The agents

Fewer agents.
Every one honest.

Five AI agents that read your actual security reality, tier every claim by what was truly observed, and hand the decision to you. None of them writes your evidence. None of them approves anything on its own.

Why the list is short.

You’re doing the job of a whole GRC team. The market’s answer has been to announce dozens of agents that “automate your compliance” — including quietly generating your evidence. That’s the failure mode the category just got burned for: AI that declares without ever observing.

GRC Solo ships five, and every one respects the same hard line: observe reality, tier the claim by its source, route the consequence to a human. An agent here multiplies your output — it never replaces your judgment, and never pretends to see what it hasn’t.

The line every agent holds

The GRC expert, amplified — you stay in the loop, the agents do the reading.

Observes, never assertseach claim is tiered by whether a connector actually saw it.
Never writes your evidenceit chases and flags; you and your systems produce the proof.
Never auto-approvesa named person makes every consequential decision, and it freezes in an append-only ledger.
Your data stays yoursit all runs on your own infrastructure; your operational security data never leaves your walls.

How the loop runs solo

Five agents, one per turn of the loop.

These aren’t a feature checklist. Each agent runs a stage of the loop — Declare → Observe → Reconcile → Decide, then declare outward — so the whole thing stays in sync while one person runs it. The stage tag on each card is where it sits on the spine.

DeclarePolicy Agent
Keeps your written policy true to what the company actually does.

Drafts policies from what your company actually does, explains what changed and why in plain language, and reconciles each requirement against its observed state — so the prose stops drifting out of sync with reality.

The boundaryIt proposes the prose and a one-screen decision brief; a named person approves, and that approval freezes in the ledger. Editing an approved policy voids its approval.
ObserveEvidence & Freshness Agent
Tells you what to re-verify — it chases evidence, it never writes it.

Tracks which evidence is stale, missing, or contradicted by what’s observed, and hands you a prioritized re-verify list.

The boundaryThis is the line the category is getting wrong: it chases evidence — requests it, flags it — and never generates it.
ReconcileReconciliation Agent
Checks what you declared against what your systems actually do.

Continuously compares what your program claims against what your systems are observed doing, tiers every claim by whether a connector saw it, and surfaces the divergences as a work queue — not a green dashboard. It’s the whole idea in one agent.

The boundaryIt observes and flags. It never fabricates the observation or closes the gap for you.
DecideThreat-Exposure Agent
Reprioritizes when a passing control is under active exploitation.

Folds live advisories and known-exploited vulnerabilities into your control priorities, so a control that’s declared-passing but under active exploitation jumps to the top with a “prove it again” flag.

The boundaryIt prioritizes and briefs. It doesn’t take remediation action for you.
Declare — outwardQuestionnaire & Trust Agent
Drafts questionnaire answers from your real posture, and flags any that overclaim.

Drafts answers to security questionnaires from your observed posture, and flags any answer that would overclaim versus reality before it goes out.

The boundaryIt drafts grounded answers and overclaim warnings; a human sends. It never asserts an unobserved control as “in place.”

Under the hood

Each agent is powered by AI surfaces already running in production — every one with its own evaluation suite, model governance, caching, and telemetry. No new black box, no autonomy you didn’t ask for: a named, scoped capability you point at a job, that ends at your decision.

See the agents work against a live synthetic environment.

Walk the loop on a synthetic sample company — no signup — and watch each agent observe, tier, and hand you the decision. Then read our own live posture before you spend a minute on a call.

See it work — no signupSee our live posture →
Agents — fewer agents, every one honest