THE LATEST

COMPANY / AI + ENTERPRISE

Complyance wants your auditors to arrive bored

The enterprise GRC company is putting AI agents to work on evidence, vendors and policies. Its most revealing customer story begins with a CISO who wanted nothing to do with AI.

Neal Bridges had heard enough about artificial intelligence. The chief information security officer at Query AI was frustrated with his GRC software, unimpressed by the promises surrounding it, and prepared to test alternatives. In Complyance’s account of his experience, the decisive moment was wonderfully unceremonious: someone uploaded a piece of SOC 2 evidence. The software reviewed it immediately and returned specific feedback. An argument about AI became a question about whether a document actually held up.

THE STORY IN 30 SECONDS
  • Complyance connects controls, risks, vendors, policies and customer trust.
  • Its AI agents handle repeatable work using configurable criteria; people retain decision checkpoints.
  • Customer stories show that connected workflows matter alongside the AI.

Bridges’s objection had been to tools that generated the appearance of progress. What persuaded him was useful analysis inside the workflow he already needed to run. That is a good place to begin with Complyance, an enterprise governance, risk and compliance company whose ambition is to make the administrative work surrounding an audit considerably less eventful.

“When it’s everywhere, it’s hard not to think it’s nowhere.”

NEAL BRIDGES · QUERY AI CISO · ON AI PROMISES

A privacy problem in enterprise clothing

Founder and CEO Richa Kaul arrived at the problem from the consumer’s side. In a Pathfounders interview, she connected her interest in privacy to a close friend’s identity theft following the Equifax breach. Individuals could adjust their habits, but companies still held the data. Her answer was to help protect those companies. Compliance, viewed from there, concerns the person whose information is sitting in somebody else’s system.

Complyance founder and CEO Richa Kaul seated on an orange sofa
Privacy has a face. Richa Kaul built her company around the enterprises entrusted with other people’s data. Company portrait.

Complyance’s operating legal entity, Securely Technology Limited, was incorporated in 2022. The company now reports serving more than 200 organizations. Its publicly named customers include Major League Soccer, CVS Health, Dropbox and Wellstar Health System. Healthcare, technology and manufacturing feature prominently in its positioning: places where a small compliance team can inherit a very large collection of obligations.

Five modules, fewer loose ends

The product has five connected modules: Controls, Policies, Risks, Third Parties and Customer Trust. Controls link requirements to evidence. Policies organize drafting, approvals and versions. Risks connect findings to treatment plans and accountable owners. Third Parties handles vendor diligence and monitoring. Customer Trust packages security information for customers and helps draft questionnaire answers from existing policies, controls and approved responses.

The connections are the useful part. Evidence can support multiple controls; a policy can explain a control; a vendor finding can become a tracked risk. Complyance advertises more than 100 framework templates, including SOC 2, ISO 27001 and HIPAA, alongside custom frameworks and integrations. A company can configure its own controls, fields, roles and risk matrices without asking a developer to rebuild the application.

Core AI provides assistance such as mapping evidence to controls. Specialized agents extend that foundation into evidence review, vendor scoring and policy drafting. Complyance says their outputs include reasoning, client data is never used to train models, and AI features can be disabled. Its funding announcement describes agents operating within defined workflows and checking with humans for decisions. Those boundaries matter when the output may eventually meet an auditor.

Complyance questionnaire interface showing questions, draft answers and Ready for review statuses
The questionnaire has acquired an assistant. Draft answers queue for review in Complyance’s product interface. The human still has a job.

The plumbing earns its keep

Consider Ebbo. Its evidence lived in SharePoint and its risk register in a spreadsheet. Maintaining the connections to its previous GRC platform had become work in itself. Complyance’s customer account describes automated evidence collection, cross-framework mapping and a shared risk environment after the switch. It reports a 90% reduction in manual evidence collection. The first thing to fail, in this story, was the arrangement of the work.

Lotto.com supplies a useful corrective to AI enthusiasm. Its published case study reports gap assessments falling to six weeks, roughly half the previous duration. Evidence could be linked once and reused across controls. Yet the results described came from rule-based workflow automation; AI agents were a planned next step. Any buyer impressed by an AI label should pause here. Connecting records and removing duplicate submissions can deliver value before an agent performs a single review.

TWO CUSTOMERS. TWO DIFFERENT MEASURES.
90%Less manual evidence collectionEbbo · company-published account
50%Shorter gap assessmentsLotto.com · approximate reported reduction

Reported customer outcomes, not a forecast for every deployment.

Buying back the working day

Complyance sells enterprise SaaS, with contract pricing arranged through sales or AWS Marketplace. Core AI is included and specialized agents are available according to need. Its materials advertise unlimited users, controls, frameworks, vendors and risks. The commercial proposition is that a growing compliance program should produce more useful work without requiring more administrative effort at every turn.

The buying process still requires organizational work. Complyance’s August 2026 platform guide describes six to twelve weeks for implementation, managed by its GRC team. In March it joined the AWS Partner Network and announced AWS Marketplace availability, giving customers a purchasing route through existing AWS arrangements. A $20 million Series A led by GV, announced in February, was earmarked for market expansion and further agents.

The market includes established enterprise systems such as Archer, ServiceNow and OneTrust. Complyance’s pitch emphasizes configurable execution and close implementation support. Its declared values include trust and customer partnership; its practical expression is working alongside teams to fit their processes. The fit is strongest where several frameworks, entities and departments share evidence. A narrow checklist may offer less opportunity to recover the effort of a platform rollout.

Bring a problem, watch it run

The company has taken that proposition into live GRC AI Labs. Its August recap describes New York practitioners co-building agents around real workflows, including escalation thresholds and guardrails. A September follow-up covers Boston and Chicago. Participants watched reasoning and actions as the agents ran. This offers a useful evaluation habit: bring a task whose annoying details you already understand.

Choose one workflow, record the time it consumes, and test the output against your own criteria. Check who can see the evidence and who approves the next action. Automation needs connected data, clear rules and someone responsible for the result; confusion merely travels faster without them. The interesting outcome is a compliance expert who spends less time asking where the document went, and more time deciding what it means.