Skip to main content

How SolveGRC fits together

SolveGRC is one connected system, not a bundle of modules. Anything you feed it keeps working across the platform: a policy you upload becomes evidence, backs controls, grounds AI answers, and shows up in reports — without being entered twice. This page is the map. Every module page in the app carries the same map for its own neighborhood, behind the Connections button in the page header.

The map

Five flows worth knowing

Upload once, prove everywhere. A document is extracted, chunked, and embedded on upload. From that moment it is searchable, citable by the AI, linkable to controls as evidence, and packagable for auditors. The Evidence Locker registers and quality-scores everything at birth, and a nightly sweep marks aging evidence stale so nothing quietly rots.

Map once, satisfy every framework. Controls crosswalk between frameworks. Assess a control once and every framework that recognizes an equivalent control gets the credit — activating a second framework is a head start, not a restart.

The cloud does its own paperwork. A read-only cloud connection syncs every six hours. Findings arrive already mapped to compliance standards, assets land in one canonical registry, topology and attack paths redraw themselves, and anything security-significant lands in a change feed with email alerts.

Answers compound. Every questionnaire answer your team approves becomes reusable evidence and preferred wording for the next questionnaire. The tenth questionnaire is dramatically faster than the first — that is the design, not an accident.

Everything explains itself. Scores show their inputs. AI answers cite their sources and flag their own weak spots. Derived numbers carry a provenance affordance telling you what fed them and when. If you ever wonder "where did this number come from," the answer is one click away — and if it isn't, that is a bug we want to hear about.

Follow a single document through the system

  1. You upload InfoSec-Policy.pdf to Documents.
  2. It is extracted, embedded, registered as evidence, and quality-scored — automatically.
  3. You link it to three access-control controls; those controls' frameworks credit the evidence in their compliance scores.
  4. A customer questionnaire arrives asking about access reviews. The AI drafts the answer citing the exact passage in your policy; a teammate approves it.
  5. That approved answer registers as evidence itself, and next quarter's questionnaire prefills from it.
  6. Your auditor receives the policy and the answer in a sealed evidence pack — same document, never re-uploaded.

That is the platform in one sentence: feed it once, and every module keeps proving things with it.