⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply TiLedger FlowChat Partners Resources About Pricing Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
GRC platform

Compliance, continuously.

grComply is the GRC operating system for organisations that must prove control, evidence, risk, and audit readiness across frameworks — without losing tenant branding, deployment flexibility, or auditor trust. A GRC platform is software that governs compliance controls, tracks risk, and manages audit evidence in one system instead of scattered spreadsheets. grComply does this across multiple frameworks at once — NIST, CIS, SOC 2, and tenant-specific requirements — sharing one control tree with cross-framework mapping. It runs as cloud SaaS, hybrid sync, or air-gapped private on-prem.

One platform for every framework, every gap, every audit. Cloud · Hybrid · Private on-prem · Scanning · Risk · Audit delivery.
Book a meeting WhatsApp us
17Product screens
3Deployment modes
5Role-true stakeholder homes
BYOKAI, confirm-before-complete
Why grComply

One inventory, every framework

Multi-framework, one inventory

Map once, cover many. NIST, CIS, SOC 2, and tenant frameworks share one control tree with cross-framework mapping, coverage matrices, and an impact preview before you adopt a new framework version.

Client brand first

Tenant logos and names own the workspace and every export package. grComply stays quiet infrastructure — the way auditors and executives expect a compliance tool to behave.

Cloud to air-gap

Same product, three postures: SaaS for speed, hybrid sync for regulated estates, and private on-prem for air-gapped programmes, with license meters and outbound-only paid activation.

Discover, triage, risk

External and internal vulnerability scanning with CVE enrichment, findings triage straight to controls, and a configurable risk register with formal executive acceptance.

Auditor-grade delivery

Observations, responses, peer countersign, control sign-offs, and versioned audit reports — built for how audit engagements actually run, not how a slide deck describes them.

AI that stays accountable

BYOK AI drafts narratives and suggestions. Humans confirm before completion moves. grComply never treats machine-generated text as verified evidence.

What's inside

Every module, built for how compliance actually runs

Control mapping and coverage

grComply's control browser gives compliance officers a technical, dense view of the framework tree rather than a simplified dashboard. Declare a control not-applicable, publish narratives, and track completion — with a cross-framework coverage matrix showing what one control covers across every adopted framework, and an impact preview before you take on a new framework version. Status vocabulary is auditor-recognised: Compliant, Partial, Gap, N/A — one language across controls, dashboards, and exports. 13 frameworks are seeded today — international standards and regional regulations alike — and any additional framework loads as data, not code.

See every supported framework →

Evidence management

Evidence attaches directly to requirements — upload, approve, version, and store. The completion cache updates live, so executives see current readiness rather than last month's export. Every artefact is versioned, every approval sits on a defined path before it credits toward completion, and every export is built to survive scrutiny.

Vulnerability scanning and findings

grComply runs agentless external checks and internal agent scans across asset groups on a schedule, enriching results with NVD, OSV, and CISA KEV context so triage starts informed rather than blind. Findings land in one register, get triaged by severity and asset context, and map straight into the control tree and risk register.

Risk register

Configure your own scoring methodology — likelihood × impact, or a tenant-specific schema — once, and the register and executive heat map stay aligned. Risk items link back from findings and controls, and executive acceptance is formally recorded with rationale, not parked in a slide deck nobody revisits.

Audit delivery and AI assist

Auditors get a purpose-built engagement home: raise, respond to, and close observations with a full timeline, peer reviewers countersign, and completed engagements produce versioned audit report packages. A BYOK AI assistant (currently built on Claude) drafts narratives and suggestions on request — labelled as AI-generated, and never allowed to mark a control complete without a human decision.

Security awareness training & LMS

A portal-managed training catalog where every course requires a stated purpose and a compliance-framework mapping before it can publish — completion rolls into the same completion percentage as every other control. Curriculum authoring, a learning board, recurring refreshers, and automated phishing simulation, licensed with training-only seats separate from your platform user count.

Explore security awareness training →
Deployment

One product line, three postures

Deployment posture is not negotiable for regulated organisations — grComply meets you where your data has to live.

Cloud SaaS

Fastest to pilot

Full feature surface on Mutex-managed infrastructure (Vercel and Supabase) — built for pilot and growth-stage tenants.

Hybrid

Sensitive data stays local

Summaries and configuration sync outbound, with category toggles per tenant controlling exactly what leaves your estate.

Private on-prem

Fully air-gapped

Paid license activation and offline renewal paths — for regulated estates where nothing leaves the building.

Role-true homes

Same platform, different jobs

Tenant Admin, Compliance Officer, Executive, Auditor, and Peer Reviewer each land in a purpose-built shell on sign-in — nobody is forced into a dashboard built for someone else's role.

Tenant AdminFrameworks, users, setup posture
Compliance OfficerDaily work queue of controls and gaps
ExecutiveHealthy / Attention / At risk dashboard
AuditorEngagement, observation, review workflow
Peer ReviewerCountersign and quality review
Product screens

17 screens, captured from the live workspace

Across sign-in, compliance operations, scanning, risk, audit, deployment, and platform administration — not mockups.

Who it's for

Built for compliance teams under real audit pressure

Compliance and GRC teams preparing for ISO 27001, SOC 2, or sector-specific audits (FCA, State Bank of Pakistan, SECP, PTA, SAMA, and comparable regulators). Consultancies running multi-tenant compliance programmes for several clients from one platform. Regulated organisations that need private on-prem or hybrid deployment rather than pure SaaS. Security teams that want vulnerability scanning and the risk register to feed the same control tree the auditors will review.

Pricing

Start at £0 — full platform from £999/mo

Trial is £0 / €0 for 3 months. Paid is £999/month (£9,990/year) in the UK, or €1,149/month (€11,490/year) in the EU — full multi-framework platform, no six-figure enterprise contract.

Trial — £0 / €0

3 months, 1 framework, up to 5 users, basic control and evidence features. No card required.

Paid — £999/mo

Multi-framework (up to 50), up to 200 users, risk, scanning, AI assist, and audit delivery.

Deployment

Cloud SaaS, hybrid sync, or private on-prem — each carries a different infrastructure and support footprint.

See full pricing Compare vs GRC platforms
Frequently asked questions

Common questions about grComply

What is a GRC platform?

A GRC platform is software that manages Governance, Risk, and Compliance in one system — control inventories, evidence, risk registers, and audit workflow — replacing spreadsheets and disconnected tools with a single source of truth auditors and executives can both trust.

Can grComply run on-premise?

Yes. grComply deploys as cloud SaaS, hybrid sync, or fully air-gapped private on-prem, with license meters and offline renewal paths for regulated estates that cannot use pure cloud infrastructure.

How does cross-framework control mapping work?

Controls live in one shared tree. When a control satisfies requirements in NIST, CIS, SOC 2, or a tenant-specific framework simultaneously, grComply maps it once and shows coverage across all adopted frameworks in a matrix — including an impact preview before you adopt a new framework version.

Does grComply use AI to auto-complete compliance work?

No. A BYOK AI assistant drafts narratives and suggestions on request, clearly labelled as AI-generated. A human always confirms before any control moves to complete.

How do you prepare evidence for a SOC 2 audit in grComply?

Upload evidence against the specific control requirement, route it through the approval path, and it versions automatically as you update it. The completion cache updates live, reflecting current evidence state rather than a stale export.

What's the difference between cloud and hybrid deployment?

Cloud SaaS runs the full feature surface on Mutex-managed infrastructure (Vercel and Supabase) — fastest to pilot. Hybrid keeps sensitive data on your own infrastructure while summaries and configuration sync outbound, with per-tenant category toggles.

Ready to pilot grComply?

Powered by Mutex Systems — engagement-grade GRC workflow with Mutex Systems as the platform provider. Explore the full SaaS portfolio →

Get in touch

Talk to us about a grComply pilot

Tell us about your frameworks and deployment posture — cloud, hybrid, or private on-prem — and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to pilot grComply?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us