Live Web app live now · Microsoft Teams Store listing coming soon

Run the risk program.
Compliance is the byproduct.

AuditBull runs your risk program inside Microsoft Teams. Hierarchical registers, named owners, treatment plans, and an immutable audit trail. Install in 60 seconds. Free forever for small teams.

Free Foundation tier. No credit card. No per-seat fees.

Hierarchical registers

Charters own registers. Registers own risks. The committee structure is the data model.

Named accountability

Every risk has an owner. Every state change is logged. No more registers full of "TBD" and stale dates.

Immutable audit trail

Every decision recorded with actor, timestamp, and reason. Append-only. Auditor-ready by default.

60-second setup

Install. Auto-provision. Run the program.

No signup form, no credit card, no sales call. Three clicks from Teams Store to a working risk register in your tenant.

1

Install from the Teams Store

Open the AuditBull listing in your Teams Store. Click "Add." No admin consent needed for first install — the bot starts with User.Read.

~10 sec
2

Tenant provisions itself

Send your first message to the bot. AuditBull auto-creates your tenant against your Entra identity, scaffolds default departments, and assigns you the admin role.

~30 sec
3

Spin up your first register

Bot prompts: "What's your first committee?" Answer in chat. AuditBull creates the charter, register, and a starter risk template — all named, all owned.

Live
The risk program

AuditBull is built around the risk register. Everything else, from system inventory to vendors to access reviews, exists to keep it accurate.

A real risk program — concretely

Charters own registers. Registers own risks. Risks have owners, lifecycles, and treatment plans. Every change is logged.

Charter
Information Security Committee
Chair: Diana Chen, CISO Cadence: Monthly Members: 6
Risk register
Information Security Risks
Owner: Diana Chen Risks: 14 active · 3 mitigated Last review: 2026-04-22
Risk · RR-001
Unencrypted PHI in transit between system A and vendor B
Owner: Marcus Lee Mitigated Likelihood: Low · Impact: High
Treatment + audit trail
TLS 1.3 enforced on all egress · State change logged 2026-04-22 14:08 by Marcus Lee
Risk · RR-002
Vendor B SOC 2 expiring within 60 days
Owner: Pri Patel Active Treatment: Renewal request sent
Risk · RR-003
Stale admin access to production from former contractors
Owner: Diana Chen Under review Linked to: Q2 access review
ChatOps inside Teams

Your risk program runs as a conversation.

AuditBull's bot lives in the Teams chats your people already have open. It asks for the next decision, captures the answer, and writes the state transition + audit-trail entry — without anyone opening another tool.

  • Risk reviews land as inline cards with one-click actions
  • Access reviews respond directly in chat — no spreadsheet exports
  • System intake is a guided conversation, not a form
  • Every bot interaction writes to the immutable audit trail
  • Bot speaks the same data model as the web UI
Team · Risk Committee
AuditBull 2:14 PM
Diana — risk RR-001 (Unencrypted PHI in transit) is up for its quarterly review.
State: Mitigated. Treatment plan: TLS 1.3 enforcement. Want to keep it as-is, accept the residual risk, or reopen?
Keep mitigated Accept residual Reopen + comment
AuditBull 2:31 PM
Marcus — Q2 access review for system A: 4 personnel still have admin. Confirm appropriateness?
All appropriate Revoke 1+ Defer to Diana
AuditBull 3:02 PM
New system spotted in onboarding: Datadog. Should I add it to the inventory?
Add + classify Not relevant
Enablement

Everything else exists to keep the register accurate.

System inventory

Know what you run.

Systems with ownership and data classification. Risks attach to systems — not the other way around.

Vendor registry

Track who you depend on.

Vendors with criticality ratings and obligations. Risks attach to vendors. Assessments fire when certifications expire.

Access reviews

Keep access appropriate.

Reviews land as Teams conversations. Owners answer in the tool they already have open. Evidence captures itself.

Pricing

Foundation is a real risk program — operated manually. Paid tiers automate the chasing, scheduling, and syncing. You always make the decisions. Flat monthly. No per-seat fees. Pay annually for the discounted rate.

Foundation
$0/ forever

A real risk program, operated manually.

  • Hierarchical registers with full lifecycle tracking
  • Immutable audit trail
  • System inventory + vendor registry
  • Manual access reviews in Teams
  • 25 systems · 25 vendors
  • 2 registers · 200 personnel
  • Single admin user
Request access
Enterprise
$2,500/ month, billed annually ($30,000/yr)
or $3,500 month-to-month

The bolt-on modules, higher limits, procurement-friendly.

  • Everything in Pro
  • Dedicated CSM + named SLAs
  • Custom volume limits
  • NET-30 invoicing + procurement
  • Security questionnaires + MSA
  • White-glove onboarding
Talk to us
Modules & add-ons

Simple add-on pricing.

Every plan includes the full risk loop — registers & committees, system inventory, access reviews, the vendor dashboard, and pulse surveys. Add-on modules extend it.

Add-on modules
$250/ month each — all included with Enterprise
  • Vendor Risk Management: quarterly vendor review cycles
  • Assessment Engine: AI-assisted assessments (uses credits)
  • Personnel onboarding: new-hire policy acknowledgments
  • Offboarding: departure checklists in Teams
  • Resilience Lens & AI Lens: cross-cutting coverage views
Assessment credits
Includedper period

Consumption-based: each AI-assisted assessment response draws from your credit pool.

  • Foundation: 100 credits
  • Pro: 1,000 credits
  • Enterprise: 10,000 credits
  • Need more? Talk to us
Category of one

Not attestation software. Not enterprise GRC.

AuditBull is the risk program itself, running where your organization already talks.

Conway's law, used on purpose

Your systems mirror how your organization communicates. So the program lives in the conversation: committees, owners, and decisions are the data model — not fields in a portal nobody opens.

Momentum compounds

Risk programs die of friction. Every review answered in the flow of work makes the next cycle lighter — cadences keep themselves, evidence accretes, the program runs like a habit.

Compliance falls out

Run the program for real and the artifacts already exist — a defensible register, documented reviews, an append-only trail. The byproduct, not the point.

No per-seat fees. Add-on modules available on any paid plan — all included with Enterprise.

Ready when AuditBull is.

We'll send one email when AuditBull lands in the Teams store.
That's it — no nurture sequence, no sales follow-up.

Get notified at launch →