{"directory":"GRC Platforms","url":"https://grcplatforms.com","lastUpdated":"2026-09-25","dataAsOf":"2026-08-10","count":142,"categoryCount":11,"categories":[{"slug":"compliance-automation","name":"Compliance Automation","blurb":"Automated evidence collection and continuous monitoring for SOC 2, ISO 27001, and similar frameworks."},{"slug":"enterprise-grc-suites","name":"Enterprise GRC Suites","blurb":"Integrated enterprise platforms spanning risk, compliance, audit, and policy management."},{"slug":"integrated-risk-management","name":"Integrated Risk Management","blurb":"Enterprise and operational risk, risk registers, and risk quantification."},{"slug":"third-party-risk","name":"Third-Party Risk","blurb":"Vendor, supplier, and third-party risk assessment and monitoring."},{"slug":"privacy-data-governance","name":"Privacy & Data Governance","blurb":"Privacy program management, data mapping, and consent."},{"slug":"audit-management","name":"Audit Management","blurb":"Internal audit, SOX, and controls testing."},{"slug":"policy-training-awareness","name":"Policy, Training & Awareness","blurb":"Policy lifecycle management, compliance training, and security awareness."},{"slug":"financial-crime-aml","name":"Financial Crime & AML","blurb":"Anti-money-laundering, KYC, sanctions screening, and financial-services compliance."},{"slug":"ehs-quality-esg","name":"EHS, Quality & ESG","blurb":"Environment, health, safety, quality, and ESG compliance."},{"slug":"cyber-risk-ccm","name":"Cyber Risk & CCM","blurb":"Cyber risk quantification and continuous control monitoring."},{"slug":"ai-governance","name":"AI Governance","blurb":"Governance, risk, and compliance for AI systems: ISO 42001, the EU AI Act, and NIST AI RMF."}],"platforms":[{"id":"6clicks","name":"6clicks","slug":"6clicks","logo":"","brief_summary":"AI-enabled GRC platform with a hub-and-spoke model aimed at advisors, enterprises and their supply chains.","description":"6clicks is an Australian GRC platform offering risk management, compliance, audit and third-party assessments with an AI engine and a content marketplace of frameworks and templates. Its hub-and-spoke architecture lets consultancies and multi-entity enterprises manage many programs from one instance. It competes with integrated risk and compliance-automation suites.","category":"enterprise-grc-suites","tags":["ISO 27001","SOC 2","NIST CSF","Essential Eight","GDPR"],"hq":"Melbourne, Australia","company_size":"mid-market","url":"https://www.6clicks.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/6clicks/","frameworks":["ISO 27001","SOC 2","NIST CSF","Essential Eight","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"a1-tracker","name":"A1 Tracker","slug":"a1-tracker","logo":"","brief_summary":"Configurable risk, contract, and compliance tracking software for mid-market operations teams.","description":"A1 Tracker from A1 Enterprise is a web-based platform that centralizes risk registers, contract lifecycle tracking, claims, and compliance workflows. It targets organizations that want a configurable system of record without a heavy enterprise GRC rollout. Modules can be licensed individually and tailored to specific risk and compliance processes.","category":"integrated-risk-management","tags":["ISO 27001","SOC 2","HIPAA"],"hq":"Roseville, California, USA","company_size":"startup","url":"https://www.a1tracker.com","docs_url":"","linkedin":"https://www.linkedin.com/company/a1-tracker","frameworks":["ISO 27001","SOC 2","HIPAA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"alessa","name":"Alessa","slug":"alessa","logo":"","brief_summary":"AML compliance, screening and fraud-prevention platform now owned by Tier1 Financial Solutions.","description":"Alessa delivers anti-money-laundering compliance including due diligence, sanctions and watchlist screening, transaction monitoring, regulatory reporting and case management for banks, MSBs, casinos and fintechs. Tier1 Financial Solutions acquired Alessa in 2021 and continues to sell it under that name. It serves regulated firms across several continents.","category":"financial-crime-aml","tags":["BSA/AML","FATF","FINTRAC","OFAC"],"hq":"Ottawa, Ontario, Canada","company_size":"mid-market","url":"https://alessa.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/alessa-tier1/","frameworks":["BSA/AML","FATF","FINTRAC","OFAC"],"deployment":"SaaS","ownership":"acquired by Tier1 Financial Solutions (2021)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"allgress","name":"Allgress","slug":"allgress","logo":"","brief_summary":"IT risk and GRC software focused on continuous compliance and risk visualization.","description":"Allgress provides GRC and IT risk management tooling built around risk registers, control assessments, and executive dashboards. Its Insight product line supports vendor risk, compliance mapping, and continuous monitoring for security and risk teams. The company serves mid-market and enterprise buyers in regulated sectors.","category":"integrated-risk-management","tags":["ISO 27001","NIST CSF","PCI DSS","SOC 2","HIPAA"],"hq":"Livermore, California, USA","company_size":"mid-market","url":"https://www.allgress.com","docs_url":"","linkedin":"https://www.linkedin.com/company/allgress","frameworks":["ISO 27001","NIST CSF","PCI DSS","SOC 2","HIPAA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"anecdotes","name":"Anecdotes","slug":"anecdotes","logo":"","brief_summary":"Enterprise GRC platform built on a compliance data layer that collects audit-grade evidence directly from company systems.","description":"Anecdotes runs a Compliance OS that ingests structured data from cloud, on-premise, and SaaS tools through proprietary integrations, then normalizes it into a GRC data model for controls, risks, and policies. It layers configurable AI agents on top to run compliance, risk, and policy workflows across 60-plus frameworks. The product targets enterprises that want continuous, data-backed evidence rather than point-in-time uploads.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST"],"hq":"Tel Aviv, Israel","company_size":"startup","url":"https://www.anecdotes.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/anecdotes-ai","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"ansarada-grc","name":"Ansarada GRC","slug":"ansarada-grc","logo":"","brief_summary":"GRC platform for financial services covering risk, compliance, and operational resilience.","description":"Ansarada GRC is a cloud platform aimed at financial services firms managing governance, risk, compliance, and operational resilience obligations. When Datasite acquired the Ansarada data room business in 2024, the ESG, GRC, and board assets were carved out and retained by Ansarada founder Sam Riley, and the GRC product continues to be sold. It offers risk registers, incident and breach tracking, attestations, and policy management.","category":"integrated-risk-management","tags":["ISO 27001","APRA CPS 230","APRA CPS 234","SOC 2"],"hq":"Sydney, Australia","company_size":"mid-market","url":"https://www.ansarada.com/grc","docs_url":"","linkedin":"https://www.linkedin.com/company/ansarada","frameworks":["ISO 27001","APRA CPS 230","APRA CPS 234","SOC 2"],"deployment":"SaaS","ownership":"independent (carved out from Ansarada after Datasite acquisition, 2024)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"apptega","name":"Apptega","slug":"apptega","logo":"","brief_summary":"Cybersecurity compliance management platform popular with MSPs and MSSPs.","description":"Apptega helps organizations and service providers build, manage, and report on cybersecurity and compliance programs across common frameworks. It maps controls across standards, tracks evidence, and generates audit-ready reporting. The platform is widely used by managed service providers delivering compliance-as-a-service to clients.","category":"compliance-automation","tags":["SOC 2","ISO 27001","PCI DSS","HIPAA","NIST CSF","CMMC"],"hq":"Atlanta, Georgia, USA","company_size":"mid-market","url":"https://www.apptega.com","docs_url":"","linkedin":"https://www.linkedin.com/company/apptega","frameworks":["SOC 2","ISO 27001","PCI DSS","HIPAA","NIST CSF","CMMC"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"aravo","name":"Aravo","slug":"aravo","logo":"","brief_summary":"Third-party risk and supplier management platform with a large connector ecosystem.","description":"Aravo provides third-party risk management software covering onboarding, due diligence, ongoing monitoring and offboarding across domains such as cybersecurity, ESG, anti-bribery and privacy. Its Intelligence First platform integrates dozens of third-party risk intelligence feeds and ERP/CRM systems. Aravo is recognized as a Leader in Gartner's TPRM tools evaluations.","category":"third-party-risk","tags":["ISO 27001","SOC 2","GDPR","NIST CSF"],"hq":"San Francisco, California, USA","company_size":"mid-market","url":"https://aravo.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/aravo-solutions/","frameworks":["ISO 27001","SOC 2","GDPR","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"archer","name":"Archer","slug":"archer","logo":"","brief_summary":"Enterprise integrated risk management suite formerly known as RSA Archer.","description":"Archer is one of the longest-running enterprise GRC platforms, spanning risk, compliance, audit, policy, and operational resilience. It was spun out of RSA and now operates as an independent company under Cinven ownership. Large regulated enterprises use it as a configurable system of record for integrated risk management.","category":"enterprise-grc-suites","tags":["ISO 27001","NIST CSF","SOX","PCI DSS","GDPR"],"hq":"Overland Park, Kansas, USA","company_size":"enterprise","url":"https://www.archerirm.com","docs_url":"","linkedin":"https://www.linkedin.com/company/archer-irm","frameworks":["ISO 27001","NIST CSF","SOX","PCI DSS","GDPR"],"deployment":"Hybrid","ownership":"independent (spun out of RSA 2020, Cinven-backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"audit-prodigy","name":"Audit Prodigy","slug":"audit-prodigy","logo":"","brief_summary":"Audit, risk, and compliance management platform with a strong SOX focus.","description":"Audit Prodigy is a GRC platform covering internal audit, SOX compliance, controls testing, risk, and issue management. It positions itself as an all-in-one alternative to legacy audit tooling for finance and audit teams. The product emphasizes rapid deployment and a unified workflow across audit and compliance activities.","category":"audit-management","tags":["SOX","ISO 27001","SOC 2","COSO"],"hq":"USA","company_size":"startup","url":"https://www.auditprodigy.com","docs_url":"","linkedin":"https://www.linkedin.com/company/audit-prodigy","frameworks":["SOX","ISO 27001","SOC 2","COSO"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"axio","name":"Axio","slug":"axio","logo":"","brief_summary":"Cyber-risk quantification and assessment platform tied to insurance and financial exposure.","description":"Axio provides cyber-risk quantification and program assessment, helping organizations estimate financial exposure from cyber events and align controls and insurance accordingly. Its Axio360 platform supports scenario-based loss analysis and maturity assessments. It serves enterprise risk and security leaders.","category":"cyber-risk-ccm","tags":["NIST CSF","C2M2","FAIR","ISO 27001"],"hq":"New York, New York, USA","company_size":"startup","url":"https://axio.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/axio/","frameworks":["NIST CSF","C2M2","FAIR","ISO 27001"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"benchmark-gensuite","name":"Benchmark Gensuite","slug":"benchmark-gensuite","logo":"","brief_summary":"EHS, ESG, quality and operational-risk platform with a broad application suite.","description":"Benchmark Gensuite provides cloud software for environment, health, safety, sustainability, quality and operational risk, with a large set of configurable modules and mobile apps. It serves industrial, manufacturing and enterprise customers. The company also markets ESG and product-stewardship capabilities.","category":"ehs-quality-esg","tags":["ISO 14001","ISO 45001","OSHA","GRI"],"hq":"Cincinnati, Ohio, USA","company_size":"mid-market","url":"https://benchmarkgensuite.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/benchmarkgensuite/","frameworks":["ISO 14001","ISO 45001","OSHA","GRI"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"bigid","name":"BigID","slug":"bigid","logo":"","brief_summary":"Data discovery, privacy and data-governance platform for finding and governing sensitive data at scale.","description":"BigID scans structured and unstructured data across the enterprise to discover, classify and map sensitive and personal data, powering privacy, data governance and data-security programs. It supports data subject rights, retention and consent workflows on top of its discovery engine. It is used by large enterprises for privacy and data governance.","category":"privacy-data-governance","tags":["GDPR","CCPA","ISO 27001","HIPAA"],"hq":"New York, New York, USA","company_size":"enterprise","url":"https://bigid.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/bigid/","frameworks":["GDPR","CCPA","ISO 27001","HIPAA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"bitsight","name":"Bitsight","slug":"bitsight","logo":"","brief_summary":"Security ratings and cyber-risk analytics platform positioned for third-party and enterprise cyber risk.","description":"Bitsight produces external security ratings and exposure analytics used for third-party risk management, cyber-risk quantification and continuous monitoring of supplier ecosystems. It is used by security, risk and board-level stakeholders to benchmark and track cyber posture. The company has expanded from ratings into broader cyber-risk and TPRM tooling.","category":"third-party-risk","tags":["NIST CSF","ISO 27001","SOC 2"],"hq":"Boston, Massachusetts, USA","company_size":"enterprise","url":"https://www.bitsight.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/bitsight/","frameworks":["NIST CSF","ISO 27001","SOC 2"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"mega-international-hopex","name":"Bizzdesign HOPEX (formerly MEGA International)","slug":"mega-international-hopex","logo":"","brief_summary":"Enterprise architecture and GRC platform (HOPEX), now sold under the Bizzdesign brand after MEGA International merged into Bizzdesign.","description":"HOPEX is an enterprise architecture and GRC platform originally from MEGA International, a French software vendor. MEGA merged into Bizzdesign (announced October 2024, consolidated under the Bizzdesign brand in early 2025 alongside Alfabet), and the product continues as Bizzdesign HOPEX. Its GRC modules span integrated risk management, compliance and data governance, letting organizations map risks and controls onto their processes and IT landscape. It is used by large enterprises and financial institutions.","category":"enterprise-grc-suites","tags":["ISO 27001","GDPR","Basel","DORA"],"hq":"Paris, France","company_size":"mid-market","url":"https://bizzdesign.com/transformation-suite/hopex","docs_url":"","linkedin":"https://www.linkedin.com/company/mega-international/","frameworks":["ISO 27001","GDPR","Basel","DORA"],"deployment":"Hybrid","ownership":"Merged into Bizzdesign (Main Capital Partners portfolio), 2024-2025","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"camms","name":"Camms","slug":"camms","logo":"","brief_summary":"Integrated risk, strategy and project GRC platform from an Australian vendor serving public sector and enterprise.","description":"Camms provides GRC software spanning enterprise and operational risk, incident and compliance management, internal audit, strategy execution and project risk. The Camms.Risk product is widely used across government, healthcare and financial services, particularly in Australia and the UK. It positions as an integrated risk management suite.","category":"integrated-risk-management","tags":["ISO 31000","ISO 27001","COSO"],"hq":"Adelaide, Australia","company_size":"mid-market","url":"https://www.cammsgroup.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/camms/","frameworks":["ISO 31000","ISO 27001","COSO"],"deployment":"SaaS","ownership":"independent (Riverside-backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"caseware","name":"Caseware","slug":"caseware","logo":"","brief_summary":"Audit, assurance and financial reporting platform used by accounting firms and internal audit teams.","description":"Caseware provides audit, assurance, financial reporting and analytics software used by public accounting firms, corporates and government auditors. Its cloud platform supports engagement management, working papers and data-driven audit. It is a long-established vendor in the audit-technology market.","category":"audit-management","tags":["IFRS","GAAP","ISA"],"hq":"Toronto, Ontario, Canada","company_size":"mid-market","url":"https://www.caseware.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/caseware-international/","frameworks":["IFRS","GAAP","ISA"],"deployment":"Hybrid","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"centraleyes","name":"Centraleyes","slug":"centraleyes","logo":"","brief_summary":"Cyber risk and compliance management platform with automated framework mapping.","description":"Centraleyes is a cloud GRC platform focused on cyber risk quantification and compliance management. It automates control assessments, maps overlapping frameworks, and provides real-time risk dashboards. The product targets security and risk teams that want continuous visibility rather than point-in-time spreadsheets.","category":"cyber-risk-ccm","tags":["ISO 27001","NIST CSF","SOC 2","GDPR","HIPAA","PCI DSS"],"hq":"New York, USA","company_size":"startup","url":"https://www.centraleyes.com","docs_url":"","linkedin":"https://www.linkedin.com/company/centraleyes","frameworks":["ISO 27001","NIST CSF","SOC 2","GDPR","HIPAA","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"certa","name":"Certa","slug":"certa","logo":"","brief_summary":"No-code third-party lifecycle and risk management platform spanning onboarding, risk and ESG.","description":"Certa provides a configurable, no-code platform for third-party onboarding, due diligence, risk assessment and ongoing monitoring across compliance, ESG and financial risk domains. Its workflow engine lets enterprises tailor supplier and partner processes without heavy development. It targets large organizations managing complex third-party ecosystems.","category":"third-party-risk","tags":["ISO 27001","SOC 2","GDPR"],"hq":"Palo Alto, California, USA","company_size":"startup","url":"https://www.certa.ai/","docs_url":"","linkedin":"https://www.linkedin.com/company/certa-inc/","frameworks":["ISO 27001","SOC 2","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"cetbix","name":"Cetbix","slug":"cetbix","logo":"","brief_summary":"AI-powered enterprise platform unifying cybersecurity governance, risk, compliance, and OT governance.","description":"Cetbix is an AI-powered enterprise platform that unifies cybersecurity governance, risk, compliance, audits, assets, and OT governance across more than 40 frameworks including ISO 27001, NIS2, DORA, SOC 2, and TISAX. It bundles IT and OT asset management, risk assessment, quality management, document management, third-party management, and incident management. The vendor emphasizes AI-driven automation to reduce manual compliance effort and provide audit-ready documentation.","category":"enterprise-grc-suites","tags":["ISO 27001","NIS2","DORA","SOC 2","TISAX","NIST"],"hq":"Germany","company_size":"mid-market","url":"https://www.cetbix.com","docs_url":"","linkedin":"https://www.linkedin.com/company/cetbix","frameworks":["ISO 27001","NIS2","DORA","SOC 2","TISAX","NIST"],"deployment":"Hybrid","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"collibra","name":"Collibra","slug":"collibra","logo":"","brief_summary":"Data governance and data intelligence platform underpinning privacy, quality and regulatory data programs.","description":"Collibra provides a data governance and catalog platform that documents data ownership, lineage, quality and policy to support privacy, regulatory and analytics use cases. It gives compliance and data teams a governed inventory of data assets and their obligations. It is used by large regulated enterprises.","category":"privacy-data-governance","tags":["GDPR","CCPA","BCBS 239"],"hq":"New York, New York, USA","company_size":"enterprise","url":"https://www.collibra.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/collibra/","frameworks":["GDPR","CCPA","BCBS 239"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"comp-ai","name":"Comp AI","slug":"comp-ai","logo":"","brief_summary":"Open-source, self-hostable compliance automation platform for SOC 2, ISO 27001, HIPAA, and GDPR.","description":"Comp AI is an AGPLv3-licensed compliance platform that companies can inspect, modify, and self-host, positioned as an open-source alternative to Vanta and Drata. It generates policies, connects to infrastructure to pull evidence for control frameworks, and runs a device agent that checks endpoint settings. The company was founded in early 2025 and reports supporting 25-plus frameworks from a single dashboard.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR"],"hq":"United States","company_size":"startup","url":"https://trycomp.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/trycompai","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR"],"deployment":"Hybrid","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"compliancequest","name":"ComplianceQuest","slug":"compliancequest","logo":"","brief_summary":"Quality, EHS, and compliance management suite built natively on Salesforce.","description":"ComplianceQuest delivers quality management, environment health and safety, and compliance software on the Salesforce platform. It serves regulated manufacturers and life sciences companies managing QMS, EHS, and supplier compliance. The product emphasizes AI-driven automation across quality and safety processes.","category":"ehs-quality-esg","tags":["ISO 9001","ISO 45001","ISO 14001","FDA 21 CFR Part 11"],"hq":"Tampa, Florida, USA","company_size":"mid-market","url":"https://www.compliancequest.com","docs_url":"","linkedin":"https://www.linkedin.com/company/compliancequest","frameworks":["ISO 9001","ISO 45001","ISO 14001","FDA 21 CFR Part 11"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"complyadvantage","name":"ComplyAdvantage","slug":"complyadvantage","logo":"","brief_summary":"AI-driven financial crime detection, AML screening, and transaction monitoring.","description":"ComplyAdvantage provides financial crime risk data and software for AML screening, KYC, sanctions checks, and transaction monitoring. It serves banks, fintechs, and payment firms with real-time risk databases and configurable detection rules. The platform is used to automate customer onboarding and ongoing monitoring obligations.","category":"financial-crime-aml","tags":["AML","KYC","Sanctions Screening","FATF"],"hq":"London, United Kingdom","company_size":"enterprise","url":"https://www.complyadvantage.com","docs_url":"","linkedin":"https://www.linkedin.com/company/complyadvantage","frameworks":["AML","KYC","Sanctions Screening","FATF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"complycube","name":"ComplyCube","slug":"complycube","logo":"","brief_summary":"SaaS and API platform for identity verification, KYC, KYB, AML, and fraud prevention.","description":"ComplyCube is a British platform offering identity verification, AML, KYC, and KYB across financial services, transport, healthcare, gaming, and crypto. In January 2026 it launched an enhanced Compliance Suite adding a no-code KYC workflow builder, fraud intelligence tools, a global eID hub, and US SSN verification. It combines AI-powered verification with real-time risk intelligence in a single unified platform.","category":"financial-crime-aml","tags":["AML","KYC","KYB","GDPR"],"hq":"London, United Kingdom","company_size":"mid-market","url":"https://www.complycube.com","docs_url":"","linkedin":"https://www.linkedin.com/company/complycube","frameworks":["AML","KYC","KYB","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"compyl","name":"Compyl","slug":"compyl","logo":"","brief_summary":"Integrated GRC platform for mid-market teams spanning compliance, risk, contracts, and asset management.","description":"Compyl is an integrated GRC platform that automates compliance across SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and 20-plus frameworks while adding governance, risk, contract, and asset management in one system. It positions itself between lightweight compliance tools and heavyweight enterprise GRC suites, aimed at mid-market companies. Its embedded assistant, Compyl AI, drafts evidence, policies, vendor scores, and questionnaire answers from a company's own data.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","PCI DSS","GDPR"],"hq":"United States","company_size":"startup","url":"https://compyl.com","docs_url":"","linkedin":"https://www.linkedin.com/company/compyl","frameworks":["SOC 2","ISO 27001","HIPAA","PCI DSS","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"controlcase","name":"ControlCase","slug":"controlcase","logo":"","brief_summary":"Continuous compliance platform and certification services across security frameworks.","description":"ControlCase combines a continuous compliance platform with assessment services across PCI DSS, ISO 27001, SOC 2, and related standards. Its software automates evidence collection and control monitoring so multiple certifications can be maintained together. The company is known for the One Audit approach that consolidates overlapping framework requirements.","category":"compliance-automation","tags":["PCI DSS","ISO 27001","SOC 2","HIPAA","GDPR","HITRUST"],"hq":"Fairfax, Virginia, USA","company_size":"mid-market","url":"https://www.controlcase.com","docs_url":"","linkedin":"https://www.linkedin.com/company/controlcase","frameworks":["PCI DSS","ISO 27001","SOC 2","HIPAA","GDPR","HITRUST"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"conveyor","name":"Conveyor","slug":"conveyor","logo":"","brief_summary":"AI platform that automates security questionnaires, RFPs, and trust centers for customer security reviews.","description":"Conveyor automates the buyer side of security reviews, using AI agents to answer security questionnaires and RFPs, run trust centers, and share documents securely. It grounds responses in customer source material to keep accuracy high and hallucination rates low, and is often cited as the closest thing the security questionnaire category has to a market leader. In 2026 it launched an agentic trust center that turns static portals into an AI-driven buyer experience.","category":"third-party-risk","tags":["SOC 2","ISO 27001","GDPR","HIPAA"],"hq":"San Francisco, USA","company_size":"startup","url":"https://www.conveyor.com","docs_url":"","linkedin":"https://www.linkedin.com/company/conveyor-hq","frameworks":["SOC 2","ISO 27001","GDPR","HIPAA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"cority","name":"Cority","slug":"cority","logo":"","brief_summary":"Enterprise EHS, quality, and sustainability management software.","description":"Cority is a longstanding provider of environment health and safety, occupational health, quality, and ESG software. It serves large enterprises managing worker safety, environmental compliance, and sustainability reporting. The platform is delivered as a configurable cloud suite across industrial and regulated sectors.","category":"ehs-quality-esg","tags":["ISO 45001","ISO 14001","ISO 9001","GRI","OSHA"],"hq":"Toronto, Canada","company_size":"enterprise","url":"https://www.cority.com","docs_url":"","linkedin":"https://www.linkedin.com/company/cority","frameworks":["ISO 45001","ISO 14001","ISO 9001","GRI","OSHA"],"deployment":"SaaS","ownership":"independent (private equity backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"corporater","name":"Corporater","slug":"corporater","logo":"","brief_summary":"Configurable business management platform covering GRC and performance.","description":"Corporater offers a business management platform that combines GRC with strategy and performance management. Organizations use it to align risk, compliance, audit, and enterprise objectives in one configurable environment. The vendor targets mid-size to large enterprises wanting an adaptable rather than fixed GRC toolset.","category":"enterprise-grc-suites","tags":["ISO 27001","ISO 31000","COSO","GDPR"],"hq":"Stavanger, Norway","company_size":"mid-market","url":"https://www.corporater.com","docs_url":"","linkedin":"https://www.linkedin.com/company/corporater","frameworks":["ISO 27001","ISO 31000","COSO","GDPR"],"deployment":"Hybrid","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"credo-ai","name":"Credo AI","slug":"credo-ai","logo":"","brief_summary":"Enterprise AI governance platform for managing model risk, compliance, and responsible AI use.","description":"Credo AI is an enterprise AI governance platform that continuously monitors AI models, agents, and applications and enforces policies with automated workflows. It ships prebuilt policy packs for the EU AI Act, NIST AI RMF, ISO 42001, and SOC 2, plus an AI registry and intake to centralize use cases and track evidence. Credo AI was ranked among Fast Company's most innovative companies of 2026 in applied AI.","category":"ai-governance","tags":["EU AI Act","ISO 42001","NIST AI RMF","SOC 2"],"hq":"San Francisco, USA","company_size":"startup","url":"https://www.credo.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/credo-ai","frameworks":["EU AI Act","ISO 42001","NIST AI RMF","SOC 2"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"cyber-sierra","name":"Cyber Sierra","slug":"cyber-sierra","logo":"","brief_summary":"Unified cybersecurity and compliance automation platform out of Singapore.","description":"Cyber Sierra is a cybersecurity and GRC platform that combines compliance automation, continuous control monitoring, and third-party risk in one product. It targets enterprises and fast-growing companies across Asia Pacific and beyond. The platform automates evidence collection and control assurance across multiple frameworks.","category":"compliance-automation","tags":["ISO 27001","SOC 2","GDPR","PCI DSS","HIPAA"],"hq":"Singapore","company_size":"startup","url":"https://cybersierra.co","docs_url":"","linkedin":"https://www.linkedin.com/company/cyber-sierra","frameworks":["ISO 27001","SOC 2","GDPR","PCI DSS","HIPAA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"cyberday","name":"Cyberday","slug":"cyberday","logo":"","brief_summary":"Finnish compliance platform that turns frameworks into prioritized security tasks inside Microsoft Teams.","description":"Cyberday helps European businesses manage information security and reach compliance with ISO 27001, NIS2, DORA, ISO 27701, and GDPR. It breaks selected frameworks into prioritized tasks executed directly within Microsoft Teams, and uses AI to build a baseline ISMS and draft policies. Formerly Agendium, the company operates a Finnish equivalent called Digiturvamalli for local customers.","category":"compliance-automation","tags":["ISO 27001","NIS2","DORA","ISO 27701","GDPR"],"hq":"Finland","company_size":"startup","url":"https://www.cyberday.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/cyberday-ai","frameworks":["ISO 27001","NIS2","DORA","ISO 27701","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"cybersaint","name":"CyberSaint","slug":"cybersaint","logo":"","brief_summary":"Cyber-risk management and quantification platform for continuous control monitoring.","description":"CyberSaint's CyberStrong platform automates cyber-risk assessment, control scoring against frameworks, and financial cyber-risk quantification for boards and security leaders. It aims to give a continuous, quantified view of cyber posture and compliance. It targets enterprise security and risk teams.","category":"cyber-risk-ccm","tags":["NIST CSF","NIST 800-53","ISO 27001","FAIR"],"hq":"Boston, Massachusetts, USA","company_size":"startup","url":"https://www.cybersaint.io/","docs_url":"","linkedin":"https://www.linkedin.com/company/cybersaint-security/","frameworks":["NIST CSF","NIST 800-53","ISO 27001","FAIR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"cypago","name":"Cypago","slug":"cypago","logo":"","brief_summary":"Cyber GRC automation platform that correlates evidence across IT systems for continuous compliance.","description":"Cypago runs a Cyber GRC Automation platform that integrates with corporate IT to automatically collect evidence across data silos, detect compliance gaps, and continuously monitor posture. It uses correlation engines and generative AI to cover multiple frameworks and lets teams build bespoke GRC programs. In 2026 the company added automation support for AI governance, including NIST AI RMF and ISO 42001.","category":"compliance-automation","tags":["SOC 2","ISO 27001","GDPR","NIST AI RMF","ISO 42001","NIST"],"hq":"Israel","company_size":"startup","url":"https://cypago.com","docs_url":"","linkedin":"https://www.linkedin.com/company/cypago","frameworks":["SOC 2","ISO 27001","GDPR","NIST AI RMF","ISO 42001","NIST"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"datagrail","name":"DataGrail","slug":"datagrail","logo":"","brief_summary":"Privacy management platform automating data subject requests, consent and data mapping.","description":"DataGrail automates privacy operations including data subject access requests, consent management, and live data mapping across a company's SaaS and data systems through prebuilt integrations. It helps privacy teams meet GDPR, CCPA and similar obligations with less manual work. It targets mid-market and enterprise privacy programs.","category":"privacy-data-governance","tags":["GDPR","CCPA","CPRA"],"hq":"San Francisco, California, USA","company_size":"startup","url":"https://www.datagrail.io/","docs_url":"","linkedin":"https://www.linkedin.com/company/datagrail/","frameworks":["GDPR","CCPA","CPRA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"dataguard","name":"DataGuard","slug":"dataguard","logo":"","brief_summary":"European security and compliance platform that pairs automation with expert advisory across privacy and infosec.","description":"DataGuard is a Munich-based platform, founded 2018, that helps organizations manage security risk and reach certifications across ISO 27001, TISAX, SOC 2, GDPR, NIS2, and the EU AI Act. It combines AI-driven workflows with tailored consultancy, an approach rooted in its origins as a privacy-as-a-service provider. The company serves more than 4,000 organizations with offices across Europe.","category":"compliance-automation","tags":["ISO 27001","SOC 2","GDPR","TISAX","NIS2","EU AI Act"],"hq":"Munich, Germany","company_size":"mid-market","url":"https://www.dataguard.com","docs_url":"","linkedin":"https://www.linkedin.com/company/dataguard","frameworks":["ISO 27001","SOC 2","GDPR","TISAX","NIS2","EU AI Act"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"didomi","name":"Didomi","slug":"didomi","logo":"","brief_summary":"Paris-based consent and preference management platform for privacy compliance across digital channels.","description":"Didomi is a consent management platform headquartered in Paris that helps organizations collect, store, and manage user consent across websites, apps, and connected TV. It offers consent banners, preference management, DSAR handling, compliance monitoring, and vendor tracking from a centralized system. Marlin Equity Partners made a majority investment in 2025, after which Didomi acquired Addingwell and Sourcepoint to expand into server-side tagging and publisher privacy infrastructure.","category":"privacy-data-governance","tags":["GDPR","CCPA","IAB TCF"],"hq":"Paris, France","company_size":"mid-market","url":"https://www.didomi.io","docs_url":"","linkedin":"https://www.linkedin.com/company/didomi","frameworks":["GDPR","CCPA","IAB TCF"],"deployment":"SaaS","ownership":"majority investment by Marlin Equity (2025)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"digitalxforce","name":"DigitalXForce","slug":"digitalxforce","logo":"","brief_summary":"AI-native automated GRC and digital trust management platform.","description":"DigitalXForce is an AI-native platform for automated governance, risk, and compliance and enterprise security posture management. Founded in 2023, it delivers continuous control assurance, risk quantification, attack surface management, and automated audit reporting. It was named a Leader in the 2025 IDC MarketScape for GRC software.","category":"cyber-risk-ccm","tags":["NIST CSF","ISO 27001","SOC 2","PCI DSS","HIPAA"],"hq":"Southlake, Texas, USA","company_size":"startup","url":"https://digitalxforce.com","docs_url":"","linkedin":"https://www.linkedin.com/company/digitalxforce","frameworks":["NIST CSF","ISO 27001","SOC 2","PCI DSS","HIPAA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"diligent-one-platform","name":"Diligent One Platform","slug":"diligent-one-platform","logo":"","brief_summary":"Diligent's integrated GRC and board governance platform, incorporating the former Galvanize tools.","description":"The Diligent One Platform unifies board governance, audit, risk, and compliance capabilities, including the analytics and GRC tooling from the former Galvanize and ACL acquisitions. It serves boards, executives, and assurance teams across large organizations. Diligent is a major player in governance and integrated risk software.","category":"enterprise-grc-suites","tags":["SOX","ISO 27001","COSO","GDPR","ESG Reporting"],"hq":"New York, USA","company_size":"enterprise","url":"https://www.diligent.com","docs_url":"","linkedin":"https://www.linkedin.com/company/diligent","frameworks":["SOX","ISO 27001","COSO","GDPR","ESG Reporting"],"deployment":"SaaS","ownership":"independent (Clearlake and Insight Partners backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"drata","name":"Drata","slug":"drata","logo":"","brief_summary":"Security and compliance automation platform for continuous framework readiness.","description":"Drata automates security compliance by continuously monitoring controls and collecting evidence for frameworks like SOC 2, ISO 27001, and HIPAA. It integrates with cloud and SaaS systems to keep audit readiness current rather than periodic. The platform is widely adopted by startups and mid-market companies pursuing multiple certifications.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST CSF"],"hq":"San Diego, California, USA","company_size":"enterprise","url":"https://drata.com","docs_url":"","linkedin":"https://www.linkedin.com/company/drata","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"enablon","name":"Enablon","slug":"enablon","logo":"","brief_summary":"Wolters Kluwer's enterprise EHS, operational risk, and sustainability platform.","description":"Enablon is an enterprise platform for environment health and safety, operational risk, and ESG and sustainability management. It is part of Wolters Kluwer and serves large industrial and process-heavy organizations. The product supports incident management, process safety, and sustainability reporting at scale.","category":"ehs-quality-esg","tags":["ISO 45001","ISO 14001","GRI","ISO 31000"],"hq":"Paris, France","company_size":"enterprise","url":"https://www.wolterskluwer.com/en/solutions/enablon","docs_url":"","linkedin":"https://www.linkedin.com/company/enablon","frameworks":["ISO 45001","ISO 14001","GRI","ISO 31000"],"deployment":"SaaS","ownership":"acquired by Wolters Kluwer (2016)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"eqs-group","name":"EQS Group","slug":"eqs-group","logo":"","brief_summary":"Compliance, whistleblowing and corporate governance platform serving European enterprises.","description":"EQS Group provides compliance, whistleblowing (integrity line), policy management, insider-list and disclosure, and investor-relations software for regulated companies, with a strong European base. Its compliance suite supports whistleblower-directive obligations and integrity programs. Thoma Bravo took the company private in 2024.","category":"policy-training-awareness","tags":["EU Whistleblowing Directive","GDPR","MAR"],"hq":"Munich, Germany","company_size":"mid-market","url":"https://www.eqs.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/eqs-group/","frameworks":["EU Whistleblowing Directive","GDPR","MAR"],"deployment":"SaaS","ownership":"acquired by Thoma Bravo (2024)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"fastpath","name":"Fastpath","slug":"fastpath","logo":"","brief_summary":"Access governance and segregation-of-duties platform for ERP and financial applications, now part of Delinea.","description":"Fastpath automates access risk analysis, user access reviews, segregation-of-duties monitoring and compliant provisioning across ERP systems such as NetSuite, Microsoft Dynamics, Oracle and SAP. Delinea acquired Fastpath in early 2024 and continues to sell it as Fastpath Access Control and Access Governance. It is used by internal audit and controls teams to keep application access aligned with GRC requirements.","category":"enterprise-grc-suites","tags":["SOX","SOC 2","ISO 27001"],"hq":"Des Moines, Iowa, USA","company_size":"mid-market","url":"https://delinea.com/products/fastpath-access-control","docs_url":"","linkedin":"https://www.linkedin.com/company/delinea/","frameworks":["SOX","SOC 2","ISO 27001"],"deployment":"SaaS","ownership":"acquired by Delinea (2024)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"feedzai","name":"Feedzai","slug":"feedzai","logo":"","brief_summary":"AI platform for financial fraud prevention and anti-money-laundering risk management.","description":"Feedzai uses machine learning to detect payment fraud, money laundering and account-opening risk in real time for banks, payment providers and merchants. Its RiskOps platform spans transaction monitoring, screening and case management. It serves large financial institutions globally.","category":"financial-crime-aml","tags":["BSA/AML","FATF","PSD2","OFAC"],"hq":"San Mateo, California, USA","company_size":"enterprise","url":"https://www.feedzai.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/feedzai/","frameworks":["BSA/AML","FATF","PSD2","OFAC"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"fenergo","name":"Fenergo","slug":"fenergo","logo":"","brief_summary":"Client lifecycle management and financial crime compliance for financial institutions.","description":"Fenergo provides client lifecycle management, KYC, and AML compliance software for banks and financial institutions. It automates onboarding, due diligence, and regulatory compliance across complex jurisdictions. The platform is used by large financial services firms to streamline client compliance operations.","category":"financial-crime-aml","tags":["AML","KYC","FATCA","CRS","Sanctions Screening"],"hq":"Dublin, Ireland","company_size":"enterprise","url":"https://www.fenergo.com","docs_url":"","linkedin":"https://www.linkedin.com/company/fenergo","frameworks":["AML","KYC","FATCA","CRS","Sanctions Screening"],"deployment":"SaaS","ownership":"independent (Astorg and Bridgepoint backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"formalize","name":"Formalize","slug":"formalize","logo":"","brief_summary":"Danish whistleblowing and compliance platform that expanded into broader ethics and compliance management.","description":"Formalize, the brand of Whistleblower Software ApS, provides a whistleblowing and case-management platform for confidential or anonymous reporting built to comply with the EU Whistleblower Protection Directive and GDPR. It has evolved from a standalone reporting tool into a broader compliance ecosystem covering NIS2, DORA, and ISO 27001. The Danish company raised a large Series A and works with 500-plus consultancy partners including major firms.","category":"policy-training-awareness","tags":["EU Whistleblower Directive","GDPR","NIS2","DORA","ISO 27001"],"hq":"Aarhus, Denmark","company_size":"mid-market","url":"https://formalize.com","docs_url":"","linkedin":"https://www.linkedin.com/company/formalize","frameworks":["EU Whistleblower Directive","GDPR","NIS2","DORA","ISO 27001"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"fusion-risk-management","name":"Fusion Risk Management","slug":"fusion-risk-management","logo":"","brief_summary":"Operational resilience, business continuity, and risk management platform.","description":"Fusion Risk Management delivers operational resilience, business continuity, third-party risk, and crisis management software. Built substantially on the Salesforce platform, it serves enterprises that need to map dependencies and recover from disruption. The product connects risk data with continuity planning and response.","category":"integrated-risk-management","tags":["ISO 22301","ISO 31000","DORA","NIST CSF"],"hq":"Rolling Meadows, Illinois, USA","company_size":"mid-market","url":"https://www.fusionrm.com","docs_url":"","linkedin":"https://www.linkedin.com/company/fusion-risk-management","frameworks":["ISO 22301","ISO 31000","DORA","NIST CSF"],"deployment":"SaaS","ownership":"independent (private equity backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"gan-integrity","name":"GAN Integrity","slug":"gan-integrity","logo":"","brief_summary":"Ethics, compliance and third-party risk management platform for anti-corruption and integrity programs.","description":"GAN Integrity provides a compliance management platform covering third-party due diligence, anti-bribery and corruption, conflicts of interest, disclosures and risk assessments. It centralizes integrity and compliance data for multinational programs. The vendor operates from Copenhagen and New York.","category":"third-party-risk","tags":["FCPA","UK Bribery Act","GDPR"],"hq":"Copenhagen, Denmark","company_size":"startup","url":"https://www.ganintegrity.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/gan-integrity/","frameworks":["FCPA","UK Bribery Act","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"governance-com","name":"Governance.com","slug":"governance-com","logo":"","brief_summary":"Governance and compliance operating system for regulated fund and asset management professionals.","description":"Governance.com provides a platform for regulated fund professionals such as depositaries, AIFMs, and administrators to unify data, automate workflows, and maintain compliance oversight. It targets the alternatives and asset management industry rather than general enterprise GRC. The product centralizes governance and audit-ready reporting across jurisdictions.","category":"enterprise-grc-suites","tags":["AIFMD","GDPR","ISO 27001"],"hq":"Luxembourg","company_size":"startup","url":"https://www.governance.com","docs_url":"","linkedin":"https://www.linkedin.com/company/governance-com","frameworks":["AIFMD","GDPR","ISO 27001"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"heydata","name":"heyData","slug":"heydata","logo":"","brief_summary":"Berlin-based data protection platform bundling an external DPO with compliance software for SMBs.","description":"heyData offers a modular compliance platform aimed at small and medium businesses, bundling an external data protection officer with software for GDPR, NIS2, ISO 27001, and the EU AI Act. Features include a digital GDPR audit, a document vault hosted on German servers, and certified staff training. Pricing starts at roughly 89 euros per month, positioning it for cost-conscious smaller companies.","category":"privacy-data-governance","tags":["GDPR","ISO 27001","NIS2","EU AI Act"],"hq":"Berlin, Germany","company_size":"startup","url":"https://heydata.eu","docs_url":"","linkedin":"https://www.linkedin.com/company/heydata","frameworks":["GDPR","ISO 27001","NIS2","EU AI Act"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"holistic-ai","name":"Holistic AI","slug":"holistic-ai","logo":"","brief_summary":"Enterprise AI governance platform with automated testing and runtime enforcement for AI systems.","description":"Holistic AI is an enterprise AI governance platform that discovers AI systems, tests them for bias, robustness, and hallucinations, and enforces policy using a policy-as-code approach with deployment gates and kill switches. It covers the EU AI Act, ISO 42001, and NIST AI RMF, and in 2026 was named a Challenger in Gartner's first Magic Quadrant for AI Governance Platforms. It has moved into runtime enforcement with guardian agents.","category":"ai-governance","tags":["EU AI Act","ISO 42001","NIST AI RMF"],"hq":"London, United Kingdom","company_size":"startup","url":"https://www.holisticai.com","docs_url":"","linkedin":"https://www.linkedin.com/company/holisticai","frameworks":["EU AI Act","ISO 42001","NIST AI RMF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"hyperproof","name":"Hyperproof","slug":"hyperproof","logo":"","brief_summary":"Compliance operations platform for managing controls, evidence, and multiple frameworks.","description":"Hyperproof is a compliance operations and risk management platform that helps teams manage controls, collect evidence, and scale across many frameworks. It emphasizes reusing control work across overlapping standards to reduce duplicate effort. The product suits growing security and compliance teams handling multiple audits.","category":"compliance-automation","tags":["SOC 2","ISO 27001","NIST CSF","PCI DSS","HIPAA","GDPR"],"hq":"Seattle, Washington, USA","company_size":"mid-market","url":"https://hyperproof.io","docs_url":"","linkedin":"https://www.linkedin.com/company/hyperproof","frameworks":["SOC 2","ISO 27001","NIST CSF","PCI DSS","HIPAA","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"ibm-openpages","name":"IBM OpenPages","slug":"ibm-openpages","logo":"","brief_summary":"IBM's AI-augmented enterprise GRC platform for integrated risk and compliance.","description":"IBM OpenPages is an enterprise GRC platform spanning operational risk, regulatory compliance, internal audit, policy, and financial controls. It uses IBM Watson AI to support risk identification and workflow automation for large regulated organizations. It remains a core enterprise offering within IBM's software portfolio.","category":"enterprise-grc-suites","tags":["SOX","Basel","ISO 27001","GDPR","COSO"],"hq":"Armonk, New York, USA","company_size":"public","url":"https://www.ibm.com/products/openpages","docs_url":"","linkedin":"https://www.linkedin.com/company/ibm","frameworks":["SOX","Basel","ISO 27001","GDPR","COSO"],"deployment":"Hybrid","ownership":"public (IBM)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"ideagen-pentana-audit","name":"Ideagen Pentana Audit","slug":"ideagen-pentana-audit","logo":"","brief_summary":"Internal audit management software within the Ideagen compliance and quality portfolio.","description":"Pentana Audit is Ideagen's internal audit management solution covering risk-based audit planning, fieldwork, findings and reporting. It sits alongside Ideagen's wider quality, EHS and compliance product lines. Ideagen is a UK compliance-software group backed by Hg.","category":"audit-management","tags":["IIA Standards","ISO 27001","SOX"],"hq":"Nottingham, United Kingdom","company_size":"mid-market","url":"https://www.ideagen.com/products/pentana-audit","docs_url":"","linkedin":"https://www.linkedin.com/company/ideagen/","frameworks":["IIA Standards","ISO 27001","SOX"],"deployment":"SaaS","ownership":"independent (Hg-backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"ideagen-q-pulse","name":"Ideagen Q-Pulse","slug":"ideagen-q-pulse","logo":"","brief_summary":"Quality, safety, and compliance management software within the Ideagen portfolio.","description":"Q-Pulse is a quality management, document control, audit, and compliance product now part of Ideagen. It serves regulated industries such as aviation, healthcare, and manufacturing that need traceable QMS and safety processes. Ideagen continues to sell and develop it as part of its broader compliance software suite.","category":"ehs-quality-esg","tags":["ISO 9001","ISO 45001","ISO 14001","AS9100"],"hq":"Nottingham, United Kingdom","company_size":"enterprise","url":"https://www.ideagen.com","docs_url":"","linkedin":"https://www.linkedin.com/company/ideagen","frameworks":["ISO 9001","ISO 45001","ISO 14001","AS9100"],"deployment":"SaaS","ownership":"acquired by Ideagen","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"intelex","name":"Intelex","slug":"intelex","logo":"","brief_summary":"EHS, quality and sustainability management platform, part of Fortive.","description":"Intelex provides environment, health, safety, quality and ESG management software with a large library of configurable applications for incident, audit, compliance and supplier management. It serves large industrial and enterprise customers globally. Intelex is part of Fortive's portfolio.","category":"ehs-quality-esg","tags":["ISO 14001","ISO 45001","ISO 9001","GRI"],"hq":"Toronto, Ontario, Canada","company_size":"enterprise","url":"https://www.intelex.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/intelex-technologies/","frameworks":["ISO 14001","ISO 45001","ISO 9001","GRI"],"deployment":"SaaS","ownership":"acquired by Fortive (2019)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"isms-online","name":"ISMS.online","slug":"isms-online","logo":"","brief_summary":"UK compliance platform with preconfigured tooling for ISO 27001 and related management systems.","description":"ISMS.online is an integrated compliance management platform that helps organizations achieve and maintain ISO 27001 along with GDPR, ISO 27701, and many other standards. It ships prebuilt templates and a structured, step-by-step approach, claiming users can make significant progress from first login. In 2026 the company emphasizes AI-native evidence agents, continuous control monitoring, and data residency.","category":"compliance-automation","tags":["ISO 27001","ISO 27701","GDPR","SOC 2","NIS2"],"hq":"United Kingdom","company_size":"mid-market","url":"https://www.isms.online","docs_url":"","linkedin":"https://www.linkedin.com/company/isms-online","frameworks":["ISO 27001","ISO 27701","GDPR","SOC 2","NIS2"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"isometrix","name":"IsoMetrix","slug":"isometrix","logo":"","brief_summary":"EHS, ESG and integrated risk software with strong footprint in mining, energy and heavy industry.","description":"IsoMetrix is a South African vendor of environment, health, safety, ESG and integrated risk management software, with its Aurora platform used across mining, energy and industrial sectors. A Carlyle Group growth fund took a majority stake in 2019 to fund international expansion. The product combines operational risk, incident and sustainability management.","category":"ehs-quality-esg","tags":["ISO 14001","ISO 45001","GRI","ISO 31000"],"hq":"Johannesburg, South Africa","company_size":"mid-market","url":"https://www.isometrix.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/isometrix-software","frameworks":["ISO 14001","ISO 45001","GRI","ISO 31000"],"deployment":"SaaS","ownership":"acquired by The Carlyle Group majority stake (2019)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"kaseya-compliance-manager-grc","name":"Kaseya Compliance Manager GRC","slug":"kaseya-compliance-manager-grc","logo":"","brief_summary":"GRC and compliance management tool aimed at MSPs and their SMB clients.","description":"Kaseya Compliance Manager GRC helps managed service providers assess, document, and manage compliance obligations for their clients. It automates risk assessments, evidence gathering, and reporting across common regulatory frameworks. The product fits within Kaseya's broader IT management and security suite for MSPs.","category":"compliance-automation","tags":["HIPAA","GDPR","PCI DSS","CMMC","NIST CSF"],"hq":"Miami, Florida, USA","company_size":"enterprise","url":"https://www.kaseya.com/products/grc-software/","docs_url":"","linkedin":"https://www.linkedin.com/company/kaseya","frameworks":["HIPAA","GDPR","PCI DSS","CMMC","NIST CSF"],"deployment":"SaaS","ownership":"independent (part of Kaseya)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"kertos","name":"Kertos","slug":"kertos","logo":"","brief_summary":"Privacy and compliance automation platform focused on GDPR and data protection.","description":"Kertos is a German platform that automates privacy and compliance operations, including data protection, records of processing, and vendor assessments. It targets European companies managing GDPR and related obligations with less manual effort. The product connects data sources to keep privacy documentation current.","category":"privacy-data-governance","tags":["GDPR","ISO 27001","SOC 2","NIS 2","DORA"],"hq":"Munich, Germany","company_size":"startup","url":"https://kertos.io","docs_url":"","linkedin":"https://www.linkedin.com/company/kertos","frameworks":["GDPR","ISO 27001","SOC 2","NIS 2","DORA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"ketch","name":"Ketch","slug":"ketch","logo":"","brief_summary":"Data permissioning and privacy platform for consent, data rights, and privacy-safe data activation.","description":"Ketch runs a data permissioning platform that helps brands collect, control, and activate privacy-safe data across devices, systems, and third-party apps. It manages consent and data subject rights across jurisdictions, maps and monitors personal data with AI-powered discovery and classification, and supports ROPAs and continuous governance. Ketch has been recognized by G2 as a leader across consent management, data privacy, and DSAR categories.","category":"privacy-data-governance","tags":["GDPR","CCPA","CPRA"],"hq":"San Francisco, USA","company_size":"mid-market","url":"https://www.ketch.com","docs_url":"","linkedin":"https://www.linkedin.com/company/ketch-com","frameworks":["GDPR","CCPA","CPRA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"kovrr","name":"Kovrr","slug":"kovrr","logo":"","brief_summary":"Cyber-risk quantification platform for enterprises and boards using financial modeling.","description":"Kovrr provides on-demand cyber-risk quantification, modeling the financial impact of cyber scenarios to support board reporting, control prioritization and regulatory disclosure such as SEC cyber rules. It combines threat data with financial exposure modeling. It serves enterprise risk and security functions.","category":"cyber-risk-ccm","tags":["FAIR","NIST CSF","SEC Cyber Disclosure"],"hq":"Tel Aviv, Israel","company_size":"startup","url":"https://www.kovrr.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/kovrr/","frameworks":["FAIR","NIST CSF","SEC Cyber Disclosure"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"logicgate","name":"LogicGate","slug":"logicgate","logo":"","brief_summary":"Risk Cloud, a no-code integrated risk and GRC platform.","description":"LogicGate's Risk Cloud is a no-code GRC platform for building risk, compliance, and audit workflows without heavy engineering. It supports enterprise risk, third-party risk, and controls management through configurable applications. The vendor positions it as a flexible alternative to rigid legacy GRC suites.","category":"integrated-risk-management","tags":["ISO 27001","SOC 2","NIST CSF","GDPR","PCI DSS"],"hq":"Chicago, Illinois, USA","company_size":"mid-market","url":"https://www.logicgate.com","docs_url":"","linkedin":"https://www.linkedin.com/company/logicgate","frameworks":["ISO 27001","SOC 2","NIST CSF","GDPR","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"logicmanager","name":"LogicManager","slug":"logicmanager","logo":"","brief_summary":"Enterprise risk management and GRC platform with taxonomy-driven risk linking.","description":"LogicManager is an ERM and GRC platform that connects risk, compliance, audit, and governance activities through a shared taxonomy. It emphasizes root-cause and downstream impact analysis across risk areas. The product serves mid-market and enterprise risk teams looking for connected, See-Through visibility.","category":"integrated-risk-management","tags":["ISO 27001","SOX","NIST CSF","GDPR","COSO"],"hq":"Boston, Massachusetts, USA","company_size":"mid-market","url":"https://www.logicmanager.com","docs_url":"","linkedin":"https://www.linkedin.com/company/logicmanager","frameworks":["ISO 27001","SOX","NIST CSF","GDPR","COSO"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"lrn","name":"LRN","slug":"lrn","logo":"","brief_summary":"Ethics, compliance and corporate-culture training and program platform.","description":"LRN provides ethics and compliance training, code-of-conduct management and program benchmarking to help organizations build ethical culture and meet regulatory training obligations. It combines e-learning content with advisory and analytics. It serves large multinational compliance functions.","category":"policy-training-awareness","tags":["FCPA","UK Bribery Act","GDPR"],"hq":"New York, New York, USA","company_size":"mid-market","url":"https://www.lrn.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/lrn/","frameworks":["FCPA","UK Bribery Act","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"mastercontrol","name":"MasterControl","slug":"mastercontrol","logo":"","brief_summary":"Quality and compliance management software for regulated manufacturing and life sciences.","description":"MasterControl provides quality management and manufacturing compliance software for highly regulated industries, particularly life sciences. It covers document control, training, CAPA, and validated manufacturing records. The platform is designed to help companies meet FDA and ISO quality requirements.","category":"ehs-quality-esg","tags":["ISO 9001","FDA 21 CFR Part 11","GxP","ISO 13485"],"hq":"Salt Lake City, Utah, USA","company_size":"enterprise","url":"https://www.mastercontrol.com","docs_url":"","linkedin":"https://www.linkedin.com/company/mastercontrol","frameworks":["ISO 9001","FDA 21 CFR Part 11","GxP","ISO 13485"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"metacompliance","name":"MetaCompliance","slug":"metacompliance","logo":"","brief_summary":"Security awareness training and policy management platform.","description":"MetaCompliance provides security awareness training, phishing simulation, and policy management software. It helps organizations build a human-focused compliance and security culture with automated campaigns. The product covers policy attestation and awareness reporting for regulated environments.","category":"policy-training-awareness","tags":["ISO 27001","GDPR","NIS 2","PCI DSS"],"hq":"Derry, United Kingdom","company_size":"mid-market","url":"https://www.metacompliance.com","docs_url":"","linkedin":"https://www.linkedin.com/company/metacompliance","frameworks":["ISO 27001","GDPR","NIS 2","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"metricstream","name":"MetricStream","slug":"metricstream","logo":"","brief_summary":"Enterprise GRC platform spanning risk, compliance, audit, and cyber risk.","description":"MetricStream is a major enterprise GRC vendor covering operational risk, regulatory compliance, internal audit, third-party risk, and cyber GRC. Its cloud platform serves large regulated organizations that need integrated risk and compliance at scale. The company is one of the established pure-play enterprise GRC providers.","category":"enterprise-grc-suites","tags":["ISO 27001","SOX","NIST CSF","Basel","GDPR"],"hq":"San Jose, California, USA","company_size":"enterprise","url":"https://www.metricstream.com","docs_url":"","linkedin":"https://www.linkedin.com/company/metricstream","frameworks":["ISO 27001","SOX","NIST CSF","Basel","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"mitratech","name":"Mitratech","slug":"mitratech","logo":"","brief_summary":"Legal, risk, and compliance software group with a broad GRC portfolio.","description":"Mitratech provides a wide portfolio of legal operations, risk, and compliance software, expanded through many acquisitions including Alyne, Prevalent, and PolicyHub. It serves corporate legal, risk, and compliance teams across mid-market and enterprise organizations. The company consolidates numerous GRC tools under one vendor.","category":"enterprise-grc-suites","tags":["ISO 27001","GDPR","SOX","NIST CSF"],"hq":"Austin, Texas, USA","company_size":"enterprise","url":"https://mitratech.com","docs_url":"","linkedin":"https://www.linkedin.com/company/mitratech","frameworks":["ISO 27001","GDPR","SOX","NIST CSF"],"deployment":"SaaS","ownership":"independent (private equity backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"modulo-risk-manager","name":"Modulo Risk Manager","slug":"modulo-risk-manager","logo":"","brief_summary":"Brazilian integrated GRC platform for risk, compliance and cyber-defense monitoring.","description":"Modulo Risk Manager is a governance, risk and compliance platform from Modulo, a Rio de Janeiro vendor with a long track record in Latin American public-sector and enterprise risk programs. It supports risk registers, control assessments and continuous compliance monitoring. The company has positioned the product around integrated risk and command-and-control style operational risk monitoring.","category":"enterprise-grc-suites","tags":["ISO 27001","ISO 31000","LGPD","PCI DSS"],"hq":"Rio de Janeiro, Brazil","company_size":"mid-market","url":"https://www.modulo.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/modulogrc","frameworks":["ISO 27001","ISO 31000","LGPD","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"modulos","name":"Modulos","slug":"modulos","logo":"","brief_summary":"ISO 42001-certified AI governance platform for EU AI Act, ISO 42001, and NIST AI RMF compliance.","description":"Modulos is a Swiss AI governance platform that governs AI systems from models to autonomous agents across the EU AI Act, ISO 42001, and NIST AI RMF. It became the first AI governance platform assessed in conformity with ISO 42001, with the assessment conducted by Swiss auditor CertX. The platform helps teams operationalize governance, quantify risk, and produce audit-ready evidence with human-in-the-loop agents.","category":"ai-governance","tags":["EU AI Act","ISO 42001","NIST AI RMF","ISO 27001"],"hq":"Zurich, Switzerland","company_size":"startup","url":"https://www.modulos.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/modulos","frameworks":["EU AI Act","ISO 42001","NIST AI RMF","ISO 27001"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"mycomplianceoffice","name":"MyComplianceOffice","slug":"mycomplianceoffice","logo":"","brief_summary":"Compliance management platform for financial services conduct and conflicts risk.","description":"MyComplianceOffice (MCO) offers compliance software for financial firms managing employee conduct, personal trading, conflicts of interest, and third-party risk. It helps regulated firms enforce policies and monitor conduct obligations. The product is aimed at asset managers, banks, and advisory firms.","category":"financial-crime-aml","tags":["SEC Rules","MiFID II","AML","FCA Rules"],"hq":"Dublin, Ireland","company_size":"mid-market","url":"https://www.mycomplianceoffice.com","docs_url":"","linkedin":"https://www.linkedin.com/company/mycomplianceoffice","frameworks":["SEC Rules","MiFID II","AML","FCA Rules"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"napier-ai","name":"Napier AI","slug":"napier-ai","logo":"","brief_summary":"AI-powered anti-money-laundering platform for screening and transaction monitoring.","description":"Napier AI provides modular AML compliance software covering client screening, transaction monitoring and risk assessment for banks, payments firms and wealth managers. It emphasizes explainable AI to reduce false positives. The UK RegTech is trusted by more than 150 financial institutions.","category":"financial-crime-aml","tags":["BSA/AML","FATF","6AMLD","OFAC"],"hq":"London, United Kingdom","company_size":"startup","url":"https://www.napier.ai/","docs_url":"","linkedin":"https://www.linkedin.com/company/napier-ai/","frameworks":["BSA/AML","FATF","6AMLD","OFAC"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"naq","name":"Naq","slug":"naq","logo":"","brief_summary":"Automated compliance platform covering 20-plus frameworks with a focus on UK and EU regulated-market deals.","description":"Naq Cyber automates compliance across more than 20 frameworks including GDPR, ISO 27001, Cyber Essentials, and NHS-specific standards like DSPT and DTAC, with policy generation, risk monitoring, and dashboards. It claims to automate over 80 percent of the work needed to build an ISMS and provides expert support for the rest. The platform is aimed at startups and vendors selling into regulated UK and EU markets, especially healthcare.","category":"compliance-automation","tags":["GDPR","ISO 27001","Cyber Essentials","NHS DSPT","SOC 2"],"hq":"London, United Kingdom","company_size":"startup","url":"https://www.naqcyber.com","docs_url":"","linkedin":"https://www.linkedin.com/company/naq-cyber","frameworks":["GDPR","ISO 27001","Cyber Essentials","NHS DSPT","SOC 2"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"nasdaq-verafin","name":"Nasdaq Verafin","slug":"nasdaq-verafin","logo":"","brief_summary":"Cloud financial-crime management platform for AML, fraud and sanctions, owned by Nasdaq.","description":"Verafin offers cloud-based anti-financial-crime software covering AML, fraud detection, high-risk customer management and sanctions screening, with a consortium data model across thousands of financial institutions. Nasdaq acquired Verafin in 2021 and sells it as Nasdaq Verafin. It is widely used by North American banks and credit unions.","category":"financial-crime-aml","tags":["BSA/AML","FinCEN","OFAC","FATF"],"hq":"St. John's, Newfoundland, Canada","company_size":"public","url":"https://verafin.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/verafin/","frameworks":["BSA/AML","FinCEN","OFAC","FATF"],"deployment":"SaaS","ownership":"acquired by Nasdaq (2021)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"navex","name":"NAVEX","slug":"navex","logo":"","brief_summary":"Ethics, compliance, policy, and third-party risk platform, known for hotline and GRC.","description":"NAVEX provides an integrated risk and compliance platform covering ethics and compliance hotlines, policy management, compliance training, and third-party risk. It is widely used for whistleblowing case management and program governance. The company is one of the largest dedicated ethics and compliance software vendors.","category":"policy-training-awareness","tags":["SOX","GDPR","ISO 37001","EU Whistleblowing Directive"],"hq":"Lake Oswego, Oregon, USA","company_size":"enterprise","url":"https://www.navex.com","docs_url":"","linkedin":"https://www.linkedin.com/company/navex-global","frameworks":["SOX","GDPR","ISO 37001","EU Whistleblowing Directive"],"deployment":"SaaS","ownership":"independent (BC Partners backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"ncontracts","name":"Ncontracts","slug":"ncontracts","logo":"","brief_summary":"Integrated compliance, risk and vendor management platform built for banks, credit unions and other financial institutions.","description":"Ncontracts provides SaaS for enterprise risk management, regulatory compliance, vendor and third-party risk, and findings management, targeted at the US financial services sector. In 2024 it acquired third-party-risk vendor Venminder in an Hg-backed transaction, growing to more than 5,000 customers. The combined business spans both software and knowledge-as-a-service compliance content.","category":"enterprise-grc-suites","tags":["FFIEC","SOX","GLBA","BSA/AML"],"hq":"Brentwood, Tennessee, USA","company_size":"mid-market","url":"https://www.ncontracts.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/ncontracts/","frameworks":["FFIEC","SOX","GLBA","BSA/AML"],"deployment":"SaaS","ownership":"independent (Hg-backed)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"nice-actimize","name":"NICE Actimize","slug":"nice-actimize","logo":"","brief_summary":"Enterprise financial-crime platform for AML, fraud and market-surveillance compliance.","description":"NICE Actimize provides anti-money-laundering, transaction monitoring, watchlist screening, fraud detection and market-surveillance software for banks and financial institutions. It is one of the largest players in financial-crime and compliance technology. It is a division of the publicly listed NICE Ltd.","category":"financial-crime-aml","tags":["BSA/AML","FATF","MiFID II","OFAC"],"hq":"Hoboken, New Jersey, USA","company_size":"public","url":"https://www.niceactimize.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/nice-actimize/","frameworks":["BSA/AML","FATF","MiFID II","OFAC"],"deployment":"Hybrid","ownership":"public (NICE)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"novisto","name":"Novisto","slug":"novisto","logo":"","brief_summary":"Sustainability and ESG data management and reporting platform for enterprises.","description":"Novisto helps enterprises collect, audit and report ESG data to meet frameworks and regulations such as CSRD, IFRS, GRI and SASB, with a focus on auditability and data quality. It centralizes sustainability disclosures and supporting evidence. The Montreal company raised a $27M Series C in 2025 and later added carbon accounting via an acquisition.","category":"ehs-quality-esg","tags":["CSRD","GRI","SASB","IFRS S1/S2"],"hq":"Montreal, Quebec, Canada","company_size":"startup","url":"https://novisto.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/novisto/","frameworks":["CSRD","GRI","SASB","IFRS S1/S2"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"etq-reliance","name":"Octave Reliance (formerly ETQ Reliance)","slug":"etq-reliance","logo":"","brief_summary":"SaaS quality management system with EHS and compliance modules, now Octave Reliance after Hexagon spun ETQ into Octave.","description":"Octave Reliance (formerly ETQ Reliance) is a configurable quality management platform covering nonconformance, CAPA, document control, audits and supplier quality, plus EHS and compliance applications. Hexagon acquired ETQ in 2022, then spun it off in 2026 into Octave, an independent public software company; the product was rebranded Octave Reliance. It serves manufacturing, life sciences and industrial customers.","category":"ehs-quality-esg","tags":["ISO 9001","ISO 14001","FDA 21 CFR Part 11","ISO 45001"],"hq":"Burlington, Massachusetts, USA","company_size":"mid-market","url":"https://www.octave.com/products/asset-performance-management/reliance","docs_url":"","linkedin":"https://www.linkedin.com/company/etqllc/","frameworks":["ISO 9001","ISO 14001","FDA 21 CFR Part 11","ISO 45001"],"deployment":"SaaS","ownership":"Octave (spun off from Hexagon as an independent public company, 2026)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"oneleet","name":"Oneleet","slug":"oneleet","logo":"","brief_summary":"Security-first compliance platform that bundles penetration testing, monitoring, and evidence automation.","description":"Oneleet consolidates security tooling and compliance into one platform, covering penetration testing, code scanning, cloud security posture management, attack surface monitoring, and training alongside automated compliance workflows. It helps companies reach SOC 2, ISO 27001, and other standards with a security-first approach rather than pure paperwork. The company raised a Series A led by Dawn Capital and is widely used in the Y Combinator community.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS"],"hq":"Amsterdam, Netherlands","company_size":"startup","url":"https://www.oneleet.com","docs_url":"","linkedin":"https://www.linkedin.com/company/oneleet","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"onetrust","name":"OneTrust","slug":"onetrust","logo":"","brief_summary":"Privacy, data governance, and trust platform, with GRC and third-party risk modules.","description":"OneTrust is a leading privacy and trust management platform covering data privacy, consent, data governance, GRC, and third-party risk. It also incorporates the former Tugboat Logic certification automation capabilities. Large organizations use it to operationalize privacy and broader trust programs.","category":"privacy-data-governance","tags":["GDPR","CCPA","ISO 27001","SOC 2","NIST CSF"],"hq":"Atlanta, Georgia, USA","company_size":"enterprise","url":"https://www.onetrust.com","docs_url":"","linkedin":"https://www.linkedin.com/company/onetrust","frameworks":["GDPR","CCPA","ISO 27001","SOC 2","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"onspring","name":"Onspring","slug":"onspring","logo":"","brief_summary":"No-code GRC and business process automation platform.","description":"Onspring is a no-code platform for GRC, business process automation, and reporting, letting teams build risk, audit, and compliance workflows. It supports enterprise risk, third-party risk, and controls management with configurable dashboards. The product appeals to teams wanting flexibility without custom development.","category":"integrated-risk-management","tags":["ISO 27001","SOC 2","NIST CSF","SOX","GDPR"],"hq":"Overland Park, Kansas, USA","company_size":"mid-market","url":"https://onspring.com","docs_url":"","linkedin":"https://www.linkedin.com/company/onspring-technologies","frameworks":["ISO 27001","SOC 2","NIST CSF","SOX","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"optial-smartstart","name":"Optial SmartStart","slug":"optial-smartstart","logo":"","brief_summary":"Enterprise GRC, audit, and EHS software delivered as a configurable suite.","description":"Optial SmartStart is an enterprise platform combining governance, risk, and compliance with audit and environment health and safety modules. It is used by large organizations across many countries and offers SaaS, private cloud, and on-premise deployment. The vendor has operated in the GRC and EHS space for over twenty years.","category":"enterprise-grc-suites","tags":["ISO 27001","SOX","ISO 45001","HIPAA"],"hq":"London, United Kingdom","company_size":"mid-market","url":"https://www.optial.com","docs_url":"","linkedin":"https://www.linkedin.com/company/optial","frameworks":["ISO 27001","SOX","ISO 45001","HIPAA"],"deployment":"Hybrid","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"optimiso-suite","name":"Optimiso Suite","slug":"optimiso-suite","logo":"","brief_summary":"Swiss internal control, process, and GRC software now part of the Iskera group.","description":"Optimiso Suite is a GRC, internal control, and business process management platform used for ISO certification support and risk management. In 2025 Optimiso Group combined with Acuredge and Pocket Result to form Iskera, a European tech-GRC group, and the Optimiso product continues to be sold. It serves public and private organizations mainly across French-speaking Europe.","category":"integrated-risk-management","tags":["ISO 9001","ISO 27001","ISO 31000"],"hq":"Geneva, Switzerland","company_size":"mid-market","url":"https://optimiso-group.com","docs_url":"","linkedin":"https://www.linkedin.com/company/optimiso","frameworks":["ISO 9001","ISO 27001","ISO 31000"],"deployment":"SaaS","ownership":"independent (part of Iskera group, formed 2025)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"auditboard","name":"Optro (formerly AuditBoard)","slug":"auditboard","logo":"","brief_summary":"Connected risk platform spanning audit, SOX, risk, and compliance; rebranded from AuditBoard to Optro in 2026.","description":"Optro (formerly AuditBoard) is a cloud platform for internal audit, SOX compliance, enterprise risk, and IT compliance, built for finance and audit teams. AuditBoard rebranded to Optro in March 2026 as it repositioned around AI-driven GRC; the company is backed by private equity investor Hg. The product connects audit workstreams with risk and controls data in a single system.","category":"audit-management","tags":["SOX","ISO 27001","SOC 2","NIST CSF","PCI DSS"],"hq":"Cerritos, California, USA","company_size":"enterprise","url":"https://optro.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/auditboard","frameworks":["SOX","ISO 27001","SOC 2","NIST CSF","PCI DSS"],"deployment":"SaaS","ownership":"Hg-backed; rebranded from AuditBoard to Optro, 2026","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"origami-risk","name":"Origami Risk","slug":"origami-risk","logo":"","brief_summary":"Integrated risk, insurance, and safety management platform.","description":"Origami Risk is a configurable platform for risk management, insurance and claims, safety, and compliance. It serves risk managers, insurers, and TPAs alongside GRC use cases in mid-market and enterprise organizations. The product connects risk data, claims, and safety processes in one system.","category":"integrated-risk-management","tags":["ISO 31000","OSHA","SOX"],"hq":"Chicago, Illinois, USA","company_size":"enterprise","url":"https://www.origamirisk.com","docs_url":"","linkedin":"https://www.linkedin.com/company/origami-risk","frameworks":["ISO 31000","OSHA","SOX"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"osano","name":"Osano","slug":"osano","logo":"","brief_summary":"Unified data privacy platform automating consent, subject rights, data mapping, and vendor monitoring.","description":"Osano is a unified data privacy management platform that automates consent, preferences, subject rights, data mapping, assessments, and vendor risk across 95-plus privacy laws in over 50 countries. It continuously tracks the privacy practices of more than 60,000 vendors and alerts customers to policy changes or breaches. A certified B Corp and public benefit corporation, Osano backs compliance with a no fines, no penalties guarantee and targets mid-market companies.","category":"privacy-data-governance","tags":["GDPR","CCPA","CPRA"],"hq":"Austin, USA","company_size":"mid-market","url":"https://www.osano.com","docs_url":"","linkedin":"https://www.linkedin.com/company/osano","frameworks":["GDPR","CCPA","CPRA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"panaseer","name":"Panaseer","slug":"panaseer","logo":"","brief_summary":"Continuous controls monitoring platform for security and compliance measurement.","description":"Panaseer aggregates data from security and IT tools to continuously measure control coverage and effectiveness, surfacing gaps for security, risk and compliance teams. Its continuous controls monitoring approach supports audit readiness and risk reporting. It targets large enterprises with complex toolsets.","category":"cyber-risk-ccm","tags":["NIST CSF","ISO 27001","PCI DSS","SOC 2"],"hq":"London, United Kingdom","company_size":"startup","url":"https://panaseer.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/panaseer/","frameworks":["NIST CSF","ISO 27001","PCI DSS","SOC 2"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"panorays","name":"Panorays","slug":"panorays","logo":"","brief_summary":"Third-party security risk platform combining external attack-surface scanning with security questionnaires.","description":"Panorays automates third-party and supply-chain security risk assessment by pairing outside-in attack-surface ratings with automated security questionnaires and continuous monitoring. It is aimed at security and vendor-risk teams managing large supplier portfolios. The company is headquartered in Israel with US operations.","category":"third-party-risk","tags":["ISO 27001","SOC 2","GDPR","NIST CSF"],"hq":"Tel Aviv, Israel","company_size":"startup","url":"https://panorays.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/panorays/","frameworks":["ISO 27001","SOC 2","GDPR","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"pathlock","name":"Pathlock","slug":"pathlock","logo":"","brief_summary":"Application access governance and ERP GRC platform for SoD and controls.","description":"Pathlock provides application access governance, segregation of duties, and continuous controls monitoring focused on ERP systems like SAP and Oracle. Formed from the consolidation of several access and ERP GRC vendors, it automates access risk and compliance controls. It serves enterprises with complex business application landscapes.","category":"enterprise-grc-suites","tags":["SOX","ISO 27001","GDPR","NIST CSF"],"hq":"Flemington, New Jersey, USA","company_size":"mid-market","url":"https://pathlock.com","docs_url":"","linkedin":"https://www.linkedin.com/company/pathlock","frameworks":["SOX","ISO 27001","GDPR","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"predict360","name":"Predict360","slug":"predict360","logo":"","brief_summary":"AI-powered GRC and regulatory compliance suite from 360factors for banking.","description":"Predict360 by 360factors is a GRC and regulatory compliance platform with a strong focus on banking and financial services. It combines risk, compliance, audit, and regulatory change management with predictive analytics. The product helps regulated institutions manage exams, controls, and compliance obligations.","category":"enterprise-grc-suites","tags":["SOX","FFIEC","Basel","NIST CSF"],"hq":"Austin, Texas, USA","company_size":"mid-market","url":"https://www.360factors.com","docs_url":"","linkedin":"https://www.linkedin.com/company/360factors","frameworks":["SOX","FFIEC","Basel","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"prevalent","name":"Prevalent","slug":"prevalent","logo":"","brief_summary":"Third-party and vendor risk management platform, now part of Mitratech.","description":"Prevalent is a third-party and supplier risk management platform covering vendor assessments, continuous monitoring, and risk scoring. Mitratech acquired Prevalent in October 2024 and continues to sell it within its enterprise risk portfolio. The product remains a recognized dedicated TPRM offering.","category":"third-party-risk","tags":["ISO 27001","SOC 2","NIST CSF","GDPR"],"hq":"Phoenix, Arizona, USA","company_size":"mid-market","url":"https://mitratech.com/products/prevalent/","docs_url":"","linkedin":"https://www.linkedin.com/company/prevalent-networks","frameworks":["ISO 27001","SOC 2","NIST CSF","GDPR"],"deployment":"SaaS","ownership":"acquired by Mitratech (2024)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"probo","name":"Probo","slug":"probo","logo":"","brief_summary":"Open-source compliance automation paired with managed compliance experts for SOC 2, ISO 27001, GDPR, and more.","description":"Probo is an open-source, self-hostable compliance platform that combines automation with dedicated compliance experts to run a program end to end: policies, controls, evidence collection, reviews, and vendor assessments. It supports SOC 2, ISO 27001, ISO 27701, ISO 42001, GDPR, HIPAA, CCPA, NIS2, and DORA, and publishes a branded trust page for customers. The codebase is on GitHub (getprobo/probo) with Docker Compose deployment.","category":"compliance-automation","tags":["SOC 2","ISO 27001","GDPR","ISO 42001","open-source"],"hq":"","company_size":"startup","url":"https://www.probo.com","docs_url":"","linkedin":"","frameworks":["SOC 2","ISO 27001","ISO 27701","ISO 42001","GDPR","HIPAA","CCPA","NIS2","DORA"],"deployment":"Hybrid","ownership":"independent (open-source, GitHub getprobo/probo)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"founder-flag"},{"id":"processunity","name":"ProcessUnity","slug":"processunity","logo":"","brief_summary":"Third-party risk management platform combined with the CyberGRX risk exchange.","description":"ProcessUnity is a third-party risk management platform that merged with CyberGRX to pair workflow automation with a large cyber risk exchange. It covers vendor onboarding, assessments, continuous monitoring, and due diligence. The combined company is a leading dedicated TPRM provider.","category":"third-party-risk","tags":["ISO 27001","SOC 2","NIST CSF","GDPR"],"hq":"Concord, Massachusetts, USA","company_size":"mid-market","url":"https://www.processunity.com","docs_url":"","linkedin":"https://www.linkedin.com/company/processunity","frameworks":["ISO 27001","SOC 2","NIST CSF","GDPR"],"deployment":"SaaS","ownership":"independent (merged with CyberGRX, 2023)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"protecht-erm","name":"Protecht ERM","slug":"protecht-erm","logo":"","brief_summary":"Enterprise risk management platform from Australia with strong risk analytics.","description":"Protecht ERM is an enterprise risk management platform covering risk registers, controls, incidents, compliance, and risk analytics. It originated in Australia and serves risk teams across financial services, government, and other regulated sectors. The product emphasizes practical operational risk management and reporting.","category":"integrated-risk-management","tags":["ISO 31000","APRA CPS 230","ISO 27001"],"hq":"Sydney, Australia","company_size":"mid-market","url":"https://www.protechtgroup.com","docs_url":"","linkedin":"https://www.linkedin.com/company/protecht","frameworks":["ISO 31000","APRA CPS 230","ISO 27001"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"quantexa","name":"Quantexa","slug":"quantexa","logo":"","brief_summary":"Decision intelligence and entity-resolution platform used for AML, KYC and financial-crime investigations.","description":"Quantexa builds a contextual, connected view of customers and counterparties through entity resolution and network analytics, powering AML, KYC, fraud and investigations use cases. Financial institutions and government agencies use it to uncover hidden risk across data silos. The company is a UK-based decision-intelligence unicorn.","category":"financial-crime-aml","tags":["BSA/AML","FATF","KYC","OFAC"],"hq":"London, United Kingdom","company_size":"enterprise","url":"https://www.quantexa.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/quantexa/","frameworks":["BSA/AML","FATF","KYC","OFAC"],"deployment":"Hybrid","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"quantivate","name":"Quantivate","slug":"quantivate","logo":"","brief_summary":"GRC and enterprise risk software with a focus on banking and credit unions.","description":"Quantivate provides GRC, enterprise risk, business continuity, and vendor management software, with a focus on banks and credit unions. It offers modular tools for risk assessments, compliance, audit, and third-party management. The product suits financial institutions wanting an integrated risk and compliance system.","category":"integrated-risk-management","tags":["FFIEC","SOX","ISO 27001","NIST CSF"],"hq":"Woodinville, Washington, USA","company_size":"mid-market","url":"https://quantivate.com","docs_url":"","linkedin":"https://www.linkedin.com/company/quantivate","frameworks":["FFIEC","SOX","ISO 27001","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"resolver","name":"Resolver","slug":"resolver","logo":"","brief_summary":"Risk intelligence and GRC platform owned by Kroll.","description":"Resolver is a risk intelligence platform covering enterprise risk, compliance, incident management, security operations, and third-party risk. It is owned by Kroll and serves enterprises that want to connect risk data to business impact. The product spans both corporate risk and physical security use cases.","category":"integrated-risk-management","tags":["ISO 27001","ISO 31000","SOX","GDPR"],"hq":"Toronto, Canada","company_size":"enterprise","url":"https://www.resolver.com","docs_url":"","linkedin":"https://www.linkedin.com/company/resolver-inc","frameworks":["ISO 27001","ISO 31000","SOX","GDPR"],"deployment":"SaaS","ownership":"acquired by Kroll (2022)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"riskonnect","name":"Riskonnect","slug":"riskonnect","logo":"","brief_summary":"Integrated risk management platform spanning ERM, insurance, and resilience.","description":"Riskonnect is an integrated risk management platform covering enterprise risk, insurance and claims, third-party risk, health and safety, and business continuity. It serves large organizations wanting a single view of risk across the enterprise. The company has grown through acquisitions into a broad IRM provider.","category":"integrated-risk-management","tags":["ISO 31000","ISO 22301","SOX","GDPR"],"hq":"Atlanta, Georgia, USA","company_size":"enterprise","url":"https://riskonnect.com","docs_url":"","linkedin":"https://www.linkedin.com/company/riskonnect","frameworks":["ISO 31000","ISO 22301","SOX","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"riskwatch","name":"RiskWatch","slug":"riskwatch","logo":"","brief_summary":"Risk assessment and compliance platform covering many security frameworks.","description":"RiskWatch is a risk and compliance management platform that automates security and regulatory assessments across dozens of frameworks. Operating since the 1990s, it serves healthcare, financial services, government, and other regulated sectors. The product focuses on assessment-driven risk scoring and compliance reporting.","category":"integrated-risk-management","tags":["ISO 27001","NIST CSF","HIPAA","PCI DSS","GDPR"],"hq":"Sarasota, Florida, USA","company_size":"startup","url":"https://www.riskwatch.com","docs_url":"","linkedin":"https://www.linkedin.com/company/riskwatch","frameworks":["ISO 27001","NIST CSF","HIPAA","PCI DSS","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"safe-security","name":"SAFE Security","slug":"safe-security","logo":"","brief_summary":"Cyber-risk quantification and management platform (SAFE One), parent of RiskLens methodology.","description":"SAFE Security provides cyber-risk quantification and management through its SAFE platform, translating security telemetry and control posture into financial risk estimates using FAIR-based methods. It acquired RiskLens and consolidated cyber-risk quantification under the SAFE brand. It serves enterprise CISOs and risk teams.","category":"cyber-risk-ccm","tags":["FAIR","NIST CSF","ISO 27001"],"hq":"Palo Alto, California, USA","company_size":"startup","url":"https://safe.security/","docs_url":"","linkedin":"https://www.linkedin.com/company/safesecurity/","frameworks":["FAIR","NIST CSF","ISO 27001"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"safebase","name":"SafeBase","slug":"safebase","logo":"","brief_summary":"Trust center platform for publishing security posture and streamlining vendor security reviews.","description":"SafeBase pioneered the trust center category, giving companies a public portal to share security and compliance documentation and reduce friction in customer security reviews. It served over 1,000 organizations including large enterprises before Drata agreed to acquire it in a deal announced February 2025 valued at around 250 million dollars. The product continues to be sold and is now integrated into Drata's trust management portfolio.","category":"third-party-risk","tags":["SOC 2","ISO 27001","GDPR","HIPAA"],"hq":"San Francisco, USA","company_size":"mid-market","url":"https://safebase.io","docs_url":"","linkedin":"https://www.linkedin.com/company/safebase","frameworks":["SOC 2","ISO 27001","GDPR","HIPAA"],"deployment":"SaaS","ownership":"acquired by Drata (2025)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"sai360","name":"SAI360","slug":"sai360","logo":"","brief_summary":"Integrated GRC and ethics and compliance learning platform.","description":"SAI360 provides an integrated GRC platform combined with ethics and compliance learning content, covering risk, compliance, EHS, and policy. It carries forward the former SAI Global compliance business and the legacy Compliance 360 product. The company serves enterprises wanting GRC software paired with compliance training.","category":"enterprise-grc-suites","tags":["ISO 27001","GDPR","ISO 45001","SOX"],"hq":"Chicago, Illinois, USA","company_size":"enterprise","url":"https://www.sai360.com","docs_url":"","linkedin":"https://www.linkedin.com/company/sai360","frameworks":["ISO 27001","GDPR","ISO 45001","SOX"],"deployment":"SaaS","ownership":"independent (compliance business of former SAI Global)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"sap-grc","name":"SAP GRC","slug":"sap-grc","logo":"","brief_summary":"SAP's suite of access control, process control and risk management modules embedded in the SAP enterprise stack.","description":"SAP GRC covers access risk analysis, segregation of duties, automated controls testing and enterprise risk management for organizations running SAP. It is aimed at large enterprises that need governance controls tightly coupled to their ERP and business processes. Modules include Access Control, Process Control and Risk Management.","category":"enterprise-grc-suites","tags":["SOX","GDPR","ISO 27001"],"hq":"Walldorf, Germany","company_size":"public","url":"https://www.sap.com/products/financial-management/grc.html","docs_url":"","linkedin":"https://www.linkedin.com/company/sap/","frameworks":["SOX","GDPR","ISO 27001"],"deployment":"Hybrid","ownership":"public (SAP)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"sas-anti-money-laundering","name":"SAS Anti-Money Laundering","slug":"sas-anti-money-laundering","logo":"","brief_summary":"Enterprise AML and financial-crime analytics from analytics vendor SAS.","description":"SAS Anti-Money Laundering provides transaction monitoring, watchlist screening, customer due diligence and alert management built on SAS analytics and machine learning, aimed at large banks and regulators. It is part of SAS's broader fraud and financial-crime portfolio. SAS Institute is a large privately held analytics company.","category":"financial-crime-aml","tags":["BSA/AML","FATF","OFAC","FinCEN"],"hq":"Cary, North Carolina, USA","company_size":"enterprise","url":"https://www.sas.com/en_us/software/anti-money-laundering.html","docs_url":"","linkedin":"https://www.linkedin.com/company/sas/","frameworks":["BSA/AML","FATF","OFAC","FinCEN"],"deployment":"Hybrid","ownership":"independent (SAS Institute)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"scrut-automation","name":"Scrut Automation","slug":"scrut-automation","logo":"","brief_summary":"Cloud-based GRC platform that automates compliance, risk assessment, and audit prep for growth-stage companies.","description":"Scrut Automation provides a security compliance and risk management platform aimed at growth-stage SaaS and cloud-native companies. It automates evidence collection, control monitoring, and audit readiness, and has added generative AI features to cut manual work for risk and compliance teams. The company has raised roughly 20 million dollars from investors including Lightspeed and MassMutual Ventures.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS"],"hq":"Palo Alto, USA","company_size":"startup","url":"https://www.scrut.io","docs_url":"","linkedin":"https://www.linkedin.com/company/scrutauto","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"scytale","name":"Scytale","slug":"scytale","logo":"","brief_summary":"Compliance automation platform for SOC 2, ISO 27001, and related frameworks.","description":"Scytale automates security compliance by streamlining evidence collection, control monitoring, and audit readiness across multiple frameworks. It targets growing companies that need to achieve and maintain certifications efficiently. The product combines automation with guided support through audits.","category":"compliance-automation","tags":["SOC 2","ISO 27001","GDPR","HIPAA","PCI DSS"],"hq":"New York, USA","company_size":"startup","url":"https://scytale.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/scytale-ai","frameworks":["SOC 2","ISO 27001","GDPR","HIPAA","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"secfix","name":"Secfix","slug":"secfix","logo":"","brief_summary":"End-to-end security compliance platform focused on ISO 27001 and EU regulations for mid-sized companies.","description":"Secfix automates security compliance across ISO 27001, the EU AI Act, NIS2, GDPR, and SOC 2, running more than 250 automated checks against ISO 27001 controls. The Munich-based company pairs its platform with a CISO-as-a-service offering and speaks German, targeting small and mid-sized European businesses. It closed an oversubscribed 12 million dollar Series A in February 2026 led by Alstin Capital.","category":"compliance-automation","tags":["ISO 27001","SOC 2","GDPR","NIS2","EU AI Act"],"hq":"Munich, Germany","company_size":"startup","url":"https://www.secfix.com","docs_url":"","linkedin":"https://www.linkedin.com/company/secfix","frameworks":["ISO 27001","SOC 2","GDPR","NIS2","EU AI Act"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"secureframe","name":"Secureframe","slug":"secureframe","logo":"","brief_summary":"Security and privacy compliance automation platform.","description":"Secureframe automates security and privacy compliance, helping companies get and stay compliant with frameworks like SOC 2, ISO 27001, and HIPAA. It continuously monitors controls and integrates with cloud infrastructure to collect evidence. The platform serves startups and mid-market companies managing multiple standards.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST CSF"],"hq":"San Francisco, California, USA","company_size":"mid-market","url":"https://secureframe.com","docs_url":"","linkedin":"https://www.linkedin.com/company/secureframe","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"securiti","name":"Securiti","slug":"securiti","logo":"","brief_summary":"Data command center for privacy, security, governance, and AI data risk.","description":"Securiti provides a unified data controls platform covering privacy, data security, data governance, and AI data risk. It automates data discovery, mapping, consent, and privacy request handling across large data estates. The product targets enterprises managing complex data and emerging AI governance requirements.","category":"privacy-data-governance","tags":["GDPR","CCPA","ISO 27001","SOC 2","EU AI Act"],"hq":"San Jose, California, USA","company_size":"enterprise","url":"https://securiti.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/securiti-ai","frameworks":["GDPR","CCPA","ISO 27001","SOC 2","EU AI Act"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"securityscorecard","name":"SecurityScorecard","slug":"securityscorecard","logo":"","brief_summary":"Security ratings platform used for third-party and supply-chain cyber risk management.","description":"SecurityScorecard rates organizations' external security posture using continuously collected internet signals, and packages this into third-party risk, supply-chain and cyber-risk management workflows. Security and vendor-risk teams use it to monitor supplier portfolios and benchmark their own posture. It positions strongly in the GRC and TPRM space alongside its ratings core.","category":"third-party-risk","tags":["NIST CSF","ISO 27001","SOC 2","PCI DSS"],"hq":"New York, New York, USA","company_size":"enterprise","url":"https://securityscorecard.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/security-scorecard/","frameworks":["NIST CSF","ISO 27001","SOC 2","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"servicenow-grc","name":"ServiceNow GRC","slug":"servicenow-grc","logo":"","brief_summary":"ServiceNow's Integrated Risk Management applications on the Now Platform.","description":"ServiceNow GRC, delivered as its Integrated Risk Management product line, brings risk, compliance, audit, and policy management onto the Now Platform. It connects risk and compliance workflows with IT and operational data already in ServiceNow. Large enterprises adopt it to unify GRC with their broader digital workflows.","category":"enterprise-grc-suites","tags":["ISO 27001","SOX","NIST CSF","GDPR","PCI DSS"],"hq":"Santa Clara, California, USA","company_size":"public","url":"https://www.servicenow.com/products/governance-risk-and-compliance.html","docs_url":"","linkedin":"https://www.linkedin.com/company/servicenow","frameworks":["ISO 27001","SOX","NIST CSF","GDPR","PCI DSS"],"deployment":"SaaS","ownership":"public (NOW)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"skillcast","name":"Skillcast","slug":"skillcast","logo":"","brief_summary":"Compliance training, e-learning and policy management platform for regulated businesses.","description":"Skillcast delivers compliance e-learning, policy attestation, registers and RegTech tools aimed at UK and European regulated firms. It covers areas such as anti-money laundering, GDPR, conduct and health and safety training. It targets compliance and HR teams needing auditable training and policy records.","category":"policy-training-awareness","tags":["GDPR","FCA","AML","Bribery Act"],"hq":"London, United Kingdom","company_size":"mid-market","url":"https://www.skillcast.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/skillcast/","frameworks":["GDPR","FCA","AML","Bribery Act"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"smart-global-governance","name":"Smart Global Governance","slug":"smart-global-governance","logo":"","brief_summary":"French modular GRC platform combining risk, compliance, and AI across 200-plus standards.","description":"Smart Global Governance, founded 2019 in Valbonne, France, sells a modular GRC platform with 13 functional modules spanning risk management and compliance. The platform automates a large share of key processes and covers more than 200 standards and regulations, with EuroPrivacy accreditation and support for the EU AI Act. It offers on-premises, hybrid, or cloud deployment, including SecNumCloud hosting in France.","category":"enterprise-grc-suites","tags":["ISO 27001","GDPR","SOC 2","EU AI Act","NIS2","DORA"],"hq":"Valbonne, France","company_size":"startup","url":"https://www.smart-global-governance.com","docs_url":"","linkedin":"https://www.linkedin.com/company/smartglobalgovernance","frameworks":["ISO 27001","GDPR","SOC 2","EU AI Act","NIS2","DORA"],"deployment":"Hybrid","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"sphera","name":"Sphera","slug":"sphera","logo":"","brief_summary":"ESG, EHS, and operational risk software for industrial and process sectors.","description":"Sphera, delivered through SpheraCloud, provides ESG and sustainability, environment health and safety, operational risk, and product stewardship software. It serves industrial and process-heavy enterprises managing safety and sustainability obligations. The company is owned by Blackstone and focuses on operational excellence and risk.","category":"ehs-quality-esg","tags":["ISO 45001","ISO 14001","GRI","REACH"],"hq":"Chicago, Illinois, USA","company_size":"enterprise","url":"https://sphera.com","docs_url":"","linkedin":"https://www.linkedin.com/company/sphera","frameworks":["ISO 45001","ISO 14001","GRI","REACH"],"deployment":"SaaS","ownership":"independent (Blackstone-owned)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"sprinto","name":"Sprinto","slug":"sprinto","logo":"","brief_summary":"Compliance automation platform for fast-growing cloud companies.","description":"Sprinto automates security compliance for cloud-first companies, continuously monitoring controls and collecting evidence for frameworks like SOC 2 and ISO 27001. It targets startups and scaleups that want to achieve certifications quickly and maintain them. The platform integrates with cloud tools to keep compliance continuous.","category":"compliance-automation","tags":["SOC 2","ISO 27001","GDPR","HIPAA","PCI DSS"],"hq":"San Francisco, California, USA","company_size":"mid-market","url":"https://sprinto.com","docs_url":"","linkedin":"https://www.linkedin.com/company/sprinto","frameworks":["SOC 2","ISO 27001","GDPR","HIPAA","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"squalify","name":"Squalify","slug":"squalify","logo":"","brief_summary":"Munich Re-backed top-down cyber risk quantification platform for boards and CISOs.","description":"Squalify is a Munich-based cyber risk quantification venture of reinsurer Munich Re that quantifies cyber risk in financial terms for benchmarking, insurance decisions, and board reporting. Its top-down approach draws on more than 15 years of cyber risk data, and in January 2026 it launched Essential CRQ, which produces a financial quantification in as little as 24 hours from a minimal set of inputs. The platform helps identify high-ROI controls and simulate business impacts.","category":"cyber-risk-ccm","tags":["FAIR","NIST","ISO 27001"],"hq":"Munich, Germany","company_size":"startup","url":"https://www.squalify.io","docs_url":"","linkedin":"https://www.linkedin.com/company/squalify","frameworks":["FAIR","NIST","ISO 27001"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"standardfusion","name":"StandardFusion","slug":"standardfusion","logo":"","brief_summary":"GRC platform for managing compliance, risk, and audits in one place.","description":"StandardFusion is a GRC platform that helps teams manage compliance, risk, audits, and policies across frameworks such as ISO 27001 and SOC 2. It focuses on giving small and mid-size organizations an accessible, structured GRC system. The product centralizes controls, evidence, and risk in a single tool.","category":"compliance-automation","tags":["ISO 27001","SOC 2","NIST CSF","GDPR","PCI DSS"],"hq":"Vancouver, Canada","company_size":"startup","url":"https://www.standardfusion.com","docs_url":"","linkedin":"https://www.linkedin.com/company/standardfusion","frameworks":["ISO 27001","SOC 2","NIST CSF","GDPR","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"sumsub","name":"Sumsub","slug":"sumsub","logo":"","brief_summary":"Full-cycle identity verification and compliance platform for KYC, KYB, AML, and fraud prevention.","description":"Sumsub is a London-headquartered verification platform offering an integrated solution for KYC, KYB, AML screening, transaction monitoring, Travel Rule compliance, and fraud prevention. Founded 2015, it serves more than 4,000 companies and processes millions of verifications daily across 220-plus countries and thousands of document types. In 2026 it partnered with ComplyAdvantage to strengthen AML screening.","category":"financial-crime-aml","tags":["AML","KYC","KYB","GDPR"],"hq":"London, United Kingdom","company_size":"mid-market","url":"https://sumsub.com","docs_url":"","linkedin":"https://www.linkedin.com/company/sum-and-substance-ltd-","frameworks":["AML","KYC","KYB","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"supply-wisdom","name":"Supply Wisdom","slug":"supply-wisdom","logo":"","brief_summary":"Real-time third-party and location risk intelligence platform spanning financial, cyber, ESG and operational domains.","description":"Supply Wisdom is a SaaS platform that continuously monitors third-party and supply-chain risk across financial, cyber, operational, ESG and compliance domains, including location-based risk. It emphasizes always-on risk intelligence rather than point-in-time assessments. The company raised $14M and appointed a new CEO in 2025.","category":"third-party-risk","tags":["ISO 27001","NIST CSF","GDPR"],"hq":"New York, New York, USA","company_size":"startup","url":"https://www.supplywisdom.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/supply-wisdom/","frameworks":["ISO 27001","NIST CSF","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"surecloud","name":"SureCloud","slug":"surecloud","logo":"","brief_summary":"AI-powered GRC platform connecting risk, compliance, audit, and privacy.","description":"SureCloud is a UK-based GRC platform that connects risk, compliance, audit, third-party risk, and data privacy in one place. Founded in 2006, it was recognized in Gartner and Forrester analyst coverage in 2025. The product emphasizes configurable workflows and AI assistance across GRC use cases.","category":"enterprise-grc-suites","tags":["ISO 27001","GDPR","PCI DSS","SOC 2","NIST CSF"],"hq":"Reading, United Kingdom","company_size":"mid-market","url":"https://www.surecloud.com","docs_url":"","linkedin":"https://www.linkedin.com/company/surecloud","frameworks":["ISO 27001","GDPR","PCI DSS","SOC 2","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"teammate","name":"TeamMate+","slug":"teammate","logo":"","brief_summary":"Internal audit management platform from Wolters Kluwer used by audit teams worldwide.","description":"TeamMate+ is Wolters Kluwer's audit management software covering audit planning, workpapers, controls, issue tracking and data analysis, aligned to IIA standards. It serves internal audit functions across corporates, government and financial services in over 150 countries. Wolters Kluwer continues to invest in it, adding AI documentation features in 2025.","category":"audit-management","tags":["IIA Standards","SOX","COSO"],"hq":"Alphen aan den Rijn, Netherlands","company_size":"public","url":"https://www.wolterskluwer.com/en/solutions/teammate","docs_url":"","linkedin":"https://www.linkedin.com/company/wolters-kluwer/","frameworks":["IIA Standards","SOX","COSO"],"deployment":"SaaS","ownership":"public (Wolters Kluwer)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"tenacy","name":"Tenacy","slug":"tenacy","logo":"","brief_summary":"French cyber GRC platform that maps, orchestrates, and manages cybersecurity across complex organizations.","description":"Tenacy is a French cyber GRC platform designed for complex organizations, hosted in France and aligned with digital sovereignty requirements. It centralizes entities, frameworks, and processes for full visibility into cyber impact and uses intelligent modeling of frameworks and risks to interconnect cyber processes. More than 200 teams use it to move from compliance ambition to structured, sustainable ISMS management.","category":"enterprise-grc-suites","tags":["ISO 27001","NIS2","GDPR","NIST","DORA"],"hq":"France","company_size":"startup","url":"https://www.tenacy.io","docs_url":"","linkedin":"https://www.linkedin.com/company/tenacy","frameworks":["ISO 27001","NIS2","GDPR","NIST","DORA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"thoropass","name":"Thoropass","slug":"thoropass","logo":"","brief_summary":"Compliance automation platform that pairs evidence collection and continuous monitoring with an in-house audit team.","description":"Thoropass, formerly Laika, combines a compliance automation platform with connected audits delivered through an affiliated CPA firm. It automates control mapping, recurring evidence collection, risk assessments, and third-party reviews across more than 30 frameworks. The company reported over 1,200 customers in 2026 and positions itself as an end to end path from readiness to attestation.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST"],"hq":"New York, USA","company_size":"mid-market","url":"https://www.thoropass.com","docs_url":"","linkedin":"https://www.linkedin.com/company/thoropass","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"transcend","name":"Transcend","slug":"transcend","logo":"","brief_summary":"Real-time data governance and privacy platform that answers whether data can be used for a given purpose.","description":"Transcend is a data governance and privacy platform that embeds data-use permissions directly into the systems that collect and process data, creating an enforceable source of truth for consent and business rules. It automates data subject requests, unifies consent and preference management, and adds data discovery, classification, risk intelligence, and AI governance. The company was named a Leader in the 2025 IDC MarketScape for data privacy compliance software.","category":"privacy-data-governance","tags":["GDPR","CCPA","HIPAA"],"hq":"San Francisco, USA","company_size":"mid-market","url":"https://transcend.io","docs_url":"","linkedin":"https://www.linkedin.com/company/transcend-inc","frameworks":["GDPR","CCPA","HIPAA"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"trustarc","name":"TrustArc","slug":"trustarc","logo":"","brief_summary":"Privacy management platform for data privacy programs and assessments.","description":"TrustArc provides privacy management software covering data privacy assessments, consent, data mapping, and regulatory research. It helps organizations operationalize and demonstrate compliance with global privacy laws. The company is one of the established dedicated privacy technology vendors.","category":"privacy-data-governance","tags":["GDPR","CCPA","ISO 27001","APEC CBPR"],"hq":"San Francisco, California, USA","company_size":"mid-market","url":"https://trustarc.com","docs_url":"","linkedin":"https://www.linkedin.com/company/trustarc","frameworks":["GDPR","CCPA","ISO 27001","APEC CBPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"trustcloud","name":"TrustCloud","slug":"trustcloud","logo":"","brief_summary":"AI-native GRC and security assurance platform that ties compliance to day-to-day security operations.","description":"TrustCloud, based in Boston, sells an AI-native security assurance platform that connects governance, risk, and compliance with security operations, emphasizing automation and continuous monitoring. It automates evidence collection and offers a trust portal, and is notable for a free tier that gives startups under 20 employees SOC 2 readiness at no software cost. The audit itself is a separate paid engagement.","category":"compliance-automation","tags":["SOC 2","ISO 27001","GDPR","HIPAA","NIST"],"hq":"Boston, USA","company_size":"startup","url":"https://www.trustcloud.ai","docs_url":"","linkedin":"https://www.linkedin.com/company/trustcloudai","frameworks":["SOC 2","ISO 27001","GDPR","HIPAA","NIST"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"trustero","name":"Trustero","slug":"trustero","logo":"","brief_summary":"AI-powered compliance-as-a-service platform that auto-collects and maps evidence to controls.","description":"Trustero offers compliance-as-a-service for emerging companies, using AI receptors to automatically collect and map evidence to controls without manual data rooms. It provides policy templates, automated evidence gathering, continuous monitoring, and a central portal for tracking compliance progress toward SOC 2 and other frameworks. The company has completed its own SOC 2 Type 1 audit and markets patented AI for GRC and internal audit.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR"],"hq":"San Francisco, USA","company_size":"startup","url":"https://trustero.com","docs_url":"","linkedin":"https://www.linkedin.com/company/trustero","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"unit21","name":"Unit21","slug":"unit21","logo":"","brief_summary":"No-code risk and compliance platform for transaction monitoring, fraud and case management.","description":"Unit21 offers a no-code platform for transaction monitoring, fraud detection, KYC/KYB and case management aimed at fintechs, banks and crypto firms. Its rule-building interface lets risk analysts adjust detection logic without engineering. It targets modern financial and payments companies.","category":"financial-crime-aml","tags":["BSA/AML","FinCEN","KYC","OFAC"],"hq":"San Francisco, California, USA","company_size":"startup","url":"https://www.unit21.ai/","docs_url":"","linkedin":"https://www.linkedin.com/company/unit21/","frameworks":["BSA/AML","FinCEN","KYC","OFAC"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"upguard","name":"UpGuard","slug":"upguard","logo":"","brief_summary":"Attack-surface and third-party risk platform combining security ratings with vendor questionnaires.","description":"UpGuard pairs external attack-surface monitoring and data-leak detection with vendor security questionnaires and remediation workflows for third-party risk management. It is used by security teams to score their own exposure and continuously assess suppliers. The company operates out of the US and Australia.","category":"third-party-risk","tags":["ISO 27001","SOC 2","NIST CSF","PCI DSS"],"hq":"Mountain View, California, USA","company_size":"startup","url":"https://www.upguard.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/upguard/","frameworks":["ISO 27001","SOC 2","NIST CSF","PCI DSS"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"usercentrics","name":"Usercentrics","slug":"usercentrics","logo":"","brief_summary":"Leading consent management platform for GDPR and global privacy compliance across web and apps.","description":"Usercentrics is a consent management platform that helps businesses collect and manage user consent for GDPR, CCPA, and other privacy laws without disrupting website performance. It is Google-certified and supports IAB TCF and Google Consent Mode, and by 2026 was trusted by around 2.4 million websites and apps processing billions of consents monthly. Its Cookiebot product extends the same capability to smaller sites.","category":"privacy-data-governance","tags":["GDPR","CCPA","IAB TCF","POPIA"],"hq":"Munich, Germany","company_size":"enterprise","url":"https://usercentrics.com","docs_url":"","linkedin":"https://www.linkedin.com/company/usercentrics","frameworks":["GDPR","CCPA","IAB TCF","POPIA"],"deployment":"SaaS","ownership":"acquired by EQT (2024)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"vanta","name":"Vanta","slug":"vanta","logo":"","brief_summary":"Trust management and compliance automation platform.","description":"Vanta automates security and compliance, continuously monitoring controls and collecting evidence across frameworks such as SOC 2, ISO 27001, and HIPAA. It has expanded into broader trust management, including vendor risk and questionnaire automation. The platform is widely used by startups and mid-market companies to reach and maintain certifications.","category":"compliance-automation","tags":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST CSF"],"hq":"San Francisco, California, USA","company_size":"enterprise","url":"https://www.vanta.com","docs_url":"","linkedin":"https://www.linkedin.com/company/vanta-security","frameworks":["SOC 2","ISO 27001","HIPAA","GDPR","PCI DSS","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"vcomply","name":"VComply","slug":"vcomply","logo":"","brief_summary":"Cloud GRC platform for policy, compliance, and risk management.","description":"VComply is a cloud GRC platform covering compliance management, policy management, risk, and controls for mid-market organizations. It emphasizes ease of use and quick deployment for teams moving off spreadsheets. The product spans governance, risk, and compliance workflows in one accessible system.","category":"integrated-risk-management","tags":["ISO 27001","SOC 2","HIPAA","GDPR","NIST CSF"],"hq":"Sunnyvale, California, USA","company_size":"startup","url":"https://www.v-comply.com","docs_url":"","linkedin":"https://www.linkedin.com/company/vcomply","frameworks":["ISO 27001","SOC 2","HIPAA","GDPR","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"velocityehs","name":"VelocityEHS","slug":"velocityehs","logo":"","brief_summary":"Cloud EHS and ESG platform covering safety, chemical management and sustainability.","description":"VelocityEHS offers cloud environment, health, safety and ESG software spanning incident management, chemical and SDS management, industrial ergonomics, and sustainability reporting. It serves a broad base of mid-market and enterprise customers. The Accelerate platform ties these programs together.","category":"ehs-quality-esg","tags":["ISO 14001","ISO 45001","OSHA","GRI"],"hq":"Chicago, Illinois, USA","company_size":"mid-market","url":"https://www.ehs.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/velocityehs/","frameworks":["ISO 14001","ISO 45001","OSHA","GRI"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"vendict","name":"Vendict","slug":"vendict","logo":"","brief_summary":"AI-native platform for automating security questionnaire responses and compliance reviews.","description":"Vendict automates security and compliance reviews, generating answers from verified security documentation with a citation on every response. It cross-maps evidence against more than 40 framework requirements, flags gaps before customers find them, and answers questionnaires in multiple languages. In February 2026 it launched an interactive trust center that turns security reviews into a shared workspace between vendors and buyers.","category":"third-party-risk","tags":["SOC 2","ISO 27001","GDPR","HIPAA","NIST"],"hq":"Israel","company_size":"startup","url":"https://vendict.com","docs_url":"","linkedin":"https://www.linkedin.com/company/vendict","frameworks":["SOC 2","ISO 27001","GDPR","HIPAA","NIST"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"venminder","name":"Venminder","slug":"venminder","logo":"","brief_summary":"Third-party risk management platform with in-house vendor assessment and due-diligence services, now part of Ncontracts.","description":"Venminder combines TPRM software with a managed service that produces vendor risk assessments, contract reviews and control validations for regulated industries. Ncontracts acquired it in September 2024, and the product continues to be sold under the Venminder name within the combined portfolio. It is widely used by banks and credit unions.","category":"third-party-risk","tags":["FFIEC","SOC 2","GLBA","ISO 27001"],"hq":"Elizabethtown, Kentucky, USA","company_size":"mid-market","url":"https://www.venminder.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/venminder/","frameworks":["FFIEC","SOC 2","GLBA","ISO 27001"],"deployment":"SaaS","ownership":"acquired by Ncontracts (2024)","status":"acquired-still-sold","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"whistic","name":"Whistic","slug":"whistic","logo":"","brief_summary":"Vendor security assessment and profile-sharing network for third-party risk teams.","description":"Whistic runs a two-sided network where vendors publish security profiles and customers assess them, streamlining questionnaire exchange and continuous vendor risk monitoring. Its Vendor Security Network reduces duplicated assessment work between buyers and sellers. The platform is used by security and procurement teams for TPRM.","category":"third-party-risk","tags":["ISO 27001","SOC 2","CAIQ","NIST CSF"],"hq":"Pleasant Grove, Utah, USA","company_size":"startup","url":"https://www.whistic.com/","docs_url":"","linkedin":"https://www.linkedin.com/company/whistic/","frameworks":["ISO 27001","SOC 2","CAIQ","NIST CSF"],"deployment":"SaaS","ownership":"independent","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"wolters-kluwer-onesumx","name":"Wolters Kluwer OneSumX","slug":"wolters-kluwer-onesumx","logo":"","brief_summary":"Regulatory reporting, risk and finance platform for banks and financial institutions.","description":"OneSumX is Wolters Kluwer's finance, risk and regulatory reporting suite for financial institutions, covering regulatory compliance, risk management and finance data. It helps banks meet reporting obligations across many jurisdictions from a single data foundation. It is part of Wolters Kluwer's Financial and Corporate Compliance division.","category":"financial-crime-aml","tags":["Basel III","IFRS","CRR","DORA"],"hq":"Alphen aan den Rijn, Netherlands","company_size":"public","url":"https://www.wolterskluwer.com/en/solutions/onesumx-for-finance-risk-and-regulatory-reporting","docs_url":"","linkedin":"https://www.linkedin.com/company/wolters-kluwer/","frameworks":["Basel III","IFRS","CRR","DORA"],"deployment":"Hybrid","ownership":"public (Wolters Kluwer)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"research"},{"id":"workiva","name":"Workiva","slug":"workiva","logo":"","brief_summary":"Cloud platform for connected financial, ESG, audit, and risk reporting.","description":"Workiva is a public company providing a connected reporting and compliance platform spanning financial reporting, ESG, audit, and risk. It links data and narrative across regulatory and internal reports to keep them consistent and controlled. Large enterprises use it for SEC, ESG, and assurance reporting.","category":"audit-management","tags":["SOX","ESG Reporting","SEC Reporting","COSO"],"hq":"Ames, Iowa, USA","company_size":"public","url":"https://www.workiva.com","docs_url":"","linkedin":"https://www.linkedin.com/company/workiva","frameworks":["SOX","ESG Reporting","SEC Reporting","COSO"],"deployment":"SaaS","ownership":"public (WK)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"},{"id":"zengrc","name":"ZenGRC","slug":"zengrc","logo":"","brief_summary":"GRC platform from RiskOptics for compliance, risk, and audit management.","description":"ZenGRC is a GRC platform for compliance, risk, and audit management, sold by RiskOptics (formerly Reciprocity). It consolidates the capabilities previously split across ZenGRC and ZenComply into one product. The platform helps teams map controls, track compliance, and manage risk across frameworks.","category":"integrated-risk-management","tags":["SOC 2","ISO 27001","NIST CSF","PCI DSS","GDPR"],"hq":"San Francisco, California, USA","company_size":"mid-market","url":"https://www.zengrc.com","docs_url":"","linkedin":"https://www.linkedin.com/company/risk-optics","frameworks":["SOC 2","ISO 27001","NIST CSF","PCI DSS","GDPR"],"deployment":"SaaS","ownership":"independent (RiskOptics, formerly Reciprocity)","status":"alive","publish_after":null,"date_added":"2026-08-10","source":"seed"}]}