We're a GRC company. Hold us to the same standard.
Everything below is either true today or clearly marked as pending, we'd rather show you an honest gap than a polished claim we can't back up.
Our own security programme is being built to the same standard we hold customers to: encryption in transit, access controls, and a responsible disclosure path.
Detailed security whitepaper pendingOur Privacy Policy explains what we collect, why, and how to exercise your rights. Read it in full, not a summary.
Read the Privacy Policy →We don't claim certifications we don't hold. As GRXForce completes independent audits, results will be published here, verified, not just asserted.
No certifications to display yetOur Privacy Policy and Terms of Service are public. Internal security and acceptable-use policies are available under NDA for enterprise evaluations.
Read the Terms →A current list of subprocessors, who they are, what they do, and where they're located, will be published here as our infrastructure stabilizes.
List available on request, email usA public status page and historical uptime numbers are on our roadmap. Until then, ask us directly, we'll answer honestly.
Status page pendingWe follow the same contain-assess-notify-document discipline we recommend to customers in the GRC Emergency Room. Found a security issue? Tell us.
Report a security issue →We collect what's needed to run the service and nothing more, retain it only as long as necessary, and never sell personal data. Details are in the Privacy Policy.
See data handling details →AI
GRXForce's AI Evidence Agent discovers where evidence for a selected control actually lives, extracts it, and reviews it against the control requirement. Every assessment shows its reasoning: what was checked, what was found, and why it does or doesn't satisfy the requirement, rather than a bare pass/fail score. The agent never issues an audit opinion. Its output is a draft recommendation that a human reviewer accepts, rejects, requests more evidence against, or overrides with professional judgement before anything is concluded.
Security
Access to GRXForce is structured around enterprise roles, so what a user can see and approve maps to their actual responsibility. Every evidence record carries its provenance, source, timestamp, scope and reviewer, so any assessment can be traced back to where it came from. Actions taken on a control test are recorded and sealed once an auditor concludes, so the record cannot be quietly altered after the fact. See the Security card above for what's documented today versus pending.
Architecture
GRXForce is a web application: a browser-based interface backed by cloud infrastructure, with the AI Evidence Agent running as a server-side service that never has write access to the systems it reads evidence from. Read-only connections are the design principle for any future integration, evidence collection should not be able to change the state of the systems it's evaluating. Full architecture documentation is being prepared for enterprise evaluations.
Audit Principles
AI prepares. Humans decide. Auditors conclude.
Every control test GRXForce runs follows the same boundary: the AI Evidence Agent prepares evidence and a draft recommendation, a human reviewer decides what to do with it, and where an independent auditor is involved, that auditor retains sole authority over the final conclusion. GRXForce is a platform, not an auditor, and does not issue audit opinions or certifications.