A company can have an immaculate security policy and a broken security process. At Summit Utilities, the written requirement was sound. An encryption gap nevertheless appeared after a step in a new process was missed. According to the utility's account, its existing security tools did not catch it. Nine Anecdotes plugins, feeding a mix of standard and custom monitoring rules, did. The discovery makes a sharp opening for a story about compliance software: the interesting part is not the certificate on the wall. It is the thing the certificate failed to notice.
- Anecdotes connects to enterprise systems, collects live evidence and maps it to controls, frameworks and risks.
- Customers include security and GRC teams at Axonius, WELL Health, Bitsight and Summit Utilities.
- Its wager is that structured records, with provenance and timestamps, make both audits and AI agents more useful.
- Pricing is by request; its public offer lists unlimited frameworks and 230+ native plugins.
The founders knew the less cinematic version of this problem. Before starting Anecdotes in 2020, Yair Kuznitsov and Roi Amior had spent hours pulling evidence for GRC teams. Their colleague Eitan Adler joined as a co-founder and original CTO. The recurring request was familiar to anyone who has endured an enterprise audit: export the access list, capture the cloud setting, find the policy approval, attach it to the correct control, repeat next quarter. Kuznitsov later described the irritation as evidence that was already out of date by the time it had been collected.
The screenshot has a short shelf life
Anecdotes' first answer was practical. Connect to the systems where the facts live and pull records continuously. Its Data Engine now advertises more than 230 native plugins and more than 1,000 predefined evidence artifacts. It takes inputs from tools such as AWS, Okta, GitHub and Jira, then normalizes the data so a compliance team can inspect it, write a test against it and reuse it. The company also offers no-code custom pipelines for the parts of an enterprise stack that never resemble a standard demo.
That architecture matters because an audit file is a poor substitute for an operating record. A screenshot may show one moment. A structured record can carry its source, collection time, item count and history. A single record may support requirements under SOC 2, ISO 27001 and HIPAA, provided the mapping is right. The same record can tell a risk manager that a control changed yesterday. The trick is less glamorous than AI: preserve the data well enough that the next layer can be trusted.
The software grew outward from there. Anecdotes now sells applications for compliance, enterprise risk, policies, user access reviews, audit work, trust sharing and third-party risk. Its AI agents can inspect policy language against system evidence, detect a control gap, notify an owner, open a task and request fresh evidence after a fix. The company calls this agentic GRC. A plainer description is that it tries to join the steps between finding a problem and proving the problem was fixed.
“We had the right policy, but the process wasn't working like we thought, and our security tools weren't catching the problem.”Aaron Baillio, Summit Utilities
The last manual handoff
Anecdotes' customer stories are most persuasive when they expose a remaining chore. Axonius was already collecting evidence automatically, but its auditor, Schellman, used AuditSource. The Axonius team still had to download the records and upload them to the auditor's platform. Anecdotes and Schellman built a direct integration with a quality-control step. Axonius reported a 60% faster audit process. Automation, in this case, meant repairing the seam between two systems rather than replacing the auditor.
WELL Health presented a different kind of seam. Acquisitions had left subsidiaries with distinct requirements and habits. Instead of forcing each business unit into one identical setup, WELL used separate workspaces under a common oversight layer. Its case study says eight units were onboarded in weeks and 38 plugins now collect and test data continuously. WELL reports a 73% reduction in manual GRC work. These are customer-reported outcomes, with the usual caveat that another organization will arrive with another stack and another audit calendar.

The market for a less convenient truth
Anecdotes sits between two familiar markets. Traditional enterprise GRC suites can hold sprawling control libraries and approval workflows, but often depend on people to feed them current evidence. Lighter compliance automation tools have made first audits much easier for young software companies. Anecdotes aims at the awkward middle and beyond: mature organizations with subsidiaries, custom controls, several frameworks, auditors with preferred tools and data that should move without being chased. ServiceNow IRM and AuditBoard are enterprise alternatives; Vanta and Drata are automation alternatives. Those labels are imperfect, but they explain the buyer's choice.
The company sells a subscription platform to enterprises through a demo and request-pricing process. Its pricing page says the offer includes unlimited frameworks, all 230-plus native plugins, custom integrations, GRC modules and AI features. It does not publish a dollar amount. A buyer can therefore compare the architecture in public but must ask for a proposal to compare the bill. The more relevant cost question may be how much engineering time, audit preparation and integration upkeep the platform actually removes after rollout.
Start with the repeated requests: hours spent pulling evidence, time between a control failure and discovery, the number of handoffs to auditors, and the share of systems a connector can truly cover. Those figures make a sharper business case than a count of AI features.
Funding gave Anecdotes room to widen the bet. A $5 million seed round in 2021 was followed by a $25 million Series A in 2022. Its Series B began with $25 million in 2024 and added $30 million in 2025, bringing disclosed funding to $85 million. In 2025 the company launched AI agents with Google Cloud, including Policy Guardian. In 2026 it announced FedRAMP 20x Moderate certification using its own platform. Each development serves the same sales argument: evidence is useful only when it can survive inspection, whether the inspector is an auditor, a customer or a federal program.
What the reader can steal
You do not need to buy Anecdotes to borrow the method. Pick one stubborn control, name the system of record, preserve the timestamp and source with every export, and define what would count as a failed test. Connect that failure to a named owner and require a fresh reading after remediation. Map the same evidence to a second framework only when it really proves the second requirement. This is a modest experiment, which is precisely why it can expose the limits of a grand compliance program.
It also reveals where this approach has a boundary. An organization with few systems and one annual certification may not recover the work of installing an enterprise data layer. A missing connector, an unreliable source system or a badly written test can turn continuous monitoring into continuous noise. And an AI agent can move a task along without owning the judgment of whether the control is adequate. The strongest version of Anecdotes' idea keeps a human accountable for that decision while making the underlying facts less elusive.
That returns us to Summit's encryption gap. The policy was there. The assurance was not. Anecdotes made the mismatch visible because it looked at what the systems were doing, rather than what the document said they ought to do. A company named Anecdotes has built an unusually literal business on the proposition that a good story needs a record behind it.