Trust Center

We're a GRC company. Hold us to the same standard.

Everything below is either true today or clearly marked as pending, we'd rather show you an honest gap than a polished claim we can't back up.

Security

Our own security programme is being built to the same standard we hold customers to: encryption in transit, access controls, and a responsible disclosure path.

Detailed security whitepaper pending
Privacy

Our Privacy Policy explains what we collect, why, and how to exercise your rights. Read it in full, not a summary.

Read the Privacy Policy →
Certifications

We don't claim certifications we don't hold. As GRXForce completes independent audits, results will be published here, verified, not just asserted.

No certifications to display yet
Policies

Our Privacy Policy and Terms of Service are public. Internal security and acceptable-use policies are available under NDA for enterprise evaluations.

Read the Terms →
Subprocessors

A current list of subprocessors, who they are, what they do, and where they're located, will be published here as our infrastructure stabilizes.

List available on request, email us
Availability

A public status page and historical uptime numbers are on our roadmap. Until then, ask us directly, we'll answer honestly.

Status page pending
Incident management

We follow the same contain-assess-notify-document discipline we recommend to customers in the GRC Emergency Room. Found a security issue? Tell us.

Report a security issue →
Data handling

We collect what's needed to run the service and nothing more, retain it only as long as necessary, and never sell personal data. Details are in the Privacy Policy.

See data handling details →

AI

GRXForce's AI Evidence Agent discovers where evidence for a selected control actually lives, extracts it, and reviews it against the control requirement. Every assessment shows its reasoning: what was checked, what was found, and why it does or doesn't satisfy the requirement, rather than a bare pass/fail score. The agent never issues an audit opinion. Its output is a draft recommendation that a human reviewer accepts, rejects, requests more evidence against, or overrides with professional judgement before anything is concluded.

Data handling in GRX AssistChat interactions are processed by our AI provider to generate a response and are retained only as long as needed to support your enquiry, then deleted or anonymized. Please don't submit confidential, sensitive, or regulated information through GRX Assist. Full detail in the Privacy Policy's data retention section.

Security

Access to GRXForce is structured around enterprise roles, so what a user can see and approve maps to their actual responsibility. Every evidence record carries its provenance, source, timestamp, scope and reviewer, so any assessment can be traced back to where it came from. Actions taken on a control test are recorded and sealed once an auditor concludes, so the record cannot be quietly altered after the fact. See the Security card above for what's documented today versus pending.

Architecture

GRXForce is a web application: a browser-based interface backed by cloud infrastructure, with the AI Evidence Agent running as a server-side service that never has write access to the systems it reads evidence from. Read-only connections are the design principle for any future integration, evidence collection should not be able to change the state of the systems it's evaluating. Full architecture documentation is being prepared for enterprise evaluations.

Audit Principles

AI prepares. Humans decide. Auditors conclude.

Every control test GRXForce runs follows the same boundary: the AI Evidence Agent prepares evidence and a draft recommendation, a human reviewer decides what to do with it, and where an independent auditor is involved, that auditor retains sole authority over the final conclusion. GRXForce is a platform, not an auditor, and does not issue audit opinions or certifications.

Questions about how we operate?

Ask us directly, before you sign anything.