Self-hosted GRC with enterprise integrity.
Free to start.
Every claim in the GRCFlow column maps to real, shipping code in a public repository. Everything we say about anyone else is attributed to their own public documentation — and dated, so you can re-check it. Here is how a self-hosted, air-gap-capable GRC platform compares to cloud compliance automation and to legacy GRC suites.
GRCFlow compared to SaaS and legacy GRC platforms
How to read this. The GRCFlow column describes behaviour implemented in our public repository; you can read the source and the licence gates behind each tier yourself. The other three columns are generalised at the category level from how those vendors describe their own products in their public documentation, checked July 2026. They are not test results, we have not run those products, and capabilities change — treat them as a starting list of questions for the vendor, not as findings. Where a cell says “not publicly documented”, that means we did not find it described in public vendor material, not that the product cannot do it. We publish no third-party pricing. All product and company names are trademarks of their respective owners and are used here for identification only.
| Feature | GRCFlow traced to public code |
Compliance automation SaaS category, e.g. Vanta, Drata |
Enterprise GRC suites category, e.g. AuditBoard, Hyperproof |
Legacy GRC platforms category, e.g. Archer, ServiceNow |
|---|---|---|---|---|
| Licensing model | Free Community edition Self-host free forever — 5 seats, full platform, all 20 frameworks. Professional and Enterprise are quoted on contact; no list price is published yet. See GRCFlow pricing. |
Vendor quote Commercial subscription, quoted by the vendor. We do not publish other companies’ prices — ask them. |
Vendor quote Commercial subscription, quoted by the vendor. We do not publish other companies’ prices — ask them. |
Vendor quote Commercial licence, usually with an implementation project. Pricing comes from the vendor. |
| Audit trail integrity | Cryptographic proof SHA-256 hash chain, per-user Ed25519 signatures, Merkle-anchored batches — re-verifiable in the app |
Vendor-documented Evidence captures and change history, as described in their docs. Ask whether you can verify it cryptographically. |
Vendor-documented Workflow and version history, as described in their docs. Ask the same verification question. |
Vendor-documented Platform and database audit logging, as described in their docs. Ask the same verification question. |
| AI architecture | Agentic + optional consensus LangGraph orchestration. Single-model analysis is the default; configure a second model and both analyse the evidence independently, with disagreements flagged for human review. Bring your own key, or none |
Vendor AI features AI assistants and questionnaire automation are marketed by these vendors; implementation details are theirs to disclose. |
Vendor AI features Analytics, predictive dashboards and AI add-ons, varying by product and plan. |
Product-dependent Varies widely by module and release — check the vendor’s current documentation. |
| Risk language | FAIR quantitative Monte Carlo simulation → annualised loss exposure in dollars, with VaR percentiles |
Registers & scoring Qualitative risk registers and scored heatmaps are the documented norm here. |
Registers & scoring Likelihood × impact registers; quantitative modules vary by product and plan. |
Configurable Highly configurable scoring; quantitative capability depends on the modules licensed. |
| Vendor risk | A2A attestation Agent-to-Agent protocol with Ed25519-signed vendor attestations, alongside ordinary questionnaires |
Questionnaires Questionnaire workflows and continuous vendor monitoring, per their docs. |
Vendor portal Portal-based questionnaire exchange, per their docs. |
TPRM module Configurable third-party risk modules, per their docs. |
| Evidence storage | WORM + lineage S3/R2 Object Lock retention in GOVERNANCE mode (365-day default), plus lineage from raw telemetry → policy verdict → final result |
Vendor-managed Stored in the vendor’s cloud; retention and immutability options vary — ask what you can export and prove. |
Vendor-managed Stored in the vendor’s cloud; retention options vary by plan. |
Deployment-dependent Depends on how your instance is deployed and configured. |
| Deployment | Self-host + air-gap Docker Compose on your own infrastructure; fully offline tier with a local vLLM model |
SaaS Delivered as a hosted service, per their public documentation. |
Mostly SaaS Primarily cloud-delivered; ask about private or single-tenant options. |
On-prem or cloud Self-managed deployment is available; typically a larger implementation effort. |
| Independent verification | You can re-verify it Auditors and regulators can recompute the hash chain, check Ed25519 signatures and validate Merkle anchors themselves |
Not publicly documented We found no public description of customer-recomputable cryptographic proofs (checked July 2026). Ask the vendor. |
Not publicly documented We found no public description of customer-recomputable cryptographic proofs (checked July 2026). Ask the vendor. |
Not publicly documented We found no public description of customer-recomputable cryptographic proofs (checked July 2026). Ask the vendor. |
| Where your data lives | Your infrastructure Your Postgres and your object storage. Stop paying and you keep the data — and a working Community install |
Vendor tenancy Hosted by the vendor; check their export, retention and termination terms. |
Vendor tenancy Hosted by the vendor; check their export, retention and termination terms. |
Varies Depends on whether you run it yourself or consume it as a service. |
| Frameworks | 20 frameworks, 2,082 controls — in every edition, including free Community. Includes the full NIST SP 800-53 Rev. 5 catalogue (1,014 controls), NIST 800-171 Rev. 2 (110), CMMC L1/L2/L3 (15/110/24), CCPA/CPRA (107), NIST CSF 2.0 (106), ISO/IEC 27001:2022 (93), TISAX (80), DORA (64), PCI DSS v4.0.1 (63), NIS2 (63), SOC 2 Type II (61), ISO/IEC 42001:2023 (38), GDPR (30), HIPAA (25), NYDFS Part 500 (25), EU AI Act (19), NIST AI RMF (19), GLBA (16). |
Framework libraries and any per-framework add-on pricing vary by vendor and plan — check their current list. | Framework libraries and any per-framework add-on pricing vary by vendor and plan — check their current list. | Typically configurable to any framework you are willing to build out. |
What each role gets
Four common frustrations with compliance tooling, and what GRCFlow does instead. The left-hand column describes patterns we see across the category, not any one named product.
CISO & VCISO — Cyber Risk in Dollars
Security Engineer — Zero Trust Ingress
Compliance Lead & Auditor — Evidence Lineage
Engineering Team — Modern Stack, Any Network
docker compose up -d.Start-to-finish audit readiness
Complete an audit without leaving the platform. Every step is automated, deterministic, and tamper-evident.
Discovery
Steampipe maps your infrastructure in real time — AWS and Azure connections today, with control-evidence queries verified against the published plugin schemas. Live SQL queries, not stale snapshots.
Deterministic Testing
OPA Rego policies provide code-is-law pass/fail evaluation. Deterministic, reproducible, version-controlled.
AI Consensus (optional)
Single-model analysis is the default. Configure a second model and both LLMs analyze the same evidence independently; the consensus engine scores their agreement and escalates disagreements to human review.
Cryptographic Seal
Verdict, evidence, policy, and user changes enter a SHA-256 hash chain with per-user Ed25519 signatures; Merkle trees anchor batches. The chain and signatures are re-verifiable in-app.
Evidence Lock
Raw evidence is written to S3/R2 under Object Lock in GOVERNANCE retention mode (365-day default), so it cannot be overwritten or deleted through normal application or operator paths — only a principal you explicitly grant bypass-retention rights can override it. Set COMPLIANCE mode on the bucket if your regulator requires unbypassable retention.
Report Generation
Export auditor-ready reports in PDF, XLSX, or HTML. Full finding details with evidence references and control mapping.
Questions buyers actually ask
Short answers, each one checkable against the repository or the pricing page.
Is the free GRCFlow Community Edition really free?
How many compliance frameworks does GRCFlow support?
Can GRCFlow run air-gapped, with no internet connection?
How is GRCFlow different from SaaS compliance automation tools?
How were the comparisons on this page sourced?
Run it yourself before you talk to anyone
Install the free Community Edition on your own infrastructure — no key, no signup, no credit card. Then check the numbers on this page against the code.