Global · 19 frameworks · SOC 2 in 6 weeks

The defensive security platform that replaces
Vanta + Burp + Nessus.

Continuous VAPT, AI-driven exploit verification, 35 audit-grade policies, and incident workflows for SOC 2 / ISO 27001 / NIS2 / DORA / DPDP / CERT-In — one tenant-scoped SaaS. Used by SaaS, fintechs, banks, and regulated SMBs worldwide.

No credit card · Self-host or SaaS · Region pick: US · EU · India · APAC

The problem

Compliance + security, today, is 8 vendors and 4 spreadsheets.

Vanta + Drata don't do VAPT

They monitor controls but you still pay a separate empanelled auditor for the actual penetration test — annual, ₹3-15 lakh, no continuous coverage.

Burp + Nessus don't map to controls

Findings live in PDFs nobody opens. Mapping CVE-2024-1234 to RBI CSF Annex-III §4 takes a security-eng plus a GRC-analyst, plus a week.

RBI / SEBI / CERT-In are India-specific

US tools don't speak DPDP Act §8(5), §70B 6-hour notification, or the empanelled-auditor format. You glue together three vendors.

The platform

Three pillars. One tenant. One UI.

🛠

VAPT (continuous)

40+ tools shipped: DAST, SAST, SCA, secrets, IaC, container, mobile, cloud (CSPM), SQLi probe, Nuclei, YARA, web fuzzer. Run on-demand or scheduled.

  • Findings auto-mapped to OWASP / CWE / CVE / EPSS
  • Sentinel AI verifies exploitability + drops PoC
  • One-click retest after fix
📜

GRC (audit-grade)

35 real policy templates (ISMS, KYC, AML, DPDP, ABAC, POSH …) — adopt → fill org tokens → publish → download PDF/DOCX. Auditor-ready.

  • Continuous control monitoring (CCM) every hour
  • Evidence Vault — WORM, encrypted, 7-year retention
  • Risk register, vendor risk, DSAR, training LMS
🌐

Global compliance · 19 frameworks

SOC 2, ISO 27001/27017/27018/27701, HIPAA, PCI-DSS v4, GDPR + UK GDPR, CCPA, NIST CSF + 800-53, FedRAMP, NIS2, DORA — plus IT Act, DPDP, RBI CSF, SEBI, IRDAI, CERT-In §70B.

  • Region overlays — pick US, EU, India, or APAC residency
  • Auditor portal with empanelment / firm-cover support
  • Sectoral routing (banking · payments · health · insurance)

Built-in tools

Replace 12+ point tools with one tenant.

All tools native, all results landing in the same finding tracker, all framework-mapped, all retestable.

🔍 Nmap-class port scan 💉 SQL Injection Scanner 🧪 Nuclei (10 templates) 🔥 Web fuzzer (ffuf) 🦠 Malware Classifier (+ ClamAV) 🧬 YARA rules 📡 DoS exposure (passive) 🌐 Subdomain enum (CT logs + Wayback) 🦴 Packet inspector (pcap) 🔐 Password + breach audit (HIBP k-anon) 👤 MFA factor audit 📊 UEBA anomaly score 🛡 WAF rule eval (OWASP CRS) 🕸 Network segmentation analyzer 🎣 Phishing simulator (4 templates) 🍯 Honeytokens (5 kinds) 🧠 Sentinel AI exploit chain 📨 DLP regex (PII / PCI / secrets) 🔓 Forensics triage 🗺 IOC store + STIX 2.1 ingest 🌊 Public OSINT feeds (5 sources) 🛰 DoH domain reputation 🖥 Endpoint agent receiver 🔐 HashiCorp Vault connector 🧰 OpenCTI bidirectional sync 🦅 Velociraptor VQL receiver 🦠 VirusTotal + AbuseIPDB 📚 35-template policy library 🎓 Awareness training LMS 📋 CERT-In §70B drafter + email submit

Frameworks

Pre-mapped to 19 standards.

SOC 2 · CC1-CC9
ISO 27001:2022
ISO 27017
ISO 27018
ISO 27701
ISO 22301 · BCMS
ISO 42001 · AI
HIPAA
PCI-DSS v4
GDPR + UK GDPR
CCPA / CPRA
NIST CSF v2
NIST SP 800-53
FedRAMP Mod
CIS v8
NIS2 (EU)
DORA (EU)
IT Act 2000
DPDP Act 2023
RBI CSF
SEBI CSCRF
IRDAI ICSG
CERT-In §70B

Compliancly vs the rest

Why teams switch from Vanta or Drata.

Compliancly Vanta Drata Burp + Nessus + Vanta
Continuous VAPT (DAST/SAST/SCA)✓ Native✗ Integrate✗ Integrate✓ via Burp/Nessus
AI exploit verification (PoC)✓ Sentinel✗ manual
India: RBI CSF / SEBI CSCRF / IRDAI✓ Built-in
DPDP Act 2023 + DSAR workflow
CERT-In §70B incident drafter✓ 6-hour clock
Empanelled auditor portal
Self-host on-prem✓ Docker compose✗ SaaS only✗ SaaS only✓ partial
Phishing simulator + LMSAdd-onAdd-on
35-template policy library + DOCXLimitedLimited
Threat intel: 5 OSINT feeds + STIX 2.1✓ NativeVirusTotal $
Honeytokens + WAF rule eval + DLP

Global pricing

Pay 1× for AI cost, 5× for the platform. Transparent.

Every plan bundles AI credit (Sentinel exploit verify, NL→policy generation, finding triage). The bundled credit is the floor — usage above the included credit is billed at $5 per $1 of underlying AI cost. No hidden seats. No "regulated tier" tax. Same product worldwide.

Free Trial

$0

$10 AI credit · 14 days · live test

  • 1 target URL · 2 users
  • 5 Sentinel scans / mo
  • $10 AI wallet — burns through real scans
  • Read-only policy library + framework view
  • No card required
Start free

Starter

$99/mo

$20 AI credit included

  • 5 assets · 5 users
  • 50 scans / mo · all VAPT tools
  • $20 AI credit (overage @ $5/$1)
  • Policy library: PDF + DOCX export
  • SOC 2 + ISO 27001 audit-pack
  • Email support
Start Starter
Most popular

Growth

$299/mo

$60 AI credit included

  • 25 assets · 25 users
  • Unlimited scans + Sentinel AI
  • $60 AI credit (overage @ $5/$1)
  • Phishing simulator + Training LMS
  • SAML SSO + SCIM provisioning
  • All 19 frameworks · regional overlays
  • Priority support · 24h SLA
Start Growth

Business

$999/mo

$200 AI credit included

  • 100 assets · 100 users
  • $200 AI credit (overage @ $5/$1)
  • Vault / OpenCTI / Velociraptor connectors
  • Audit-log export · 7-yr retention
  • Multi-region: US · EU · India · APAC
  • Dedicated CSM + 4h SLA
Contact sales

Enterprise · Custom

Self-host on-prem · VPC isolation · custom framework mappings · pen-test bundle · regulated-entity overlays (RBI / SEBI / IRDAI / CERT-In / NIS2 / DORA / FedRAMP).

Talk to sales →

💡 How AI billing works: Sentinel AI uses upstream LLM tokens. Underlying cost from OpenAI / Anthropic / your own gateway is charged through at . Example: a deep exploit-chain analysis costing $0.40 in tokens bills as $2.00 against your wallet. Wallet top-ups always available. No surprise invoices.

FAQ

Common questions.

Is Compliancly a CERT-In empanelled auditor?

No — empanelment is given to specific audit firms (KPMG, EY, SISA, etc). What we do: automate the data collection + report generation in CERT-In format so an empanelled auditor can sign off in days, not weeks. We also draft + submit §70B incident reports.

Can I self-host?

Yes. Docker compose, single-VM or k8s. Tenant data never leaves your boundary. Same image as our SaaS.

Do you train AI on customer data?

Never. AI inference is configured with noTraining: true against the upstream LLM gateway. Customer content is your data, full stop.

Indian data residency?

Mumbai region by default (ap-south-1). EU + US regions available. Cross-border transfers governed by EU SCCs / DPDP §16.

SOC 2 timeline?

Type I in 4-6 weeks once policies are adopted + controls are evidence-attached. Type II requires the 6-month operating window — Compliancly auto-collects evidence so you don't run a fire drill at audit time.

Do you compete with our pen-test firm?

No — we make their job 70% faster. Most engagements bill 60% on data collection. We collect, they verify + sign. Customers save ~50% of the audit fee.

What about RBI CSF / SEBI CSCRF?

Both pre-mapped. Our control catalogue covers all 60+ controls of RBI CSF Annex-II + III, plus SEBI's 2023 CSCRF for stockbrokers + DPs.

How fast to onboard?

5 minutes for SOC 2 / ISO posture. 1 day for full asset onboarding + first scan. 4-6 weeks to audit-ready Type I.

Open source?

Core platform is closed source. We open-source the SDK + integrations + ~5 supporting libraries on GitHub.

Compare to Sprinto, Tugboat, Scrut?

Sprinto/Scrut: India-first GRC, no native VAPT. Tugboat: SOC 2 only. Compliancly = GRC + VAPT + AI in one tenant. We replace 3 of these.

Stop paying for 4 vendors and 2 spreadsheets.

Free to start, 5 min to your first finding, audit-grade by default.

Start free → no credit card