All use cases
    Use case

    GRC & compliance

    Automate evidence and pass audits without the spreadsheet sprawl.

    Why this fits, Governance, risk and compliance automation for SOC 2, ISO 27001, DORA, NIS2 and more.

    97 vendors for this

    IntelliGRC logo
    IntelliGRC
    Compliance & GRC
    1 product

    IntelliGRC is a cloud-based governance, risk, and compliance platform built for organizations pursuing certifications such as CMMC, NIST 800-171, SOC 2, ISO 27001, HIPAA, and CIS Controls. It targets managed service providers and managed security service providers that operationalize compliance work across multiple clients, as well as compliance teams managing a single organization's certification. The platform maps assets across people, technology, facilities, and data, then uses AI-assisted evidence collection and gap analysis against a chosen framework. Continuous monitoring dashboards, audit-ready reporting, and cross-framework control mapping help teams track remediation and maintain compliance on an ongoing basis rather than as a one-time audit exercise.

    Asset scoping and mapping+5
    LogicGate Risk Cloud logo
    LogicGate Risk Cloud
    Compliance & GRC
    1 product

    LogicGate Risk Cloud is a configurable GRC platform focused on compliance workflow automation, evidence collection, control mapping, and audit preparation. In the Compliance & GRC category, it is positioned as a central system for linking obligations, assessments, controls, and reporting across regulatory programs. The platform is best suited for mid-market and enterprise teams managing recurring compliance tasks across multiple frameworks and internal control sets. LogicGate also offers adjacent GRC modules such as risk quantification and broader risk management, but the compliance offering centers on automating the operational side of governance and assurance.

    Automates evidence collection with support for unlimited evidence sources to reduce manual chasing of audit artifacts and control attestations.
    Netwrix logo
    Netwrix
    Identity Governance & Administration (IGA)
    8 products

    Netwrix provides a SaaS-based Identity Governance and Administration (IGA) platform, primarily through Netwrix Identity Manager (formerly Usercube), automating identity lifecycle management across hybrid IT environments. It handles provisioning, deprovisioning, access reviews, and policy enforcement for joiner-mover-leaver processes. The solution builds role catalogs mapping technical entitlements to business roles, detects toxic role combinations and Segregation of Duties (SoD) conflicts, and generates compliance reports. Best suited for mid-to-large enterprises needing scalable IGA for Active Directory, Azure AD, and multi-system access governance to enforce least privilege and support audits.

    Automate joiner mover leaver workflows+11
    Panorays logo
    Panorays
    Compliance & GRC
    6 products

    Panorays is a third-party risk and vendor compliance platform used by security and procurement teams to collect evidence, run security questionnaires, and document risk decisions across supplier relationships. Within Compliance & GRC, it centers on vendor onboarding, assessment workflows, remediation tracking, and audit-ready records rather than enterprise-wide policy management. The platform is best suited for organizations that need repeatable third-party due diligence, especially where security, legal, and compliance teams must review SOC 2, ISO 27001, and similar attestations. It can also synchronize third-party risk data into Archer for broader GRC workflows.

    Automated third-party security questionnaires with configurable workflows to collect vendor responses and supporting evidence during onboarding and periodic reviews.
    Swimlane logo
    Swimlane
    SOAR
    6 products

    Swimlane provides Swimlane Turbine, an agentic AI automation platform for AI SOCs, integrating AI agents, low-code playbooks, case management, dashboards, and reporting with infinite integrations. It automates triage, investigation, and response through governed workflows, delivering 60,000 SOC analyst equivalents daily across customers. The Investigation Agent synthesizes threat intelligence, past investigations, and knowledge bases to generate NIST-aligned, four-phase response plans (containment, eradication, recovery, hardening) with actionable steps. Best for enterprise SOCs and MSSPs seeking transparent, auditable AI execution to reduce context switching and MTTR by up to 75%. Leader in GenAI SOC platforms, #1 on Gartner Peer Insights.

    Autonomous AI investigation agents+7