Real GRC, sized for one
You’re doing a whole GRC team’s job.
Alone.
Today’s GRC makes you choose: hire a team, hand your data to someone else’s cloud, or trust AI that never looked. GRC Solo is none of those — real GRC one person runs, on your own infrastructure, that shows you its own posture first.

Why us
Every GRC vendor asks for your trust.
We show you ours.
Our trust site is real, not a marketing page.
Most GRC vendors publish a polished trust badge. We publish what a connector actually observed about our own security — tiered by whether it’s observed or merely declared, the same way the product tiers yours. A GRC tool that won’t show its own posture is asking you to do what it won’t.
OBSERVED, not asserted — applied to us. → /trust
One operator, many AI agents — in the open.
GRC Solo is built and run AI-native: the human makes the judgment calls, the agents do the reading, the ledger remembers. We don’t hide that — it’s the point. The next wave of companies will be solo operators with dozens of AI agents, and GRC Solo is the assurance layer built that way, and for that world.
The operating model is the proof of the thesis.
Evaluate on your terms
Built for how you actually buy now.
You don’t buy from a booth anymore. You research, you verify, you shortlist — then you talk. GRC Solo is built for that: see it work on a synthetic company with no signup, interrogate our grounded assistant (it cites its source or refuses), and read our live posture before you spend a minute on a call. The evaluation is self-serve because the product is.
The difference
Store what you declare, or observe vs. declare.
The product
It’s a loop, not a dashboard.
Every other GRC tool is a place to store what you declare. GRC Solo is the loop that keeps your declarations true: you declare your program in prose, it observes your real environment, reconciles the two, and routes each gap to a decision that’s remembered — then re-baselines and runs it again.
The real thing — not mockups
Then it re-baselines: the decision updates your declared program, and the loop turns again — continuously, solo-runnable, on your own infrastructure. Not an annual scramble; a system that stays in sync.
The screens above are the real product on the synthetic NovaHR demo tenant — every figure is live-computed from observed state, never fabricated.
The moat — federated by default
Run it on your own infrastructure —
your security data never leaves your walls.
Every other GRC tool routes your security data through their cloud. GRC Solo runs as one isolated install per company — never a shared-cloud partition. Federate it on your own infrastructure and it observes your reality without your data ever leaving your walls — nothing on our side to breach or subpoena. (Prefer hosted? Still your own isolated install, never a shared tenancy.) Real data sovereignty, by design.
The outcome: the busywork gets handled, and you run an effective, always-current risk-reduction program — solo, without a team and without surrendering your data.
Fix what matters most
You can’t fix everything alone.
Fix what costs you the most.
Every other tool hands you a wall of red. GRC Solo puts a dollar figure on each gap — your real loss exposure, computed from what a connector actually observed — and ranks them. So the one person doing the whole job knows the three moves that most reduce the number, and does those first. Risk you can defend to a board; a queue you can actually clear.
Quantify — not colour-code
What is your risk worth in dollars?
Estimate your annual loss exposure — then see how GRC Solo computes it from your real posture and ranks the few gaps to fix first.
Pricing
Priced against a hire, not a department.
The real alternative to serious GRC is a platform subscription plus a dedicated hire. GRC Solo is priced against that combined cost — one operator’s output, multiplied, at a fraction of the loaded spend, with your data on your side.
Free
$0
Not a timed trial
- Learn a real program — the basics
- Community support
- "Runs on GRC Solo" badge
Learners · getting started · evaluating
See Free details →Most chosenPro
$250/mo
or $2,500/yr
Save $500/yr · ~2 months free
- One install
- Full reconciliation engine
- Own your control library
- Best-effort support
Solo operators · fractional CISOs · Series A
See Pro details →Business
$850/mo
or $8,500/yr
Save $1,700/yr · ~2 months free
- Up to 5 installs
- Multi-framework
- White-label trust portal (roadmap)
- Everything in Pro
Fractional CISOs running multiple clients
See Business details →Enterprise
Custom
from ~$30k/yr
- White-glove onboarding
- Named support SLA
- Contractual responsibility matrix
- Sales-led · custom terms
Larger entities · multi-install · custom terms
See Enterprise details →Private preview — pricing indicative. Public access opening soon.
Questions
Straight answers.
Where does my data live?
On your side. GRC Solo runs as one install per company — hosted, or federated on your own infrastructure. Your operational security data never gets routed through our cloud. Data sovereignty is the default.
Which region is my data in, and which regions do you serve?
Your operational data never leaves your infrastructure — residency is your choice. The only thing we store is the email you submit, held in US-East (Ohio). We serve US businesses today; EU, APAC and other regions are on the roadmap, and the federated model makes them a clean fit when we open there.
How do I get my data out if I leave?
You own your install and the control library you build — export is yours at any time, and nothing is trapped in our schema. If we vanished, your program keeps running on your own infrastructure.
Is this “policy-as-code”?
No. Turning your policies into code throws away the prose a human and an auditor actually read. We keep the written policy as the anchor and reconcile each requirement against its real, observed state. The document stays — it just stops drifting out of sync with reality.
Do you use autonomous agents to write my evidence?
No — deliberately. An agent that generates your evidence is an agent that can fabricate it. We observe your environment, tier every claim by whether a connector actually saw it, and route any consequential judgment to you. The AI does the reading; a human does the vetting; the ledger does the remembering.
Does my data train your AI?
No. The assistant runs on Anthropic’s API, whose default is not to train on inputs. In the product the AI reads your environment on your side and routes consequential judgments to you — it never generates your evidence, because an agent that writes your evidence is one that can fabricate it.
How is this different from a generic GRC platform?
Three structural things: it’s federated (your data stays yours), you own your control library forever (no lock-in to someone else’s schema), and every AI read ends at a tracked, provenance-stamped decision — not just another dashboard tile.
What exactly is an “install” — is pricing per company or per client?
An install is one isolated deployment for one company. Pro is a single install; Business is up to five installs (built for fractional CISOs running multiple clients); Enterprise is multi-install with custom terms. Pricing is per install, not per user.
Do you have SOC 2, a DPA, and a subprocessor list?
SOC 2 Type II and ISO 27001 alignment are on our roadmap — and we say so plainly rather than imply a badge we don’t hold yet. A DPA is available on request (/dpa), our subprocessors are published (/subprocessors), and our vulnerability-disclosure policy is live (/security).
Does this make me audit-ready, or replace my auditor?
Neither, and we won’t pretend otherwise. GRC Solo reconciles each requirement against its real, observed state and gives you a mapping you can explain to an auditor. You walk in knowing the gaps; your auditor still audits.
What frameworks does it cover?
An ISO 27001:2022 spine, plus the ability to import the frameworks you need into your own control library (SOC 2, NIST CSF, CIS, and more) with a mapping you can explain to your auditor.
What does onboarding look like?
Install, connect your first source, and the system starts reconciling. A guided first-run checklist walks you to first value; Enterprise gets white-glove onboarding.
Don’t take our word for it — that’s the whole idea.
Private preview. Walk through the product on a synthetic sample company, then look at our own live posture — real GRC, sized for one, running where your data already lives.