Skip to main content

SolveGRC documentation

SolveGRC is one connected system for running your compliance program — evidence, controls, frameworks, third-party risk, cloud posture, risk, reports, and audits, all feeding each other. These docs cover how to set each part up, run it day to day, and get value out of it.

Start here

  • Getting started — your first insight, fast: pick a goal, follow a journey, and understand how much data it takes before the numbers mean something.
  • How SolveGRC fits together — the one-page map of what feeds what across the platform.
  • How SolveGRC thinks — the ideas underneath: how AI answers are grounded, how evidence quality and freshness work, how crosswalks satisfy many frameworks, and what runs automatically.

Module guides

  • Questionnaires — send, answer, and manage security questionnaires.
  • Third-Party Risk (TPRM) — onboard vendors, assess risk, and monitor continuously.
  • Frameworks — activate frameworks, scope them, assess controls, and crosswalk.
  • Evidence — add, classify, quality-check, reuse, and package evidence.
  • Risks — raise, treat, promote from signals, and quantify risk in dollars.
  • Cloud Posture — connect a cloud account and turn findings into framework coverage.
  • Reports — build and deliver generated compliance reports.
  • Audits — plan, run, and close out audit engagements with an auditor portal.
New here?

Read Getting started first — it's built around getting you to a meaningful result with the least setup.