GRCEye

Frequently Asked Questions

Everything you need to know about GRCEye — features, modules, AI capabilities, and how it all works.

GRCEye Product Datasheet

Full feature breakdown, AI capabilities, architecture overview, and module details.

View Datasheet

Getting Started

Click 'Get started free' and fill in your name, email, organization name, and a unique slug. You'll get instant access to the full platform for 14 days — no credit card required.

Risk Management

The risk register supports full CRUD operations with likelihood × impact scoring on a configurable 5×5 matrix. Each risk has a severity classification, owner, next-review date, treatment plan, and full activity history.

Compliance & Frameworks

GRCEye includes 76 built-in frameworks: ISO 27001:2022, SOC 2, GDPR, NIS2, DORA, AI Act, NIST CSF 2.0, NIST 800-53 Rev5, PCI DSS 4.0, HIPAA, CIS Controls v8, MITRE ATT&CK, and many more.

Audit Management

Audit Management covers the full audit lifecycle: planning, control assignment, checklist execution, finding creation, remediation tracking, and final report generation. Supports internal and external audit types.

Policy & Document Management

The Document Generator uses your local AI to produce complete, ready-to-adopt GRC documents (29 types across 4 categories) tailored to your organization's name, industry, size, country, and selected compliance frameworks. Generated documents auto-save as drafts.

Vendor Risk (TPRM)

Vendor Risk Management covers vendor onboarding with risk tiers (critical/high/medium/low), contract upload and AI review, a 6-dimension risk cartography heatmap, AI-powered prescreening questionnaires, and contract versioning with CISO approval workflows.

AI Capabilities

All AI processing runs on your self-hosted LLM inside your own infrastructure using Ollama. No contract text, personal data, policy content, or sensitive information is ever transmitted to external AI providers — zero data egress, full privacy.

Security & Platform

Yes. GRCEye supports GDPR breach notification workflows, DPA templates, and data subject request tracking. The platform itself is designed with privacy-by-design principles — including local AI processing that ensures no personal data is sent to external AI providers.

Reporting & Integrations

GRCEye generates 5 automated PDF report types: Executive Summary, Risk Report, Compliance Report, Vendor Risk Report, and Audit Report. Reports are generated weekly or on-demand.

Still have questions?

Can't find the answer you're looking for? Our support team is here to help you get started.