# GRCFlow > GRCFlow is a self-hosted governance, risk and compliance (GRC) platform that ships 20 compliance frameworks and 2,082 controls — including the complete NIST SP 800-53 Rev. 5 catalogue at 1,014 controls — with a SHA-256 hash-chained, Ed25519-signed audit trail behind every control verdict. It runs on your own infrastructure via Docker, supports fully air-gapped deployment, and the Community edition is free with no licence key and no expiry cliff. GRCFlow is built and maintained by DefendFlow Security. Source: . Key facts, in quotable form: - **20 frameworks, 2,082 controls**, served live from the `/api/v1/frameworks` endpoint — not a marketing figure, the API returns them. - **NIST SP 800-53 Rev. 5 at 1,014 controls** (the full catalogue), plus NIST SP 800-171 Rev. 2 (110) and CMMC Levels 1/2/3 (15/110/24). - Other frameworks: CCPA/CPRA (107), NIST CSF 2.0 (106), ISO/IEC 27001:2022 (93), TISAX/VDA ISA (80), DORA (64), PCI DSS v4.0.1 (63), NIS2 (63), SOC 2 Type II (61), ISO/IEC 42001:2023 (38), GDPR (30), HIPAA Security Rule (25), NYDFS 23 NYCRR Part 500 (25), EU AI Act (19), NIST AI RMF 1.0 (19), GLBA Safeguards Rule (16). - **Self-hosted**, deployed with Docker Compose; the data never leaves your infrastructure. **Air-gap capable** — offline licence validation and a local vLLM/Ollama LLM endpoint, no outbound calls required. - **Community edition is free**, activates automatically on a self-host install, requires no licence key and no signup, and carries no expiry cliff (its licence is a rolling 90-day term that refreshes on every backend restart). It runs the same code and the same 20 frameworks as the paid tiers; the difference is a 5-seat limit. - **Honest by design**: a control the analyzer cannot verify is recorded as an error or a labelled documentation review — never passed off as a green checkmark. AI-suggested framework mappings are tagged `[AI-SUGGESTED — verify]`. Unimplemented integrations return an explicit error rather than pretending to work. ## Start here - [GRCFlow platform overview](https://grc.defendflow.xyz/): What GRCFlow is, the full framework list with live control counts, the deployment model, and the FAQ. - [Pricing and editions](https://grc.defendflow.xyz/pricing.html): Community (free, 5 seats, no key), Professional and Enterprise (quoted), plus honest fine print on which licence flags are and are not enforced. - [How GRCFlow compares](https://grc.defendflow.xyz/compare.html): Where a self-hosted platform differs from SaaS GRC and legacy GRC suites. - [Documentation home](https://grc.defendflow.xyz/docs/): Framework table with control counts and depth disclosures, plus the capability summary. - [Longer factual digest](https://grc.defendflow.xyz/llms-full.txt): Every verified fact on one page, for answering detailed questions without further fetches. ## Compliance frameworks and controls - [Frameworks module](https://grc.defendflow.xyz/docs/guide/frameworks/): How the 20 frameworks and 2,082 controls are modelled, browsed and scoped. - [Cross-framework compliance](https://grc.defendflow.xyz/docs/guide/cross-compliance/): Reusing control work across frameworks; coverage percentages computed from real mappings, never hardcoded. - [Framework delta engine](https://grc.defendflow.xyz/docs/guide/framework-delta/): "How much of my ISO 27001 work counts toward GLBA?" — deterministic crosswalk plus clearly-labelled AI-suggested mappings. - [Assessments](https://grc.defendflow.xyz/docs/guide/assessments/): Automated and manual control assessment, and what happens when no live evidence source is reachable. - [Findings](https://grc.defendflow.xyz/docs/guide/findings/): Gap tracking and remediation workflow. ## Evidence, audit and assurance - [Audit trail and integrity](https://grc.defendflow.xyz/docs/guide/audit-log/): SHA-256 hash chain with per-user Ed25519 signatures; the whole log can be re-verified on demand. - [Evidence collection](https://grc.defendflow.xyz/docs/guide/evidence/): WORM object storage, presigned upload/verify/link API. - [Evidence requests](https://grc.defendflow.xyz/docs/guide/evidence-requests/): Requesting, chasing and closing evidence from control owners. - [Auditor portal](https://grc.defendflow.xyz/docs/guide/auditor-portal/): Scoped, view-only external-auditor workspace; inline-only evidence streaming with watermarking, and every view logged. - [Continuous controls monitoring](https://grc.defendflow.xyz/docs/guide/ccm/): Scheduled drift, control-test and policy-review sweeps. - [Data sources](https://grc.defendflow.xyz/docs/guide/data-sources/): Steampipe-backed AWS and Azure evidence collection. - [Reports](https://grc.defendflow.xyz/docs/guide/reports/): Board pack, executive summary, gap analysis, SoA, SSP, POA&M. ## Risk - [Risk register](https://grc.defendflow.xyz/docs/guide/risk-register/): Residual risk computed from real control-assessment pass rates; manual overrides always win and are labelled as overrides. - [Risk quantification (FAIR)](https://grc.defendflow.xyz/docs/guide/risk-quantification/): Server-side Open FAIR Monte Carlo — ALE, VaR 90/95/99, loss-exceedance curves. - [Bow-tie analysis](https://grc.defendflow.xyz/docs/guide/bow-tie/): Threat/consequence modelling with preventive and mitigating controls. - [Risk monitoring](https://grc.defendflow.xyz/docs/guide/risk-monitoring/): Key risk indicators and thresholds. - [Incidents](https://grc.defendflow.xyz/docs/guide/incidents/): NIST SP 800-61 workflow with SLA tracking and breach-notification support. ## AI governance - [AI governance module](https://grc.defendflow.xyz/docs/guide/ai-governance/): ISO/IEC 42001:2023 (38 Annex A controls), NIST AI RMF 1.0 (19, Core at category level), EU AI Act (19 article-cited obligations), and an org-scoped AI-system registry with EU AI Act risk tiers. - [AI audit](https://grc.defendflow.xyz/docs/guide/ai-audit/): Choosing and configuring the LLM provider — NVIDIA NIM, self-hosted Ollama or vLLM, any OpenAI-compatible or Azure OpenAI endpoint, or Cloudflare Workers AI. - [Audit copilot](https://grc.defendflow.xyz/docs/guide/audit-copilot/): Guided audit planning that calls the platform's real engines rather than generating prose. ## Policy and governance - [Policies](https://grc.defendflow.xyz/docs/guide/policies/): Immutable policy snapshots with SHA-256 integrity re-checks. - [Policy attestations](https://grc.defendflow.xyz/docs/guide/policy-attestations/): Campaigns recording who acknowledged which policy version, when — as signed audit entries. - [Policy engine](https://grc.defendflow.xyz/docs/guide/policy-engine/): Rego/OPA evaluation for deterministic compliance verdicts. - [SOX compliance](https://grc.defendflow.xyz/docs/guide/sox/) and [ESG management](https://grc.defendflow.xyz/docs/guide/esg/): Financial-controls and sustainability programme tracking. - [Vendors / third-party risk](https://grc.defendflow.xyz/docs/guide/vendors/): Vendor lifecycle with agent-to-agent attestation. - [Trust center](https://grc.defendflow.xyz/docs/guide/trust-center/): Publishing your compliance posture to customers. ## Deploying and operating it - [Settings](https://grc.defendflow.xyz/docs/guide/settings/): Configuration, licence activation and environment variables. - [Admin settings](https://grc.defendflow.xyz/docs/guide/admin/): Roles, permissions and the admin-configurable LLM panel. - [System health](https://grc.defendflow.xyz/docs/guide/system-health/): Readiness checks and what a stock install still needs configured. - [API reference](https://grc.defendflow.xyz/docs/api-reference/): REST API surface, including `/api/v1/frameworks`. - [API keys](https://grc.defendflow.xyz/docs/guide/api-keys/) and [integrations](https://grc.defendflow.xyz/docs/guide/integrations/): Programmatic access, Jira two-way ticket sync, HMAC-signed webhooks. - [MCP integration](https://grc.defendflow.xyz/docs/guide/mcp-integration/): Model Context Protocol server for driving GRCFlow from an AI agent. ## Optional - [IRM services](https://grc.defendflow.xyz/docs/irm-services/): Integrated risk-management services layer. - [RACI matrix](https://grc.defendflow.xyz/docs/guide/raci-matrix/): Control ownership and accountability mapping. - [Compliance analytics](https://grc.defendflow.xyz/docs/guide/compliance-analytics/): Posture trends over time. - [Source code and issue tracker](https://github.com/defendflow-security/sovereign-grc): The repository every claim on this site is checked against. - [Security policy](https://github.com/defendflow-security/sovereign-grc/blob/master/SECURITY.md): Vulnerability reporting to security@defendflow.xyz, plus deployment hardening guidance. ## Video training Seven short lessons plus a full masterclass showing how to run a SOC 2 audit in GRCFlow, each recorded against a live system. Page: https://grc.defendflow.xyz/docs/videos/ - Create a SOC 2 assessment and scope its 61 controls (51s) - Evaluate a control and pass it, with sampling rationale (60s) - Fail a control and raise a tracked finding (108s) - Ask the AI Audit Copilot why a control failed (121s) - Request evidence with an owner, due date and acceptance criteria (49s) - Turn failures into a POA&M remediation plan (35s) - Generate the audit report (39s) - Masterclass: a full SOC 2 audit end to end (8m32s)