GRC Oversight

A walk through every surface

Six stops, from the free scan to the MCP server. Scroll to see how the pieces connect, illustrated with native mockups, not screenshots.

Prefer to click around first? Try the interactive sandbox with sample data, no login needed.

Stop 01

The free scanner

Start with a free trust scan

Run a passive, browser-equivalent scan on any domain. See TLS, security headers, and cookie posture scored, no signup required to get started. In a live demo, we run this on your own domain first.

  • Passive checks only, no intrusive probing
  • Scored against recognized public baselines
  • A real entry point, not a gated teaser
Learn more
Trust scanLive
TLS configuration92
Security headers74
Cookie hygiene88
Stop 02

The compliance graph

Map results to frameworks and controls

Scan findings and connected systems feed the same graph that backs your frameworks: frameworks roll down to controls, controls down to tests. Map a requirement once and reuse it everywhere.

  • Requirement-level mapping, not just control families
  • One passing test satisfies many frameworks
  • See coverage and gaps at a glance
Learn more

Compliance graph

SOC 2ISOHIPAAControlEvidence
Stop 03

Evidence & trust center

Publish proof as a living page

Tests produce evidence; the trust center publishes it. Share a security profile, list subprocessors and frameworks, and gate sensitive documents behind NDA, so security reviews stop blocking deals.

  • Public posture, framework, and subprocessor lists
  • NDA-gated document sharing with access requests
  • Self-serve answers that shorten reviews
Learn more
Trust centerPublic
  • Security overview
  • Subprocessors
  • Frameworks
  • Documents (NDA)
Stop 04

Questionnaire automation

Answer questionnaires from the same evidence

Upload a security questionnaire and get draft answers grounded in your policies, evidence, and approved history; each one cites its source. A human reviews and approves before anything is sent.

  • Drafts grounded in your own evidence, not boilerplate
  • Every suggestion cites the policy or test it came from
  • Nothing sent without human sign-off
Learn more
QuestionnaireDraft
“Do you encrypt data at rest?”
Yes: AES-256 at rest, enforced by 3 passing controls.Source: Encryption Policy v4 · cited evidence
Stop 05

ChatGRC

Ask your compliance data

Query posture in plain language, grounded in your own policies and evidence. Every answer is a draft your team reviews before it's used.

  • Grounded in your documents and evidence
  • Drafts questionnaire answers and summaries
  • Human approves before anything ships
Learn more
ChatGRC
Which controls cover encryption at rest?
Three controls map to it, all passing. The draft cites your encryption policy and the test that proves it.
Stop 06

The MCP server

Bring it to your AI tools

Connect Claude, Cursor, and other MCP clients to your tenant's compliance graph, securely, scoped to your organization.

  • Tenant-scoped tools, never cross-org
  • Read posture and failing controls from your editor
  • Works with standard MCP clients
Learn more
MCP server
tool: list_failing_controls
scope: org:acme
→ 2 controls need evidence
→ scoped to your tenant only

Connect Claude or Cursor to your org's compliance data.

FAQ

The tour, answered

No, they're native mockups built in code (DOM and SVG) that illustrate each surface. In a guided demo we'll show you the actual platform on real data.

Not to start. The free trust scan runs on any domain without an account; it's a real entry point, not a gated teaser. The deeper surfaces (trust center, ChatGRC, the MCP server) come with an account and connected systems.

They're all views onto the same evidence graph. The scanner and connected systems produce test results that feed it; frameworks and controls map onto it; the trust center publishes proof from it; questionnaire answers, ChatGRC, and the MCP server all query it. Prove something once and it shows up everywhere it matters.

If you're evaluating, start with the free scan to see real output on your own domain. If you're ready to build a program, the compliance graph is the foundation; everything else reads from it.

See it on your own data

Book a guided demo, or start free by scanning any domain.