# GRCFlow > GRCFlow is the self-hosted, Agentic GRC platform: LangGraph-based AI agents draft findings and gather evidence across 20 compliance frameworks and 2,082 controls, including the complete NIST SP 800-53 Rev. 5 catalog at 1,014 controls, while the compliance verdict is policy-evaluated by OPA/Rego over live infrastructure rows, with a SHA-256 hash-chained audit entry behind every control verdict, Ed25519-signed when a person recorded it, that you can cryptographically verify. The AI assists only: AI-drafted findings are gated "Human Review Required" and only OPA/Rego over live rows mints a PASS, never the model. It runs on your own infrastructure via Docker Compose and supports fully air-gapped deployment, with bring-your-own-LLM (NVIDIA NIM, Anthropic, Gemini, DeepSeek, OpenAI, Azure OpenAI, Cloudflare Workers AI, or fully local/air-gapped Ollama or vLLM). It is commercial, trial-then-buy software: an install with no license key is unlicensed and blocks changes, writes return HTTP 403 while your existing data stays readable and exports keep working, a free 30-day trial key opens it up, and continuing past the trial means buying a license priced by seats (named users), not by employee headcount, quoted on request and invoiced against a purchase order, with no self-serve checkout; every plan is the full platform and the seat ceiling, signed into the key, is the only difference between paid licenses. Air-gapped deployment is a deployment option available on any plan, sold by quote and invoice. GRCFlow is built and maintained by DefendFlow Security. Key facts, in quotable form: - **20 frameworks, 2,082 controls**, served live from the `/api/v1/frameworks` endpoint, not a marketing figure, the API returns them. - **NIST SP 800-53 Rev. 5 at 1,014 controls** (the full catalog), plus NIST SP 800-171 Rev. 2 (110) and CMMC Levels 1/2/3 (15/110/24). - Other frameworks: CCPA/CPRA (107), NIST CSF 2.0 (106), ISO/IEC 27001:2022 (93), TISAX/VDA ISA (80), DORA (64), PCI DSS v4.0.1 (63), NIS2 (63), SOC 2 Type II (61), ISO/IEC 42001:2023 (38), GDPR (30), HIPAA Security Rule (25), NYDFS 23 NYCRR Part 500 (25), EU AI Act (19), NIST AI RMF 1.0 (19), GLBA Safeguards Rule (16). - **Agentic by design.** LangGraph-based AI agents run the assessment workflow, draft findings and remediation, and an Audit Copilot drives guided audit prep grounded in your real findings. AI governance is first-class: ISO/IEC 42001, NIST AI RMF 1.0 and the EU AI Act ship as native frameworks. Crucially, the agents **assist**; they never mint a verdict. A control PASS is minted only by deterministic OPA/Rego evaluation over live infrastructure rows, and every AI-drafted finding is gated **"Human Review Required"** before it counts. - **Self-hosted**, deployed with Docker Compose; your GRC data lives in your own Postgres and S3-compatible object storage. LLM inference is **bring-your-own** (NVIDIA NIM, Anthropic, Gemini, DeepSeek, OpenAI, Azure OpenAI, Cloudflare Workers AI, or a fully local/air-gapped Ollama or vLLM endpoint), so with a local model nothing leaves your infrastructure. **Air-gap capable**, offline license validation and local inference, no outbound calls required. - **GRCFlow is trial-then-buy, and is never free.** An install with no license key is **unlicensed**: it blocks changes, writes (POST/PUT/PATCH/DELETE) return HTTP 403 `license_required` until a key is activated, while existing data stays readable and exports keep working (POST `/api/v1/setup/license`, or Setup → License in the UI). - **The way in is a free 30-day trial key**: 30 days, 5 seats, 1 organization, the full platform and all 20 frameworks. It is a real Ed25519-signed key, requested from the form on the homepage (one trial per email address; repeat requests are refused), shown on the page and emailed as a backup copy. **No credit card is taken, so it does not convert into a paid plan and nothing auto-renews**, when it expires you decide whether to buy. - **Then you buy, priced by seats (named users) rather than by employee headcount**: **quoted on request and invoiced against a purchase order, with no self-serve checkout**. Start with the free trial, or contact sales@defendflow.xyz. A "seat" is any active user record, the platform counts every active user with no role filter, so operators, control owners, policy attesters, training participants, your auditor and service accounts all count. Each is a **1-year license, prepaid, no auto-renew**, delivered as a 1-year Ed25519-signed key with no card kept on file. Licenses are quoted and invoiced (sales@defendflow.xyz) and can be invoiced against a PO on request. **Plans differ by seat ceiling and nothing else**, identical entitlements, all 20 frameworks, the same code. - **The seat ceiling is the one hard limit, and here is the exact mechanic.** The signed key carries the license's seat ceiling as a signed integer, sized to the plan you buy. `require_seats_available` returns 403 `seat_limit_exceeded` on user create, user invite and invitation accept, counting every active user with no role filter. Pick the plan whose seat ceiling covers everyone you provision. Unlike the retired employee-headcount model, seats are enforced in real time at invite/create; the seat count is a signed integer in the claim. Existing users are never removed when you outgrow a tier, you simply cannot add past the ceiling until you move up a tier. - **Keys already sold on the retired plans stay valid.** The earlier Starter / Team / Business seat tiers, the employee-size bands and the per-seat Professional (25 seats) and Enterprise (100 seats) keys run to their signed expiry on exactly the terms they were sold on; the backend enforces and displays each as before. Nobody who already paid is affected; you move onto a current seat-based license at renewal. - **Air-gapped deployment is a deployment option available on any plan, sold by quote and invoice** (sales@defendflow.xyz), there is deliberately no self-serve checkout for it, and it is not a separate SKU, priced tier or seat tier. It is the one option that is genuinely capability-differentiated: it mints the `tier1` deployment claim, which carries the `vllm` entitlement, drops `bedrock`, and causes `require_cloud_tier` to return 403 `air_gap_mode` on the cloud data-source connectors. Note carefully: **every** edition validates its license fully offline against a local public key and never phones home, trial included, the air-gap option is the deployment entitlement, not the absence of a phone-home that was never there. - **Self-hosted is not the same as free.** The platform still runs entirely on your own infrastructure, air-gapped if you want, and never phones home, license validation is a local Ed25519 signature check. You just need a valid key to run it. - **Continuous, machine-readable compliance attestation (A2A)**: GRCFlow exposes an Agent-to-Agent endpoint (`POST /api/v1/a2a/mcp`) that answers a signed request to attest a named framework with an Ed25519-signed statement of control status (COMPLIANT / PARTIAL / NON_COMPLIANT / NOT_ASSESSED), recomputed from the org's latest completed assessment on each request and valid 30 days. Returns a control-backed posture over A2A for SOC 2, ISO 27001, PCI DSS, HIPAA and CMMC Level 2 today; further frameworks are recognized by the protocol as their control mappings are added. Every attestation event is routed to your SIEM via an HMAC-SHA256 signed webhook or email ("A2A Alerts"). The human-readable counterpart is a public Trust Center page (`/trust-center/`), which is NOT signed. This capability is included in every edition, including the free 30-day trial. There is NO parent/subsidiary org hierarchy in the product, each entity self-hosts and instances attest peer-to-peer. - **Honest by design**: a control the analyzer cannot verify is recorded as an error or a labeled documentation review, never passed off as a green checkmark. AI-suggested framework mappings are tagged `[AI-SUGGESTED, verify]`. Unimplemented integrations return an explicit error rather than pretending to work. - **One connector collects control evidence today: AWS.** It backs **70 controls across SOC 2, ISO 27001 and CMMC Level 2, with 82 live Steampipe queries, every one of them against an `aws_*` table**. Nine further connection types, Azure, GitHub, Okta, Kubernetes, SSH, WinRM, LDAP, PostgreSQL and MySQL, can be configured, credential-tested and health-checked, but none of them feeds the assessment engine yet; Azure (26 queries) and Okta (6) control libraries are written and schema-verified but nothing calls them. Jira sync is real (outbound create/close/comment against Jira Cloud REST API v3, inbound over the HMAC-signed generic webhook). ServiceNow returns an honest "not yet supported". There is no GCP connector, and none is claimed. - **Audit Copilot covers ISO 27001 today**, and its offline template drafts are labeled and never auto-saved. ## Start here - [GRCFlow homepage](https://defendflow.xyz/): The short version: what GRCFlow is in one sentence, the 20 frameworks by name, six screenshot-led capability cards that link into `/platform`, a three-step install/assess/prove summary, the A2A attestation teaser, and the free-trial form (`/#trial`). It carries no technical prose by design. - [Platform capabilities, in technical depth](https://defendflow.xyz/platform): The specification behind the homepage screens: a definition of a GRC platform, twelve capability sections grouped into Verification, Monitoring, Governance and Operations (each stating what is verified, what is only configured, and where each number comes from), the full framework list with live control counts (`/platform#frameworks`), the install and update steps (`/platform#deploy`), and the 8-question FAQ (`/platform#faq`). This is where every detailed answer lives. - [Continuous multi-entity compliance attestation (A2A)](https://defendflow.xyz/continuous-attestation): How GRCFlow's Agent-to-Agent (A2A) protocol lets a parent company, PE/VC investor, prime contractor, MSP, bank or payment network request a counterparty's compliance posture as a machine-readable, Ed25519-signed attestation, recomputed on demand and verifiable offline, instead of trading annual PDFs and security questionnaires. Endpoint `POST /api/v1/a2a/mcp`; methods `compliance/attest|verify|status|capabilities`; control-backed posture for SOC 2, ISO 27001, PCI DSS, HIPAA and CMMC Level 2 today (further frameworks protocol-recognized as mappings are added); 30-day validity. GRCFlow has NO in-app parent/subsidiary org hierarchy, each entity self-hosts its own instance and they attest peer-to-peer. - [Documentation home](https://defendflow.xyz/docs/): Framework table with control counts and depth disclosures, plus the capability summary. - [Longer factual digest](https://defendflow.xyz/llms-full.txt): Every verified fact on one page, for answering detailed questions without further fetches. ## Platform capabilities, section by section Twelve capability sections on , grouped into four themes, followed by the reference sections (`#frameworks`, `#deploy`, `#faq`). Each anchor is stable and is the target the matching homepage card or footer link points to. Verification: - [Tamper-evident audit trail](https://defendflow.xyz/platform#audit-trail): SHA-256 hash chain over every control verdict, evidence action, policy edit and user change; entries a person recorded or approved additionally carry that person's Ed25519 signature, machine verdicts are chained but unsigned; re-verifiable on demand. - [Honest state, never a fake green](https://defendflow.xyz/platform#honest-state): a control the engine cannot verify is an honest error or gap; coverage percentages are computed, never hardcoded; anything not implemented says so. Monitoring: - [Continuous controls monitoring](https://defendflow.xyz/platform#ccm): a Postgres-backed scheduler with six daily CCM jobs (evidence-source health & drift, control-test sweeps, policy-review-due, PBC evidence-request reminders, stale needs-review reminders, training reminders) plus a seventh A2A notification-delivery sweep on a 60-second interval. - [Automated assessments](https://defendflow.xyz/platform#assessments): AI-assisted evaluation with live Steampipe cloud queries and deterministic OPA verdicts across all 20 frameworks; controls with no reachable collector fall back to a clearly labeled documentation review. - [Collect once, map everywhere](https://defendflow.xyz/platform#cross-framework): the cross-framework delta engine, deterministic crosswalk first, AI suggestions always labeled "AI-suggested, verify". Governance: - [Policy versioning and attestations](https://defendflow.xyz/platform#policy): immutable version snapshots with live SHA-256 integrity checks; attestation campaigns recorded as signed audit entries. - [AI governance, built in](https://defendflow.xyz/platform#ai-governance): ISO/IEC 42001, NIST AI RMF and the EU AI Act as first-class frameworks with curated crosswalks, plus an org-scoped AI-system registry carrying EU AI Act risk tiers. - [Risk: residual and FAIR](https://defendflow.xyz/platform#risk): residual risk computed from real assessment pass rates (untested controls earn no credit, manual overrides win and are labeled); server-side Open FAIR Monte Carlo, ALE, VaR and loss exceedance, every analysis persisted. Operations: - [Board packs and auditor evidence](https://defendflow.xyz/platform#reporting): executive roll-ups of posture, readiness and top residual risks; auditors on a grant view evidence inline only, watermarked and audit-logged. - [Integrations, honestly labelled](https://defendflow.xyz/platform#integrations): AWS backs 70 controls across SOC 2, ISO 27001 and CMMC Level 2 with 82 live Steampipe queries; nine further connector types configure and health-check only; Jira sync is real; ServiceNow says "not yet supported"; there is no GCP connector. - [Incidents, vendors and evidence](https://defendflow.xyz/platform#incidents): NIST SP 800-61 incident workflow with SLA tracking and breach notification, agent-to-agent vendor attestation, and versioned hash-verified evidence storage on your own S3-compatible object storage (R2, S3 or the bundled MinIO). - [Audit copilot](https://defendflow.xyz/platform#copilot): guided audit prep grounded in real framework content and your own findings, resumable sessions, progress recomputed from real findings on every resume. ISO 27001 today. ## Compliance frameworks and controls - [Frameworks module](https://defendflow.xyz/docs/guide/frameworks/): How the 20 frameworks and 2,082 controls are modeled, browsed and scoped. - [Cross-framework compliance](https://defendflow.xyz/docs/guide/cross-compliance/): Reusing control work across frameworks; coverage percentages computed from real mappings, never hardcoded. - [Framework delta engine](https://defendflow.xyz/docs/guide/framework-delta/): "How much of my ISO 27001 work counts toward GLBA?", deterministic crosswalk plus clearly-labeled AI-suggested mappings. - [Assessments](https://defendflow.xyz/docs/guide/assessments/): Automated and manual control assessment, and what happens when no live evidence source is reachable. - [Findings](https://defendflow.xyz/docs/guide/findings/): Gap tracking and remediation workflow. ## Evidence, audit and assurance - [Audit trail and integrity](https://defendflow.xyz/docs/guide/audit-log/): SHA-256 hash chain covering every control verdict; entries a person recorded or approved additionally carry that person's Ed25519 signature, while machine-generated verdicts are chained but unsigned. The whole log can be re-verified on demand. - [Evidence collection](https://defendflow.xyz/docs/guide/evidence/): presigned upload/verify/link API over your own S3-compatible object storage (Cloudflare R2, AWS S3 or the bundled MinIO). The storage layer can apply S3/R2 Object Lock retention in GOVERNANCE mode (365-day default), which holders of the bypass permission can still override; the browser upload path uses presigned PUTs that stamp no per-object retention, so WORM semantics require you to enable Object Lock **and a default retention rule** on the bucket yourself. - [Evidence requests](https://defendflow.xyz/docs/guide/evidence-requests/): Requesting, chasing and closing evidence from control owners. - [Auditor portal](https://defendflow.xyz/docs/guide/auditor-portal/): Scoped, view-only external-auditor workspace; inline-only evidence streaming with watermarking, and every view logged. - [Continuous controls monitoring](https://defendflow.xyz/docs/guide/ccm/): Scheduled drift, control-test and policy-review sweeps. - [Data sources](https://defendflow.xyz/docs/guide/data-sources/): Steampipe-backed AWS control evidence. AWS backs 70 controls across SOC 2, ISO 27001 and CMMC Level 2, with 82 live Steampipe queries, every one of them against an `aws_*` table. Nine further connection types, Azure, GitHub, Okta, Kubernetes, SSH, WinRM, LDAP, PostgreSQL, MySQL, configure and health-check only; they do not yet feed the assessment engine. Azure (26 queries) and Okta (6) libraries are written but uncalled; there is no GCP connector. - [Reports](https://defendflow.xyz/docs/guide/reports/): Board pack, executive summary, gap analysis, SoA, SSP, POA&M. ## Risk - [Risk register](https://defendflow.xyz/docs/guide/risk-register/): Residual risk computed from real control-assessment pass rates; manual overrides always win and are labeled as overrides. - [Risk quantification (FAIR)](https://defendflow.xyz/docs/guide/risk-quantification/): Server-side Open FAIR Monte Carlo, ALE, VaR 90/95/99, loss-exceedance curves. - [Bow-tie analysis](https://defendflow.xyz/docs/guide/bow-tie/): Threat/consequence modeling with preventive and mitigating controls. - [Risk monitoring](https://defendflow.xyz/docs/guide/risk-monitoring/): Key risk indicators and thresholds. - [Incidents](https://defendflow.xyz/docs/guide/incidents/): NIST SP 800-61 workflow with SLA tracking and breach-notification support. ## AI governance - [AI governance module](https://defendflow.xyz/docs/guide/ai-governance/): ISO/IEC 42001:2023 (38 Annex A controls), NIST AI RMF 1.0 (19, Core at category level), EU AI Act (19 article-cited obligations), and an org-scoped AI-system registry with EU AI Act risk tiers. - [AI audit](https://defendflow.xyz/docs/guide/ai-audit/): Choosing and configuring the LLM provider, NVIDIA NIM, self-hosted Ollama or vLLM, any OpenAI-compatible or Azure OpenAI endpoint, or Cloudflare Workers AI. - [Audit copilot](https://defendflow.xyz/docs/guide/audit-copilot/): Guided audit planning that calls the platform's real engines rather than generating prose. ISO 27001 today. ## Policy and governance - [Policies](https://defendflow.xyz/docs/guide/policies/): Immutable policy snapshots with SHA-256 integrity re-checks. - [Policy attestations](https://defendflow.xyz/docs/guide/policy-attestations/): Campaigns recording who acknowledged which policy version, when, as signed audit entries. - [Policy engine](https://defendflow.xyz/docs/guide/policy-engine/): Rego/OPA evaluation for deterministic compliance verdicts. - [SOX compliance](https://defendflow.xyz/docs/guide/sox/) and [ESG management](https://defendflow.xyz/docs/guide/esg/): Financial-controls and sustainability program tracking. - [Vendors / third-party risk](https://defendflow.xyz/docs/guide/vendors/): Vendor lifecycle with agent-to-agent attestation. - [Trust center](https://defendflow.xyz/docs/guide/trust-center/): Publishing your compliance posture to customers. ## Deploying and operating it - Install is one command, `curl -sSL https://get.defendflow.xyz | bash`, or clone the repository and run `docker compose up -d` from `deploy/docker`. Upgrades run `./update.sh` from the install directory, which takes a timestamped database backup, records the previous image digests for rollback, then pulls and verifies. - [Settings](https://defendflow.xyz/docs/guide/settings/): Configuration, license activation (required before the GRC endpoints work) and environment variables. - [Admin settings](https://defendflow.xyz/docs/guide/admin/): Roles, permissions and the admin-configurable LLM panel. - [System health](https://defendflow.xyz/docs/guide/system-health/): Readiness checks and what a stock install still needs configured. - [API reference](https://defendflow.xyz/docs/api-reference/): REST API surface, including `/api/v1/frameworks`. - [API keys](https://defendflow.xyz/docs/guide/api-keys/) and [integrations](https://defendflow.xyz/docs/guide/integrations/): Programmatic access, Jira two-way ticket sync, HMAC-signed webhooks. - [MCP integration](https://defendflow.xyz/docs/guide/mcp-integration/): Model Context Protocol server for driving GRCFlow from an AI agent. ## Optional - [IRM services](https://defendflow.xyz/docs/irm-services/): Integrated risk-management services layer. - [RACI matrix](https://defendflow.xyz/docs/guide/raci-matrix/): Control ownership and accountability mapping. - [Compliance analytics](https://defendflow.xyz/docs/guide/compliance-analytics/): Posture trends over time. - [Security policy](https://defendflow.xyz/.well-known/security.txt): Vulnerability reporting to security@defendflow.xyz, plus deployment hardening guidance. ## Video training Seven short lessons plus a full masterclass showing how to run a SOC 2 audit in GRCFlow, each recorded against a live system. Page: https://defendflow.xyz/docs/videos/ - Create a SOC 2 assessment and scope its 61 controls (51s) - Evaluate a control and pass it, with sampling rationale (60s) - Fail a control and raise a tracked finding (114s) - Ask the AI Audit Copilot why a control failed (121s) - Request evidence with an owner, due date and acceptance criteria (49s) - Turn failures into a POA&M remediation plan (33s) - Generate the audit report (45s) - Masterclass: a full SOC 2 audit end to end (7m21s)