Eight agents work the weekend. Monday, you approve.
Nobody trained in security to spend audit season chasing screenshots. CarcGRC does the collecting: eight agents find your gaps, score new threats against your own stack, and keep the audit room packaged — continuously, in the background, without being asked. You review and decide. Nothing touches your compliance record until you approve it.
The category sells you a filing cabinet and calls the search box artificial intelligence. You still gather the evidence. You still chase the vendors. You still score the risks and package the documents, and the tool watches you do it. We built the opposite: the AI does the work and you hold the authority.
What you do today
You open the dashboard and it hands you a list. Work out what is missing. Go and find the evidence. Ask the AI for help, if you remember to. Then do the whole thing again in a month, because audit prep is not a task — it is a season.
▪The inversion
EVERY OTHER GRC PLATFORM CARCGRC
──────────────────────────── ────────────────────────────
you open the dashboard agents work through the weekend
↓ ↓
you read a list of controls gaps are already filed as tasks
↓ ↓
you work out what is missing evidence is already collected
↓ ↓
you collect the evidence new CVEs are already scored
↓ ↓
AI helps — if you ask it to the audit room is already packaged
↓ ↓
audit prep is a month-long project you approve, and decide
EVERY OTHER PLATFORM CARCGRC
────────────────────── ──────────────────────
you open the dashboard agents work through the weekend
↓ ↓
you read a list of controls gaps are already filed as tasks
↓ ↓
you work out what is missing evidence is already collected
↓ ↓
you collect the evidence new CVEs are already scored
↓ ↓
AI helps — if you ask it to the audit room is already packaged
↓ ↓
audit prep is a month-long project you approve, and decide
EVERY OTHER PLATFORM
────────────────────────
you open the dashboard
↓
you read the controls
↓
you find what is missing
↓
you collect the evidence
↓
AI helps — if you ask
↓
audit prep takes a month
CARCGRC
────────────────────────
agents work all weekend
↓
gaps are already filed
↓
evidence is collected
↓
new CVEs are scored
↓
the audit room is packed
↓
you approve, and decide
Comparison of the conventional GRC workflow with the CarcGRC workflow
Every other GRC platform: you open the dashboard, then you read a list of controls, then you work out what is missing, then you collect the evidence, then AI helps — if you ask it to, then audit prep is a month-long project.
CarcGRC: agents work through the weekend, then gaps are already filed as tasks, then evidence is already collected, then new CVEs are already scored, then the audit room is already packaged, then you approve, and decide.
Every other platform makes you the collector. This one makes you the approver.
What you would do instead
Open it Monday and the work is already done. Gaps found and filed. Evidence pulled from your own integrations. New CVEs scored against your stack over the weekend. The audit room packaged and waiting. Your job is the part that needs judgement: approve, or send it back.
How it works
Connect it once. Review what it found.
There is no new methodology to adopt and no workflow to migrate. You connect the systems you already run, and the compliance work that used to fill your calendar starts arriving as decisions instead of tasks.
01OAuth · read-only scopes
Connect your stack
Your cloud, your code host, your identity provider, your device fleet. Each connection is an OAuth flow that shows you which controls it satisfies before you approve it, and 20 of them ship in Phase 1.
02Continuous · unattended
The work happens without you
Overnight and continuously, 8 specialist agents do the collecting: finding control gaps, pulling and grading evidence, scoring new threats against your stack, and keeping the audit package current. This is the part that is usually your team's month.
03Human decision · always logged
You approve, or you do not
Everything arrives as a proposal with its reasoning attached. You accept it and it enters your compliance record, or you reject it and it does not. That decision is always a person, it is always logged, and there is no path that skips it.
Four things waiting for you, not four more things to do.
Every one of these is a job a compliance team currently does by hand, on a deadline, usually twice. These are what the platform hands back.
Gaps, found nightly
A prioritised list of what is actually wrong.
Controls with nothing behind them, controls whose evidence is too thin to survive an auditor, and controls whose evidence quietly expired. Rebuilt every night, so the list you open is the list as of this morning.
┌───────────────────────────────────────────────────┐
│ CRITICAL CC6.1 — Logical Access Controls │
│ SOC 2 · no evidence in the last 90 days │
│ │
│ Suggested fix: connect Okta to auto-collect MFA │
│ status. Estimated time: 30 minutes. │
└───────────────────────────────────────────────────┘
┌───────────────────────────────────────────────────┐
│ CRITICAL CC6.1 — Logical Access Controls │
│ SOC 2 · no evidence in the last 90 days │
│ │
│ Suggested fix: connect Okta to auto-collect MFA │
│ status. Estimated time: 30 minutes. │
└───────────────────────────────────────────────────┘
Example of a compliance gap as the Gap Agent files it. A critical gap on control CC6.1, Logical Access Controls, for SOC 2, with no evidence in the last 90 days. The suggested fix is to connect the Okta integration to auto-collect MFA status, with an estimated time of 30 minutes.
Evidence packaged and grouped by control, each item carrying the note explaining why it satisfies that control. A time-limited link, every download watermarked and logged, access expiring on the audit end date.
├── Access Control (CC6.x)
│ ├── ✓ MFA enforcement log
│ ├── ✓ IAM policy export
│ └── ⚠ Evidence ageing
├── System Operations (CC7.x)
└── Evidence requests
Structure of the auditor evidence room. Evidence is grouped by control category, then by individual control, then by evidence item. Each item records its source integration, collection date, quality score and an AI context note. Auditors raise evidence requests in a threaded conversation inside the platform.
New threat findings arrive, get scored against the controls they actually touch, and the heat map redraws itself. Nobody owns the file, because there is no file.
Risk scoring model. Risks are scored on a five by five matrix of likelihood against impact, giving an inherent score from 1 to 25. Bands are 1 to 4 low, 5 to 9 moderate, 10 to 14 high, and 15 to 25 critical. A residual score is recorded once a treatment plan is applied.
Access review is a SOC 2 requirement, an ISO clause and a HIPAA safeguard — the same control wearing three reference numbers. Map it once and the cross-walk credits it everywhere it counts.
YOUR CONTROL SOC 2 ISO 27001 NIST CSF HIPAA PCI-DSS
────────────────────────────────────────────────────────────────────────────────────
MFA enforced for all admins CC6.1 A.9.4.2 PR.AC-7 164.312(d) 8.4.2
Access removed on termination CC6.3 A.9.2.6 PR.AC-1 164.308(a)(3) 7.3.1
Vulnerability scanning quarterly CC7.1 A.12.6.1 DE.CM-8 164.308(a)(8) 11.3.1
YOUR CONTROL SOC 2 ISO 27001
──────────────────────────────────────────────────
MFA enforced for all admins CC6.1 A.9.4.2
Access removed on termination CC6.3 A.9.2.6
Vulnerability scanning quarterly CC7.1 A.12.6.1
YOUR CONTROL SOC 2 ISO 27001
───────────────────────────────
MFA on admins CC6.1 A.9.4.2
Offboard access CC6.3 A.9.2.6
Quarterly scans CC7.1 A.12.6.1
How one control maps to requirements across five compliance frameworks
Twenty connectors, and a rule about what a connector has to do.
Most GRC tools count a connector as done when it authenticates and shows you a green tick. Ours does not count until it collects evidence that satisfies a named control without a human exporting anything. That rule is why this list is twenty and not two hundred. The connector framework is in build, so read this as what Phase 1 ships — not as twenty connectors running in someone's production today.
20
Phase 1 connectors
Documented catalogue · connector framework in build
Connecting a tool and showing its raw data is not an integration. Every connector has to earn its place in the evidence chain.
01
Map its data to specific control requirements in every active framework
feeds the cross-walk
02
Assign a quality score from 1 to 10 to every piece of auto-collected evidence
quality score 1–10
03
Trigger the Evidence Agent to re-evaluate control health after every sync
feeds control health
04
Create risk entries when threat data is detected (Snyk, Wiz, AWS GuardDuty)
feeds the heat map
05
Update the asset inventory with any new resources discovered
feeds the asset inventory
Safety, privacy and security
Letting software work unattended is a trust decision. Here is ours.
An autonomous system touching a compliance record is either safe by construction or it is a liability. These are the three structural answers — not policies we intend to follow, but the shape of how the product is built.
Safety
The AI proposes. A person decides.
Nothing an agent produces enters your compliance record on its own. Every result arrives as a proposal with its reasoning attached and waits for a human to accept or reject it. There is no auto-commit path — not a discouraged one, not one behind a setting. Your auditor will ask who approved a control, and there is always a name.
Not your row in someone else’s table, behind someone else’s query. Each customer gets a dedicated deployment — app, worker and database — provisioned and sized to their contract. When your own customers send you the questionnaire asking how tenant data is isolated, this is the answer that ends the thread.
We sell security software, so here is our answer sheet.
Encryption in transit and at rest, multi-factor authentication enforced for owners and admins, role- and attribute-based access checks on every route, and an append-only audit log of every write. Published in full, with each item’s status stated plainly rather than implied.
There are no customers yet, and we are not going to pretend otherwise.
You have visited enough vendor sites to know what a logo wall of strangers is worth. There isn't one here, because we have not earned one. What we can show you is the finish line we set before we started selling: ten design partners running it in production, zero critical bugs, all six frameworks fully seeded, and an onboarding wizard that five non-technical people got through unaided. Every one of those is checkable, and you are early enough to watch them land.
Built and merged
Merged
—The full agent suite with human approval. Every run pauses and waits for a person before anything is committed.
—Complete traceability on every AI decision — what it read, what it cost, and which version of its instructions it followed.
—Certainty thresholds per agent, so a result the system is unsure about is flagged for a closer look instead of queued as routine.
—Staleness detection, so a finding calculated against data that has since moved is flagged rather than quietly applied.
—Permission checks on every approval, and rejected results retired automatically after ninety days.
—All six core modules, with every write recorded in an audit log nobody can edit.
In build
In build
—Integration connectors. AWS and GitHub stubs exist today; the rest of the twenty Phase 1 connectors are in progress.
—The external portal layout group — the auditor room and the vendor questionnaire.
—Env-driven licensing and entitlements, and the read-only admin licence page that shows them.
Designed, not built
Designed · add-on module
—Pre-Audit Readiness Check — a paid add-on module. Its recorded status is “designed, not yet built”, and it is listed here rather than above for exactly that reason.
Candidate list only
Not a commitment
—Everything on the roadmap candidate list, which opens by saying it is a prioritized list from founder brainstorming, not a build commitment.
ProductHow is CarcGRC different from Vanta, Drata or Sprinto?
Those platforms are collection tools with AI added afterwards — you still spend hours per audit gathering evidence, chasing vendors, scoring risks and packaging documents. We built it the other way round: the software does the collecting and your team does the deciding. The work runs continuously in the background, so when your security team opens the dashboard on Monday the findings are staged and waiting for a decision rather than waiting to be started.
AI governanceCan the AI change our compliance data without our approval?
No, and not as a policy — as a structural fact. Results are written to a staging area and wait there. A person reviews the finding and its reasoning, then accepts or rejects it, and only acceptance commits anything to your compliance record. Both the acceptance and the rejection are written to an audit log you cannot edit. Where the system is less certain of itself, it says so and asks for a closer look rather than queueing the result as routine.
DeploymentHow is CarcGRC deployed? Is it shared multi-tenant SaaS?
No. Each customer gets a dedicated deployment — its own application, its own background worker and its own database — provisioned and sized to the signed contract. Your data does not share a database with another customer, and the boundary between customers is the deployment itself rather than a column in a shared table. Isolation still runs inside your own deployment as well, so subsidiaries can be separated from each other.
CommercialHow does pricing work? I cannot find a pricing page.
There is not one, by design. Scope — which frameworks, how many people, how many integrations, how much storage — is agreed with you and written into the contract, then configured on your deployment. There are no plan tiers, no checkout and no upgrade button anywhere in the product. Inside it you can always see what your contract covers against what you are using; changing that is a conversation with us rather than a card form.
FrameworksWhich frameworks are live today, and what is on the roadmap?
Six are live: SOC 2 Type I & II, ISO/IEC 27001:2022, GDPR, NIST CSF 2.0, HIPAA and PCI-DSS v4.0. Others are planned across financial services, healthcare, government, cloud and regional privacy, and are labelled as roadmap everywhere they appear on this site — a framework you cannot use yet is not a feature. The cross-walk matters more than the count: when one control satisfies requirements in several frameworks, one piece of evidence covers all of them.
OnboardingHow long until we see real data from our own stack?
Our target is fifteen minutes from first login to real compliance data — a goal we hold ourselves to, not a benchmark measured off a live deployment. Setup connects AWS, GitHub, Okta and Google Workspace, and shows you a dashboard built from your own stack before you leave the flow. The first prioritised gap list is then waiting the next morning.
Launch criterion
Ten design partners. That is the launch criterion, and it is the whole ask.
Ten is not a growth target we are working towards. It is the number we decided we needed before calling this sellable, which means the partners who take those places are the ones whose problems shape what gets built next. This is the offer, not a waitlist — you will speak to the people writing the code, and if it is not right for you yet we would rather tell you that now than onboard you into a product that is not ready.
A live walkthrough with the people who built it — not a deck, and not a recorded demo.
What a design partner gets
A dedicated deployment — app, worker and database — provisioned and sized by CarcGRC ops, rather than a seat on shared infrastructure.
Scope negotiated into a contract instead of into a plan tier, with entitlements set per deployment and shown read-only in the product.
Direct access to the people building it.
Influence over which candidate module gets designed next. Everything past Phase 3 is a candidate list rather than a commitment, so partner input genuinely moves it.
What we ask in return
Run it in production against a real framework. That is the launch criterion as written: ten design partners using it in production.
Let us watch your onboarding wizard run with a non-technical user — also a launch criterion, tested with five of them.
Tell us when an agent output is wrong. Human approval rate is the quality bar we hold ourselves to, and we would rather hear it from you than measure it late.