thegrcguys

GRC engineering

Compliance that runs itself.

We're GRC engineers. We take the control framework you're being held to, turn it into checks that run against your real infrastructure, and collect the evidence automatically — so an audit is a query, not a quarter.

control register · production 0/5 passing
CC6.1 MFA enforced on every account with admin access queued
CC7.2 Anomalous activity monitored, alerted and triaged queued
CC8.1 Changes reviewed and approved before they ship queued
A.8.16 Logs centralised, immutable and retained queued
A.5.23 Cloud configuration baselined, drift caught daily queued

What we do

Four things, done properly.

We don't sell you a dashboard and leave. We build the plumbing behind it and hand you the keys.

controls

Control automation

We map each control in your framework to a check that runs against your cloud on a schedule. When something drifts, you hear about it that day — not the week before the audit.

evidence

Evidence pipelines

Evidence pulled straight from AWS, GitHub, Okta and Jira, timestamped and filed against the control it proves. No more screenshot folders named "final_v3".

policy

Policy as code

Policies live in version control and get reviewed like any other pull request. Every change has an author, a reason and a date, because that's what an auditor is going to ask for.

audit

Audit support

We sit in the room. We speak auditor, we speak engineer, and we translate between them so your team can get back to shipping.

How it works

Four to eight weeks, start to handover.

01

Map

We read your framework and your stack side by side, and write down which controls can be automated, which can't, and which you're already meeting without knowing it.

02

Build

Checks, evidence collectors and the register that ties them together. All of it in your repos, in your cloud account, under your control.

03

Run

We run it alongside your team for a full cycle, tune the noise out, and fix what the checks turn up.

04

Hand off

Documentation, a runbook, and a training session. You keep the system whether or not you keep us.

Frameworks

The ones we've done this for.

If yours isn't listed, ask anyway — the method is the same.

SOC 2 Type II ISO 27001 ISO 27701 PCI DSS 4.0 HIPAA GDPR NIST CSF 2.0 CIS Benchmarks

Get started

Tell us what you're being audited against.

A 30-minute call. We'll tell you honestly whether we can help and roughly what it costs.

hello@thegrcguys.com