Compliance, continuously.
grComply is the GRC operating system for organisations that must prove control, evidence, risk, and audit readiness across frameworks — without losing tenant branding, deployment flexibility, or auditor trust. A GRC platform is software that governs compliance controls, tracks risk, and manages audit evidence in one system instead of scattered spreadsheets. grComply does this across multiple frameworks at once — NIST, CIS, SOC 2, and tenant-specific requirements — sharing one control tree with cross-framework mapping. It runs as cloud SaaS, hybrid sync, or air-gapped private on-prem.
One inventory, every framework
Multi-framework, one inventory
Map once, cover many. NIST, CIS, SOC 2, and tenant frameworks share one control tree with cross-framework mapping, coverage matrices, and an impact preview before you adopt a new framework version.
Client brand first
Tenant logos and names own the workspace and every export package. grComply stays quiet infrastructure — the way auditors and executives expect a compliance tool to behave.
Cloud to air-gap
Same product, three postures: SaaS for speed, hybrid sync for regulated estates, and private on-prem for air-gapped programmes, with license meters and outbound-only paid activation.
Discover, triage, risk
External and internal vulnerability scanning with CVE enrichment, findings triage straight to controls, and a configurable risk register with formal executive acceptance.
Auditor-grade delivery
Observations, responses, peer countersign, control sign-offs, and versioned audit reports — built for how audit engagements actually run, not how a slide deck describes them.
AI that stays accountable
BYOK AI drafts narratives and suggestions. Humans confirm before completion moves. grComply never treats machine-generated text as verified evidence.
Every module, built for how compliance actually runs
Control mapping and coverage
grComply's control browser gives compliance officers a technical, dense view of the framework tree rather than a simplified dashboard. Declare a control not-applicable, publish narratives, and track completion — with a cross-framework coverage matrix showing what one control covers across every adopted framework, and an impact preview before you take on a new framework version. Status vocabulary is auditor-recognised: Compliant, Partial, Gap, N/A — one language across controls, dashboards, and exports. 13 frameworks are seeded today — international standards and regional regulations alike — and any additional framework loads as data, not code.
See every supported framework →Evidence management
Evidence attaches directly to requirements — upload, approve, version, and store. The completion cache updates live, so executives see current readiness rather than last month's export. Every artefact is versioned, every approval sits on a defined path before it credits toward completion, and every export is built to survive scrutiny.
Vulnerability scanning and findings
grComply runs agentless external checks and internal agent scans across asset groups on a schedule, enriching results with NVD, OSV, and CISA KEV context so triage starts informed rather than blind. Findings land in one register, get triaged by severity and asset context, and map straight into the control tree and risk register.
Risk register
Configure your own scoring methodology — likelihood × impact, or a tenant-specific schema — once, and the register and executive heat map stay aligned. Risk items link back from findings and controls, and executive acceptance is formally recorded with rationale, not parked in a slide deck nobody revisits.
Audit delivery and AI assist
Auditors get a purpose-built engagement home: raise, respond to, and close observations with a full timeline, peer reviewers countersign, and completed engagements produce versioned audit report packages. A BYOK AI assistant (currently built on Claude) drafts narratives and suggestions on request — labelled as AI-generated, and never allowed to mark a control complete without a human decision.
Security awareness training & LMS
A portal-managed training catalog where every course requires a stated purpose and a compliance-framework mapping before it can publish — completion rolls into the same completion percentage as every other control. Curriculum authoring, a learning board, recurring refreshers, and automated phishing simulation, licensed with training-only seats separate from your platform user count.
Explore security awareness training →One product line, three postures
Deployment posture is not negotiable for regulated organisations — grComply meets you where your data has to live.
Fastest to pilot
Full feature surface on Mutex-managed infrastructure (Vercel and Supabase) — built for pilot and growth-stage tenants.
Sensitive data stays local
Summaries and configuration sync outbound, with category toggles per tenant controlling exactly what leaves your estate.
Fully air-gapped
Paid license activation and offline renewal paths — for regulated estates where nothing leaves the building.
Same platform, different jobs
Tenant Admin, Compliance Officer, Executive, Auditor, and Peer Reviewer each land in a purpose-built shell on sign-in — nobody is forced into a dashboard built for someone else's role.
17 screens, captured from the live workspace
Across sign-in, compliance operations, scanning, risk, audit, deployment, and platform administration — not mockups.
Sign-in

Compliance operations




Scanning & findings


Risk register


Mapping & executive view


Audit delivery & AI


Deployment

Platform & ops


Getting started

Built for compliance teams under real audit pressure
Compliance and GRC teams preparing for ISO 27001, SOC 2, or sector-specific audits (FCA, State Bank of Pakistan, SECP, PTA, SAMA, and comparable regulators). Consultancies running multi-tenant compliance programmes for several clients from one platform. Regulated organisations that need private on-prem or hybrid deployment rather than pure SaaS. Security teams that want vulnerability scanning and the risk register to feed the same control tree the auditors will review.
Start at £0 — full platform from £999/mo
Trial is £0 / €0 for 3 months. Paid is £999/month (£9,990/year) in the UK, or €1,149/month (€11,490/year) in the EU — full multi-framework platform, no six-figure enterprise contract.
Trial — £0 / €0
3 months, 1 framework, up to 5 users, basic control and evidence features. No card required.
Paid — £999/mo
Multi-framework (up to 50), up to 200 users, risk, scanning, AI assist, and audit delivery.
Deployment
Cloud SaaS, hybrid sync, or private on-prem — each carries a different infrastructure and support footprint.
Common questions about grComply
What is a GRC platform?
A GRC platform is software that manages Governance, Risk, and Compliance in one system — control inventories, evidence, risk registers, and audit workflow — replacing spreadsheets and disconnected tools with a single source of truth auditors and executives can both trust.
Can grComply run on-premise?
Yes. grComply deploys as cloud SaaS, hybrid sync, or fully air-gapped private on-prem, with license meters and offline renewal paths for regulated estates that cannot use pure cloud infrastructure.
How does cross-framework control mapping work?
Controls live in one shared tree. When a control satisfies requirements in NIST, CIS, SOC 2, or a tenant-specific framework simultaneously, grComply maps it once and shows coverage across all adopted frameworks in a matrix — including an impact preview before you adopt a new framework version.
Does grComply use AI to auto-complete compliance work?
No. A BYOK AI assistant drafts narratives and suggestions on request, clearly labelled as AI-generated. A human always confirms before any control moves to complete.
How do you prepare evidence for a SOC 2 audit in grComply?
Upload evidence against the specific control requirement, route it through the approval path, and it versions automatically as you update it. The completion cache updates live, reflecting current evidence state rather than a stale export.
What's the difference between cloud and hybrid deployment?
Cloud SaaS runs the full feature surface on Mutex-managed infrastructure (Vercel and Supabase) — fastest to pilot. Hybrid keeps sensitive data on your own infrastructure while summaries and configuration sync outbound, with per-tenant category toggles.
Ready to pilot grComply?
Powered by Mutex Systems — engagement-grade GRC workflow with Mutex Systems as the platform provider. Explore the full SaaS portfolio →
Talk to us about a grComply pilot
Tell us about your frameworks and deployment posture — cloud, hybrid, or private on-prem — and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to pilot grComply?
We respond within one working day — or reach us instantly on WhatsApp.