Self-hosted · Air-gap ready · Never fakes a green light

The self-hosted GRC platform for compliance you can
cryptographically verify

Continuous controls monitoring, cross-framework reuse, and AI governance on your own infrastructure — with a signed, hash-chained audit trail behind every verdict. A control we cannot verify is an honest gap, never a green checkmark. Deploy with Docker in minutes.

All 20 frameworks — 2,082 controls, NIST SP 800-53 Rev. 5 complete — in every edition, including the free one

NIST SP 800-53 Rev. 5 1,014 controls
CMMC Level 2 110 controls
NIST SP 800-171 Rev. 2 110 controls
CCPA/CPRA 107 controls
NIST CSF 2.0 106 controls
ISO/IEC 27001:2022 93 controls
TISAX (VDA ISA) 80 controls
DORA 64 controls
PCI DSS v4.0.1 63 controls
NIS2 Directive 63 controls
SOC 2 Type II 61 controls
ISO/IEC 42001:2023 38 controls
GDPR 30 controls
HIPAA Security Rule 25 controls
NYDFS Part 500 25 controls
CMMC Level 3 24 controls
NIST AI RMF 1.0 19 categories
EU AI Act 19 obligations
GLBA Safeguards (FTC) 16 controls
CMMC Level 1 15 controls

GRCFlow at a glance

Frameworks
20Shipped in every edition
Controls
2,082Across all 20 frameworks
Largest catalogue
1,014NIST SP 800-53 Rev. 5, complete
Deployment
Self-hostedDocker Compose; air-gap overlay included
Community edition
Free5 seats, no licence key, rolling 90-day term that refreshes on restart
Licence
ProprietaryNot open source; self-hosted, no telemetry
The GRCFlow compliance dashboard: per-framework readiness bars, control status counts, open findings and recent audit-trail entries.

What is a GRC platform?

Governance, risk and compliance (GRC) is the practice of setting the rules an organisation runs by (governance), working out what could go wrong and how much it would cost (risk), and proving to regulators, customers and auditors that the required safeguards are actually in place and operating (compliance).

A GRC platform is the system of record for that work. It holds the control catalogue for each framework you are held to, collects and versions the evidence that each control is operating, tracks findings through to remediation, manages policies and who has attested to them, maintains the risk register, and produces the reports an auditor asks for — so that compliance is a continuously maintained state rather than a spreadsheet rebuilt each audit cycle.

Where GRCFlow fits

GRCFlow is a GRC platform you host yourself. It ships 20 compliance frameworks and 2,082 controls — including the complete NIST SP 800-53 Rev. 5 catalogue at 1,014 controls — and runs as a Docker Compose stack on your own infrastructure, with an air-gap overlay for deployments that must make no outbound connections at all. The Community edition is free.

The design constraint that shapes everything else: a control GRCFlow cannot verify is recorded as an honest error or gap, never as a pass. Every verdict, evidence action, policy edit and user change is written to a SHA-256 hash chain signed with per-user Ed25519 keys, and an auditor can re-verify the whole chain from inside the application, and every entry signature through the audit API.

Trust you can verify, not a dashboard you have to believe

Most compliance tools show you a green light and ask for faith. Ours shows its work — cryptographically.

🔒

Tamper-Evident Audit Trail

Every control-verdict change, evidence action, policy edit, and user change is written to a SHA-256 hash chain, signed with per-user Ed25519 keys — and you can re-verify the entire chain from the Audit Log page any time, with per-entry signature verification available through the audit API. An auditor doesn't have to trust your dashboard; they can check the math.

Honest State — Never a Fake Green

A control the engine cannot verify is an honest error or gap, never a fabricated verdict. Assessments only report “completed” when controls received real verdicts; coverage percentages are computed, never hardcoded; deterministic Rego rules only fire on live cloud evidence; and anything not implemented says so instead of pretending it ran.

🔄

Continuous Controls Monitoring

A real scheduler with a Postgres-backed jobstore ships six daily CCM jobs out of the box: evidence-source health & drift checks, control-test sweeps that trigger and execute due assessments, policy-review-due sweeps, PBC evidence-request reminders, stale needs-review finding reminders, and security-awareness training reminders — plus a seventh job, an A2A notification-delivery sweep that runs every 60 seconds rather than daily. On by default — and if the scheduler ever fails to start, the log shouts it instead of hiding it.

Collect Once, Map Everywhere

The cross-framework delta engine shows how much of your existing ISO 27001 or SOC 2 work already covers a new framework — GLBA, ISO 42001, and more — with full/partial/none coverage per control and an honest reuse percentage. Deterministic crosswalk mappings first; AI suggestions are always labelled “AI-suggested — verify” and never block or fake a result.

🤖

AI Governance, Built In

ISO/IEC 42001, NIST AI RMF, and the EU AI Act ship as first-class frameworks with curated crosswalks to your ISMS — so AI governance becomes a delta on work you've already done, not a rebuild. An org-scoped AI-system registry tracks each system's EU AI Act risk tier, owner, model provider, and linked controls.

Automated Assessments

AI-assisted control evaluation with live Steampipe cloud queries and deterministic OPA verdicts, across all 20 frameworks (2,082 controls). Connect your own LLM key (NVIDIA NIM, Anthropic Claude, Google Gemini, DeepSeek, OpenAI, Azure OpenAI, Cloudflare Workers AI, or any OpenAI-compatible server) — configurable from the admin panel, including pointing at a local Ollama/vLLM endpoint, with a Test Connection check. Cloud queries use the optional Steampipe sidecar. Controls with no reachable cloud collector are evaluated against your in-force policy documents — clearly labelled as documentation review, not live verification.

📝

Policy Versioning & Attestations

Every policy create, update, and approval pins an immutable version snapshot with a live SHA-256 integrity check. Attestation campaigns assign policies to users or roles and record who attested to exactly which version, when — as signed entries in the audit chain.

📊

Board Packs & Auditor Evidence Rights

An executive board-pack report rolls up posture, per-framework readiness, top residual risks, and open gaps. External auditors on a grant view evidence inline only — watermarked images, no download links, every view and every denied download audit-logged. Deterrence and auditability, not DRM: a browser view still delivers bytes.

Risk: Residual + FAIR

Map controls to risk-register entries and residual risk is computed from real assessment pass rates — untested controls earn no credit, and a manual override always wins and is always labelled. Open FAIR Monte Carlo quantification (ALE, VaR, loss exceedance) runs server-side and persists every analysis.

🧭

Audit Copilot

Guided audit prep grounded in real framework content and your organization's own findings — “new to this” and “seasoned” modes, resumable sessions, and agentic actions that pull real verdicts, save AI remediation drafts onto findings, or run the reuse delta. Progress is recomputed from real findings on every resume, never stored — so it can't go stale or be faked. ISO 27001 today; offline template drafts are labelled and never auto-saved.

🔗

Integrations, Honestly Labelled

Ten evidence connectors ship — AWS, Azure, GitHub, Okta, Kubernetes, SSH, WinRM, LDAP, PostgreSQL and MySQL — and the 26 Azure control queries are verified against the published plugin schema. Jira sync is real: outbound create, close and comment against the Jira Cloud REST API v3, with inbound comments and status changes arriving over the HMAC-signed generic webhook — which also drives any other tracker. ServiceNow returns an honest “not yet supported” instead of pretending; no GCP connector is claimed because none exists yet.

Incidents, Vendors & Evidence

NIST 800-61 incident workflow with SLA tracking and breach-notification support; Agent-to-Agent vendor attestation with signed responses; versioned, hash-verified evidence storage with WORM object lock. Evidence needs your own S3-compatible object storage (R2, S3, or the bundled MinIO).

Transparent pricing — no framework tax, no surprise renewal

Every edition ships the full platform and all 20 frameworks. Tiers differ only in seats, license term, and deployment mode.
See the full tier matrix, traced to the license gates in the code →  ·  Compare to Vanta, Drata, AuditBoard →

Not-final pricing: final list prices are not published yet — anything marked “Contact for quote” is a placeholder, not an official price. Only “Free” is final.

Professional

Contact · placeholder
1-year signed key for teams past 5 users. Same platform, more seats.
  • Everything in Community
  • 25 seats (signed into your key)
  • 1-year term, validated offline
  • No auto-renew — expiry shown in-app
  • Email support
Contact Sales

Enterprise

Contact · placeholder
Custom seat counts plus the air-gap deployment tier for regulated buyers.
  • Everything in Professional
  • 100+ seats (custom)
  • Air-gap tier: offline validation, local vLLM
  • Cloud connectors off on air-gap keys, by design
  • Custom license terms
Contact Sales

Frequently asked questions

Direct answers, with the real numbers. Nothing here is aspirational.

What is GRCFlow?

GRCFlow is a self-hosted governance, risk and compliance (GRC) platform that you run on your own infrastructure as a Docker Compose stack. It ships 20 compliance frameworks totalling 2,082 controls — including the full NIST SP 800-53 Rev. 5 catalogue at 1,014 controls — together with continuous controls monitoring, cross-framework control reuse, policy versioning and attestations, a risk register with Open FAIR quantification, and a tamper-evident audit trail. The Community edition is free.

Which compliance frameworks does GRCFlow support?

GRCFlow ships 20 frameworks totalling 2,082 controls: NIST SP 800-53 Rev. 5 (1,014), CMMC Level 2 (110), NIST SP 800-171 Rev. 2 (110), CCPA/CPRA (107), NIST CSF 2.0 (106), ISO/IEC 27001:2022 (93), TISAX (80), DORA (64), PCI DSS v4.0.1 (63), NIS2 (63), SOC 2 Type II (61), ISO/IEC 42001:2023 (38), GDPR (30), HIPAA Security Rule (25), NYDFS Part 500 (25), CMMC Level 3 (24), NIST AI RMF 1.0 (19), EU AI Act (19), GLBA Safeguards Rule (16) and CMMC Level 1 (15). Every edition ships all 20, including the free Community edition — there is no per-framework upsell.

Framework documentation →

Is GRCFlow open source?

No. GRCFlow is proprietary software licensed by DefendFlow Security, not an open-source project. What it is instead is self-hosted: the Community edition is free with no licence key and no signup, and the whole platform runs on your own servers, your own PostgreSQL database and your own object storage, so no compliance data leaves your infrastructure.

What does GRCFlow cost?

The Community edition is free and includes the full platform, all 20 frameworks and 5 user seats. It activates automatically at install with no licence key, no signup and no expiry cliff — the built-in 90-day term rolls forward every time the backend restarts. Professional (25 seats, 1-year signed key) and Enterprise (100+ seats plus the air-gap tier) are quoted on request: list prices are not published yet, so every “contact for quote” entry on the pricing page is a placeholder rather than an official price.

Full tier matrix →

Can GRCFlow run air-gapped?

Yes. GRCFlow ships an air-gap deployment overlay (docker-compose.airgap.yml) that runs with zero external network access. Licence validation is offline Ed25519 signature verification with no call to a licence server, AI inference runs locally on vLLM or Ollama with a CPU-only override for machines without an NVIDIA GPU, evidence is stored locally instead of in cloud object storage, and services bind to localhost or a specified LAN IP only. Cloud evidence connectors are disabled on air-gap licences by design.

Does GRCFlow phone home or collect telemetry?

No. GRCFlow contains no telemetry, product-analytics or usage-reporting code in either the backend or the frontend, and licence keys are validated offline by Ed25519 signature rather than by calling a licence server. The only outbound network traffic comes from the integrations you configure yourself — your LLM endpoint (which can be a local Ollama or vLLM server), your cloud accounts for evidence collection, and your ticketing system — plus the trial-key request you explicitly click. The air-gap deployment requires no outbound connectivity at all.

How is GRCFlow different from Vanta or Drata?

The difference is the deployment model and how results are proven. Vanta and Drata are multi-tenant cloud SaaS, so your compliance data lives in their systems; GRCFlow is self-hosted on your own PostgreSQL inside your own network, with an air-gap mode that makes no outbound connections. GRCFlow also writes every control verdict, evidence action, policy edit and user change into a SHA-256 hash chain signed with per-user Ed25519 keys that an auditor can re-verify from inside the app, and it refuses to fabricate a pass: a control the engine cannot verify is recorded as an honest error or gap, never a green checkmark.

Side-by-side comparison →

Does GRCFlow cover AI governance and the EU AI Act?

Yes. ISO/IEC 42001:2023 (38 controls), the NIST AI Risk Management Framework 1.0 (19 categories) and the EU AI Act (19 article-cited obligations) ship as first-class frameworks, with 46 curated crosswalk rows across the AI-governance pack — 21 mapping ISO/IEC 27001 to ISO/IEC 42001, 13 mapping ISO/IEC 42001 to the EU AI Act and 12 mapping the NIST AI RMF to ISO/IEC 42001 — so AI governance becomes a delta on work you have already done rather than a rebuild. An organisation-scoped AI-system registry tracks each system's EU AI Act risk tier, owner, model provider and linked controls.

AI governance documentation →

How long does GRCFlow take to deploy?

GRCFlow installs with a single command that checks prerequisites, generates secrets, pulls prebuilt images from ghcr.io and starts a Docker Compose stack of PostgreSQL, Redis, the backend, the frontend and optional MinIO object storage — no source download required. It runs on Linux, macOS and Windows via WSL2, with docker compose v2 or legacy v1. Features that depend on your own credentials — AI-assisted assessment, evidence storage and ticket sync — are switched on afterwards from the admin panel, and the in-app setup checklist shows exactly which of them are still missing a key.

Deployment steps →

Get your free 30-day trial key

Enter your email and your key is minted instantly and shown right here on this page — there is no email round-trip and no credit card. Deploy on your own infrastructure in minutes.

Deploy in minutes

Docker Compose stack with PostgreSQL, Redis, backend, frontend, and optional MinIO. OPA and Steampipe are available in the full source deployment. The installer brings up the core stack; flagship features (AI, evidence storage, ticketing) are enabled by connecting your own keys and integrations afterward.

# One-line install — pulls pre-built images, generates secrets,
# and starts the stack (schema is created on backend startup).
curl -sSL https://get.defendflow.xyz | bash

# Portable across Linux, macOS (stock bash 3.2 + BSD tools, Docker
# Desktop), and Windows WSL2 — with docker compose v2 or legacy v1.
# No source download required — images ship from ghcr.io.
Step 1

Install

One command downloads the compose file and env template, checks prerequisites, generates secrets, and pulls prebuilt images to start the stack.

Step 2

Activate

Paste your trial or purchased license key in Settings.

Step 3

Connect

Add your LLM, object storage, and ticketing. The LLM is configured from the admin panel — NVIDIA NIM, a local Ollama/vLLM endpoint, or any OpenAI-compatible server — with a Test Connection check. The in-app Setup readiness checklist shows what is ready and what still needs a key.

Step 4

Assess

Create your first assessment and connect cloud providers.