DDefendFlow Security
GRCFlow One-Pager

Self-hosted GRC for teams that cannot put compliance evidence in generic SaaS.

GRCFlow is DefendFlow's governance, risk and compliance platform: a commercial, trial-then-buy product that runs on customer infrastructure, supports air-gapped deployment, and gives auditors verifiable evidence instead of static assertions.

Start a conversation sales@defendflow.xyz
support@defendflow.xyz
grc.defendflow.xyz
Documentation
20
Compliance frameworks
2,082
Included controls
1,014
NIST 800-53 Rev. 5 controls
30 days
Full-platform trial

What It Does

GRCFlow centralizes compliance programs, evidence, control assessments, findings, risk, policy attestations, reporting, and auditor review in a self-hosted system.

It is built for organizations that need SOC 2, ISO 27001, CMMC, NIST, HIPAA, PCI DSS, DORA, NIS2, AI governance, or privacy programs without exporting sensitive compliance data into a multi-tenant vendor tenant.

Product Capabilities

  • Cross-framework control reuse: map overlapping requirements so prior work carries forward across audits and regulations.
  • Continuous controls monitoring: scheduled control checks, drift detection, evidence requests, findings, and remediation workflows.
  • Verifiable audit trail: SHA-256 hash chaining for control verdicts, with Ed25519 signatures when a person records or approves entries.
  • Risk and reporting: risk register, Open FAIR quantification, POA&M-style remediation, board packs, SSP, gap analysis, SoA, and audit reports.
  • Machine-readable assurance: Agent-to-Agent attestations can answer signed compliance posture requests for SOC 2, ISO 27001, PCI DSS, HIPAA, and CMMC Level 2.

Framework Coverage

Every license includes the full platform and all frameworks. No per-framework upsell.

SOC 2ISO 27001CMMC L1/L2/L3NIST 800-53NIST 800-171NIST CSF 2.0HIPAAGDPRPCI DSSDORANIS2CCPA/CPRANYDFS 500GLBATISAXISO 42001NIST AI RMFEU AI Act

Deployment and Data Posture

  • Self-hosted: Docker Compose stack with PostgreSQL, Redis, backend, frontend, and optional MinIO object storage.
  • Air-gap capable: zero outbound network access, local evidence storage, offline license validation, and local vLLM or Ollama AI inference.
  • No telemetry: no product analytics or usage reporting code; licenses verify locally with Ed25519 signatures.
  • Customer-controlled integrations: outbound traffic only comes from configured LLM endpoints, cloud evidence sources, ticketing, SIEM/webhooks, or an explicit trial-key request.

Commercial Model

  • Free trial: 30 days, 5 seats, 1 organization, no credit card, full platform, all 20 frameworks.
  • Paid licenses: annual, prepaid, quoted by named-user seats, and invoiced on request.
  • Seat ceiling: plans differ by signed seat count, not by feature bundle. New invites or users are blocked after the licensed seat ceiling.
  • Air-gap: available as a deployment option, quoted and invoiced for environments that require isolated operation.

Best-Fit Buyers

  • Defense contractors and CMMC/NIST-driven suppliers.
  • Regulated financial, healthcare, critical infrastructure, and AI-governance programs.
  • MSPs, private equity or venture portfolios, and enterprises that need repeatable compliance assurance across many entities.
  • Security teams that need a bounded pilot before connecting evidence sources, LLM providers, object storage, ticketing, and auditor workflows.