Softwr

Cybersecurity · head to head

Osano vs Semperis

Osano logo

Osano

Cybersecurity

Consent management and data privacy platform with a published self-serve tier

From
Free
Rated
-
Semperis logo

Semperis

Cybersecurity

Identity threat detection and Active Directory forest recovery for AD, Entra ID and Okta, from a privately held US vendor.

From
On request
Rated
-

The short version

  • Only Osano has a free tier, so it costs nothing to try first.
  • Each has a real cost: Osano the published visitor ceilings are low, with the paid self-serve tier stopping around 30,000 monthly visitors, so any consumer facing site with real traffic leaves published pricing immediately and negotiates a quote with no public anchor.; Semperis scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
  • They diverge on capability: Osano covers Consent banner, Semperis covers Active Directory Forest Recovery.
  • Prices and features above were last checked on 31 August 2026.

Where they differ

Only the attributes on which Osano and Semperis actually diverge.

Attributes where Osano and Semperis differ
AttributeOsanoSemperis
Starting priceFreeOn request
Pricing modelPer month by monthly website visitorsquote
Free tierYesNo

Identical on both: platforms (Web), user rating (Not yet rated), category (Cybersecurity).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Osano

  • Consent banner
  • Pre-consent tag blocking
  • Consent record
  • No fines guarantee
  • Subject rights requests
  • Data mapping
  • Vendor privacy monitoring
  • Cookie scanning

Only in Semperis

  • Active Directory Forest Recovery
  • Malware-free restore
  • Replication-stream monitoring
  • Automated rollback
  • Attack indicator scoring
  • Entra ID and Okta coverage
  • Purple Knight
  • Forest Druid

What people use each for

The jobs each tool is most often brought in to do.

Osano

  • A mid market company selling into the EU and California that needs one banner honouring different consent rules by visitor regionnot Semperis
  • A privacy counsel who wants a vendor that will contractually stand behind its consent product rather than disclaim all liabilitynot Semperis
  • A marketing team that needs Google Consent Mode signals wired correctly so analytics and ads degrade rather than break when consent is refusednot Semperis
  • A company with a handful of brand domains wanting one consent record and one scanning schedule across all of themnot Semperis

Semperis

  • An organisation that cannot answer an auditor or insurer asking how long it would take to rebuild Active Directory after a destructive attacknot Osano
  • Post-incident recovery where domain controllers are compromised and restoring from system-state backup would reintroduce the attacker's footholdnot Osano
  • Continuous detection of privileged group changes and directory-level tampering that domain controller security logs missnot Osano
  • Hybrid estates where AD, Entra ID and Okta all matter and no single tool currently shows changes across the threenot Osano

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Osano

  • The published visitor ceilings are low, with the paid self-serve tier stopping around 30,000 monthly visitors, so any consumer facing site with real traffic leaves published pricing immediately and negotiates a quote with no public anchor.
  • The no fines guarantee is bounded and conditional on configuring the product as instructed, so it is a marketing differentiator with an indemnity cap rather than the insurance policy the name suggests, and the limits should be read before it influences a decision.
  • Everything beyond consent, including subject rights automation, data mapping and vendor monitoring, is enterprise quoted, so the transparent pricing that attracts buyers covers only the cheapest part of the platform.
  • Tag blocking depends on tags being loaded through the mechanisms Osano can intercept, and marketing teams that inject scripts directly into templates or through server side tagging routinely leak trackers past the banner without anyone noticing.
  • It is a privacy platform rather than a security compliance one, so organisations that also need SOC 2 or ISO 27001 evidence collection run it alongside a separate tool and duplicate parts of the vendor and asset inventory.

Semperis

  • Scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
  • The licence buys tooling, not a proven runbook: forest recovery is only worth what your last rehearsal demonstrated, and a plan that has never been executed end to end in a lab is an untested assumption regardless of what was purchased.
  • It overlaps with backup and directory management products from Quest, Veeam, Commvault and others, so the buyer must argue internally why a dedicated product is needed alongside a backup contract that already claims to protect Active Directory.
  • Running Directory Services Protector well requires someone who understands AD internals, replication metadata and Tier 0 attack paths, and without that person the alerts on privileged changes are either ignored or auto-reverted in ways that break legitimate administration.
  • Licensing is driven by identity object counts, so directories carrying years of stale user accounts and service principals pay for objects that should have been deleted, and the cleanup project that would reduce the bill is the one nobody has time for.

Pricing, plan by plan

Osano

Free
  • FreeFree
    • 1 user
    • 1 domain
    • 5,000 monthly visitors
  • Plus$199/month
    • 2 users
    • 3 domains
    • 30,000 monthly visitors
  • Enterprise$undefined/year
    • Unlimited domains and higher visitor volumes
    • Subject rights request automation
    • Data mapping and assessments

Semperis

On request

No published plan breakdown. See the Semperis review.

Which should you pick?

Choose Osano if

  • You need consent banner.
  • You want to start without paying.
  • You also want pre-consent tag blocking.

Choose Semperis if

  • You need active directory forest recovery.
  • You also want malware-free restore.

Questions people ask

Is Osano or Semperis better?
Neither clearly leads. Osano starts at Free and Semperis at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Osano or Semperis?
Osano has a free tier; the other does not. Paid plans start at Free for Osano and On request for Semperis.
Does Osano or Semperis run on more platforms?
Both run on Web, so platform support will not decide this one for you.
Can I use Osano for free?
Yes. Osano has a free tier, so you can try it without paying. Semperis starts at On request.
What is Osano best used for?
Osano is most often used for a mid market company selling into the eu and california that needs one banner honouring different consent rules by visitor region, a privacy counsel who wants a vendor that will contractually stand behind its consent product rather than disclaim all liability, a marketing team that needs google consent mode signals wired correctly so analytics and ads degrade rather than break when consent is refused, a company with a handful of brand domains wanting one consent record and one scanning schedule across all of them. Of those, a mid market company selling into the eu and california that needs one banner honouring different consent rules by visitor region and a privacy counsel who wants a vendor that will contractually stand behind its consent product rather than disclaim all liability are not what Semperis is typically brought in for.
What can Osano do that Semperis cannot?
Osano covers Consent banner, Pre-consent tag blocking, Consent record, No fines guarantee. Semperis covers Active Directory Forest Recovery, Malware-free restore, Replication-stream monitoring, Automated rollback.

Answered from the vendors’ own pages

Osano: Does the free tier include the no fines guarantee?

No. The guarantee attaches to paid use of the consent product, and the free tier is capped at one domain and 5,000 monthly visitors.

Semperis: Does this replace my backups?

No. It replaces the Active Directory recovery procedure specifically. You still need backups for everything else, and the point of Semperis is that a generic system-state backup of a domain controller is a poor way to recover a forest because it restores the operating system along with whatever compromised it.

Osano: How is Osano priced?

By monthly website visitors, number of domains and tier. The self-serve path stops at a low visitor ceiling and everything above is quoted.

Semperis: Is it useful if we are cloud-only on Entra ID?

Partly. Directory Services Protector covers Entra ID and Okta for change tracking and posture, but the forest recovery product, which is the strongest reason to buy, applies to on-premises Active Directory. A genuinely cloud-only organisation should weigh it against Microsoft's own tooling.

Osano: Can it handle US state privacy laws as well as GDPR?

Yes, with region aware rule sets covering GDPR, ePrivacy and the US state regimes, so an EU visitor sees an opt-in banner and a US visitor sees the applicable opt-out.

Semperis: Are Purple Knight and Forest Druid really free?

Yes, both are free downloads with no licence requirement, and they are widely used by organisations that are not Semperis customers. They are also, transparently, the top of the sales funnel.

Osano: Does Osano do subject access requests?

Yes, but in the enterprise tier rather than the published plans, and it is quoted separately from consent.

Semperis: How long does forest recovery actually take?

The honest answer is whatever your rehearsal took. The vendor's case is hours instead of days, and automation genuinely removes most manual steps, but the number that matters for your board is the one from a test in your own environment.

Semperis: Does it require agents on domain controllers?

It collects directory changes from the AD replication stream, which is what lets it see changes that bypass the security log. Deployment details vary by product and version, so confirm the exact architecture against your domain controller change-control rules.

Share

Related pages

Other head to heads