Loading...

GRC & Compliance

Industry-leading governance, risk management, compliance automation, and third-party risk providers

Try:

Capability Legend

GRC GRC Platform
Comply Compliance Automation
Risk Risk Assessment
Policy Policy Management
Audit Audit Management
TPRM Third-Party Risk
SOC 2 SOC 2 Automation
ISO ISO 27001
Vendor Vendor Risk
Privacy Privacy Compliance
Monitor Continuous Monitoring
Showing 151 of 151 vendors

Enterprise GRC Platform (19)

ServiceNow
ServiceNow is an American software company that supplies a cloud computing platform for the creation and management of automated business workflows. I
GRC Comply Risk
OneTrust
OneTrust helps companies manage privacy, consent, and AI governance while automating compliance and reducing risk to build trust and drive innovation.
GRC Comply Risk
Archer
Archer is a leading integrated risk management platform that enables organizations to manage governance, risk, and compliance across the enterprise. T
GRC Comply Risk
LogicGate
LogicGate provides industry-leading Governance, Risk, and Compliance (GRC) software solutions that streamline and automate processes, helping organiza
GRC Comply Risk
Avertro
Avertro provides a unified platform for threat defense, automating compliance and quantifying risk across enterprise environments. The company offers
GRC Comply Risk
Cyber Sierra
Cyber Sierra offers an AI-powered cybersecurity platform that provides automated continuous control monitoring, third-party risk management, and GRC s
GRC Comply Risk
DRTConfidence
DRTConfidence enables enterprises and government agencies to automate compliance management with multiple regulatory frameworks, enhancing their overa
GRC Comply Policy
DataBee
DataBee unlocks the power of data with a cloud-native security data fabric and AI-powered network detection and response solutions for cybersecurity a
GRC Comply Risk
DigitalXForce
DigitalXForce leads the IDC MarketScape 2025 assessment for worldwide governance, risk, and compliance software vendors. It provides an Enterprise Sec
GRC Comply Risk
Diligent
Diligent Corporation is a software as a service company that enables groups to share and collaborate information for board meetings. It offers AI-powe
GRC Comply Risk
FAIR Institute
The FAIR Institute The company provides enterprise-grade governance, risk, and compliance solutions for organizations worldwide. Its platform is desig
GRC Risk
MetricStream
MetricStream offers Governance, Risk Management and Compliance (GRC) software solutions that allow companies across industries to streamline and autom
GRC Comply Risk
Panaseer
Panaseer's Continuous Controls Monitoring platform helps organizations reduce control failures by providing automated, trusted insight into their cybe
GRC Risk Monitor
Reasonable Risk
Reasonable Risk is a DoCRA-based GRC SaaS Platform that facilitates SEC Compliance and helps organizations establish reasonable security. It serves th
GRC Risk
RiskApp
RiskApp Solutions Platform automates compliance with AI, providing real-time risk management and tailored risk scoring based on risk appetite. The com
GRC Risk TPRM
Safe Security
SAFE is a leader in Autonomous Cyber Risk Management for strategic (CRQ), exposure (CTEM), and third-party (TPRM) risk management on a unified platfor
GRC Risk TPRM
SafePaaS
SafePaaS provides a comprehensive access governance platform that enables organizations to automate security incident detection and prevention, access
GRC Comply Risk
SmartSuite
SmartSuite is a cloud-based enterprise platform that unifies risk, compliance, audit, third-party risk, resilience, and workflows to drive execution.
GRC Comply Policy
StandardFusion
StandardFusion provides a centralized and adaptive GRC platform that gives organizations clarity and consistency in managing risk, compliance, and aud
GRC Comply Risk

Compliance Automation (15)

Drata
Drata is a leading compliance automation platform that helps companies achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR compliance thro
Comply Policy Audit
Vanta
Vanta automates the complex and time-consuming process of SOC 2, HIPAA, ISO 27001, PCI, and GDPR compliance certification. The company provides a plat
Comply Risk Policy
Secureframe
Secureframe automates compliance and security processes for businesses using AI-powered capabilities, streamlining tasks such as evidence collection,
Comply Risk Policy
Hyperproof
Hyperproof's GRC platform turns GRC into a growth engine. Eliminate duplicate work and see 66% reduction in duplicative controls. The company automate
Comply Risk Policy
Controllo
Controllo simplifies compliance across multiple frameworks by linking controls, artifacts, and risks, eliminating redundancy and duplication. One Plat
Comply Risk Audit
FireMon
FireMon's firewall policy management platform provides real-time visibility and control over hybrid IT environments. It unifies, governs, and continuo
Comply Policy Monitor
Scrut Automation
Scrut Automation helps businesses build risk-aligned security programs that scale with them, providing AI-powered solutions for compliance and risk ma
Comply Risk Policy
Segura
Segura is a leading provider of Privileged Access Management (PAM) solutions, offering a comprehensive suite of products and services to secure and co
Comply Risk Audit
Sky BlackBox
Sky BlackBox is an AI-powered Vendor Risk Management platform that automates third-party risk assessments, enhances vendor compliance, supports supply
Comply Audit Monitor
Sprinto
Sprinto delivers autonomous trust with real-time monitoring, continuous compliance, and unified risk management for organizations across various indus
Comply Policy Audit
Thoropass
Compliance with confidence - Thoropass is the only end-to-end compliance solution offering expert guidance, thorough prep, and a seamless security aud
Comply Audit SOC 2
Tripwire
Tripwire, now part of Fortra, provides enterprise security configuration management, vulnerability management, and file integrity monitoring solutions
Comply Policy Monitor
Trustero
Trustero is Advanced AI for Security and Compliance Teams that handles time-consuming tasks like gap analysis, remediation, questionnaire automation,
Comply Audit SOC 2
VioletX
VioletX operates the trust infrastructure that makes audits routine and risk visible in real time. Federal-grade security and compliance for the compa
Comply Policy Monitor
ZenGRC by Reciprocity
ZenGRC offers comprehensive GRC solutions that unify, simplify, and automate compliance, risk, and governance initiatives for organizations. The compa
GRC Comply Risk

Third-Party & Vendor Risk (13)

SecurityScorecard
SecurityScorecard is a cybersecurity company that provides a supply chain and third-party risk management platform powered by AI. It helps organizatio
Risk TPRM Vendor
Bitsight Technologies
Bitsight Technologies, Inc. is a cybersecurity company that provides security performance monitoring, exposure analysis, and risk management for compa
Risk TPRM Vendor
Black Kite
Black Kite offers a cyber ratings tool dedicated to third-party risk intelligence, providing real-time, multi-source verified intelligence for vendors
Risk TPRM Vendor
Attaxion
Attaxion helps lean security teams find and manage their web-facing assets, uncovering exposures and prioritizing cyber risks through agentless traffi
Risk TPRM Vendor
CybelAngel
CybelAngel offers a range of products and services for external threat intelligence, including Attack Surface Management, Data Breach Prevention, Dark
Risk TPRM Vendor
Cybersixgill
BitSight Technologies, Inc. is a cybersecurity company that does security performance monitoring, exposure analysis, and risk management for companies
Risk TPRM Vendor
Nudge Security
SaaS and AI security platform that provides visibility and control over distributed application ecosystems. Offers shadow SaaS/AI discovery, SaaS secu
Panorays
Panorays is a comprehensive third-party cyber risk management platform that monitors Risk DNA for early threat detection and proactive defense. It pro
Risk TPRM Vendor
Prevalent
Mitratech Prevalent is an AI-powered third-party risk management software that automates workflows and simplifies compliance for organizations. The co
Risk Audit TPRM
ProcessUnity
ProcessUnity is a top-rated provider of Third-Party Vendor Risk Management solutions, helping organizations safeguard themselves through AI-powered in
Comply Risk Policy
RiskRecon by Mastercard
RiskRecon provides actionable insights to help organizations manage cyber risks and threats through its threat intelligence and third-party risk manag
Risk TPRM Vendor
UpGuard
UpGuard is the #1 Cyber Risk Posture Management Software Platform that helps businesses manage security risks across their information technology supp
Risk TPRM Vendor
Whistic
Whistic is a third-party risk management software company that automates vendor assessments and shares security posture to build customer trust. It of
TPRM Vendor

Privacy & Data Governance (12)

TrustArc
TrustArc bridges the gap between privacy and data for deeper insights, broader access, and continuous compliance. The company provides software and se
Comply Policy Privacy
Arexdata Security Solutions
Arexdata DSPM is a comprehensive data security platform that audits, classifies, and protects sensitive company data, ensuring centralized visibility
Privacy Monitor
DataSunrise
DataSunrise offers comprehensive database security solutions with advanced database firewall, activity monitoring, masking, and compliance capabilitie
Policy Audit Privacy
Ethyca
Ethyca builds trusted data infrastructure to govern sensitive data in real time with automated inventory, consent, and AI enforcement. The company pro
Comply Policy Privacy
Exterro (FTK)
Maker of the Forensic Toolkit (FTK), a gold-standard full-disk forensic imaging, processing, and review platform trusted for decades in courtrooms wor
Privacy
Global Relay
Global Relay is a technology services company providing software-as-a-service electronic message archiving, instant messaging, compliance and supervis
Comply Audit Privacy
Jatheon Technologies
Jatheon Technologies Inc develops AI-enabled data archiving and information governance solutions for regulated industries. The company provides softwa
Comply Audit Privacy
Lumos
Lumos is an autonomous identity platform that eliminates identity sprawl and fatigue by providing a single platform for access reviews, self-service a
Policy Audit Privacy
Protecto AI
Protecto AI provides secure AI solutions with real-time Role-Based Access Control (RBAC) and context-based access control to prevent sensitive data le
Privacy
Smarsh
Smarsh provides comprehensive archiving and compliance solutions for highly regulated industries through its cloud-based platform, offering tools for
Comply Policy Audit
Spirion
archTIS is a data security company that specializes in sensitive data governance and protection. Its core business involves providing automated discov
Privacy
Zivver
Zivver Secure Business Email provides complete email security and effortless data compliance for businesses. It offers secure email solutions, threat
Comply Privacy

Audit & Assurance (11)

A-LIGN
A-LIGN is a compliance and cybersecurity services provider that helps organizations navigate the scope and complexity of their specific security needs
Comply Risk Audit
AuditBoard
Optro is an AI-powered Governance, Risk, and Compliance (GRC) platform that helps enterprises manage risk and compliance through a unified system of a
Comply Risk Audit
Bureau Veritas
Bureau Veritas is a global leader in testing, inspection, and certification services. The company provides a wide range of products and services to en
Comply Audit ISO
Bureau Veritas Cybersecurity
Bureau Veritas Cybersecurity provides cybersecurity services to organizations, including risk assessment, compliance management, and incident response
Comply Risk Audit
Coalfire
Coalfire is a cybersecurity and compliance services company that works with enterprises and tech businesses in FedRAMP, cloud migration, AI Risk, pene
Comply Risk Audit
Optro
Optro is an AI-powered Governance, Risk, and Compliance (GRC) platform that unifies audit, risk, infosec, and compliance into a single connected syste
Comply Risk Audit
Pen Test Partners
Pen Test Partners provides cyber security consulting and testing to a huge variety of industries and organisations. With offices in the US and UK, we'
Risk Audit
Prescient Security
Prescient Security simplifies cybersecurity and compliance for over 5,000 clients worldwide by providing services such as SOC, ISO, HITRUST, FedRAMP,
Comply Risk Audit
SISA
SISA is a cybersecurity leader that specializes in securing payment ecosystems through compliance, security, and privacy solutions. It serves global p
Comply Risk Audit
depthfirst
depthfirst is an AI-native platform that understands your code, business logic, and infrastructure to find more vulnerabilities, slash false positives
Audit
risk3sixty
risk3sixty helps businesses build and manage robust security, privacy, and compliance programs to empower them and assure stakeholders. They specializ
Comply Risk Audit

AI Governance & Risk (10)

ALERT AI
ALERT AI - "Secure AI Anywhere" AI Security gateway. Autonomous AI Security, Resilience, Policy Management - AI Apps, AI Agents, AI Tools.. The compan
Comply Risk Policy
Cranium AI
Cranium AI provides end-to-end AI cybersecurity governance solutions to global enterprises, helping them ensure the security and compliance of their A
Comply Risk Policy
Credo AI
Credo AI provides operationalized trusted AI governance solutions that enable enterprises to discover, assess, and govern every AI agent, model, and a
Comply Risk Policy
DeepKeep AI Security Platform
DeepKeep safeguards AI with AI-native security and trustworthiness from the research and development phase of machine learning models through risk ass
Risk Monitor
FireTail
FireTail is an AI security & governance platform that provides complete visibility and control over AI usage across all environments. The company offe
Risk Policy Audit
Noma Security
Noma Security provides AI security solutions for enterprises to protect against AI-specific threats and ensure regulatory compliance. The company offe
Comply Risk Policy
Openlayer
Openlayer provides AI governance and observability solutions for trust & control in AI systems. It offers native integrations with various AI models,
Risk Monitor
Pillar Security
Pillar Security provides a unified platform to identify, assess, and mitigate security risks across the entire AI lifecycle, offering comprehensive vi
Risk Policy Monitor
Weights & Biases
Weights & Biases is an AI developer platform that enables companies to build, manage, and deploy AI models with confidence. The company provides a sui
Audit Monitor
Xeris
Xeris provides complete visibility, control, and enforcement across the entire enterprise AI universe-powered by autonomous Super Agents that govern A
Comply Risk Policy

Specialized GRC & Risk (71)

AKA Identity
AKA Identity revolutionizes identity management through data science, data engineering, and agents, serving security and IT organizations with a team
SOC 2 ISO
Aleph Alpha
Aleph Alpha develops specialized language models and AI solutions for enterprises and public institutions in Europe, focusing on large language models
Comply
Alloy
Alloy is an American financial technology company that provides an identity decisioning and risk management platform used by banks, credit unions, and
GRC Comply Risk
Anchore
Anchore provides software supply chain security solutions that automate vulnerability scanning, SBOM management, and compliance enforcement for contai
Comply Policy
Asimily
Asimily is the leading top-rated IT, IoT, OT & IoMT exposure management platform enabling Visibility, Vulnerability Prioritization, Risk Mitigation, T
GRC Risk Monitor
Astrix Security
Astrix secures agent identities with governance, least-privilege access, and full audit trails for AI agents & NHIs, a critical need in the industry.
Audit
Beyond Encryption
Beyond Encryption provides secure email and identity solutions to protect sensitive information in every interaction. The company offers Mailock for s
Risk ISO
Booli.ai
Booli is the world's first identity-centric SIEM that ties alerts to people, not just events - giving security teams the context they need to act fast
Comply
BotCity
BotCity provides enterprise governance for Python and AI at scale, helping global organizations maintain control, security, and compliance across Pyth
GRC Comply Risk
Brinqa
Brinqa delivers AI-driven exposure intelligence that unifies cyber risk data, clarifies ownership, and helps enterprises focus on what matters most. I
GRC Risk
Censys
Censys empowers security teams with the most comprehensive, accurate, and up-to-date map of the internet to defend attack surfaces and hunt for threat
Risk
Classiq
Classiq is the only enterprise-grade Quantum Software Engineering Platform that helps teams build real quantum capability and get results today. Build
SOC 2 Privacy
Codacy
Codacy governs code quality, security, and AI coding policies from a single place, enabling dev teams to ship safely without slowing down. The company
Audit
Echoworx Email Encryption
Echoworx delivers secure email encryption for modern enterprises, providing sovereignty as a service and transforming compliance challenges into compe
Comply Privacy
Fable Security
Fable Security reimagines human risk management with AI-powered interventions, assessing and mitigating employee security risks through behavioral ana
Comply Risk
Filigran
Filigran offers an open-source eXtended Threat Management platform that unifies threat intelligence, security validation, and remediation to help orga
GRC Risk Monitor
Forescout Technologies
Forescout provides continuous asset visibility, compliance, and network security across IT, OT, and IoT environments through its 4D Platform. The comp
GRC Comply Risk
Heimdall Data
Heimdall Data provides performance security intelligence to optimize and secure databases for Fortune 100 companies. The company offers database proxy
Comply
Hoxhunt
The Hoxhunt Human Risk Management Platform provides an AI-powered cybersecurity training platform for phishing simulations and security awareness trai
GRC Risk
INSSIDE
INSSIDE provides comprehensive cybersecurity services to clients, aligning with industry standards. It offers various services including GRC, Blue Tea
GRC
Iru
Iru is an American technology company that develops an enterprise device management and security platform. It provides AI-powered solutions for identi
Comply
Jumio
Jumio is an online identity verification company that offers AI-powered identity verification and validation products for mobile and web transactions.
Risk
Keepit
Keepit offers cloud data protection services for SaaS applications, providing immutable backup and recovery solutions to ensure business continuity an
Comply Privacy
Key2XS
Key2XS provides comprehensive access governance solutions for critical organizations, ensuring security, compliance, and operational efficiency throug
Comply Audit Monitor
KnowBe4
KnowBe4 is a Gartner Magic Quadrant Leader (December 2025) delivering the HRM+ (Human Risk Management) platform combining security awareness training,
GRC Risk
Kymatio
Kymatio empowers organizations to detect and manage human cyber risk through its AI-driven platform, providing complete cybersecurity awareness and tr
Risk
Linx Security
Linx Security provides an AI-native platform for identity security, visibility, and governance, offering automated identity management, risk analysis,
GRC Comply Risk
LuxSci
LuxSci provides secure healthcare communications solutions designed for personalization and hypersegmentation, including HIPAA compliant email, market
Privacy
Mailjet
Mailjet is a French email marketing platform that provides cloud-based solutions for designing, sending, and tracking both marketing and transactional
Comply Privacy
Mandiant
Mandiant is a cybersecurity consulting firm that helps organizations transform their cyber defense capabilities through incident response, threat inte
Risk
MetaCompliance
MetaCompliance is a human risk management platform that offers security awareness, compliance, policy, and risk analytics solutions to help organisati
GRC Comply Risk
NAVEX
NAVEX is a risk and compliance solutions provider helping organizations worldwide simplify compliance and confidently manage risk by connecting its so
GRC Comply Privacy
NetRise
NetRise provides comprehensive insight into the many risks present in firmware and software components through its automated, cloud-based platform. Th
Risk TPRM Vendor
Nisos
Nisos provides human risk management and digital investigations to help organizations detect, investigate, and mitigate human threats. It offers solut
GRC Risk TPRM
Nuix
Nuix Ltd is an Australian technology company that produces investigative analytics and intelligence software for extracting knowledge from unstructure
Comply Privacy
ONEKEY
ONEKEY provides an all-in-one platform for product cybersecurity and compliance, offering automated SBOM management, vulnerability analysis, and compl
Comply Risk
One Identity
One Identity is a cybersecurity platform and unified identity security solution that enables organizations to protect their people, applications, and
GRC Risk Privacy
OpenText (EnCase)
Gold-standard computer forensics platform with 30+ years of courtroom-proven reliability. EnCase collects and analyzes data from 36,000+ device types
Comply
Opsin Security
Opsin Security helps enterprises securely deploy and govern AI applications, identifying data exposure risks and providing continuous monitoring to ke
GRC Risk Monitor
Paubox
Paubox provides HIPAA-compliant email security solutions for healthcare organizations, protecting against advanced threats and ensuring compliance wit
Comply Privacy
PhishingBox
PhishingBox offers cybersecurity training and phishing simulations to protect against ransomware, malware, mobile threats, and social engineering atta
Risk
PreVeil
PreVeil provides end-to-end encrypted email and file sharing solutions for defense and regulated industries, ensuring compliance with CMMC, NIST, ITAR
Comply Privacy
PricewaterhouseCoopers (PwC)
PricewaterhouseCoopers (PwC) is a multinational professional services network that provides audit and assurance, consulting, and tax services to clien
Comply Audit
PsyberCog Labs
PsyberCog Labs specializes in developing AI-powered risk assessment and resilience solutions that transform human risk into measurable resilience for
Risk
Qanapi
Qanapi provides quantum-resistant security solutions to protect companies' data. The company offers an encryption API that helps teams meet compliance
Comply Privacy
Qualys
Qualys, Inc. is an American technology firm specializing in cloud security, compliance, and related services, with over 10,300 customers worldwide. Th
GRC Comply Risk
Ray Security
Ray Security is a predictive data security platform that reduces data risk by over 90% through its proprietary engine and dynamic protection implement
Risk Policy
Right-Hand Cybersecurity
Right-Hand Cybersecurity offers an AI-powered platform for security awareness and human risk management, providing automated social engineering simula
GRC Risk
SMARTFENSE
SMARTFENSE offers cybersecurity solutions for risk management, culture development, and regulatory compliance. The company specializes in social engin
Comply Risk
SailPoint Technologies
SailPoint Technologies, Inc is a leader in identity security, providing a unified platform to secure every identity. The company offers adaptive ident
Risk
Sardine
Sardine's AI platform is at the core of enterprise risk and fraud workflows, allowing them to consolidate vendors and improve operational efficiency.
GRC Comply Risk
Sath
Sath's flagship product IDHub is an Identity and Access Management solution that safeguards sensitive data, prevents unauthorized access, and maintain
Comply Monitor
SecuMailer
SecuMailer offers secure and encrypted email solutions for individuals and businesses, protecting sensitive communications with GDPR-compliance. The c
Privacy
SecurEnds
SecurEnds provides cloud-based identity security solutions for forward-thinking companies to automate user access reviews, entitlement audits, and com
GRC Comply
Sepio
Sepio Zero Trust Hardware Security enhances network security by seeing, assessing, and mitigating risk across all known and shadow IT assets. The comp
Comply Risk
Stamus Networks
Uncover hidden threats and respond confidently with Clear NDR by Stamus Networks. The platform provides clear visibility, multi-layer detection, and a
Comply
Tego AI
Tego AI provides complete visibility and control over AI agents in your enterprise. Discover, govern, and monitor all AI agents with our agentic secur
GRC Comply
ThreatConnect
ThreatConnect provides a threat intelligence platform that enables companies to aggregate and act upon threat intelligence for network defense. The co
GRC Risk Monitor
Todyl
Todyl empowers businesses with innovative cybersecurity modules that consolidate comprehensive security into a quick-to-deploy, single-agent platform.
GRC Comply Risk
Upwind
Upwind secures cloud deployments and applications through real-time visibility from the inside out, providing live maps of network and application top
Risk
Utimaco
Utimaco is a company active in the sector of cybersecurity and compliance solutions with headquarters in Aachen, Germany, and Campbell, California, US
Comply Privacy
Vade Secure
Vade Secure is a global leader in AI-powered email security, protecting over 1.4 billion mailboxes worldwide with its advanced solutions for Microsoft
Comply
Veriff
Veriff is a global identity verification service company that provides AI-powered identity verification solutions for online businesses to mitigate fr
Comply
Virtru
Virtru is a global data encryption and digital privacy provider founded in 2012. The company delivers end-to-end encryption and access control for ema
Comply Privacy
Wolters Kluwer
Wolters Kluwer provides information, software, and services for professionals in various industries, including law, business, tax, accounting, finance
Comply Risk Audit
eMudhra
eMudhra Limited is a digital security company that provides SSL certificates and PKI platforms for enterprises. The company offers streamlined digital
GRC Comply Risk
enclaive.io
enclaive offers confidential cloud computing solutions that enable secure processing and storage of sensitive data in the cloud. The company provides
Risk ISO Privacy
env0
env0 enables enterprises to deliver infrastructure up to 10x faster without losing control through its cloud governance platform, providing features s
Policy
sirar by stc
sirar by stc is a cutting-edge cybersecurity provider that empowers organizations to take control of their cyber capabilities and digital environments
GRC Privacy
usecure
usecure is an automated human risk management platform that helps MSPs and IT teams reduce cyber risk, prove compliance, and save time with security a
GRC Comply Risk
xorlab
xorlab provides advanced email security solutions built on AI-powered technology to defend against sophisticated phishing attacks and protect organiza
Privacy
Vendor Directory
Lookup Tools
Analysis
Bulk & Enterprise
Resources
Close