Coriqo
Pricing & packaging · design partner stage

Straightforward packaging. No self-serve price list to hide behind, no fake numbers to justify.

Coriqo is pre-GA and working with a small number of design partner banks to shape v1 — we say that plainly on our homepage, and we're not going to contradict it here with invented dollar figures. What follows is how we actually think about packaging once you're ready to engage, and honest answers to the questions a procurement team, risk officer, or examiner-facing MRM lead will ask before they'll sign anything.

The packaging below is the same for both verticals. A clinical AI vendor running the healthcare rulepack is scoped on the same terms as a bank — deployment model, model count, and support needs — so the language here says "bank" only because that is where our design partners are today.

Packaging

Priced around deployment model and program size — not a self-serve tier picker.

Every enterprise compliance vendor a bank has ever bought from — Vanta, Drata, your core banking provider — sells this way: publish the shape of the packaging, quote the number after a conversation about your models, your deployment constraints, and your exam calendar. We do the same, with one difference worth being upfront about: at this stage, Coriqo is still shaped by the banks using it.

Design partner
Free / discounted · time-boxed
For the small number of organizations helping us build v1 right now. You get direct input into the roadmap and priority support; we get to build against a real MRM function instead of guesses.
Full platform access — inventory, validation workflow, examiner packages, Merkle attestation
Managed private cloud deployment, provisioned for your organization
Direct line to the founder, not a ticket queue
Pricing and terms revisited together as the product matures — no surprise renewal
Honest scope: roadmap items still in progress will be visible as such, not hidden — see our public capability status
Apply as a design partner
Standard
Contact us · custom quote
For community and mid-size banks, and clinical AI vendors, past the design-partner stage — a defined support SLA and a managed deployment sized to your model inventory.
Managed private cloud — single-tenant schema isolation, your data never mixed with another customer's
Model count and user seats sized to your MRM function, not per-seat metering
Defined support SLA with named response times
CSV/Excel import of your existing inventory, four-eyes rollback included
Standard MSA with a data processing addendum reviewed by your counsel
Talk to us
Enterprise / regulated
Custom · deployment-driven
For banks with on-premise or air-gapped requirements, a formal vendor risk review, or a holding company with multiple charters.
On-premise / air-gapped deployment — Kubernetes-native, no outbound network dependency required to operate
Multi-entity / multi-charter support with consultant-style cross-client views
Enhanced SLA, dedicated implementation support, and a named technical contact
Security review package: architecture diagrams, RBAC model, hash-chain design docs, penetration test summary on request
Custom contract terms, including data escrow / export guarantees (see FAQ)
Request a security review packet
Why no dollar figures on this page

A published price list implies a mature, self-serve product with a stable feature set — that's not an honest description of Coriqo today. We're pre-GA, working with a handful of design partner banks (see our homepage), and pricing that reflects deployment model, model count, and support needs is set per engagement rather than off a rate card that would be fiction. That's standard for regulated-industry software at any stage, not a stall tactic — "contact sales" is how Vanta, Drata, and every core banking vendor your bank already uses prices enterprise deployments too.

Procurement · AWS & Azure Marketplace · listings in review
AWS Marketplace Azure Marketplace

Buy through the cloud you already run on. We're listing Coriqo on AWS and Azure Marketplace, so a purchase draws down your committed cloud spend (AWS EDP / Azure MACC) and clears procurement you have already approved — a shorter cycle and lighter vendor onboarding, since the cloud has already vetted the seller. Being on both clouds is also the point: a verifier you can buy through whichever cloud you run on isn't tied to either one. Both listings are in review now. If you want to move before they go live, ask about a Private Offer — the price, the relationship, and the roadmap stay with us; the marketplace is only the billing rail.

Newly shipped · on every model and agent

Attestation status and evidence turnaround, without leaving the record.

Two things a reviewer used to leave the page to find are now on the model and agent detail view itself — no separate screen, no extra click.

Attestation
Committee sign-off, inline

The newest committee decision on this model — how many required attestations are in, and whether coverage is complete or still open — shown as a KPI on the detail page, one click from the full decision.

Evidence turnaround
Evidence-request ROI, inline

Median turnaround on evidence requests and the estimated hours saved against a manual pull, rolled up org-wide and surfaced right on the model — the number your MRM lead used to have to go dig out of the Evidence Requests screen.

Frequently asked

The questions a procurement team and a risk officer actually ask before they sign anything.

Straight answers, including where the honest answer is "not yet" or "that's still a manual step." If something below doesn't cover your question, email us — we'd rather answer it directly than have you guess.

Deployment & data
Two options today. Managed private cloud: each workspace gets its own Postgres schema (t_yourbank), not a shared row-level tenant column — every request is scoped to that schema centrally, so isolation doesn't depend on every query getting a filter right. On-premise / air-gapped: Coriqo is Kubernetes-native and built to run with no outbound network dependency required to operate day-to-day. One caveat we'll state plainly: our cryptographic checkpoint anchoring optionally posts to a public transparency log (Sigstore's Rekor) for extra verifiability, which needs outbound access — in a restricted-egress environment that step simply queues as "pending" rather than failing, and you can retry it manually whenever a connection is available. Nothing about core operation depends on it.
No. Zero-retention by design: your data is never used to train any model, and schema-per-tenant isolation on Postgres means there's no shared table your records could leak across. Optional AI features (drafting, narration) call out to a model provider per request and are never trained on your data by us or by them under our agreement.
Integration & workflow
On top. Coriqo is read-only by design — it observes and records, it never sits in a serving path and never becomes a runtime dependency for your models. Your committee still meets by calendar invite and email; adding Coriqo's address to that invite is the entire onboarding step for that workflow. Your existing inventory comes in via CSV/Excel import with a real dry-run preview and four-eyes approval, not a forced migration.
Yes — this is most of what a community bank actually governs. Attach the vendor's validation report and model card to the specific version it covers (hash-bound, so "which document did we rely on" has one answer), log your own user-gap analysis as tracked findings with owners and due dates, and set a vendor due-diligence review date once — Coriqo reminds the owner, flags it overdue, and surfaces it in board reporting automatically.
Being direct here because it's easy to oversell: CSV/Excel import is fully real today — dialect-sniffing parsing, a genuine dry-run preview, and rollback with dependency checks. Live pull-based connectors to systems like S3 or Snowflake are on the roadmap and explicitly labeled a stub in our own code today, not a working feature yet. If a live connector is a requirement for your evaluation, tell us — it's a real conversation for design partners, not a hidden gap.
Verification & cryptography
Every governance event (an approval, a finding, a committee decision) is hash-chained — each record includes the hash of the one before it, so altering any record after the fact breaks the chain and is detectable immediately. Above that, events are sealed into a Merkle tree and signed with Ed25519; an examiner can download a small inclusion proof for any single event and verify it with one command on their own machine, offline, using only a public key — no Coriqo account, no network connection, no trust in our servers required. Checkpoints can optionally be anchored to Sigstore's public Rekor transparency log — the same append-only-log technique browsers use to police TLS certificates — for a witness outside our control entirely. We publish the exact tooling (verify_proof.py) rather than asking anyone to take our word for it.
The honest answer: the hash chain makes tampering detectable, not physically impossible. A database administrator with direct database access could still delete trailing rows outright — that breaks the chain, but only surfaces if someone runs the verification endpoint. That's why Merkle checkpointing and optional third-party anchoring exist: they move the guarantee from "trust our database" toward "trust the math," and our public roadmap (Coriqo V2) adds independent third-party witness cosigning specifically to remove single-party trust entirely.
Regulatory alignment
It means the governance workflow — draft, independent review, validation, approval, production, retirement — mirrors what those frameworks expect a model risk program to evidence, and specific checks (segregation of duties between owner and reviewer, no self-approval, no approval over an open critical finding) are enforced in the workflow itself rather than left to policy memory. We're precise about the boundary: gap detection is real and runs against your live data; the specific regulatory framework labels attached to a gap are a curated cross-reference for readability (e.g. an gap raised under the superseded SR 11-7 keeps its OCC 2011-12 cross-tag, because that guidance mirrored it), not a rules engine that parses regulatory text. Coriqo does not provide legal or regulatory advice — it provides the evidence structure your own compliance program uses to demonstrate its MRM practice.
Record them — that boundary is deliberate and load-bearing. AI features across the product (examiner reply drafts, committee minutes parsing, challenge-flag narration) are grounded in your own data and produce drafts only; nothing enters the tamper-evident chain without a named human approving it, and the record always shows that person as the actor, never "AI." Committee vote tallies and quorum are independently computed from the attendee data you enter as a cross-check, but the resulting action — approve, reject, approve-with-conditions — stays a human judgment call, on purpose. Coriqo is a system of record, not the decider.
Engagement & commercials
Start with what you have: import your existing model inventory spreadsheet via CSV in an afternoon, using the same dry-run-then-commit path so nothing goes live until you've reviewed the preview. Committee onboarding is one calendar invite added once. There is no forced data migration and no new system your team has to learn from scratch — the workflows deliberately mirror the email, calendar, and spreadsheet habits you already have. For design partners, we're hands-on through this — a direct line to the founder, not a support ticket queue.
More than a mature vendor's usually are. Design partner terms are explicitly revisited together as the product matures — you won't be locked into a multi-year rate that assumed a feature set we hadn't built yet. We'll sign a standard MSA and a data processing addendum for your counsel to review, and are open to shorter initial terms, defined off-ramps, and language that scales with what's actually shipped versus what's roadmap (our public capability status document exists specifically so that conversation is grounded in fact, not sales copy).
This is exactly the right question for a regulated buyer to ask an early-stage vendor, and we take it seriously in how the product itself is built. Because verification doesn't depend on trusting our servers — Merkle inclusion proofs and Ed25519-signed checkpoints are verifiable offline with a public key alone — your evidentiary record isn't stranded if Coriqo the company disappears. On the commercial side, we're open to writing explicit data portability and export guarantees, including a full data export in open formats (CSV, JSON, the raw hash-chained event log) on request or on contract termination, into the MSA for anyone who needs that in writing before signing. Ask for it — it's a reasonable ask and one we expect from any vendor in this space.
Design partner stage: direct access to the founder by email, typically same or next business day, because the group is small by design. Standard and Enterprise tiers add a defined SLA with named response-time commitments as part of the contract — the specifics scale with deployment complexity (a managed cloud instance vs. an air-gapped on-prem deployment have different support shapes) and are set during the scoping conversation, not off a generic support-tier menu.
Yes — the homepage has a live interactive demo with illustrative data you can click through right now (inventory, governance lifecycle, lineage, and generating an examiner package), no account needed. For a deeper look, including a real security review packet, email us directly and we'll set up a walkthrough.