Skip to content

THE PLATFORM

Your compliance program, pre-structured and ready to run.

domainGRC replaces the “spreadsheets and shared drives” approach with a connected compliance system, loaded with your framework controls, your compliance calendar, and the expert practitioner-built policies your auditor expects to see.

ISMSmgr task list view, showing recurring activities with status variety

How the platform is organized.

domainGRC is organized around three areas that mirror how a real compliance program operates: managing your ongoing compliance activities, tracking the assets your program covers, and running your audit when the time comes. Everything connects.

mydomain: Run your compliance program

The operational core of your compliance program. This is where your recurring activities live, your IT service desk runs, your risks are tracked, and your corrective and preventive actions are managed.

  • Pre-loaded with public framework controls
  • Compliance calendar on day one to help you hit the ground running
  • Evidence flows to every control it supports - no repeat uploads

myDomain Modules: controlMGR, ISMSmgr, policyMGR, riskMGR, CAPmgr, TPRM, serviceMGR, changeMGR, incidentMGR, InternalAuditor

assetmgr: Know what you’re protecting

A structured inventory of everything in scope - users, software, services, and IT and information assets.

  • Link any asset to the controls and risks that govern it
  • Understand related assets that shape the risk profile
  • Audit trails of employee lifecycle events, access, or equipment requests preserved

assetMGR: Users, Software, Services, IT, Information

myAudit: Where you and your assessor work together.

Upload your assessor’s Information Request List to domainGRC and invite them directly into your domain with scoped, time-limited access.

  • Assessors review and approve evidence or request additional info live
  • Artifact owners notified automatically when items need rework
  • Track audit status through theDash in real-time

myAudit Modules: controlMGR, IRLmgr, artifactMGR

Interconnected web

Every record can be linked to every other - people, software, hardware, information, and facilities are stored as an interconnected web.

  • Understands the ripple effects when anything changes

AI compliance assistant (private beta)

A conversational AI assistant is built into domainGRC to help you get answers faster. Ask questions about your program, generate compliance documents like a Business Impact Analysis, or explore how risks and controls connect across your environment - all in a natural language.

  • In private beta now, with a broader rollout planned for H2 2026

Audit trail with field-level change history

Every change to every control, asset, and artifact record is timestamped and attributed to a specific user.

  • Always know who changed what, and when it happened

Evidence library with versioning

Centralized evidence and controls that travel across audit periods as things change.

  • Historical context from your last audit is archived but remains available for reference

Assessor collaboration in-platform

Give assessors scoped, time-limited access to review evidence live and work through your Information Request List directly in the platform.

  • Assessors flag items needing rework, notifying artifact owners automatically

Multi-framework support, no upcharge

All your frameworks in one place. The platform grows with you as you need new frameworks or expand scope.

  • No upcharges for adding additional frameworks

This year's work becomes next year's blueprint.

Most compliance programs reset with every audit. You pull together, survive it, celebrate - and then everyone goes back to their day jobs. By the time the next cycle rolls around, the evidence is scattered, the institutional knowledge has walked out the door, and you're rebuilding spreadsheets from scratch. Again.

domainGRC replaces that pattern with a structured rollover. After each audit, the platform retains:

  • Tested controls and collected evidence
  • Cited policies and assessed risks
  • Owners who closed each task

Next year’s cycle starts from last year’s blueprint. Recurring controls roll over with one click. Anything that changed since the last cycle (new assets, new vendors, new policies, departed owners, expanded scope) is flagged for review. Each cycle becomes more efficient than the last, because you are refreshing a working record instead of rebuilding a spreadsheet.

DOMAIN-34 Activity Log with field-level diff

AI-NATIVE COMPLIANCE PLATFORM

Built for AI from the data up.

Most GRC tools are collections of lists and documents pretending to be data. domainGRC is structured for AI from the data layer:

  • Graph data model linking every asset, risk, control, and piece of evidence
  • Vector-based knowledge store of compliance content refined over two decades
  • Model Context Protocol integrations for AI reasoning across structured data records

Use our conversational AI assistant to query any of your program data, the framework controls, our PSP Best Practices Knowledgebase, and even synthesize new artifacts. In private beta now, with a broader rollout planned for H2 2026.

AI assistant populated answer illustrating practitioner-side capability

Policies built by expert compliance practitioners. Not generated by AI.

Every domainGRC implementation includes access to the PSP Best Practices Library, a curated collection of Policies, Standards, and Procedures refined over two decades of real compliance programs. Each document is carefully constructed to meet the requirements of even the most stringent frameworks, including HITRUST and ISO 27001, so that your organization will be perfectly poised to expand into additional frameworks as you grow.

These are starting points, not generic templates. Every policy needs to reflect how your organization actually operates, but this well-crafted language can help you draft fresh policies with confidence or compare your existing policies to find potential coverage gaps before an auditor finds them. Our practitioners are here to help you adapt your policy library so it can meet the control requirements for your audit and become a standard your company can actually hold itself to in the real world.

theDash

Your compliance program at a glance. Audit status, upcoming activities, overdue tasks, risk distribution, and CAP progress, all in one configurable dashboard.

controlMGR

Every framework control, structured and ready to work. SOC 2 TSC criteria, ISO 27001 Annex A controls, HIPAA safeguards, all imported at onboarding.

ISMSmgr

Your compliance calendar, built in. Recurring activities pre-loaded for a standard SOC 2 program: vulnerability scanning, pen testing, policy review, and more.

riskMGR

A structured risk register to log every known threat from your risk assessment, assign a risk rating, link to corrective actions, and track remediation.

CAPmgr

Corrective and Preventive Actions. Every gap, finding, and remediation task in one place. Link CAPs to risks, controls, and assets.

policyMGR

Policy lifecycle paired with the PSP Best Practices Library. Reference the latest version of every policy, standard, and procedure your program needs.

assetMGR

Your complete compliance inventory. Users, software, services, IT assets, information assets, and attachments, all in one place.

TPRM

Third-party risk assessment, built in. Assess your vendors, document their risk profile, link them to the software assets they touch.

IRLmgr

Audit season, organized. Load your auditor’s Information Request List, assign evidence, and track status through to acceptance.

artifactMGR

All your evidence. One place. Fully linked. Centralized artifact storage with version history and cross-framework reuse.

Reports

Build the report you need in seconds. Filter, sort, group, and configure any view across any module. Save and export.

Also available

serviceMGR (compliance service desk), changeMGR (lightweight change management), incidentMGR (security incident tracking), and InternalAuditor (pre-audit internal review). For early-stage companies that haven’t bought a separate service desk or SDLC tool yet, domainGRC can be both. Bonus: when you process onboarding, offboarding, or access tickets through serviceMGR, the audit evidence captures itself in the normal course of work.

Every framework your program requires. No per-framework fees.

domainGRC ships with framework controls for the certifications your business needs. Public frameworks like SOC 2 and NIST are ready on day one. For frameworks with proprietary specs (HITRUST, the ISO suite, and others), bring your purchased license and we load the controls in for you. Add additional frameworks and we map the overlapping controls automatically, so you’re not building from scratch. Capture evidence once and reuse it across multiple controls and frameworks.

SOC 2 ISO 27001 ISO 42001 HIPAA HITRUST NIST CSF PCI DSS GDPR

Beyond the named frameworks, the platform is designed to be extensible. We’ve supported customers running ISO 9001, 14001, and 45001, NIST SP, NAID AAA, e-Stewards, R2v3, and RiOS programs, alongside the headline security frameworks. If your auditor accepts a framework, domainGRC can support it.

Risk management, corrective actions, third-party risk management, and internal audit capabilities are included in every plan. We don’t gatekeep the features you actually need to pass a real audit. And we don’t believe in nickel-and-diming you for streamlining your compliance program.

Want to see domainGRC in your environment?