Skip to content

Methodology

How this directory is built, who built it, and exactly what each entry does and does not tell you.

Who built this

GRC Compass is written by Deepak Gupta, who built compliance programs from both sides of this list. As Product and Compliance Manager at Sageworks, he built the company's SOC 2, PCI, and ISO programs. He then spent roughly a decade as CTO and CISO at LoginRadius, the CIAM platform he founded and scaled to over a billion users, running SOC 2, ISO 27001, GDPR, CCPA, and the enterprise security audits that came with selling to large customers. That is the practitioner lens behind the category structure and the buying guides here: what a team evaluating these tools actually needs to know, not what a vendor wants said about its own product.

What's in the directory

123 funded GRC and compliance vendors, 48of them researched in depth: funding, headquarters, founding year, pricing model, who the vendor says it's for, one genuine differentiator, and one real limitation, each with a source. Inclusion requires a live product and a compliance, risk, or audit product as the primary offering. There is no payment, sponsorship, or submission process, and no vendor is ranked "best."

How the categories work

Vendors describe themselves 105 different ways, which makes their own language useless for comparison. Each is sorted into one of 12 categories. That sorting is an editorial call, not a fact about the vendor, so the original self-description stays on every profile and you can disagree with it.

What the site check covers

Every listed address is fetched on a schedule. Each profile shows the date and the result: live, redirected elsewhere, blocking automated requests, or not responding. A vendor that no longer answers stays listed rather than being deleted, since a company gone quiet is itself worth knowing when you are building a shortlist.

That check answers one question only: did a server respond. It cannot tell whether the address belongs to the company named beside it, because a wrong company's live site answers exactly like a right one's. That is a separate check, and it is the next section.

Whose site is it

The vendor list began as a compiled spreadsheet, and compiled lists put the wrong company next to a name more often than you would like. So every listing was read by hand against an independent primary source: the company's own legal or about page, a registry filing, a funding announcement, or its own profile naming the domain. Each profile prints the date and links the evidence.

All 123 listings are confirmed. That was not always true: an earlier version of this page disclaimed identity across the whole directory, because the link sweep was the only check running and it cannot answer this question.

What framework coverage means

For 116 of 123vendors, one page on the vendor's own site was read and every framework the vendor says its product covers was recorded, along with that page's URL and the date it was read. Twelve frameworks are tracked: SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, PCI DSS, NIST, FedRAMP, CMMC, the EU AI Act, DORA and NIS2.

A framework missing from a vendor's list means the vendor does not claim it on its own site. It does not mean the product cannot do it. Vendors document unevenly, and a directory that turned marketing silence into a product verdict would be inventing its most consequential data. A framework that is present is a claim, not a certification: the vendor's own audit reports are a different thing and are not recorded here at all. Where a framework is named somewhere on a site but not as a coverage claim, the profile says where it was seen and why the reading is ambiguous. See the whole matrix.

Where the numbers come from

Headquarters is the registered or primary office, taken from the company's own contact, legal, or registry record, not from the markets it sells into. It is stored as a country code and the region shown on this site is derived from that code, so no region is ever typed by hand. The 123 vendors sit in 6 regions; the market map breaks that down. Every count on this site is computed from the data at build time, and a build-time check compares the handful of numbers written in prose against the computed values, because a hardcoded count is a claim that rots quietly.

What this site does not cover

GRC Compass covers compliance at the organizational level. It deliberately does not duplicate work published elsewhere on guptadeepak.com:

Related reading

Read the disclaimer