Breaking
SCYTALE named AWS Rising Star Partner of the Year, EMEA 2025 $15M acquisition of AudITech closes, adding SOX ITGC to the platform 80+ frameworks supported - SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS 4.8/5 on G2 across roughly 570 verified reviews Thousands of audits run across 44 countries Customers include Deel, Intel, Fiverr, Monday.com, Payoneer
Company Profile / Compliance Automation

The Company That Made Audit Season Boring

Meiran Galis spent years at EY watching startups treat security audits like a fire drill. Scytale is his bet that compliance can run in the background instead of eating a quarter.

Every software company that wants to sell to a bigger software company eventually gets the email. It asks for a SOC 2 report, or an ISO 27001 certificate, or a 120-line security questionnaire, and it usually arrives right as a deal is about to close. For years the standard response was panic: a scramble to screenshot settings, chase down policies nobody had written, and pray the auditor was in a good mood. Scytale was built to make that email a non-event.

Scytale is a governance, risk and compliance platform - GRC, in the trade - headquartered in New York with a large engineering base in Tel Aviv and offices scattered across Prague, Lisbon and South Africa. Its job is narrow and unglamorous, which is exactly why it works as a business: it automates the evidence-gathering behind security audits and pairs that software with human experts who know how the audits actually run. The company says it supports more than 80 frameworks and has helped run thousands of audits across 44 countries.


01 / The OriginA grudge from the EY risk desk

Founder Meiran Galis did not arrive at compliance by accident. He holds a PhD in information systems, carries the CISM security credential, and spent the early part of his career at EY advising companies on technology risk. That is where he watched the same movie on repeat: capable engineering teams losing weeks of momentum every time an enterprise buyer asked them to prove they were secure. The security was often fine. The proving was the problem.

Galis started Scytale around 2020 on a simple premise - that compliance should be a continuous, mostly automated background process rather than an annual fire drill. The name is a small in-joke for the security crowd: a scytale is an ancient Spartan device, a rod used to wrap a strip of parchment and encode a message. Old-school cryptography, rebuilt as a SaaS dashboard.

Compliance shouldn't slow companies down - it should propel them forward. Meiran Galis, Founder & CEO

02 / The ProductSoftware that ships with a human

The platform does the tedious parts. It connects to the tools a company already runs - cloud accounts on AWS, identity through Okta, code repositories, HR systems - and pulls evidence automatically instead of asking someone to take screenshots. It monitors controls continuously, so a setting that drifts out of compliance shows up as a red item on a dashboard rather than a surprise during the audit. When a control breaks, the platform flags it with a "fix now" prompt.

Scytale compliance dashboard showing SOC 2 and ISO 27001 audit progress
The cockpit. Scytale's dashboard tracks two audits at once - a SOC 2 Type II sitting at 16% approved, an ISO 27001 at 50% ready - with a control-health donut that turns audit prep into a live readout instead of a spreadsheet.

What separates Scytale from the tidy dashboard crowd is the second half of the offer: a dedicated GRC expert assigned to each account, plus a network of auditors who run the formal reviews inside the same system. Buyers on review sites consistently single this out - the software gets you 80% of the way, and a person who has seen your specific auditor before handles the awkward last 20%. In a category that likes to sell "fully automated," Scytale sells "automated, and someone picks up the phone."

What you can actually do with it

SOC 2ISO 27001 ISO 42001GDPRHIPAA PCI DSSSOX ITGCCustom

Beyond evidence collection, the platform runs vendor risk management, automates user access reviews across connected systems, manages security policies, and coordinates penetration testing. Two features do real work in sales cycles. The Trust Center is a live, customer-facing page a company can send to a prospect instead of filling out a spreadsheet - here is our posture, verified, look for yourself. And the AI security questionnaire tool drafts answers to the inbound 120-question forms that otherwise eat an engineer's afternoon.

Scytale audit management view
The auditor's side. Built-in audit management keeps evidence, reviewers and open items in one place, so the back-and-forth that used to live in a hundred emails happens inside the tool.
Scytale vendor risk management view
The supply-chain ledger. Vendor risk management scores and monitors third parties in one view - because these days your auditor cares about your vendors' vendors too.

There is also a quieter payoff to keeping all of this in one place: the frameworks start to share work. A control you proved for SOC 2 often satisfies an ISO 27001 or GDPR requirement too, and Scytale cross-maps them so a company is not re-collecting the same evidence five times. For a team juggling several audits at once, that overlap is the difference between compliance as a rolling project and compliance as a permanent second job.

80+
Frameworks supported
44
Countries with audits
4.8
G2 rating / 5
$15M
AudITech acquisition

03 / The CustomersWho is actually logging in

Scytale's core customer is a security-conscious software company that needs its first SOC 2 to close upmarket deals, then keeps adding frameworks as it grows. The published customer list has grown well past the seed-stage tier: it includes Deel, Intel, Fiverr, Monday.com, Payoneer, Taboola, Kaltura and Pagaya, among others. Deel's CTO, Yaron Lavi, sums up the pitch in a testimonial on the site - the platform "streamlined our audit readiness process."

Yaron Lavi, CTO of Deel
The reference customer. Yaron Lavi, CTO of payroll unicorn Deel, is quoted on Scytale's site - a useful logo to have when your buyer is another fast-scaling engineering team.

The business model follows the frameworks. Scytale is B2B SaaS, sold as a recurring subscription usually bundled with the expert service, and priced by company size and the number of frameworks in play. Land a startup on its first SOC 2, expand it to ISO 27001 and GDPR, then - since the 2025 acquisition - follow it upmarket into enterprise SOX controls. Compliance is a grudge purchase that renews every year, which makes it an unusually sticky thing to sell.

04 / The FieldWhere it sits against Vanta and Drata

The compliance automation category is crowded and competitive - Vanta and Drata are the best-known names, with Secureframe, Sprinto and others filling out the field. On raw connector count, the giants win: Vanta advertises 400-plus integrations, Drata 300-plus, Scytale roughly 100. Scytale's counter-argument is service depth. Rather than out-integrate the market, it leans on bundled human expertise and a built-in auditor network, and it has quietly climbed G2's ratings on the back of that choice.

G2 customer rating (out of 5)
Scytale4.8
Drata4.7
Vanta4.6
Secureframe4.6

Ratings are approximate, drawn from public G2 grids in 2026 and subject to change. The gap between vendors is small - the useful signal is that a smaller challenger holds its own on satisfaction.

05 / The MoveBuying its way into the enterprise

In June 2025 Scytale made its biggest strategic move to date, acquiring AudITech - an automation platform for SOX IT general controls - for a reported $15 million. AudITech's roughly ten employees, including its co-founders, joined Scytale, and its technology extended the platform from startup-grade SOC 2 work into the change-management and access controls that public-company audits demand. It is the standard bottom-up playbook: win the small end of the market, then buy the capability to follow customers as they grow toward an IPO.

The recognition has followed the expansion. In late 2025 Scytale was named AWS Rising Star Partner of the Year for Technology in EMEA at re:Invent, and it has picked up G2 leader placements and a Frost & Sullivan customer-value nod. For a company that sells the least exciting product in software, that is a fairly loud few years.

The short version of the story

2020-2021
Scytale is founded
Ex-EY risk advisor Meiran Galis launches the platform to automate startup security compliance.
2023
Trust Center and platform expansion
Customer-facing trust pages, vendor risk and access reviews broaden the product.
2024
AI features and pen testing
AI questionnaire responses and managed penetration testing arrive.
2025
AudITech acquisition + AWS award
A $15M deal adds SOX ITGC; AWS names Scytale a Rising Star Partner of the Year in EMEA.
2026
GRC leader recognition
Named a G2 GRC leader and a Frost & Sullivan customer-value honoree, now spanning 80+ frameworks.

06 / The ReadWhy boring is the point

The interesting thing about Scytale is not that it uses AI or that it has a slick dashboard - most of its rivals can claim both. It is the wager underneath: that the winning move in compliance is not more automation but the right split between machine and human. Software collects the evidence and watches the controls; a person handles the auditor, the edge cases and the moment a founder panics two weeks before a deadline. That is a less futuristic story than "agentic GRC," and probably a more accurate one.

Where would this not work? Companies with sprawling, long-tail SaaS stacks may still hit the integration ceiling and want the deeper connector libraries of the larger players. And the human-expert model that customers praise is also the harder thing to scale - it is easier to add another API than another seasoned GRC consultant. For now, the bet is holding: a five-year-old company selling regulatory paperwork has turned audit season into something close to routine.