unless jurisdictional complexity is minimalMultiple when bounded in writingMultiple
Supplier-tier depthFirst-tier and supplied dependency evidence onlySelected dependency tracing where evidence is provided or available within scopeMulti-tier or bespoke
Scenario comparisonNot includedIncludedDefined in writing
Data normalizationNot included beyond intake validationLimited normalization when stated in writingDefined in writing
Executive Decision BriefIncludedIncludedDefined in writing
Executive reviewOne human reviewOne executive review sessionDefined in writing
Delivery targetFive business days after accepted intake and scope confirmationSeven to ten business days after accepted intake and scope confirmationDefined in writing
Live integrationsNot includedNot included unless separately scopedAvailable in the written scope
SSO and custom governanceNot includedNot includedAvailable in the written scope
Continuous monitoringNot includedNot includedSeparate post-assessment scope
Pricing$1,500 one timeStarting at $3,500Custom

Commercial boundaries

What no assessment price includes by default

These boundaries apply to Essential, Expanded, and Enterprise alike. Anything below enters an engagement only through an approved written scope.

  • Continuous monitoring after delivery.
  • Live system integrations unless stated in writing.
  • Unlimited data cleaning, enrichment, translation, deduplication, or reconstruction.
  • Legal, customs, insurance, financial, audit, certification, or compliance determinations.
  • Guaranteed identification of every disruption or dependency.
  • Guaranteed financial or operational outcomes.
  • Automatic action without human review.
  • Work outside the approved scope.
  • Taxes and additions approved in a written scope are extra.

Client-specific AR-Scores require connected evidence. Insufficient or contradictory evidence remains Not assessed rather than being converted into a fabricated score.

ApertureRisks provides decision support. Recommendations require human owner review before action.

After the assessment

Continue only when the evidence and operating requirements justify it.

A completed assessment may lead to no continuation at all, to a Monitoring Pilot, or to an Enterprise Operating Engagement. Continuation is never automatic. Monitoring and Enterprise follow only when the findings justify the next scope.

Optional post-assessment continuation

Monitoring Pilot

Monitoring adds recurring intelligence and Action Center workflows after a usable baseline exists. Scope depends on monitored entities, signal categories, refresh cadence, action owners, review frequency, workflow requirements, and the monitoring period.

No recurring price is published, and monitoring is not part of any assessment price.

Discuss Post-Assessment Monitoring

Qualified post-assessment operating scope

Enterprise Operating Engagement

Enterprise adds governed integrations and expanded topology when the assessment identifies multi-business-unit, SSO, custom-security, retention, custom-governance, recurring-workflow, or expanded stakeholder reporting requirements.

This is an operating engagement after delivery. It is not the Enterprise Exposure Assessment described above.

Discuss an Enterprise Operating Engagement

Evaluate readiness before qualification.

Try the free Scenario Sandbox, check your file structure, or read one short file of your own in the Private Exposure Preview. Neither tool is an assessment, and neither produces a client AR-Score.

Free

File-Structure Check

See whether your supplier file structure is ready for an assessment. Only column headers are sent. Supplier rows are not transmitted or retained. It evaluates intake structure only, does not assess exposure or supplier risk, and does not produce an AR-Score. It is not a free assessment.

Run the File-Structure Check

Free

Scenario Sandbox

Walk through the product experience on synthetic records, fully in your browser. Client records are not uploaded or retained, and the output is an illustrative sample brief, not a client assessment. It is not a free assessment.

Open the Scenario Sandbox

Free, once per address

Private Exposure Preview

Read a short supplier file in your own browser against one hypothetical disruption. The file is not uploaded and no part of its contents reaches us. Access is by emailed single-use link, so the address you give is processed by our email provider. It is not an assessment, it does not produce a client AR-Score, and anything your columns do not support is labelled Not assessed. It is not a free assessment.

Request preview access

Pricing questions

Is $1,500 the price of every assessment?

No. $1,500 is the fixed price for the Essential Exposure Assessment scope. Connected questions, additional records, multiple risk categories, data remediation, jurisdictions, integrations, governance requirements, or greater evidence complexity may require an Expanded or Enterprise scope.

What does starting at $3,500 mean?

It is the minimum public starting point for an Expanded Exposure Assessment. ApertureRisks confirms the final scope and price in writing before payment.

What is an accepted record?

An accepted record is a usable, in-scope record that meets the published intake structure after validation. Duplicate, incomplete, inaccessible, out-of-scope, or materially unstructured records may require remediation or a different assessment scope.

Does qualification authorize payment?

No. Qualification does not create a contract, authorize a charge, or begin the delivery period.

When does the delivery period begin?

The delivery period begins after the scope is accepted, payment is completed where applicable, and all required usable information has been received through the approved intake path.

Is monitoring included?

No. Monitoring is a separate post-assessment engagement offered only when the assessment establishes a usable baseline and the operating requirements justify continuation.