How SolveGRC fits together
SolveGRC is one connected system, not a bundle of modules. Anything you feed it keeps working across the platform: a policy you upload becomes evidence, backs controls, grounds AI answers, and shows up in reports — without being entered twice. This page is the map. Every module page in the app carries the same map for its own neighborhood, behind the Connections button in the page header.
The map
Flows worth knowing
Upload once, prove everywhere. A document is extracted, chunked, and embedded on upload. From that moment it is searchable, citable by the AI, linkable to controls as evidence, and packagable for auditors. The Evidence Locker registers and quality-scores everything at birth, and a nightly sweep marks aging evidence stale so nothing quietly rots.
Map once, satisfy every framework. Controls crosswalk between frameworks. Assess a control once and every framework that recognizes an equivalent control gets the credit — activating a second framework is a head start, not a restart.
The cloud does its own paperwork. A read-only cloud connection syncs every six hours. Findings arrive already mapped to compliance standards, assets land in one canonical registry, topology and attack paths redraw themselves, and anything security-significant lands in a change feed with email alerts.
Answers compound. Every questionnaire answer your team approves becomes reusable evidence and preferred wording for the next questionnaire. The tenth questionnaire is dramatically faster than the first — that is the design, not an accident.
The map is a view, not a second copy. Every night the Knowledge Graph is rebuilt from your frameworks, controls, evidence, crosswalks, and cloud findings, so you can see which controls are proven and which are only asserted, and the AI assistant walks that same graph when it answers. It reads everything and edits nothing. See Knowledge Graph.
Your carrier reads the same records your auditor does. A cyber-insurance carrier states the controls it needs proven, you accept those terms once, and each reporting period SolveGRC scores the obligated controls from your assessments, evidence and cloud findings into a frozen report the carrier receives only after release. Nothing crosses that the terms did not name, and every carrier read lands on your own audit chain. See Insurance Exchange.
A partner runs many clients without living in any of them. An MSP works its whole book from one portal: per-client scores roll up into a portfolio view, evidence requests go out in batches, and reviews and SLAs sit in one queue. When an operator needs to act inside a client, they open a time-boxed session with a stated reason, do the work, and leave; the client's audit log records every minute of it. Nobody at the partner holds a standing seat in a client. See MSP Portal.
The architecture diagram becomes evidence. Upload a network diagram, or generate one from a cloud account, and SolveGRC turns it into a topology of nodes, connections and zones. Each element gets control suggestions for the frameworks you run (a firewall on a boundary points at boundary-protection controls), you confirm the ones that hold, and approving the diagram registers it as evidence with an integrity hash. Elements matched to your cloud assets feed dependencies into continuity planning. See Network Diagrams.
Everything explains itself. Scores show their inputs. AI answers cite their sources and flag their own weak spots. Derived numbers carry a provenance affordance telling you what fed them and when. If you ever wonder "where did this number come from," the answer is one click away — and if it isn't, that is a bug we want to hear about.
Follow a single document through the system
- You upload InfoSec-Policy.pdf to Documents.
- It is extracted, embedded, registered as evidence, and quality-scored — automatically.
- You link it to three access-control controls; those controls' frameworks credit the evidence in their compliance scores.
- A customer questionnaire arrives asking about access reviews. The AI drafts the answer citing the exact passage in your policy; a teammate approves it.
- That approved answer registers as evidence itself, and next quarter's questionnaire prefills from it.
- Your auditor receives the policy and the answer in a sealed evidence pack — same document, never re-uploaded.
That is the platform in one sentence: feed it once, and every module keeps proving things with it.