Skip to content

Methodology

How this directory is built, who built it, and exactly what each entry does and does not tell you.

Who built this

GRC Compass is written by Deepak Gupta, who built compliance programs from both sides of this list. As Product and Compliance Manager at Sageworks, he built the company's SOC 2, PCI, and ISO programs. He then spent roughly a decade as CTO and CISO at LoginRadius, the CIAM platform he founded and scaled to over a billion users, running SOC 2, ISO 27001, GDPR, CCPA, and the enterprise security audits that came with selling to large customers. That is the practitioner lens behind the category structure and the buying guides here: what a team evaluating these tools actually needs to know, not what a vendor wants said about its own product.

What's in the directory

127 funded GRC and compliance vendors, 48of them researched in depth: funding, headquarters, founding year, pricing model, who the vendor says it's for, one genuine differentiator, and one real limitation, each with a source. Inclusion requires a live product and a compliance, risk, or audit product as the primary offering. There is no payment, sponsorship, or submission process, and no vendor is ranked "best."

How the categories work

Vendors describe themselves 107 different ways, which makes their own language useless for comparison. Each is sorted into one of 12 categories. That sorting is an editorial call, not a fact about the vendor, so the original self-description stays on every profile and you can disagree with it.

What the site check covers

Every listed address is fetched on a schedule. Each profile shows the date and the result: live, redirected elsewhere, blocking automated requests, or not responding. A vendor that no longer answers stays listed rather than being deleted, since a company gone quiet is itself worth knowing when you are building a shortlist.

One limit worth knowing: the check confirms an address answered, not that the address belongs to the company named beside it. Source data occasionally names the wrong company for a listing; when that happens the wrong site still answers normally, so the check alone cannot catch it. Treat every listing as a starting point worth confirming, not a verified fact.

What this site does not cover

GRC Compass covers compliance at the organizational level. It deliberately does not duplicate work published elsewhere on guptadeepak.com:

Related reading

Read the disclaimer