Our column is traced to public source code · Not marketing fiction

Self-hosted GRC with enterprise integrity.
Free to start.

Every claim in the GRCFlow column maps to real, shipping code in a public repository. Everything we say about anyone else is attributed to their own public documentation — and dated, so you can re-check it. Here is how a self-hosted, air-gap-capable GRC platform compares to cloud compliance automation and to legacy GRC suites.

GRCFlow compared to SaaS and legacy GRC platforms

How to read this. The GRCFlow column describes behaviour implemented in our public repository; you can read the source and the licence gates behind each tier yourself. The other three columns are generalised at the category level from how those vendors describe their own products in their public documentation, checked July 2026. They are not test results, we have not run those products, and capabilities change — treat them as a starting list of questions for the vendor, not as findings. Where a cell says “not publicly documented”, that means we did not find it described in public vendor material, not that the product cannot do it. We publish no third-party pricing. All product and company names are trademarks of their respective owners and are used here for identification only.

Feature GRCFlow
traced to public code
Compliance automation SaaS
category, e.g. Vanta, Drata
Enterprise GRC suites
category, e.g. AuditBoard, Hyperproof
Legacy GRC platforms
category, e.g. Archer, ServiceNow
Licensing model Free Community edition
Self-host free forever — 5 seats, full platform, all 20 frameworks. Professional and Enterprise are quoted on contact; no list price is published yet. See GRCFlow pricing.
Vendor quote
Commercial subscription, quoted by the vendor. We do not publish other companies’ prices — ask them.
Vendor quote
Commercial subscription, quoted by the vendor. We do not publish other companies’ prices — ask them.
Vendor quote
Commercial licence, usually with an implementation project. Pricing comes from the vendor.
Audit trail integrity Cryptographic proof
SHA-256 hash chain, per-user Ed25519 signatures, Merkle-anchored batches — re-verifiable in the app
Vendor-documented
Evidence captures and change history, as described in their docs. Ask whether you can verify it cryptographically.
Vendor-documented
Workflow and version history, as described in their docs. Ask the same verification question.
Vendor-documented
Platform and database audit logging, as described in their docs. Ask the same verification question.
AI architecture Agentic + optional consensus
LangGraph orchestration. Single-model analysis is the default; configure a second model and both analyse the evidence independently, with disagreements flagged for human review. Bring your own key, or none
Vendor AI features
AI assistants and questionnaire automation are marketed by these vendors; implementation details are theirs to disclose.
Vendor AI features
Analytics, predictive dashboards and AI add-ons, varying by product and plan.
Product-dependent
Varies widely by module and release — check the vendor’s current documentation.
Risk language FAIR quantitative
Monte Carlo simulation → annualised loss exposure in dollars, with VaR percentiles
Registers & scoring
Qualitative risk registers and scored heatmaps are the documented norm here.
Registers & scoring
Likelihood × impact registers; quantitative modules vary by product and plan.
Configurable
Highly configurable scoring; quantitative capability depends on the modules licensed.
Vendor risk A2A attestation
Agent-to-Agent protocol with Ed25519-signed vendor attestations, alongside ordinary questionnaires
Questionnaires
Questionnaire workflows and continuous vendor monitoring, per their docs.
Vendor portal
Portal-based questionnaire exchange, per their docs.
TPRM module
Configurable third-party risk modules, per their docs.
Evidence storage WORM + lineage
S3/R2 Object Lock retention in GOVERNANCE mode (365-day default), plus lineage from raw telemetry → policy verdict → final result
Vendor-managed
Stored in the vendor’s cloud; retention and immutability options vary — ask what you can export and prove.
Vendor-managed
Stored in the vendor’s cloud; retention options vary by plan.
Deployment-dependent
Depends on how your instance is deployed and configured.
Deployment Self-host + air-gap
Docker Compose on your own infrastructure; fully offline tier with a local vLLM model
SaaS
Delivered as a hosted service, per their public documentation.
Mostly SaaS
Primarily cloud-delivered; ask about private or single-tenant options.
On-prem or cloud
Self-managed deployment is available; typically a larger implementation effort.
Independent verification You can re-verify it
Auditors and regulators can recompute the hash chain, check Ed25519 signatures and validate Merkle anchors themselves
Not publicly documented
We found no public description of customer-recomputable cryptographic proofs (checked July 2026). Ask the vendor.
Not publicly documented
We found no public description of customer-recomputable cryptographic proofs (checked July 2026). Ask the vendor.
Not publicly documented
We found no public description of customer-recomputable cryptographic proofs (checked July 2026). Ask the vendor.
Where your data lives Your infrastructure
Your Postgres and your object storage. Stop paying and you keep the data — and a working Community install
Vendor tenancy
Hosted by the vendor; check their export, retention and termination terms.
Vendor tenancy
Hosted by the vendor; check their export, retention and termination terms.
Varies
Depends on whether you run it yourself or consume it as a service.
Frameworks 20 frameworks, 2,082 controls — in every edition, including free Community.
Includes the full NIST SP 800-53 Rev. 5 catalogue (1,014 controls), NIST 800-171 Rev. 2 (110), CMMC L1/L2/L3 (15/110/24), CCPA/CPRA (107), NIST CSF 2.0 (106), ISO/IEC 27001:2022 (93), TISAX (80), DORA (64), PCI DSS v4.0.1 (63), NIS2 (63), SOC 2 Type II (61), ISO/IEC 42001:2023 (38), GDPR (30), HIPAA (25), NYDFS Part 500 (25), EU AI Act (19), NIST AI RMF (19), GLBA (16).
Framework libraries and any per-framework add-on pricing vary by vendor and plan — check their current list. Framework libraries and any per-framework add-on pricing vary by vendor and plan — check their current list. Typically configurable to any framework you are willing to build out.

What each role gets

Four common frustrations with compliance tooling, and what GRCFlow does instead. The left-hand column describes patterns we see across the category, not any one named product.

CISO & VCISO — Cyber Risk in Dollars

The common pattern
Qualitative "red/yellow/green" heatmaps. They are quick to produce, but a Board cannot weigh them against a budget request.
GRCFlow
FAIR engine with Monte Carlo simulation calculates Annualized Loss Exposure in real dollars. PERT distributions, Poisson event modeling, VaR at 90/95/99 percentiles.
The win: You can put a control investment and a modelled loss reduction in the same sentence — "this spend moves our annualised loss exposure from X to Y" — with the distribution and assumptions attached. The numbers come from your own inputs; we do not ship a headline figure and neither should anyone else.

Security Engineer — Zero Trust Ingress

The common pattern
Inbound firewall rules, long-lived API keys, and shared vendor credentials that expand the attack surface.
GRCFlow
A Cloudflare Tunnel service ships in the Docker Compose file, so production ingress is outbound-only with no host port bindings. Machine-to-machine trust via the A2A protocol and service tokens.
The win: Deployed that way, your GRC platform has no inbound listener on the public internet — nothing for opportunistic scanning or credential stuffing to reach.

Compliance Lead & Auditor — Evidence Lineage

The common pattern
"Screenshot compliance" as a working practice: evidence captured by hand ahead of the audit, and stale the moment it is filed.
GRCFlow
Full evidence lineage: raw cloud telemetry → OPA policy evaluation → AI analysis → final verdict. Every step hashed and verifiable.
The win: An auditor traces any "Pass" verdict back to the raw data, the exact Rego rule that evaluated it, and — when a second model is configured — the dual-AI reasoning that confirmed it, all sealed in a tamper-evident hash chain.

Engineering Team — Modern Stack, Any Network

The common pattern
A closed hosted backend you cannot read, extend, or stand up inside a network that has no egress.
GRCFlow
Async FastAPI + SQLAlchemy 2.0 + PostgreSQL + LangGraph. True air-gap mode with vLLM on local GPU. Docker Compose deployment in minutes.
The win: Serve defense and government clients where data never leaves the building. Deploy the full platform with docker compose up -d.

Start-to-finish audit readiness

Complete an audit without leaving the platform. Every step is automated, deterministic, and tamper-evident.

1

Discovery

Steampipe maps your infrastructure in real time — AWS and Azure connections today, with control-evidence queries verified against the published plugin schemas. Live SQL queries, not stale snapshots.

2

Deterministic Testing

OPA Rego policies provide code-is-law pass/fail evaluation. Deterministic, reproducible, version-controlled.

3

AI Consensus (optional)

Single-model analysis is the default. Configure a second model and both LLMs analyze the same evidence independently; the consensus engine scores their agreement and escalates disagreements to human review.

4

Cryptographic Seal

Verdict, evidence, policy, and user changes enter a SHA-256 hash chain with per-user Ed25519 signatures; Merkle trees anchor batches. The chain and signatures are re-verifiable in-app.

5

Evidence Lock

Raw evidence is written to S3/R2 under Object Lock in GOVERNANCE retention mode (365-day default), so it cannot be overwritten or deleted through normal application or operator paths — only a principal you explicitly grant bypass-retention rights can override it. Set COMPLIANCE mode on the bucket if your regulator requires unbypassable retention.

6

Report Generation

Export auditor-ready reports in PDF, XLSX, or HTML. Full finding details with evidence references and control mapping.

Questions buyers actually ask

Short answers, each one checkable against the repository or the pricing page.

Is the free GRCFlow Community Edition really free?

Yes. The Community Edition costs nothing, needs no licence key and no signup, and has no expiry cliff: it runs on a rolling 90-day licence that refreshes automatically every time the backend restarts. It is the same code as the paid tiers — the limits are 5 seats and the licence mechanics, not features or frameworks.

How many compliance frameworks does GRCFlow support?

20 frameworks and 2,082 controls, served live from the /api/v1/frameworks endpoint, including the full NIST SP 800-53 Rev. 5 catalogue at 1,014 controls. Every framework is in every edition, including free Community — there are no per-framework paywall flags in the code.

Can GRCFlow run air-gapped, with no internet connection?

Yes. Licence validation is an offline Ed25519 signature check against a local public key, so the product never phones home. AI features can point at a local vLLM or Ollama endpoint instead of a hosted model, and cloud evidence connectors are deliberately disabled on air-gap licences.

How is GRCFlow different from SaaS compliance automation tools?

GRCFlow runs on your infrastructure, so your evidence, risk register and audit trail stay in your own Postgres and object storage. The audit trail is a SHA-256 hash chain with per-user Ed25519 signatures and Merkle-anchored batches that you can re-verify yourself. Stop paying and you keep both your data and a working Community install.

How were the comparisons on this page sourced?

Everything in the GRCFlow column is implemented in the public repository and can be read in the source. Everything in the other columns describes how those categories of product are presented in the vendors' own public documentation as of July 2026, is generalised at the category level, and should be re-checked with the vendor before you rely on it.

Run it yourself before you talk to anyone

Install the free Community Edition on your own infrastructure — no key, no signup, no credit card. Then check the numbers on this page against the code.