Compliance tool pricing

Priced for the
risk you remove.

No fixed licence. No upfront cost. You pay when a change has been verified, so the bill tracks the risk we actually took off your desk.

01 · Evaluate

Sandbox pilot

No cost

Run Refinery against your own COBOL in an isolated sandbox for 30 days. Your code never leaves your estate; the engine runs where you put it.

  • Your programs, your infrastructure
  • Full audit engine, no feature gating
  • Signed Change Contract on every run
02 · Deploy

Per verified change

Risk-share

Once you are in production you pay against changes Refinery has actually verified, priced as a share of the compliance risk removed, not as a seat licence.

  • No fixed licence, no seat count
  • You pay when a change is verified
  • Stops when you stop shipping changes
03 · Scale

Estate-wide

Bespoke

For governing change across an entire estate rather than one team’s programs. Every dependency is mapped in advance, so what a change touches is known before anyone proposes it.

  • On-premise or private cloud
  • Multi-tenant estate scoping
  • CRO portal and evidence retention

Why Refinery is different

Five strengths, and what each one actually gets you.

The same claims the homepage makes, stated so you can check them one at a time.

Change behaviour equivalence

Verified by formal proof

Verification strategy

PIC-range proof and adversarial execution

Regulator deliverables

Signed PDF, SHA-256, evidence pack

Compliance binding

DORA Art. 25 · SS1/23 · SR 26-2

Who authors the code it checks

Any tool, or a person

How others compare

Everyone checks their own homework.
Now someone else can.

A quick look at what you get from AI migrations, AI code gates and manual review. These are good tools, honestly described; the difference is that their verification is downstream of their own code generation, and stops at the point where a risk function needs something to file.

AI migration platforms

watsonx Code Assistant for Z · AWS Transform · Imogen

What it checks

Whether its own output behaves the same

Who authors the code it checks

Itself

Verification strategy

Generated tests, over the inputs they sample

Regulator deliverables

A green pipeline

Compliance binding

Not produced

AI code-quality gates

SonarQube AI Code Assurance

What it checks

Rules, bugs and vulnerabilities

Who authors the code it checks

Any tool

Verification strategy

Not attempted

Regulator deliverables

A quality badge

Compliance binding

Not produced

Manual review

Reviewer plus regression suite

What it checks

Whatever the reviewer thinks to look at

Who authors the code it checks

Any tool

Verification strategy

Reviewer judgement

Regulator deliverables

An email

Compliance binding

Assembled by hand

Every column is drawn from the vendor’s own published documentation, current as of September 2026.

Included at every stage

There is no cut-down tier.

  • Every one of the 11 core checks, plus the semantic engine
  • Z3 formal proof of arithmetic equivalence, with counterexamples
  • A signed, tamper-evident Change Contract PDF per audit
  • Downstream impact analysis across CALL, COPY and JCL
  • DORA Article 25 evidence mapping, aligned to SS1/23 and SR 26-2
  • The compliance agent your risk team can question directly

Questions procurement asks

Does our COBOL leave our estate?+

No. Refinery runs where you deploy it, on-premise or in your own cloud. There are no mandatory external dependencies, and the engine works fully offline.

What does "a share of the risk removed" actually mean?+

You pay against changes Refinery verifies, not against how many engineers you have. If a quarter goes by without an AI tool touching production COBOL, that quarter costs you nothing.

Are we locked in?+

No. The evidence Refinery produces is a standard signed PDF plus a structured record; both are yours, readable without us, and remain valid if you stop using the product.

Do we need to replace our AI modernisation tooling?+

No. Refinery is deliberately independent of whatever writes the code. It checks the output of any tool, vendor patch or human commit, which is the whole point of an independent control.

Start with the sandbox.

Thirty days, your own COBOL, no cost. If it does not find anything worth showing your risk team, there is nothing to discuss.

Book a call →