Skip to content

AI-native GRC · Pre-launch

Eight agents work the weekend. Monday, you approve.

Nobody trained in security to spend audit season chasing screenshots. CarcGRC does the collecting: eight agents find your gaps, score new threats against your own stack, and keep the audit room packaged — continuously, in the background, without being asked. You review and decide. Nothing touches your compliance record until you approve it.


Where we are
Pre-launch. We are onboarding ten design partners who want a say in what gets built, and you would be early enough to have one.
How you buy it
Through a conversation, not a checkout. You get your own app, worker and database — never a shared tenant with someone else in it.
What you get
Eight agents, and eight is the whole number. Pre-Audit Readiness Check is an add-on module, not a ninth agent wearing a different hat.
The gap no one has filled

Every other platform makes you the collector.

The category sells you a filing cabinet and calls the search box artificial intelligence. You still gather the evidence. You still chase the vendors. You still score the risks and package the documents, and the tool watches you do it. We built the opposite: the AI does the work and you hold the authority.

What you do today
You open the dashboard and it hands you a list. Work out what is missing. Go and find the evidence. Ask the AI for help, if you remember to. Then do the whole thing again in a month, because audit prep is not a task — it is a season.

The inversion

Comparison of the conventional GRC workflow with the CarcGRC workflow

  • Every other GRC platform: you open the dashboard, then you read a list of controls, then you work out what is missing, then you collect the evidence, then AI helps — if you ask it to, then audit prep is a month-long project.
  • CarcGRC: agents work through the weekend, then gaps are already filed as tasks, then evidence is already collected, then new CVEs are already scored, then the audit room is already packaged, then you approve, and decide.
Every other platform makes you the collector. This one makes you the approver.
What you would do instead
Open it Monday and the work is already done. Gaps found and filed. Evidence pulled from your own integrations. New CVEs scored against your stack over the weekend. The audit room packaged and waiting. Your job is the part that needs judgement: approve, or send it back.
How it works

Connect it once. Review what it found.

There is no new methodology to adopt and no workflow to migrate. You connect the systems you already run, and the compliance work that used to fill your calendar starts arriving as decisions instead of tasks.

  1. OAuth · read-only scopes

    Connect your stack

    Your cloud, your code host, your identity provider, your device fleet. Each connection is an OAuth flow that shows you which controls it satisfies before you approve it, and 20 of them ship in Phase 1.

  2. Continuous · unattended

    The work happens without you

    Overnight and continuously, 8 specialist agents do the collecting: finding control gaps, pulling and grading evidence, scoring new threats against your stack, and keeping the audit package current. This is the part that is usually your team's month.

  3. Human decision · always logged

    You approve, or you do not

    Everything arrives as a proposal with its reasoning attached. You accept it and it enters your compliance record, or you reject it and it does not. That decision is always a person, it is always logged, and there is no path that skips it.

What you get

Four things waiting for you, not four more things to do.

Every one of these is a job a compliance team currently does by hand, on a deadline, usually twice. These are what the platform hands back.

Gaps, found nightly

A prioritised list of what is actually wrong.

Controls with nothing behind them, controls whose evidence is too thin to survive an auditor, and controls whose evidence quietly expired. Rebuilt every night, so the list you open is the list as of this morning.

Example of a compliance gap as the Gap Agent files it. A critical gap on control CC6.1, Logical Access Controls, for SOC 2, with no evidence in the last 90 days. The suggested fix is to connect the Okta integration to auto-collect MFA status, with an estimated time of 30 minutes.

The dashboard →
The audit room

Your auditor gets a room, not a guest login.

Evidence packaged and grouped by control, each item carrying the note explaining why it satisfies that control. A time-limited link, every download watermarked and logged, access expiring on the audit end date.

Structure of the auditor evidence room. Evidence is grouped by control category, then by individual control, then by evidence item. Each item records its source integration, collection date, quality score and an AI context note. Auditors raise evidence requests in a threaded conversation inside the platform.

Audits and the audit room →
Risk, scored continuously

The risk spreadsheet stops being a spreadsheet.

New threat findings arrive, get scored against the controls they actually touch, and the heat map redraws itself. Nobody owns the file, because there is no file.

Risk scoring model. Risks are scored on a five by five matrix of likelihood against impact, giving an inherent score from 1 to 25. Bands are 1 to 4 low, 5 to 9 moderate, 10 to 14 high, and 15 to 25 critical. A residual score is recorded once a treatment plan is applied.

Risk register and heat map →
One control, every framework

Implement it once. Satisfy all six.

Access review is a SOC 2 requirement, an ISO clause and a HIPAA safeguard — the same control wearing three reference numbers. Map it once and the cross-walk credits it everywhere it counts.

How one control maps to requirements across five compliance frameworks
Your controlSOC 2ISO 27001NIST CSFHIPAAPCI-DSS
MFA enforced for all adminsCC6.1A.9.4.2PR.AC-7164.312(d)8.4.2
Access removed on terminationCC6.3A.9.2.6PR.AC-1164.308(a)(3)7.3.1
Vulnerability scanning quarterlyCC7.1A.12.6.1DE.CM-8164.308(a)(8)11.3.1
The cross-walk engine →
Phase 1 connector catalogue

Twenty connectors, and a rule about what a connector has to do.

Most GRC tools count a connector as done when it authenticates and shows you a green tick. Ours does not count until it collects evidence that satisfies a named control without a human exporting anything. That rule is why this list is twenty and not two hundred. The connector framework is in build, so read this as what Phase 1 ships — not as twenty connectors running in someone's production today.

20

Phase 1 connectors

Documented catalogue · connector framework in build


Connecting a tool and showing its raw data is not an integration. Every connector has to earn its place in the evidence chain.

  1. 01

    Map its data to specific control requirements in every active framework

    feeds the cross-walk
  2. 02

    Assign a quality score from 1 to 10 to every piece of auto-collected evidence

    quality score 1–10
  3. 03

    Trigger the Evidence Agent to re-evaluate control health after every sync

    feeds control health
  4. 04

    Create risk entries when threat data is detected (Snyk, Wiz, AWS GuardDuty)

    feeds the heat map
  5. 05

    Update the asset inventory with any new resources discovered

    feeds the asset inventory

Safety, privacy and security

Letting software work unattended is a trust decision. Here is ours.

An autonomous system touching a compliance record is either safe by construction or it is a liability. These are the three structural answers — not policies we intend to follow, but the shape of how the product is built.

Safety

The AI proposes. A person decides.

Nothing an agent produces enters your compliance record on its own. Every result arrives as a proposal with its reasoning attached and waits for a human to accept or reject it. There is no auto-commit path — not a discouraged one, not one behind a setting. Your auditor will ask who approved a control, and there is always a name.

How approval is enforced →
Privacy

Your data sits in your database.

Not your row in someone else’s table, behind someone else’s query. Each customer gets a dedicated deployment — app, worker and database — provisioned and sized to their contract. When your own customers send you the questionnaire asking how tenant data is isolated, this is the answer that ends the thread.

Deployment and data handling →
Security

We sell security software, so here is our answer sheet.

Encryption in transit and at rest, multi-factor authentication enforced for owners and admins, role- and attribute-based access checks on every route, and an append-only audit log of every write. Published in full, with each item’s status stated plainly rather than implied.

The full security posture →
Phase 1 launch criteria

There are no customers yet, and we are not going to pretend otherwise.

You have visited enough vendor sites to know what a logo wall of strangers is worth. There isn't one here, because we have not earned one. What we can show you is the finish line we set before we started selling: ten design partners running it in production, zero critical bugs, all six frameworks fully seeded, and an onboarding wizard that five non-technical people got through unaided. Every one of those is checkable, and you are early enough to watch them land.


Built and merged

Merged
  • The full agent suite with human approval. Every run pauses and waits for a person before anything is committed.
  • Complete traceability on every AI decision — what it read, what it cost, and which version of its instructions it followed.
  • Certainty thresholds per agent, so a result the system is unsure about is flagged for a closer look instead of queued as routine.
  • Staleness detection, so a finding calculated against data that has since moved is flagged rather than quietly applied.
  • Permission checks on every approval, and rejected results retired automatically after ninety days.
  • All six core modules, with every write recorded in an audit log nobody can edit.

In build

In build
  • Integration connectors. AWS and GitHub stubs exist today; the rest of the twenty Phase 1 connectors are in progress.
  • The external portal layout group — the auditor room and the vendor questionnaire.
  • Env-driven licensing and entitlements, and the read-only admin licence page that shows them.

Designed, not built

Designed · add-on module
  • Pre-Audit Readiness Check — a paid add-on module. Its recorded status is “designed, not yet built”, and it is listed here rather than above for exactly that reason.

Candidate list only

Not a commitment
  • Everything on the roadmap candidate list, which opens by saying it is a prioritized list from founder brainstorming, not a build commitment.
Common questions

The catch you have not spotted yet.

ProductHow is CarcGRC different from Vanta, Drata or Sprinto?

Those platforms are collection tools with AI added afterwards — you still spend hours per audit gathering evidence, chasing vendors, scoring risks and packaging documents. We built it the other way round: the software does the collecting and your team does the deciding. The work runs continuously in the background, so when your security team opens the dashboard on Monday the findings are staged and waiting for a decision rather than waiting to be started.

AI governanceCan the AI change our compliance data without our approval?

No, and not as a policy — as a structural fact. Results are written to a staging area and wait there. A person reviews the finding and its reasoning, then accepts or rejects it, and only acceptance commits anything to your compliance record. Both the acceptance and the rejection are written to an audit log you cannot edit. Where the system is less certain of itself, it says so and asks for a closer look rather than queueing the result as routine.

DeploymentHow is CarcGRC deployed? Is it shared multi-tenant SaaS?

No. Each customer gets a dedicated deployment — its own application, its own background worker and its own database — provisioned and sized to the signed contract. Your data does not share a database with another customer, and the boundary between customers is the deployment itself rather than a column in a shared table. Isolation still runs inside your own deployment as well, so subsidiaries can be separated from each other.

CommercialHow does pricing work? I cannot find a pricing page.

There is not one, by design. Scope — which frameworks, how many people, how many integrations, how much storage — is agreed with you and written into the contract, then configured on your deployment. There are no plan tiers, no checkout and no upgrade button anywhere in the product. Inside it you can always see what your contract covers against what you are using; changing that is a conversation with us rather than a card form.

FrameworksWhich frameworks are live today, and what is on the roadmap?

Six are live: SOC 2 Type I & II, ISO/IEC 27001:2022, GDPR, NIST CSF 2.0, HIPAA and PCI-DSS v4.0. Others are planned across financial services, healthcare, government, cloud and regional privacy, and are labelled as roadmap everywhere they appear on this site — a framework you cannot use yet is not a feature. The cross-walk matters more than the count: when one control satisfies requirements in several frameworks, one piece of evidence covers all of them.

OnboardingHow long until we see real data from our own stack?

Our target is fifteen minutes from first login to real compliance data — a goal we hold ourselves to, not a benchmark measured off a live deployment. Setup connects AWS, GitHub, Okta and Google Workspace, and shows you a dashboard built from your own stack before you leave the flow. The first prioritised gap list is then waiting the next morning.

Launch criterion

Ten design partners. That is the launch criterion, and it is the whole ask.

Ten is not a growth target we are working towards. It is the number we decided we needed before calling this sellable, which means the partners who take those places are the ones whose problems shape what gets built next. This is the offer, not a waitlist — you will speak to the people writing the code, and if it is not right for you yet we would rather tell you that now than onboard you into a product that is not ready.

Book a demo

A live walkthrough with the people who built it — not a deck, and not a recorded demo.

What a design partner gets

  • A dedicated deployment — app, worker and database — provisioned and sized by CarcGRC ops, rather than a seat on shared infrastructure.
  • Scope negotiated into a contract instead of into a plan tier, with entitlements set per deployment and shown read-only in the product.
  • Direct access to the people building it.
  • Influence over which candidate module gets designed next. Everything past Phase 3 is a candidate list rather than a commitment, so partner input genuinely moves it.

What we ask in return

  • Run it in production against a real framework. That is the launch criterion as written: ten design partners using it in production.
  • Let us watch your onboarding wizard run with a non-technical user — also a launch criterion, tested with five of them.
  • Tell us when an agent output is wrong. Human approval rate is the quality bar we hold ourselves to, and we would rather hear it from you than measure it late.