The GRC platform built by CISOs who got tired of duct-taping point solutions together - now unifying compliance, risk and audit on one source of truth.
Every security team knows the ritual. An auditor sends an email, and within hours three people are taking screenshots, digging through spreadsheets and pasting configuration settings into a shared folder. It is tedious, it is annual, and - the founders of Compyl argue - it is unnecessary.
Compyl is a governance, risk and compliance platform, the category the industry shortens to GRC. Founded in 2020 in downtown Manhattan by two former chief information security officers, Stas Bojoukha and Simon Shaddock, the company set out to replace the tangle of point solutions security leaders had been forced to stitch together.
The premise is straightforward: pull evidence directly from the systems a company already runs, map it once against a single library of controls, and let that one set of proof satisfy dozens of frameworks at the same time. Compyl connects to more than 125 tools - all integrations built in-house - and cross-maps controls across more than 70 frameworks, from SOC 2 and ISO 27001 to HIPAA, PCI DSS, GDPR and the NIST standards.
Layered on top is agentic AI. Compyl's software can draft evidence, score vendors and answer the security questionnaires that clog enterprise sales cycles. Its stated discipline is where it draws the line: "AI prepares the work. You approve what matters." Routine collection is automated; the judgment calls stay with people.
Figures compiled from public funding announcements and company materials, June 2025 - July 2026. Total funding to date is approximately $13.7M.
The market Compyl serves is under pressure from two directions at once. Regulation keeps expanding - a fintech might juggle PCI DSS and SOC 2, a health-tech firm HIPAA alongside it - while the teams responsible for all of it stay small.
Compyl cites an industry figure that 57% of security professionals describe their teams as understaffed. Its answer is not to ask those teams to work harder, but to stop them doing the same task six times across six disconnected tools.
"The products that were on the market at the time - and still are - are just not good enough. They're not embracing technology, they're too difficult to use."
Stas Bojoukha, Founder & CEOEnd-to-end system unifying governance, compliance, risk, third-party risk, audit and reporting on a single source of truth.
Automates evidence collection, policy management and control testing, cross-mapping controls across 70+ frameworks.
Live, automated evidence collection pulled straight from integrated systems - no more screenshot spreadsheets.
Agentic AI that drafts evidence, maps controls, scores vendors and answers security questionnaires, with humans in the loop.
FAIR-based assessment with Monte Carlo simulation that expresses cyber risk in financial terms, not heat-map colors.
Vendor due diligence, automated questionnaires and continuous scoring unified with the broader GRC program.
A sample of the 70+ frameworks mapped
Compyl operates in a crowded field. Vanta is known for getting a startup certified fast; Drata for workflow flexibility; OneTrust for sprawling privacy scope. Compyl positions itself for the messy middle - organizations running many frameworks across many systems with a long list of vendors.
Three choices set it apart. First, one control library priced by program depth rather than charging for each framework you add. Second, all 125+ integrations built in-house rather than pulled from a third-party marketplace. Third, an AI philosophy that automates the busywork but keeps humans accountable for decisions.
Unified pricing. Add frameworks without per-framework surcharges.
Data-first evidence. Proof pulled from systems, not typed by hand.
In-house integrations. All 125+ connectors owned end-to-end.
Human-in-the-loop AI. Agents draft; people approve.
Compyl's users are the CISOs, compliance leads, risk managers and audit teams inside regulated organizations - typically from mid-market into the enterprise. Public case studies include capital-markets firm Torstone and analytics company OpenGamma.
The company reports doubling its customer base annually across 2023-2025. The chart is an illustrative read of where its footprint concentrates by sector.
Sector weighting is approximate, drawn from Compyl's stated focus areas - not audited market-share data.
Tiered packages spanning audit prep, full GRC and enterprise, with pricing that scales by program depth rather than by framework count.
Sold directly to security and compliance teams inside regulated organizations preparing for or maintaining audits.
A partner network of solution providers, systems integrators and MSPs, launched to reach teams without in-house GRC staff.
A 20-year cybersecurity veteran who held CISO roles across financial services, real estate and energy - including regional lead work at Cushman & Wakefield. Certifications span CISSP, CISA and CISM. Born in Klaipeda, Lithuania; raised in Canada.
More than 15 years in security program management, including a decade at IBM and APAC CISO and global architect roles. Focused on turning technical requirements into operational execution across banking, insurance and utilities.
"Existing approaches - cobbling together various point solutions or spending hours coding and configuring complex solutions - were not just outdated but inherently flawed."
Stas Bojoukha, Founder & CEOFormer CISOs Stas Bojoukha and Simon Shaddock launch Compyl to unify fragmented GRC tools on one platform.
The company raises roughly $1.7M from investors including Armory Square Ventures and Contour Venture Partners.
Compyl expands integrations and continuous-monitoring capabilities as adoption grows.
A channel partner network arrives, with BJ Ferguson named Head of Global Channel Sales.
Venture Guides leads a $12M round; Compyl grows its agentic Copilot and opens a Boston office.
Armory Square Ventures, Contour Venture Partners, Brooklyn Bridge Ventures, Zelkova Ventures, Alpine Meridian Ventures.
Led by Venture Guides; partner Anton Simunovic joined the board. Existing seed investors also participated.
"A very responsive team with great support and incredible AI capabilities to assist with managing policies, compliance, and risk."
Mike Hamrah, Chief Security Officer - G2 review"When performance visibility becomes vendor-neutral, compliance becomes measurable."
Stas Bojoukha, Founder & CEOProfile compiled from public sources including company materials, funding announcements and press coverage, current to July 2026. Figures marked approximate should be treated as such.