Same security depth. Half the cost. Core security features on every plan.
Three plans. Core security features ship on every plan: SSO, audit log, and the SOC 2 plus ISO 27001 trust badges. Watchlist and Advanced Badge Designer at Business. Regulated compliance, SCIM, and the full integration ecosystem at Enterprise.
Professional front desk with core security features.
Up to 5 sites · Unlimited employees · Unlimited visits/loc/mo
per location · per year · ~$
83/mo equivalent
Single Sign On + MFA included
Slack + MS Teams integrations
Immutable audit log
iPad kiosk + web check-in
Touchless/QR code sign-in
Visitor approvals + escort workflow
Custom workflows per visitor type
Photo capture + printed badges
Pre-registration + bulk invites
Host notification (1 channel)
NDA/legal doc signing
Email + in-kiosk evacuation alerts
Multi-site with security screening and advanced badges.
Up to 15 sites · Unlimited employees · Unlimited visits/loc/mo
per location · per month · 10% premium vs annual
Everything in Starter, plus
Watchlist + photo ID screening
Facial recognition (returning visitor)
Advanced Badge Designer
Digital badge + Apple/Google Wallet
Multi-IdP + directory sync
Recurring invites
Omnichannel host notification
Real-time presence dashboard
Audit log search + Export
Strategic vendor for regulated multi-site enterprises.
Unlimited sites and employees · regulated industries and multi-site enterprises
Annual or multi-year contract
Everything in Business, plus
Smart ID verification
Offender registry screening
ITAR-aware citizenship gating
ITAR/ CMMC/ HIPAA BAA Compliance
Calendar sync (Google, Outlook)
SIEM event streaming
SCIM 2.0 + on-prem AD
API access
Access control integrations
Guest Wi-Fi integrations
HRIS + CRM integrations
Named CSM, 99.9% SLA
What's in each plan.
Starter
Business
Enterprise
Scale across your sites
The Lobby Experience
Pre-Registration & Workflow
Visitor Identity & Badges
Security at the Perimeter
Safety & Emergency Response
Documents & Agreements
Compliance Program Support
Trust & Vendor Posture
Identity & Access
Integrations & Ecosystem
Operations & Multi-Site
Reporting & Analytics
Support & Partnership
See what switching to Visitly saves you
A few questions. About 20 seconds.
How we compare.
Six things teams ask about when evaluating us against Envoy or iLobby. Full side-by-side feature, pricing math, and migration timeline lives on the dedicated comparison pages below.
Core security features · every plan
Ship at Business
Ships at Business
One product, one contract
BYO iPad + standard printers
At Enterprise
Comparing us to a specific incumbent?
Side-by-side feature, pricing, and migration math lives on the dedicated pages rather than getting crammed into this one.
What teams ask before they buy.
Anything missing? Talk to sales, we'll route you to a human who knows multi-location enterprise deployments.
What's actually 'core security features' at every plan?
Every plan covers what InfoSec usually gates behind a higher tier elsewhere: one sign-in with your IdP, a tamper-proof audit log on every action, vendor-risk artifacts your procurement team asks for ready to share, and the standard data-handling commitments your privacy team expects. The protocol checklist (SAML 2.0 across Okta, Entra, OneLogin, Google, PingOne, generic SAML/OIDC; SOC 2 + ISO 27001 trust badges; published DPA template + sub-processor list; GDPR + CCPA) is the proof anchor. Full reports (SOC 2 Type II, ISO 27001 SoA, CAIQ Lite v4) arrive under NDA via Trust Center request.
What's different about Business vs Starter?
Business adds the security-screening bundle (watchlist, basic ID scan, facial recognition, visitor approvals), Advanced Badge Designer with watermark, multi-IdP and basic directory sync, mass broadcast via the MyVisitly app, all chat channels simultaneously, webhooks, and 15-site.
What's at Enterprise that Business doesn't have?
SCIM 2.0 auto-provisioning, on-prem AD, HRIS sync, the full integration ecosystem (PACS · Guest Wi-Fi · emergency systems · CRM · file storage · support), Smart ID Validation, advanced watchlist variants, off-hours access controls, compliance-aware controls and evidence tooling for ITAR / CMMC / HIPAA BAA / NISPOM programs, SIEM streaming, full SOC 2 report and CAIQ Lite available under NDA, legal hold, Mailroom, and the commercial posture (named CSM · QBR · 24/7 support · 99.9% SLA · custom MSA).
Do we need to buy iPads from you?
No. BYO iPad: any Apple device that runs the current iPad OS will work. We don't license hardware.
How long is implementation?
Starter: live in a week with self-serve setup. Business: typically 14 days including SSO cutover. Enterprise: 30 to 60 days for multi-region rollouts with SCIM, PACS, and HRIS integration. Switch Assist migration is included with Business and Enterprise.
How long does the front desk need to learn it?
Most front-desk teams operate Visitly on day one without a separate training cycle. The kiosk is self-serve for the visitor; reception handles exceptions (VIP fast-track, denied entry, special escort) via a 1-tap override. Multi-lingual visitor flow is built in, so reception doesn't translate. Reviewer commentary on G2 and Capterra consistently cites low training burden and quick reception adoption.
What's the visitor experience actually like?
Under 30 seconds from arrival to badge for a walk-in. Pre-registered visitors arrive with NDA, parking, and Wi-Fi already in their inbox; their flow at the kiosk is closer to 10 seconds. Returning visitors recognized via facial recognition (Business and above) or a recurring profile. See /lobby-experience for the audience-segmented walkthrough.
Annual vs monthly billing?
Annual is the default. Monthly billing carries a 20% premium on Starter and Business. Enterprise is annual or multi-year only.
What InfoSec and procurement review about us as a vendor.
SOC 2 Type II
Audited annually by an independent CPA firm. Trust badge published; full report available under NDA on request.
ISO 27001
Certified ISMS. Statement of Applicability available under NDA on request.
CSA STAR CAIQ Lite v4
Self-attestation across all 297 controls. Available under NDA on request.
DPA + Sub-processors
DPA template and sub-processor list published. Signed DPA executed at contract.
GDPR + CCPA
Standard Contractual Clauses · 72-hour breach notification · privacy program data-handling commitments.
HIPAA BAA
BAA executed at contract for covered-entity deployments.
Skip the demo gauntlet. Pull our Trust Center and pricing yourself.
Or talk to sales. We'll route you to a human who knows multi-location enterprise deployments, not a BDR running a script.













.webp)

