{"directory":"GRC Agents Directory","url":"https://grcagents.io","lastUpdated":"2026-08-29","count":54,"services":[{"id":"complyance-ai-agents","name":"Complyance AI Agents","slug":"complyance-ai-agents","logo":"","brief_summary":"Configurable GRC AI agents that review evidence, draft policies, score vendor risk, and fill trust questionnaires inside the Complyance platform.","description":"Complyance ships a fleet of named AI agents for repeatable GRC workflows: evidence review, policy drafting, vendor risk scoring, and customer-trust questionnaires. Agents run in the customer's Complyance environment, can be turned off, and are marketed as explainable rather than a generic chatbot wrapper.","agent_job":["evidence","policy","vendor risk","questionnaire response"],"frameworks":["SOC 2","ISO 27001","HIPAA","PCI DSS","NIST CSF"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://www.complyance.com/platform/ai-agents","docs_url":"https://www.complyance.com/platform/ai-agents","install_url":"https://www.complyance.com/book-demo","github_url":"","mcp_package":"","linkedin":"https://www.linkedin.com/company/complyancehq","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"complydo","name":"ComplyDo","slug":"complydo","logo":"","brief_summary":"Agentic compliance graph that maps requirements, collects evidence, fills questionnaires, and watches regulatory change.","description":"ComplyDo (Berlin, YC) turns regulations, policies, and evidence into a compliance graph so agents can map coverage, collect evidence, draft questionnaire answers, and flag regulatory change. Public modules include requirement mapping, evidence collection, and questionnaire filling.","agent_job":["evidence","audit prep","questionnaire response","policy"],"frameworks":["ISO 27001","SOC 2","GDPR","NIS2","DORA","ISO 42001","EU AI Act"],"integrations":["API"],"deployment":"SaaS","data_residency":"EU","buyer":["GRC"],"url":"https://www.complydo.io/","docs_url":"https://www.complydo.io/","install_url":"https://www.complydo.io/book-a-demo","github_url":"","mcp_package":"","linkedin":"https://www.linkedin.com/company/complydo-io","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"complyjet","name":"ComplyJet","slug":"complyjet","logo":"","brief_summary":"Startup SOC 2 and ISO platform with AI GRC agents for policy onboarding, control mapping, and questionnaires.","description":"ComplyJet markets AI GRC agents that onboard policies, map controls, and automate security questionnaires inside a flat-fee first-compliance platform. Public pages describe agentic reasoning about architecture and auditor challenges.","agent_job":["evidence","policy","questionnaire response","audit prep"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://www.complyjet.com/","docs_url":"https://www.complyjet.com/","install_url":"https://www.complyjet.com/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"compyl-copilot","name":"Compyl Copilot","slug":"compyl-copilot","logo":"","brief_summary":"Ask-your-GRC-data copilot and questionnaire assist on the Compyl platform. Does not list the not-yet-GA Agent Library.","description":"Compyl Copilot is the generally available agentic ask surface on Compyl (plus Questionnaire Assist). The Agent Library page is not generally available and is not listed. Copilot answers questions over GRC data; Questionnaire Assist drafts questionnaire answers.","agent_job":["chat/tasks","questionnaire response","policy"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://compyl.com/compyl-copilot/","docs_url":"https://compyl.com/compyl-ai/","install_url":"https://compyl.com/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"kertos-kaia","name":"Kertos KAIA","slug":"kertos-kaia","logo":"","brief_summary":"KAIA is Kertos's AI guide that automates European privacy and information-security compliance workflows.","description":"Kertos is a Munich-based compliance platform. KAIA is the named AI guide that walks teams through GDPR, ISO 27001, SOC 2, NIS2, and EU AI Act work and automates tasks on the Kertos platform. Listed as the agent surface, not the whole consultancy wrapper.","agent_job":["evidence","policy","audit prep","AI governance"],"frameworks":["GDPR","ISO 27001","SOC 2","NIS2","EU AI Act","ISO 42001","ISO 27701"],"integrations":["API"],"deployment":"SaaS","data_residency":"EU","buyer":["GRC","legal"],"url":"https://kertos.ai","docs_url":"https://www.kertos.io/en","install_url":"https://www.kertos.io/en/iec-demo","github_url":"","mcp_package":"","linkedin":"https://de.linkedin.com/company/kertos-compliance","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"norm-ai","name":"Norm AI","slug":"norm-ai","logo":"","brief_summary":"Regulatory AI agents that encode law and run compliance analyses, including a Microsoft 365 Copilot compliance agent.","description":"Norm AI builds regulatory AI agents that apply encoded law to compliance workflows. Public product surfaces include regulatory analysis agents and a compliance agent for Microsoft 365 Copilot. Buyer is typically a chief compliance officer in a regulated firm, not a generic chatbot user.","agent_job":["policy","chat/tasks","AI governance"],"frameworks":["SOC 2","GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["legal","GRC"],"url":"https://www.norm.ai/","docs_url":"https://www.norm.ai/technology","install_url":"https://www.norm.ai/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"probo-agent","name":"Probo Agent","slug":"probo-agent","logo":"","brief_summary":"Open-source compliance platform agent that handles requirements, docs, risks, controls, and evidence for SOC 2, GDPR, HIPAA, and ISO.","description":"Probo (YC) is an open-source GRC platform with a downloadable Probo Agent, MCP, CLI, and GraphQL surfaces. Official copy: you describe how you work and Probo sets requirements, handles docs and evidence, and keeps the program current. Listed as the agent/MCP surface.","agent_job":["evidence","policy","audit prep","chat/tasks"],"frameworks":["SOC 2","GDPR","HIPAA","ISO 27001","ISO 42001"],"integrations":["API","MCP"],"deployment":"open-source","data_residency":"EU","buyer":["eng","GRC"],"url":"https://www.probo.com/","docs_url":"https://www.probo.com/docs","install_url":"https://www.probo.com/download","github_url":"https://github.com/getprobo/probo","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"productiv-ai-compliance-agent","name":"Productiv AI Compliance Agent","slug":"productiv-ai-compliance-agent","logo":"","brief_summary":"Named agent that logs into SaaS apps, reads contracts and privacy settings, and checks them against the company's AI policy.","description":"Productiv's AI Compliance Agent is a distinct product page: it logs into apps, reads contracts, checks privacy settings, and measures findings against the organization's AI policy. Listed as an AI-governance / monitoring agent, not the whole SaaS-management suite.","agent_job":["AI governance","monitoring","policy"],"frameworks":["ISO 42001","GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","legal"],"url":"https://productiv.com/platform/ai-compliance-agent/","docs_url":"https://productiv.com/platform/ai-compliance-agent/","install_url":"https://productiv.com/platform/ai-compliance-agent/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"regology","name":"Regology Compliance Agent","slug":"regology","logo":"","brief_summary":"Named regulatory compliance agent that maps obligations and monitors regulatory change.","description":"Regology markets a Compliance Agent for regulatory research, obligation mapping, and change monitoring. Included as a named regulatory-compliance agent surface after Codex flagged it as a missing Google-visible name.","agent_job":["policy","monitoring"],"frameworks":["GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["legal","GRC"],"url":"https://regology.com/","docs_url":"https://regology.com/","install_url":"https://regology.com/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"responsehub","name":"ResponseHub","slug":"responsehub","logo":"","brief_summary":"Purpose-built security questionnaire automation for SaaS teams that need to answer CAIQ-style reviews without a dedicated GRC hire.","description":"ResponseHub markets itself as security questionnaire automation for SaaS teams. Official comparison pages position it against Conveyor and Vanta in the questionnaire-agent category rather than as a generic RFP suite.","agent_job":["questionnaire response"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://responsehub.ai/","docs_url":"https://responsehub.ai/security-questionnaire-automation/","install_url":"https://responsehub.ai/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"risk-cognizance-ai-grc-agents","name":"Risk Cognizance AI GRC Agents","slug":"risk-cognizance-ai-grc-agents","logo":"","brief_summary":"Named AI GRC agent fleet for governance, risk, and compliance workflows.","description":"Risk Cognizance publishes an explicit AI GRC Agent product page describing a fleet of agents for GRC work. Included as a named surface Codex found that the original seed missed.","agent_job":["chat/tasks","audit prep","monitoring"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://riskcognizance.com/product/ai-grc-agent","docs_url":"https://riskcognizance.com/product/ai-grc-agent","install_url":"https://riskcognizance.com/product/ai-grc-agent","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"scrut-teammates","name":"Scrut Teammates","slug":"scrut-teammates","logo":"","brief_summary":"AI GRC teammates inside Scrut that evaluate evidence, fill questionnaires, score vendors, and open remediation tickets.","description":"Scrut Teammates is a named agent surface on the Scrut platform. Official pages describe evaluating evidence, filling security questionnaires, vendor reviews, policy/evidence gap checks, and creating Jira tickets. Distinct from the existing Scrut Automation platform row.","agent_job":["evidence","questionnaire response","vendor risk","audit prep"],"frameworks":["SOC 2","ISO 27001","GDPR","HIPAA"],"integrations":["API","Jira"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC","AppSec"],"url":"https://www.scrut.io/platform/scrut-teammates","docs_url":"https://www.scrut.io/post/introducing-scrut-teammates-ai-powered-compliance","install_url":"https://www.scrut.io/book-a-demo","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"scy","name":"Scy (Scytale AI Agent)","slug":"scy","logo":"","brief_summary":"Scytale's named GRC AI agent for evidence review, gap scanning, policy work, and security questionnaires.","description":"Scy is the named AI agent product at scytale.ai/ai-agent. It reviews audit evidence, fills security questionnaires from platform data, and assists GRC workflows. Listed separately from the existing Scytale AI compliance platform row.","agent_job":["evidence","questionnaire response","policy","audit prep"],"frameworks":["SOC 2","ISO 27001","GDPR","ISO 42001"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://scytale.ai/ai-agent/","docs_url":"https://scytale.ai/ai-agent/","install_url":"https://scytale.ai/ai-agent/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"securitypal","name":"SecurityPal","slug":"securitypal","logo":"","brief_summary":"AI-drafted security questionnaire and trust-center workflows with certified analysts reviewing answers before send.","description":"SecurityPal combines an AI drafting engine with a managed analyst team for security questionnaires and customer-assurance reviews. Listed as a questionnaire-response agent surface, not a human consultancy without software.","agent_job":["questionnaire response"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","AppSec"],"url":"https://www.securitypalhq.com/","docs_url":"https://www.securitypalhq.com/products/security-questionnaire-concierge","install_url":"https://www.securitypalhq.com/get-started","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"simbian-grc-agent","name":"Simbian AI GRC Agent","slug":"simbian-grc-agent","logo":"","brief_summary":"Named GRC agent that fills security questionnaires and portal reviews from a sourced knowledge base, with a complimentary trust center.","description":"Simbian's AI GRC Agent is a purpose-built questionnaire and security-review agent. Official pages describe filling XLS, DOC, PDF, and portal questionnaires, source-tracked answers, and a trust-center send path. Distinct from Simbian's broader SecOps agents.","agent_job":["questionnaire response","vendor risk"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC","AppSec"],"url":"https://simbian.ai/products/ai-grc-agent","docs_url":"https://simbian.ai/products/ai-grc-agent","install_url":"https://simbian.ai/start-a-free-trial","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"skypher","name":"Skypher","slug":"skypher","logo":"","brief_summary":"YC-backed AI agent for security, privacy, DDQ, and ESG questionnaire automation across portals and files.","description":"Skypher is an agent platform whose homepage is security and compliance questionnaire automation, including OneTrust and ServiceNow portal connectors and a unified trust center. Purpose-built questionnaire agent, not a generic RFP writer.","agent_job":["questionnaire response"],"frameworks":["SOC 2","ISO 27001","GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC","AppSec"],"url":"https://www.skypher.co/","docs_url":"https://www.ycombinator.com/companies/skypher","install_url":"https://www.skypher.co/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"strike-graph","name":"Strike Graph","slug":"strike-graph","logo":"","brief_summary":"AI-native compliance management platform with agentic workflows for audits, evidence, and trust.","description":"Strike Graph markets an AI-native compliance platform with agentic automation for audit acceleration and redundant-work removal. Public pages describe a graph-based compliance model and AI assistance for GRC engineers.","agent_job":["evidence","audit prep","monitoring"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://www.strikegraph.com/","docs_url":"https://www.strikegraph.com/","install_url":"https://www.strikegraph.com/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"trustcloud-trustlens","name":"TrustCloud TrustLens","slug":"trustcloud-trustlens","logo":"","brief_summary":"Agentic third-party cyber assessment surface on TrustCloud that scores vendors from outside-in and inside-out signals.","description":"TrustLens is TrustCloud's named agentic TPRM product. Official pages describe an AI agent that automates a large share of vendor assessments while leaving final approval with the analyst. Listed as the agent surface, not the whole TrustCloud platform.","agent_job":["vendor risk"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","AppSec"],"url":"https://www.trustcloud.ai/trustlens/","docs_url":"https://www.trustcloud.ai/press/trustcloud-introduces-agentic-data-driven-third-party-cyber-assessments/","install_url":"https://www.trustcloud.ai/","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"trustero","name":"Trustero","slug":"trustero","logo":"","brief_summary":"Multi-agent GRC system with specialized control, evidence, policy, and risk agents that work on top of an existing GRC program.","description":"Trustero markets a native multi-agent architecture for GRC: control, evidence, policy, and risk agents that collect and evaluate evidence, monitor controls, analyze policies, and draft questionnaire answers. It is designed to sit beside existing GRC tools rather than replace them.","agent_job":["evidence","monitoring","policy","audit prep","questionnaire response"],"frameworks":["SOC 2","ISO 27001","NIST CSF","CMMC","HIPAA"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://trustero.com/","docs_url":"https://trustero.com/ai-for-grc","install_url":"https://trustero.com/demo","github_url":"","mcp_package":"","linkedin":"https://www.linkedin.com/company/trustero","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"vanta-ai-agent","name":"Vanta AI Agent","slug":"vanta-ai-agent","logo":"","brief_summary":"Named GRC agent inside Vanta that drafts policies, checks evidence, answers questionnaires, and flags vendor risk.","description":"The Vanta AI Agent is a distinct product surface from Vanta's continuous monitoring platform. Official pages describe it drafting policies, verifying evidence, suggesting questionnaire answers, and monitoring vendor risk. Also exposes a Vanta MCP server for coding agents. Listed separately from the existing Vanta automation and Trust Report rows.","agent_job":["policy","evidence","questionnaire response","vendor risk"],"frameworks":["SOC 2","ISO 27001","GDPR","ISO 42001"],"integrations":["API","MCP","Slack"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://www.vanta.com/products/ai","docs_url":"https://www.vanta.com/resources/introducing-the-all-new-vanta-ai-agent","install_url":"https://www.vanta.com/demo-ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-08-15","source":"seed"},{"id":"anecdotes-agentic","name":"Anecdotes","slug":"anecdotes","logo":"","brief_summary":"Enterprise agentic GRC platform with broad integrations and pre-mapped frameworks.","description":"Anecdotes positions an agentic GRC platform for large programs with many integrations and framework maps.","agent_job":["evidence","monitoring","audit prep","chat/tasks"],"frameworks":["SOC 2","ISO 27001","GDPR","NIST CSF","ISO 42001"],"integrations":["API","Jira","Slack"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://www.anecdotes.ai","docs_url":"https://www.anecdotes.ai","install_url":"https://www.anecdotes.ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"openai-deep-research-compliance","name":"ChatGPT agent workflows (compliance)","slug":"chatgpt-compliance-workflows","logo":"","brief_summary":"OpenAI ChatGPT/Custom GPTs used as workflow agents for policy drafting and compliance research.","description":"Horizontal assistant used as a GRC agent via custom GPTs and connectors. Category reference, not a specialized GRC suite.","agent_job":["chat/tasks","policy"],"frameworks":["ISO 27001","SOC 2","GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","legal"],"url":"https://chatgpt.com","docs_url":"https://platform.openai.com/docs","install_url":"https://chatgpt.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"claude-for-work-compliance","name":"Claude (compliance workflows)","slug":"claude-compliance-workflows","logo":"","brief_summary":"General-purpose Anthropic Claude used via Skills/MCP for custom GRC workflows in enterprise teams.","description":"Not a dedicated GRC product. Listed because many teams operationalize Claude Skills and MCP servers as bespoke GRC agents.","agent_job":["chat/tasks","policy","audit prep"],"frameworks":["ISO 27001","SOC 2","GDPR","EU AI Act"],"integrations":["MCP","Claude","API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC","eng","legal"],"url":"https://claude.ai","docs_url":"https://docs.anthropic.com","install_url":"https://claude.ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"conveyor","name":"Conveyor","slug":"conveyor","logo":"","brief_summary":"AI-assisted security questionnaire automation and trust center for B2B vendors.","description":"Conveyor helps security and GRC teams answer questionnaires faster with AI grounded in knowledge bases.","agent_job":["vendor risk","chat/tasks"],"frameworks":["SOC 2","ISO 27001","GDPR"],"integrations":["API","Slack"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","AppSec"],"url":"https://www.conveyor.com","docs_url":"https://www.conveyor.com","install_url":"https://www.conveyor.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"credovai","name":"Credo AI","slug":"credo-ai","logo":"","brief_summary":"AI governance platform for policy, risk, and regulatory alignment across AI systems.","description":"Credo AI provides governance workflows for responsible AI programs, model risk, and regulatory mapping.","agent_job":["AI governance","policy","audit prep"],"frameworks":["EU AI Act","ISO 42001","NIST AI RMF"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","legal"],"url":"https://www.credo.ai","docs_url":"https://www.credo.ai","install_url":"https://www.credo.ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"cursor-bugbot","name":"Cursor Bugbot","slug":"cursor-bugbot","logo":"","brief_summary":"Cursor's automated PR review agent for bugs and regressions; usage-metered agent runs on pull requests.","description":"Bugbot is Cursor's PR agent product. It is primarily a software quality reviewer, not a GRC framework agent, but teams often compare it when evaluating PR-native agents in the compliance-adjacent lane.","agent_job":["PR review"],"frameworks":[],"integrations":["GitHub","Cursor"],"deployment":"SaaS","data_residency":"US","buyer":["eng","AppSec"],"url":"https://cursor.com","docs_url":"https://cursor.com/docs","install_url":"https://cursor.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"drata-automation","name":"Drata continuous compliance","slug":"drata-automation","logo":"","brief_summary":"Automated evidence collection and continuous control monitoring for security and privacy frameworks.","description":"Drata automates evidence gathering and control testing across cloud stacks. Agent-like continuous monitoring for audit readiness.","agent_job":["evidence","monitoring","audit prep"],"frameworks":["SOC 2","ISO 27001","GDPR","HIPAA","PCI DSS"],"integrations":["API","Slack","Jira"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","AppSec"],"url":"https://drata.com","docs_url":"https://help.drata.com","install_url":"https://drata.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"lax-security","name":"Endor Labs","slug":"endor-labs","logo":"","brief_summary":"Dependency and reachability analysis to prioritize open-source risk for security programs.","description":"Endor Labs helps AppSec teams understand real exploitability of OSS risks, supporting compliance evidence for third-party risk.","agent_job":["monitoring","vendor risk"],"frameworks":["ISO 27001","SOC 2"],"integrations":["GitHub","API"],"deployment":"SaaS","data_residency":"US","buyer":["AppSec","GRC"],"url":"https://www.endorlabs.com","docs_url":"https://www.endorlabs.com","install_url":"https://www.endorlabs.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"github-copilot-coding-agent","name":"GitHub Copilot coding agent","slug":"github-copilot-coding-agent","logo":"","brief_summary":"GitHub-hosted agent that can implement tasks and open pull requests in your repositories.","description":"GitHub Copilot coding agent works on assigned issues/tasks and produces PRs. Not GRC-specialized; listed because buyers search for GitHub-native agents that touch compliance-sensitive code paths.","agent_job":["PR review","chat/tasks"],"frameworks":[],"integrations":["GitHub"],"deployment":"SaaS","data_residency":"US","buyer":["eng"],"url":"https://github.com/features/copilot","docs_url":"https://docs.github.com/en/copilot","install_url":"https://github.com/features/copilot","github_url":"https://github.com","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"harvey-ai","name":"Harvey","slug":"harvey","logo":"","brief_summary":"Domain-specific legal AI used by firms and in-house teams for research and drafting.","description":"Harvey is not a GRC platform but is an agent buyers evaluate for legal compliance research and drafting.","agent_job":["policy","chat/tasks"],"frameworks":["GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["legal"],"url":"https://www.harvey.ai","docs_url":"https://www.harvey.ai","install_url":"https://www.harvey.ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"heygrc","name":"heyGRC","slug":"heygrc","logo":"","brief_summary":"GitHub App that reviews every pull request for compliance impact: flags changes that put controls, evidence, or framework posture at risk.","description":"heyGRC is a PR-native GRC agent. It reviews diffs against your compliance frameworks and comments on compliance impact, not general bugs. Built for engineering + AppSec + GRC teams who ship with AI-written code and need an auditable review trail.","agent_job":["PR review"],"frameworks":["ISO 27001","SOC 2","GDPR","NIS2","DORA","ISO 42001","EU AI Act"],"integrations":["GitHub","API"],"deployment":"SaaS","data_residency":"multi","buyer":["eng","AppSec","GRC"],"url":"https://heygrc.com","docs_url":"https://docs.heygrc.com","install_url":"https://github.com/apps/heygrc/installations/new","github_url":"https://github.com/apps/heygrc","mcp_package":"","linkedin":"","is_house_product":true,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"holistic-ai","name":"Holistic AI","slug":"holistic-ai","logo":"","brief_summary":"AI risk management and governance tooling for enterprise AI portfolios.","description":"Holistic AI helps organizations assess, monitor, and govern AI systems for risk and compliance.","agent_job":["AI governance","monitoring"],"frameworks":["EU AI Act","ISO 42001","NIST AI RMF"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC","legal"],"url":"https://www.holisticai.com","docs_url":"https://www.holisticai.com","install_url":"https://www.holisticai.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"hyperproof","name":"Hyperproof","slug":"hyperproof","logo":"","brief_summary":"GRC platform with AI-assisted workflows for controls, audits, and risk programs.","description":"Hyperproof supports multi-framework compliance operations with automation and AI features for program work.","agent_job":["audit prep","evidence","policy"],"frameworks":["SOC 2","ISO 27001","GDPR","NIST CSF"],"integrations":["API","Jira","Slack"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://hyperproof.io","docs_url":"https://hyperproof.io","install_url":"https://hyperproof.io","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"isms-copilot","name":"ISMS Copilot","slug":"isms-copilot","logo":"","brief_summary":"Compliance AI engine for 75+ frameworks. Chat, tasks, and account MCP so agents and practitioners run GRC work with an auditable trail.","description":"ISMS Copilot is a GRC brain: chat for practitioners, agent task surfaces, public API, embed, and account-plane MCP. Covers ISO 27001, SOC 2, GDPR, NIS2, DORA, ISO 42001, EU AI Act and more. EU-trust positioning with metered platform options.","agent_job":["chat/tasks","policy","audit prep"],"frameworks":["ISO 27001","SOC 2","GDPR","NIS2","DORA","ISO 42001","EU AI Act","HIPAA"],"integrations":["API","MCP","Claude","Cursor"],"deployment":"SaaS","data_residency":"EU","buyer":["GRC","legal","AppSec"],"url":"https://www.ismscopilot.com","docs_url":"https://docs.ismscopilot.com","install_url":"https://www.ismscopilot.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":true,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"isms-copilot-for-agents","name":"ISMS Copilot for Agents","slug":"isms-copilot-for-agents","logo":"","brief_summary":"Account MCP + PAT so Claude Code, Cursor, and other agents use your ISMS Copilot workspace tools directly.","description":"Agent surface of ISMS Copilot: connect coding agents to your account via MCP with scoped tokens. Distinct from the human chat UI and from the public developer API.","agent_job":["chat/tasks","policy"],"frameworks":["ISO 27001","SOC 2","GDPR","NIS2","DORA","ISO 42001"],"integrations":["MCP","Claude","Cursor","API"],"deployment":"SaaS","data_residency":"EU","buyer":["eng","GRC"],"url":"https://www.ismscopilot.com/products/agents","docs_url":"https://docs.ismscopilot.com","install_url":"https://www.ismscopilot.com/products/agents","github_url":"","mcp_package":"","linkedin":"","is_house_product":true,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"ismsdirectory-mcp","name":"ISMS Directory MCP","slug":"ismsdirectory-mcp","logo":"","brief_summary":"MCP server that lets agents search a curated directory of human GRC services and submit listings.","description":"The ISMS Directory MCP package exposes catalog search and listing submission to coding agents. Sibling surface to this agents directory (human services catalog).","agent_job":["chat/tasks"],"frameworks":["ISO 27001","SOC 2","GDPR","NIS2","DORA"],"integrations":["MCP","Claude","Cursor","API"],"deployment":"open-source","data_residency":"EU","buyer":["eng","GRC"],"url":"https://ismsdirectory.com","docs_url":"https://ismsdirectory.com/llms.txt","install_url":"https://www.npmjs.com/package/@ismsdirectory/mcp-server","github_url":"","mcp_package":"@ismsdirectory/mcp-server","linkedin":"","is_house_product":true,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"legora","name":"Legora","slug":"legora","logo":"","brief_summary":"AI legal workspace used by legal teams for document-heavy compliance and contract workflows.","description":"Legora is an AI assistant for legal work. Included where legal/GRC teams use agents for policy and contract review adjacent to compliance programs.","agent_job":["policy","chat/tasks"],"frameworks":["GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"EU","buyer":["legal","GRC"],"url":"https://legora.com","docs_url":"https://legora.com","install_url":"https://legora.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"pagerduty-advance","name":"PagerDuty Advance AI","slug":"pagerduty-advance","logo":"","brief_summary":"AI operations agents for incident response workflows with audit-friendly operational trails.","description":"Incident AI agents that can support operational resilience evidence for frameworks like DORA and ISO 27001 Annex A operational controls.","agent_job":["monitoring","chat/tasks"],"frameworks":["DORA","ISO 27001","SOC 2"],"integrations":["API","Slack"],"deployment":"SaaS","data_residency":"multi","buyer":["eng","AppSec","GRC"],"url":"https://www.pagerduty.com","docs_url":"https://www.pagerduty.com","install_url":"https://www.pagerduty.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"safebase","name":"SafeBase","slug":"safebase","logo":"","brief_summary":"Trust center and security review automation for vendor questionnaires.","description":"SafeBase automates buyer security reviews with a trust center and AI-assisted Q&A over security docs.","agent_job":["vendor risk","chat/tasks"],"frameworks":["SOC 2","ISO 27001","GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","AppSec"],"url":"https://safebase.io","docs_url":"https://safebase.io","install_url":"https://safebase.io","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"scrut-automation","name":"Scrut Automation","slug":"scrut-automation","logo":"","brief_summary":"Continuous compliance automation platform for cloud-native companies across security and privacy frameworks.","description":"Scrut automates control monitoring and evidence for multi-framework programs.","agent_job":["evidence","monitoring","audit prep"],"frameworks":["SOC 2","ISO 27001","GDPR","HIPAA"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC","AppSec"],"url":"https://www.scrut.io","docs_url":"https://www.scrut.io","install_url":"https://www.scrut.io","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"scytale-ai","name":"Scytale AI compliance","slug":"scytale-ai","logo":"","brief_summary":"AI-powered compliance automation with expert-backed workflows for cloud-native companies.","description":"Scytale markets AI automation for continuous compliance across many frameworks, paired with human experts.","agent_job":["evidence","audit prep","monitoring"],"frameworks":["SOC 2","ISO 27001","GDPR","ISO 42001"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://scytale.ai","docs_url":"https://scytale.ai","install_url":"https://scytale.ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"seconize","name":"Seconize DeRisk Center","slug":"seconize","logo":"","brief_summary":"AI-driven compliance audit solution that collects evidence artifacts from IT systems.","description":"Seconize focuses on automated evidence collection for audits across enterprise IT systems.","agent_job":["evidence","audit prep","monitoring"],"frameworks":["ISO 27001","SOC 2","NIST CSF"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC","AppSec"],"url":"https://seconize.com","docs_url":"https://seconize.com","install_url":"https://seconize.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"secureframe-ai","name":"Secureframe AI","slug":"secureframe-ai","logo":"","brief_summary":"AI-assisted compliance automation for evidence, questionnaires, and multi-framework programs.","description":"Secureframe combines continuous compliance automation with AI features for questionnaires and workflow acceleration.","agent_job":["evidence","audit prep","vendor risk"],"frameworks":["SOC 2","ISO 27001","GDPR","HIPAA"],"integrations":["API","Slack"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://secureframe.com","docs_url":"https://secureframe.com","install_url":"https://secureframe.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"semgrep-assistant","name":"Semgrep Assistant","slug":"semgrep-assistant","logo":"","brief_summary":"AI-assisted static analysis triage and fix guidance for security findings in code.","description":"Semgrep Assistant helps teams triage SAST findings with AI. AppSec agent adjacent to compliance code review.","agent_job":["PR review","monitoring"],"frameworks":[],"integrations":["GitHub","GitLab","API"],"deployment":"SaaS","data_residency":"US","buyer":["AppSec","eng"],"url":"https://semgrep.dev","docs_url":"https://semgrep.dev/docs","install_url":"https://semgrep.dev","github_url":"https://github.com/semgrep/semgrep","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"snyk-agent-fix","name":"Snyk Agent Fix / DeepCode AI","slug":"snyk-agent-fix","logo":"","brief_summary":"Security-focused code analysis and AI fix suggestions integrated into developer workflows.","description":"Snyk's AI-assisted security remediation surfaces act as agents over code findings. Closer to AppSec than GRC frameworks, but frequently adjacent in buyer shortlists for automated compliance-relevant code review.","agent_job":["PR review","monitoring"],"frameworks":[],"integrations":["GitHub","GitLab","API"],"deployment":"SaaS","data_residency":"multi","buyer":["AppSec","eng"],"url":"https://snyk.io","docs_url":"https://docs.snyk.io","install_url":"https://snyk.io","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"socket-dev","name":"Socket","slug":"socket","logo":"","brief_summary":"Supply-chain security agent that monitors dependencies for malware and risk signals.","description":"Socket analyzes open-source dependencies for supply-chain attacks. Relevant to compliance controls around third-party software risk.","agent_job":["monitoring","PR review"],"frameworks":["ISO 27001","SOC 2"],"integrations":["GitHub","API"],"deployment":"SaaS","data_residency":"US","buyer":["AppSec","eng"],"url":"https://socket.dev","docs_url":"https://socket.dev","install_url":"https://socket.dev","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"spire-ai","name":"Spire","slug":"spire","logo":"","brief_summary":"AI-powered SOC 2 and EU AI Act compliance with continuous evidence collection.","description":"Spire connects stacks, collects evidence continuously, and assists security questionnaire workflows with AI.","agent_job":["evidence","audit prep","AI governance"],"frameworks":["SOC 2","EU AI Act"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://www.spire.ai","docs_url":"https://www.spire.ai","install_url":"https://www.spire.ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"sprinto","name":"Sprinto","slug":"sprinto","logo":"","brief_summary":"Compliance automation with continuous monitoring for SOC 2, ISO 27001, GDPR, and more.","description":"Sprinto provides automated evidence collection and compliance program workflows for startups and scale-ups.","agent_job":["evidence","monitoring","audit prep"],"frameworks":["SOC 2","ISO 27001","GDPR","HIPAA"],"integrations":["API","Slack"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://sprinto.com","docs_url":"https://sprinto.com","install_url":"https://sprinto.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"thoropass","name":"Thoropass","slug":"thoropass","logo":"","brief_summary":"End-to-end compliance platform combining AI automation with in-house audit services.","description":"Thoropass blends automated collection with human audit delivery for startups pursuing SOC 2 and ISO 27001.","agent_job":["evidence","audit prep"],"frameworks":["SOC 2","ISO 27001","HIPAA","GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://thoropass.com","docs_url":"https://thoropass.com","install_url":"https://thoropass.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"trail-ai-governance","name":"trail","slug":"trail","logo":"","brief_summary":"AI governance software helping organizations comply with the EU AI Act and manage AI-specific risk.","description":"trail focuses on AI governance programs: inventories, risk, and EU AI Act-oriented workflows.","agent_job":["AI governance","policy","audit prep"],"frameworks":["EU AI Act","ISO 42001"],"integrations":["API"],"deployment":"SaaS","data_residency":"EU","buyer":["GRC","legal"],"url":"https://www.trail-ml.com","docs_url":"https://www.trail-ml.com","install_url":"https://www.trail-ml.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"vanta-automation","name":"Vanta continuous compliance automation","slug":"vanta-automation","logo":"","brief_summary":"Continuous control monitoring and evidence collection automation for SOC 2, ISO 27001, and related frameworks.","description":"Vanta's automation layer continuously collects evidence and monitors controls. Listed as an agentic monitoring surface rather than a pure dashboard: autonomous collection and alerting over compliance state.","agent_job":["evidence","monitoring","audit prep"],"frameworks":["SOC 2","ISO 27001","GDPR","HIPAA","ISO 42001"],"integrations":["API","Slack","Jira"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","AppSec"],"url":"https://www.vanta.com","docs_url":"https://help.vanta.com","install_url":"https://www.vanta.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"vanta-trust-report","name":"Vanta Trust Report AI","slug":"vanta-trust-report-ai","logo":"","brief_summary":"AI-assisted trust and questionnaire workflows adjacent to Vanta's compliance automation suite.","description":"Listed as the questionnaire/trust agent surface buyers encounter when evaluating automated vendor security responses in the Vanta ecosystem.","agent_job":["vendor risk","chat/tasks"],"frameworks":["SOC 2","ISO 27001"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC"],"url":"https://www.vanta.com","docs_url":"https://help.vanta.com","install_url":"https://www.vanta.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"whistic-ai","name":"Whistic","slug":"whistic","logo":"","brief_summary":"Vendor risk automation with AI-assisted questionnaire and trust center workflows.","description":"Whistic helps buyers and vendors automate third-party risk questionnaires and trust exchange.","agent_job":["vendor risk"],"frameworks":["SOC 2","ISO 27001","GDPR"],"integrations":["API"],"deployment":"SaaS","data_residency":"US","buyer":["GRC","legal"],"url":"https://www.whistic.com","docs_url":"https://www.whistic.com","install_url":"https://www.whistic.com","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"},{"id":"zerberus-ai","name":"Zerberus.ai","slug":"zerberus-ai","logo":"","brief_summary":"AI-driven automation to accelerate ISO 27001 and SOC 2 for SaaS companies.","description":"Zerberus markets fast-track ISO 27001 and SOC 2 programs using AI-driven automation.","agent_job":["evidence","audit prep","policy"],"frameworks":["ISO 27001","SOC 2"],"integrations":["API"],"deployment":"SaaS","data_residency":"multi","buyer":["GRC"],"url":"https://zerberus.ai","docs_url":"https://zerberus.ai","install_url":"https://zerberus.ai","github_url":"","mcp_package":"","linkedin":"","is_house_product":false,"publish_after":null,"date_added":"2026-07-31","source":"seed"}]}