GRCFlowThe AI-native GRC Platform

  • Self-hosted
  • A2A attestation
  • Air-gap ready
  • No telemetry
Frameworks
20
Controls shipped
2,082
NIST 800-53 Rev. 5
1,014
The GRCFlow framework catalog: SOC 2 Type II, ISO/IEC 27001:2022, CMMC Levels 1 to 3 and NIST SP 800-171 Rev. 2 shown as cards, each with its control count and a link into its controls.

All 20 frameworks

  • SOC 2 Type II
  • ISO/IEC 27001:2022
  • CMMC Level 1
  • CMMC Level 2
  • CMMC Level 3
  • NIST SP 800-53 Rev. 5
  • NIST SP 800-171 Rev. 2
  • NIST CSF 2.0
  • PCI DSS v4.0.1
  • HIPAA Security Rule
  • GDPR
  • CCPA/CPRA
  • DORA
  • NIS2 Directive
  • TISAX (VDA ISA)
  • NYDFS Part 500
  • GLBA Safeguards (FTC)
  • ISO/IEC 42001:2023
  • NIST AI RMF 1.0
  • EU AI Act

Control counts for all 20

The GRCFlow Vendor Portal, subtitled third-party risk management and A2A attestation monitoring: tiles for total vendors, critical tier, high risk and A2A connected, above a vendor table with tier, risk rating, A2A status and next assessment.
A2A Attestation

Prove your posture to partners, live and signed

A parent company, prime or bank queries your instance and gets back a signed attestation they can re-check any day. No shared cloud tenant.

How continuous attestation works

Get Flowing

  • 30 days
  • 5 seats
  • 1 organization
  • All 20 frameworks

Schedule Demo