RunCompliance

The platform

A GRC engine built for precision

The Compliance Control Mesh and grounded reasoning turn 130+ regulations into answers you can defend — mapped, normalized, and scoped to your obligations.

Grounded retrieval

Every answer cited to verbatim text

RunCompliance retrieves the exact provision behind every answer and grounds the response in its verbatim wording — down to the article and paragraph. No paraphrasing layer that can silently drift. When a regulator or client asks 'where does it say that?', you click through to the source.

  • Per-provision indexing — paragraph-level granularity
  • Source text returned alongside every answer
  • Reduced hallucination risk by construction

Cross-framework mapping

Reason across standards, not one PDF at a time

A knowledge graph links articles, requirements and controls across frameworks — with NIST SP 800-53 as the canonical control spine. Ask how a DORA obligation maps to NIST controls, where ISO 27001 overlaps CSA CCM, how ISO 27701 extends your GDPR privacy controls, or which CIS safeguards satisfy a GDPR requirement — and get a traceable path, not a guess.

  • Requirement → control mappings across frameworks
  • NIST 800-53 as the common mapping spine
  • Graph-backed paths you can audit
  • Baseline-aware (NIST LOW / MOD / HIGH + Privacy)

Compliance Control Mesh

Implement once, prove everywhere

Every supported standard maps into one normalized control model — the Compliance Control Mesh. Instead of maintaining ISO, NIST, DORA and CSA control sets as separate silos, you work against a single mesh built on the NIST 800-53 spine — so one implemented control demonstrably satisfies the equivalent requirement in every framework that references it. Onboarding a standard means mapping it in, not rebuilding your library.

  • One normalized control set, many frameworks
  • A control satisfies ISO + NIST + DORA + CSA at once
  • NIST 800-53 as the canonical reference catalogue
  • Eliminate duplicate effort across overlapping standards

Gap analysis

See exactly what's missing for your scope

Point the engine at a framework and a profile, and it surfaces where your coverage is thin. Baseline-aware against NIST 800-53 (LOW / MOD / HIGH and the Privacy overlay) and service-model aware (IaaS / PaaS / SaaS), so the gaps reflect your actual obligations — not a generic checklist.

  • Scope-specific, not one-size-fits-all
  • NIST 800-53 baseline-aware (LOW / MOD / HIGH / Privacy)
  • Exportable gap reports and Statements of Applicability
  • Evidence your auditors can trust

Audit & assurance

Verify against the Compliance Control Mesh

Controls, implementation guidance and applicability live in the same Compliance Control Mesh — one normalized model behind every standard. Onboarding a new standard is a data load, not a schema rewrite, so coverage grows without re-engineering the platform.

  • Controls + guidance + applicability in one mesh
  • Add a standard with data, not code
  • Consistent querying across every framework

Coverage

Frameworks indexed verbatim

ISO 27001 ISO 27701 ISO 27002 NIST SP 800-53 NIST CSF 2.0 CIS Controls v8.1 DORA NIS2 GDPR HIPAA CSA CCM v4.1 EU AI Act EU CRA EU CER EU Data Act SOC 2 PCI DSS v4 HITRUST CSF r2 EU GMP Annex 11

Request early access

We're onboarding a small group of GRC consultants and compliance teams.

Request access