Every product in the thirteen Market Segments before this one does something. This Market Segment is about proving it. Proof is demanded everywhere:
- A customer will not sign with a software company until it has seen a SOC 2 report: an audit showing how the company protects customer data.
- An American hospital cannot hold patient records without showing that it follows HIPAA, the US health-privacy law.
- A bank has to keep every message its traders send for years, and be able to produce them.
- A company's board wants a single number for how exposed the company is.
- A regulator wants the list of risks, the policies, the evidence that the policies were followed, and the record of who checked.
The software that holds all of this is called governance, risk and compliance, or GRC. It tracks controls: the rules and safeguards a company says it has in place, such as "every laptop is encrypted". GRC is covered here, in Industry Vertical 4, rather than with the finance department's software. Most of the controls it tracks are the security products of the earlier Market Segments.
Picture a 150-person software start-up in Chennai that sells HR software to American companies. It is trying to close its first big deal, with a large American bank. Before the bank signs, it asks for proof.
One deal, three kinds of proof. The start-up proves its controls with a SOC 2 report, using tools from companies such as Sprinto, Secfix, Hyperproof and Zania. The bank adds the start-up to its register as one more supplier, on platforms such as Archer, NAVEX and Corporater. And the bank's customer data and traders' messages are governed and kept for the regulator, with OneTrust, Relyance AI and Smarsh.
This Market Segment has many small companies and one big one, and almost all their Indian teams are in Bengaluru.
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.
This Market Segment has three sub-segments:
Getting the certificate: the companies that automate collecting evidence for audits like SOC 2 and ISO 27001. This is where India has its own contenders.
The register and the board: the large platforms that hold every risk, policy, supplier and audit finding in one place.
The privacy programme and the archive: privacy software, from the largest company in this Market Segment, and the archive that keeps a regulated bank's conversations.
Getting the certificate
Compliance automation, continuous control monitoring, framework-specific compliance
Back to the start-up from the start of this Market Segment. The bank wants its SOC 2 report. Ten years ago, getting one meant six months of collecting screenshots in a shared folder for the auditor.
The companies in this sub-segment turned that into software:
- The tool connects to the start-up's cloud account, code repository, HR system and laptops.
- It checks the controls every hour. This is called continuous control monitoring.
- It hands the auditor a live dashboard, instead of a folder of screenshots.
From screenshots to a live dashboard. A compliance tool such as Sprinto, Secfix or Hyperproof connects to the start-up's cloud account, code repository, HR system and laptops, checks every control every hour, and hands the auditor a live dashboard. Ten years ago, this meant six months of screenshots in a shared folder.
The same tools work for other standards, called frameworks. The best known is ISO 27001, the international standard for managing information security.
Sprintoa Bengaluru company, is India's contender in this market. Vanta and Drata made the market famous, and they are not covered in this Market Segment. Sprinto sells the automation and the continuous monitoring to software companies that need the certificate to close a deal.
Secfixa German company with engineers in Bengaluru, does the same for ISO 27001 and SOC 2, for smaller customers.
Hyperprooffrom the Seattle area with engineers in Bengaluru, sells evidence collection and workflow across many frameworks at once.
Zaniaa young Palo Alto company with engineers in Bengaluru, sells an AI agent that gathers the evidence and answers the customer's security questionnaire itself.
One company here specialises in one industry:
Clearwaterfrom Nashville with engineers in Pune, sells compliance software for the American healthcare system. It covers HIPAA and HITRUST, a security certification for US healthcare. It adds security risk analysis and supplier-risk management built for hospitals, and a managed security service on the side. (More on it in Market Segment 23.3, Healthcare data platforms and interoperability, in Industry Vertical 23, Health insurance and billing.)
The register and the board
Enterprise GRC platforms, integrated risk management, cyber risk scoring for boards, application-specific GRC, third-party risk
Now look at the other side of the deal from the start of this Market Segment: the bank. Above the certificate sits the register. It holds every risk the bank has identified, and every policy, control, audit finding and supplier, in one system. The bank's risk team, its internal auditors and its board all read it. The start-up, once it signs, becomes one more supplier in that register.
Archerone of the older names in enterprise GRC, has engineers in Bengaluru.
NAVEXfrom Oregon, also has engineers in Bengaluru. It comes at the same register from the compliance side. Its product combines policy management, hotlines where staff can report wrongdoing, supplier risk, and awareness training.
Corporaterwith engineers in Bengaluru, presents itself as a platform for governance, performance and risk management.
ISS-Corporatein Mumbai, is the governance arm of ISS, a firm that advises investors on how to vote at shareholder meetings. It sells the board its number: a cyber-risk score, compared with similar companies. Safe Security answers the same question from the other end. (More on it in Market Segment 4.11, Vulnerability management and penetration testing.)
Two smaller companies specialise:
ToggleNowfrom Hyderabad, does GRC for a single system: SAP, the software many large companies run their finance and operations on. SAP has its own access rules and its own threats. One rule is segregation of duties: no single person should be able to both create a supplier and approve a payment to it. (More on SAP in Market Segment 10.1, ERP and business accounting software, in Industry Vertical 10, ERP and business automation.)
SecureOSa young company with engineers in Bengaluru, does only the supplier register, called third-party risk management. It also appears in Market Segment 4.12, Threat intelligence and attack surface management, because assessing a supplier now often uses a scan of the supplier from outside.
One company covered mainly in another Market Segment covers people rather than systems:
LRNsells Catalyst, a platform for ethics and compliance training and for the company's code of conduct. This is the part of the register about people's behaviour, not systems' controls. (More on it in Market Segment 43.5, Online legal services, in Industry Vertical 43, Legaltech.)
The finance department's own compliance software is covered in Market Segment 11.4, Regulatory compliance software (in Industry Vertical 11, Finance and accounting software). There, Diligent keeps the board's papers and Everbridge keeps the crisis plan. The two Market Segments meet at the board.
You're reading as a guest. Sign in free to follow links for five minutes, once an hour.
Sign in
The privacy programme and the archive
Privacy management, consent, data mapping, AI governance, communications archiving and supervision
Back to the bank from the start of this Market Segment. It holds millions of customers' personal data, and its traders send thousands of messages a day. The law has rules for both.
OneTrustis the largest company in this Market Segment. It has engineers in Bengaluru. It began as the consent banner on websites, after Europe's privacy law. It grew into the whole privacy programme: data mapping, data subject requests, and consent and preference management. It has since become a general GRC and third-party-risk platform, with AI governance added. It leads the privacy market described in Market Segment 4.8, Data security and privacy. It is covered here because the privacy programme is now one module among many in its product.
Relyance AIa Bengaluru team, is the younger version of the same idea. It keeps a live map of where data flows, including into AI models. Privacy compliance and data security are read off that map automatically.
Smarsh is a different kind of compliance:
Smarshwith engineers in Bengaluru, keeps the record of what was said, for the regulator. Regulated financial firms must archive every email, chat, text and call their staff send, and check them for misconduct. Smarsh captures and stores those communications. Lately, it also links that archive to the cyber-compliance evidence in the rest of this Market Segment. Of its rivals, only Proofpoint, which also archives, is covered in this collection. (More on it in Market Segment 4.1, Email security and anti-phishing.)
The questionnaire answered by a model.
The dullest work in this Market Segment is text in and text out. A supplier fills in a security questionnaire for every customer, and an auditor asks for the same evidence every year. The newest companies here use an AI model to do it. The model reads the policies and the control evidence, and drafts the answers. Zania is the example here, along with the automation inside OneTrust.
So the deal from the start of this Market Segment runs through all three sub-segments. The start-up proves its controls with a SOC 2 report. The bank adds the start-up to its register as a supplier. And the bank's own customer data and conversations are governed and kept for the regulator.