Pricing Intelligence~6 min read

How the Observatory works

The GRC Pricing Observatory is a living record of what companies actually pay for compliance-automation platforms. It's honest about its own limits: the percentile engine starts at zero individual prices by design, cited external benchmarks carry the launch display while our own sample grows, and every published figure shows its sample size and where it came from. This page is the full method.

The three source classes

Every figure in the Observatory belongs to exactly one class, shown inline so you always know what kind of evidence you're looking at:

  • Self-reported - a buyer told us their own number. The most abundant source, and the reason moderation exists.
  • Document-verified - the figure was read from an uploaded quote or contract, parsed and redacted, and an operator confirmed the read. (How this works is below.)
  • Researched-public - an individual price disclosed in a public source (a forum post, a filing), carried in with its citation.

The explorer lets you view the data three ways - all sources, verified-plus-researched, or verified-only - so you can weigh it by how much scrutiny each figure has had.

Moderation: nothing publishes unreviewed

Every submission lands in quarantine and is reviewed by a human before it can enter the published aggregates. An automated plausibility check drafts an approve-or-review recommendation, but it never auto-approves - the operator decides. This is why the count you see is deliberate rather than instantaneous.

How we protect individual contributors

k-anonymity (no small cells). No published cell is ever computed from fewer than five individual prices. A segment with four contributors shows "not enough data yet," never a number - because a number over a tiny group can point back at a person.

Rounding. Every computed dollar statistic is rounded to the nearest $100 before it is published. (Cited external benchmarks are shown at their published value - we never round someone else's figure.)

On the explorer's sky chart, stars represent sample counts, never individual prices. A constellation's stars and brightness come only from how many prices back a published cell (n≥5) - never from any one company's figure. The single exception is the star you see for your own quote, drawn from your own input, in your own browser session, and never persisted to any public surface.

Class-filtered views appear only when publishing them cannot isolate small contributor groups. If showing a narrower view (say, verified-only) alongside a broader one would let someone subtract one from the other and recover a group smaller than five, the narrower view is withheld for that cell.

The differencing disclosure. We're straight about the limit of that protection: from published totals, the size of a suppressed group may sometimes be inferable (you might deduce "there's one more price in here than the numbers shown"). What is not recoverable is any individual company's price - rounding and the way percentiles interpolate keep a single hidden figure bounded no more tightly than the rounding step, and we test that property against a standing attack harness.

We never alter a disclosed figure

Values are accepted or rejected, never coerced. If a submitted number is malformed or implausible, it's flagged for review or rejected outright - we never quietly round a "$38,000.50" into "$38,000" or reinterpret an ambiguous entry. A figure in the Observatory is the figure someone actually reported.

Document verification

After you submit a figure, you can optionally attach the actual quote or order form - a PDF, PNG, or JPG, up to about 4 MB. Here is exactly what happens to it, and the guarantees behind each step:

  • It's read once by an AI system to extract the figures. The document is passed to the model as content and the structured price fields - the annual total, the platform, the year - are pulled out. Nothing about the file is inferred beyond what it plainly states.
  • Identifying details are redacted. Email addresses, links, and domains are stripped from the short evidence excerpt programmatically; company and contact names are redacted by the extraction step on a best-effort basis and confirmed by a human before any figure is marked verified. A log records what kind of detail was removed - never the detail itself.
  • The file itself is never stored. It's parsed in memory and discarded; we keep only the extracted figures, the redacted excerpt, and a one-way fingerprint of the file used solely to notice the same document uploaded twice. The raw bytes are never written anywhere.
  • Your typed figure is never overwritten. The extracted numbers are compared against what you entered; if they differ, that's flagged for a human to reconcile - the machine never edits what you reported.
  • Verified status is granted only after human review. An upload does not auto-verify anything. The figure carries the document-verified badge only after an operator has confirmed the extraction. Until then it stays a self-reported figure in the moderation queue, exactly like any other.

The consent you confirm at the upload step states this plainly: “Only upload documents you have the right to share. The file is read once to extract figures and is never stored.”

If the document can't be read - a blurry scan, an unusual export - nothing is lost: your self-reported figure stands and you're told the read didn't work. A verified-figure tier isn't unusual in pricing data; what we're describing here is our own mechanism and the guarantees that come with it.

Citing the Observatory

Cite as: GRC Migrate Pricing Observatory, with a link to grcmigrate.com/observatory/ (a link is required). The machine-readable dataset lives at /observatory/data.json.

License. Free to cite and reproduce in part with attribution and a link to grcmigrate.com/observatory/. Bulk redistribution requires permission.

Our independence

We take no vendor money of any kind - no referral fees, no affiliate links, no demo bounties. Our revenue comes only from service partners we never rank.

Other independent SaaS-pricing datasets exist and some publish their methods too; we don't claim to be the only one. What this dataset does is narrower and specific: GRC platforms, segmented by company size, framework count, and new-versus-renewal, with the sample size and source shown on every figure and a published privacy floor. General SaaS-wide aggregators cover thousands of products broadly; we cover this category closely.

Two datasets, kept separate

GRC Migrate publishes two distinct pricing datasets, and they never mix:

  • Our long-standing curated benchmark set at /data/grc-pricing-benchmarks.json - editorially maintained ranges and medians drawn from procurement and public sources, cited in our pricing guides. It is not gated and stays at that canonical URL.
  • The Observatory dataset at /observatory/data.json - the living, contribution-fed record described on this page, with its own aggregation, moderation, and privacy floor.

The curated set is the reference we've long cited; the Observatory is the new, growing measurement. Cite whichever you mean by its own canonical link - they are not the same dataset.

That's the method - here's the data.

See the live dataset

Every figure on the Observatory carries the sample size and source you just read about.

Independent by structure: we take nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.