Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Every Compliance Automation Tool We Could Find

Direct answer: We published awesome-compliance-automation, a curated list of 357 tools and resources for automating compliance across SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, GDPR, PIPEDA, Quebec Law 25 and NIST CSF. It is organized twice over: by function, so you can find every access review tool in one place, and by framework, so you can find what applies to the standard you are actually being audited against. Released under CC0, with no affiliate links.

Why we built it

Compliance tooling is an unusually opaque market. The category leaders spend heavily on content, so a search for any compliance problem returns their blog explaining that the solution is their platform. That content is often good. It is not neutral, and it is not comprehensive.

Meanwhile there is a substantial open-source layer that almost never appears in those comparisons, because nobody is paying to promote it. Teams with an engineering culture and a modest budget frequently get further with open tooling and a clear control set than with a subscription they have not configured properly.

The list is the thing we would have wanted before recommending anything: a complete picture, with the commercial and open options side by side and no ordering that anybody paid for.

How it is organized

By function first, because that is how the problem usually arrives. You do not wake up wanting a GRC platform. You wake up because access reviews are late.

  • GRC platforms. The all-in-one tools, listed without ranking.
  • Policy management and evidence collection and automation.
  • Access review tools. The single most common reason a first Type II picks up an exception.
  • Vendor risk management.
  • Security awareness training and background checks.
  • Vulnerability management and cloud security posture management.
  • Penetration testing platforms and incident response.
  • Trust centers and security pages.
  • Endpoint security and device management.

Then by framework, which is the view you want when someone has told you which standard you are being held to. SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR and privacy, NIST CSF, Canadian privacy covering PIPEDA and Quebec Law 25, and AI governance under ISO 42001. That last section is the one growing fastest and the one most existing lists do not have at all.

Then a dedicated open-source section: cloud security and posture management, infrastructure as code scanning, vulnerability scanning, compliance as code, Kubernetes security, identity and secrets, incident response and forensics, and privacy tooling.

Not sure which framework applies to you? The framework finder asks about your buyers, your data and your jurisdiction, and tells you what you are actually obliged to do. Compliance framework finder

How to shortlist without burning a quarter

Tool selection expands to fill whatever time you give it. A structure that keeps it to two weeks:

Decide your control set before you look at any tool. This is the step everyone skips and it is the only one that matters. A platform configures itself around a control set. If you do not have one, you will adopt the vendor's default and then spend the audit explaining why your system description does not match your evidence.

Write down the three things that are actually failing. Not the twenty things that could be better. If access reviews and vendor reviews are late and evidence is scattered, you are shopping for three capabilities, and most of the feature matrices you are about to read are irrelevant.

Check integration coverage against your real stack, not the logo wall. The value of an automation platform is almost entirely in what it can connect to. A tool that integrates with your identity provider, your cloud and your source control does most of the work. One that misses your identity provider will generate manual tasks forever, whatever else it does.

Price the second year. First year pricing is frequently discounted against an implementation fee, and the renewal is the real number. Ask for it in writing during the sales process, when you have leverage.

Ask what happens to your data if you leave. Policies, evidence, control descriptions and register contents should be exportable in a usable format. Some platforms make this awkward enough that switching becomes a migration project, which is a supplier decision you want to make knowingly.

What a tool list cannot tell you

Whether you need one of these at all.

Automation platforms earn their fee when you have enough headcount churn, enough systems and enough framework overlap that manual collection genuinely does not scale. Below that, a platform is a subscription that produces a dashboard, and the dashboard being green tells you about the things the platform can see, which is typically cloud configuration, identity and endpoints. It does not know whether your vendor reviews were meaningful, whether your risk register reflects the business, or whether the person who left in March still has access to a system the platform does not connect to.

We have written about this trade-off at length in Vanta versus a compliance consultant and compared the market in best compliance automation software. The short version: the platform is a good answer to the evidence collection problem and a poor answer to the judgment problem, and most first audits fail on judgment.

Open questions and contributions

The AI governance section will date fastest. ISO 42001 tooling barely existed eighteen months ago and the EU AI Act is still producing obligations that vendors are racing to address. If you are working in that space and something is missing, that is the section where a pull request is most valuable.

Same rules as our other lists. One entry per pull request, a sentence saying what the tool does, no affiliate links, and competitors get merged on the same terms as anyone else.

The list is at github.com/TrazTech-Inc/awesome-compliance-automation.

Weighing a platform against people? We will tell you honestly which one your situation calls for, including when the answer is neither yet.

How we run complianceOr book a free call

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.