Right now I recommend auditors but don't have formal partnerships. Vanta/Drata's auditor relationships are... let's say on the edge of conflicted? I don't want to go that route. And at $250/month I can't play the referral game anyway (Vanta pays hundreds per referral - that math doesn't work for me).
What I can do is democratize access. I've watched too many small teams get excited about SOC 2, then ghost once they see the total cost - $15k+ for the platform, $20k+ for consultants, $15k+ for auditors. I want the barrier low enough that smaller businesses can actually get certified and compete with bigger players.
On the checkbox vs. real security thing - you're right, it's tricky. I don't want to be another "generate docs, tick boxes, forget until next audit" platform. But targeting smaller businesses actually helps here - when you're a 10-person company, management is in the compliance process, not just signing off on someone else's work. It tends to stick better.
That said, sometimes I wonder if I help too much. My System Description assistant is almost unfair - what used to take weeks now takes minutes. Is that checkbox-enabling or democratizing? Genuinely not sure.
And yes - "vs Vanta/Drata" pages are going on the list. You're not the first to ask.
Your product seems great for actually doing the spirit of these frameworks (reducing risk, improving controls and processes etc.). However from what I've seen the reality of these audits is it's a box ticking exercise for everyone involved, and so improving the efficiency there tends to be the goal. How do you position yourself in that?
Also hope this doesn't come off too critical, it's just something I've been through recently and love seeing new things! I'd definitely add a vanta/drata comparison to your website though as that is inevitable.