Compliance that does not expire.
LivingGRC replaces the annual assessment scramble with continuous coverage, prioritized gaps, and evidence that is current when an assessor asks.
Built for regulated and defense-adjacent programsNIST SP 800-171 · CMMC · ISO/IEC 27001 · SOC 2
01 / The problem
The audit passed. Then everything moved.
Point-in-time GRC produces a snapshot. The snapshot is accurate for exactly as long as nothing changes, which is never.
Static GRC
- Assessment is an event. Twelve weeks of collection, one binder, then silence until next cycle.
- Evidence is gathered for the auditor, not from the systems. Much of it is stale before the report is signed.
- Coverage is asserted once, in a spreadsheet nobody reopens.
- Every new framework is a new project with its own parallel evidence hunt.
- Gaps surface at the worst possible moment: during the audit, or after the incident.
Living GRC
- Assessment is a readout. Posture is computed continuously, so the audit reads off what is already true.
- Evidence flows from the systems that produce it, with health tracked in eight explicit states. Unknown is never a pass.
- Coverage is recomputed when anything changes: a control, a mapping, an artifact, a scope boundary.
- A new framework starts from the controls you already run. Partial coverage on day one, gaps named the same day.
- Gaps surface as ranked work items with owners and dates, not as audit findings.
02 / What living GRC means
One control set. Every framework reads it.
The Living Control Set holds canonical controls independent of any framework. Requirements attach through versioned, rationale-bearing mappings. You maintain the middle of the chain once and read the ends off it.
- Obligation
- Requirement
- Mapping
- Control· maintained once
- Implementation
- Evidence
- Result
01
Continuous visibility
Coverage is recomputed from live signals and reported with the gate that produced it. Partial always comes with a reason you can act on: the evidence gate capped it, the artifact expired 40 days ago.
02
Prioritized action
Gaps rank by risk reduction and coverage gained, not by checklist order. The queue tells each control owner what to do next and what it buys the program.
03
Living evidence
Every artifact carries a health state: current, stale, expired, missing, and four more. The default is unevaluated, and confidence sits next to every claim rather than inside it. Nothing silently passes.
04
Defensible traceability
Every number walks back to a versioned mapping with a stated relationship, rationale, and strength. An assessor can see why a claim is made, and disagree with the record in front of them.
03 / How it works
Four stages. Then it runs.
Stage 1: Baseline
Define the organization, scope, systems, and applicability. Seed the controls you already operate. This is a project, and it is also the last one.
output: a scoped baseline with applicability decided, not assumed
Stage 2: Map
Attach framework requirements to canonical controls through mappings that carry relationship type, rationale, strength, and version. Approved mappings freeze; changes supersede, never overwrite.
output: a defensible mapping layer you can show an assessor
Stage 3: Connect
Point evidence collection at the systems that produce it. Manual attestation stays available and stays capped: it can never reach the assurance of continuous collection.
output: evidence with health, scope, and period on every link
Stage 4: Operate
Posture, gaps, and POA&M read off the chain from then on. Owners work a ranked queue. An assessor can walk any number back to the record behind it.
output: audits become readouts of what is already true
04 / Proof
We publish the engineering.
The claims above are design decisions you can inspect, not positioning. The data model is built, adversarially reviewed, and behaviorally tested before any interface ships on top of it.
- Missing data is never a pass.
- A mapping is a ceiling, not a result.
- Confidence sits next to every claim, never inside it.
- AI recommends. A named human approves. The database refuses anything else.
7
gates behind every coverage number
Mapping, applicability, implementation, evidence, scope, responsibility, assessment. The minimum wins, and the failing gate is named on the row.
8
evidence health states
From current to revoked. The default is unevaluated, because missing data is never allowed to read as a pass.
205
behavioral assertions on the data plane
Run against every schema change, alongside a mechanical sweep of all 124 writable tables.
34
defects found and fixed before any interface
Three adversarial review rounds plus a systematic sweep of the writable surface attacked the schema's own guarantees. Every defect is registered, fixed, and regression-tested.
54
API paths under a validated contract
65 operations specified in OpenAPI 3.1 before service code, so the interface can promise only what the platform enforces.
Numbers from the current build of the platform's data plane and API contract.
05 / Who it is for
Built for the people on the hook.
CISO and security executives
Defend posture to the board, the prime, and the assessor from the same numbers, with confidence shown next to every claim instead of buried under one score.
GRC and compliance leads
Run 800-171, CMMC, ISO 27001, and SOC 2 off one control set instead of four parallel programs with four evidence hunts.
Control owners and operators
Work a queue with owners, dates, and stated reasons. Not a binder, not a quarterly scramble, not a surprise finding.
External service providers
Operate across client environments with explicit responsibility matrices, inherited controls made visible, and evidence packages you assemble once.
A fit if
- You answer to more than one framework and expect to add another.
- Evidence collection burns weeks of engineering time every cycle.
- You inherit controls from providers and need that boundary explicit and auditable.
Not a fit if
You need one certificate, once, at minimum cost. Lighter tools do that well, and we will say so on the call.
06 / Objections
The objections, taken seriously.
“We already have a GRC platform.”
Most platforms store your program: documents in, dashboards out. LivingGRC computes it. Coverage is derived from mappings, implementations, and evidence health, so the number moves when reality does, and shows which gate moved it.
“Our spreadsheets work.”
They do, until the one person who understands them leaves, or a second framework arrives. The failure mode is not the spreadsheet; it is silent staleness. Here, stale is a tracked state that lowers confidence on its own.
“AI drafting compliance claims is a liability.”
Agreed. AI output lands as a recommendation with provenance that survives into exports. Approving mappings, closing findings, accepting risk, and finalizing assessments all require a named human, and the restriction is enforced in the database, not the interface.
“Continuous monitoring means continuous noise.”
Signals do not page you; gates do. A change surfaces when it moves a coverage gate, contradicts a standing assertion, or starts a regulatory clock. Everything else stays history you can query when you want it.
07 / Next step
See your program as it is.
Request a living GRC assessment: a working session against your current frameworks, your evidence flow, and the gaps a continuous model would surface first.
No deck. We map a slice of your real obligations to canonical controls and show you what the chain says about them. If lighter tooling fits you better, we tell you that instead.
Prefer to read first? Explore the approach