Compliance automation companies, products & suppliers
Operating controls, testing and evidence collection for obligations, not monitoring new law. Jobs: control testing; evidence collection; issue workflow.
What is Compliance automation?
Operating controls, testing and evidence collection for obligations, not monitoring new law. Jobs: control testing; evidence collection; issue workflow.
What problems does it solve?
Control testing still is a quarterly screenshot hunt.
Typical business use cases
- Control testing
- Evidence collection
- Issue workflow
Important capabilities
- Control library
- Connectors
- Attestations
What buyers should evaluate
- Whether it is GRC theatre
- Evidence integrity
- Who attests
Risks and governance considerations
Auto-attested controls with no evidence.
Procurement checklist
- Evidence
- Attestor
- Connectors
Relevant AI Trustmark assurance
AI Trustmark independent findings appear only when an assessment or certificate exists. Category membership does not imply verification.
Companies and providers
Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.
Complyance is the innovation-driven, AI-first GRC platform for Enterprises. Automate compliance, reduce manual work by 70%, and stay audit-ready with unlimited users and integratio
AI Analysts that execute gap assessments, vendor reviews, and evidence auditing end-to-end. Cyber Sierra is used for Compliance automation work. Cyber Sierra publishes product info
Enterprise-grade Cyber GRC Automation Platform Enterprise-grade Cyber GRC solution for any security and compliance standard, across hybrid and multi cloud environments. Cypago is u
Delve AI agents eliminate compliance busywork, build security that lasts, and help you close deals faster. Delve is used for Compliance automation work. Delve publishes product inf
Kertos Compliance Software automatisiert DSGVO, ISO 27001, ISO42100, TISAX®, SOC2, EU AI ACT, C5, NIS2 und viel mehr. Schnell auditbereit, 100+ Integrationen, minimaler Aufwand. Ke
Leah, formerly ContractPodAi, is the agentic AI platform that runs contracting, legal, and procurement end to end. Leah publishes Leah Agentic CLM as named AI products. Leah is use
Looking to obtain a SOC 2 report or an ISO 27001 certification? Oneleet is the only all-in-one platform for both real world security AND compliance. Talk to us about SOC 2, HIPAA,
Scytale AI Ltd sells compliance automation for collecting audit evidence against frameworks such as SOC 2. Public pages describe control workflows, not social captions. Scytale pub
Strike Graph publishes Strike Graph as a named AI product. Strike Graph is used for Compliance automation work. Strike Graph publishes product information at strikegraph.com. Strik
Thomson Reuters CoCounsel is an AI legal assistant integrated with TR legal research and workflow products. Public marketing also emphasises legal research corpus + AI assistant. I
TrustCloud is the AI-native GRC platform that automates compliance and continuous control monitoring, cutting internal audit time from 28 days to 3. TrustCloud publishes TrustOps a
Vanta automates the complex and time-consuming process of SOC 2, HIPAA, ISO 27001, PCI, and GDPR compliance certification. Automate your security monitoring in weeks instead of mon
Products
Claimed products appear first. Ranking packs and payment do not change this list.
- Complyance· Complyance
- Cyber Sierra· Cyber Sierra
- Cypago· Cypago
- Delve· Delve
- Kertos· Kertos
- Oneleet· Oneleet
- Scytale· Scytale
- Strike Graph· Strike Graph
- TrustOps· TrustCloud
- Vanta AI· Vanta
Also used in this category
These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.
- Leah Agentic CLM· Leah
- Thomson Reuters Regulatory Intelligence· Thomson Reuters
Related categories
Relevant procurement and assurance guides
Frequently asked questions
What is Compliance automation?
Operating controls, testing and evidence collection for obligations, not monitoring new law. Jobs: control testing; evidence collection; issue workflow.
What should not be listed as Compliance automation?
Products whose buyer job is regulatory monitoring, policy management, or AI audit. Those belong on their own category page so search queries are not split.
Has AI Trustmark independently assessed every Compliance automation supplier?
No. A category listing is descriptive. Independent assessment is shown only on company or product pages that carry Trustmark evidence.
What model or provider changes should a buyer insist on being told about?
Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.
How should buyers verify where AI customer data is processed?
Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.
Does a TrustMark on one product cover the rest of the company?
No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.
What incident-handling evidence is useful for AI suppliers?
Buyers should see how AI-specific failures are detected, contained and notified — including unsafe outputs, data leakage and unauthorised agent actions. An incident policy that never mentions models, prompts or tools is incomplete for this class of product.
What security testing evidence should buyers request for an AI product?
Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.