grComply · Governance, Risk & Compliance

One Platform. Every Framework.

grComply is a multi-framework compliance and risk platform built for teams who are tired of running SOC 2, ISO 27001, and NIST as three separate projects. Controls are mapped once across frameworks, so a single piece of evidence can satisfy several requirements at the same time. Continuous scanning keeps controls checked automatically, an AI assistant suggests evidence and drafts control narratives for a human to approve, and every action is written to an immutable audit trail.

Control: Encryption at Rest

1 Control

Satisfies, at once:

SOC 2 — CC6.1

ISO 27001 — A.8.24

NIST CSF — PR.DS-1

CIS Controls — 3.11

Nexus Corp · grComply

Built-In Framework Packs

Start from a seeded framework, or author your own — everything below ships ready to configure.

SOC 2ISO 27001NIST CSFCIS ControlsCustom In-House Frameworks

Four Capabilities That Do the Heavy Lifting

Cross-Framework Mapping

Map a control once, and it counts toward every framework it satisfies — no duplicate evidence requests.

Continuous Scanning

Automated scans check controls on a schedule, with findings auto-mapped to the controls they affect.

AI-Assisted Evidence

AI suggests evidence and drafts control narratives — a person always reviews and approves before anything counts as complete.

Immutable Audit Trail

Every record change is logged, searchable, and exportable — built for when an auditor asks "prove it."

Built for Every Role in the Room

Platform Admin

Provisions tenants, assigns frameworks, and manages the shared control and mapping libraries.

Tenant Admin

Onboards the organisation, invites users, chooses deployment model, and owns tenant-wide settings.

Compliance Officer

Runs day-to-day compliance — evidence, findings, risk register, and control satisfaction across frameworks.

Auditor & Peer Reviewer

Engagement-scoped access to review evidence and controls without full tenant visibility.

Executive

Read-only oversight with the ability to formally accept residual risk.

Every Feature, In Plain English

  • Built-in framework packs — SOC 2, ISO 27001, NIST CSF, CIS, and custom in-house frameworks
  • Cross-framework control mapping, so one control and one piece of evidence can satisfy multiple frameworks at once
  • Continuous compliance scanning with findings auto-mapped to the controls they affect
  • AI-assisted evidence suggestions and control narrative drafts — always reviewed and approved by a person, never auto-approved by the AI
  • Risk register with treatment tracking, overdue alerts, and full export
  • Policy drafting straight from framework clauses, with version control
  • Immutable audit trail across every record, with search, filters, and export
  • Role-based access for Platform Admin, Tenant Admin, Compliance Officer, Auditor, and Executive users, with strict tenant data isolation

Best For

Compliance and security teams pursuing SOC 2, ISO 27001, or NIST CSF certification, especially those juggling more than one framework at once, plus auditors and reviewers who need a scoped, evidence-backed view of an engagement.

Pair grComply with our Cloud Security & GRC service if you also need the engineering hardening and compliance programme built out, not just tracked.

FAQ

grComply FAQ

Still have a question? Contact us

Can grComply handle more than one compliance framework at once?+

Yes — that is the core of the product. Controls are mapped once across frameworks, so a control that satisfies SOC 2 can also satisfy ISO 27001 or NIST CSF where the requirements overlap, without duplicating evidence collection.

Does the AI ever mark something as compliant on its own?+

No. The AI can suggest evidence and draft control narratives, but a human always reviews and approves before anything is marked complete. This is a deliberate, non-negotiable design decision, not a limitation we plan to remove.

How does continuous scanning work?+

A scan agent checks your environment against the controls in scope on a recurring schedule. Findings are automatically mapped to the control they relate to, so compliance officers triage findings against controls, not raw scan output.

Is grComply multi-tenant, and how is data isolated?+

Yes, grComply is built multi-tenant with strict data isolation enforced at the data layer — each tenant's frameworks, evidence, and records are logically separated from every other tenant.

Can we deploy on-premises instead of using the hosted SaaS?+

Yes. grComply supports both hosted SaaS and on-premises deployment for clients with specific data-residency or regulatory requirements, with a consistent experience across both.

Who can see what — is there role-based access?+

Yes. Platform Admin, Tenant Admin, Compliance Officer, Auditor, Peer Reviewer, and Executive each have distinct, scoped access — auditors and reviewers, for example, only see the engagement they are assigned to, not the whole tenant.

Does grComply connect to our existing security tools?+

grComply is built to ingest external and internal scan findings and map them to controls automatically. Specific integrations are scoped per engagement — ask us on a call about your current stack.

How does grComply relate to Nexus's Cloud Security & GRC service?+

They complement each other. Our Cloud Security & GRC service delivers the engineering hardening and compliance programme; grComply is the platform that then tracks evidence, controls, and audit-readiness on an ongoing basis. Many clients use both together.

Can I sign in to grComply right now?+

Yes. grComply is a live, hosted product — use the "Sign In to grComply" link on this page, or book a call first if you would like a walkthrough.

»

Stop Running Every Framework as a Separate Project.

Book a 30-minute walkthrough with our team, or sign in now if you're already a grComply customer.