Not loaded
Made in India
?
▾

GrcAI — Your Local AI Assistant

Runs 100% on your device · No API keys · No data leaves your browser

🔒 100% On-Device 📡 Works Offline 🆓 No API Keys ⚖️ SOX ITGC Workpaper 📋 SOC Report AI ⚔️ SOD Detection ⚡ SAP ABAP Scanner 🔀 10+ Swappable Models ✦ Transparent Reasoning 📄 Compliance PDF Export ⚔️ AI Red Team Audit 📂 Workpaper Autopilot 🧭 Exception Triage ⬇ Offline Model Vault
📋
SOC Reports
Understand SOC 1, SOC 2, CUECs, exceptions and auditor opinions
🔒
ITGC Testing
Logical access, change management, backup, operations controls
⚔️
SOD Analysis
SAP, Oracle, D365 rulesets — conflicts, risks and remediation
⚖️
Frameworks
COSO, COBIT 2019, ISO 27001, NIST CSF 2.0, SOX §404
⚠️
Audit Exceptions
How to respond, assess risk, and document compensating controls
☁️
Cloud Controls
AWS, Azure, GCP shared responsibility and cloud-native controls
Audit tools — jump straight in
NEW
⚔️Audit Prep
The AI plays a Big 4 auditor and attacks your control before they do
NEW
📂Workpaper Autopilot
One control in — PBC list, ToD + ToE procedures, sampling and QC out
NEW
🧾Workpaper Composer
Your blank form comes back filled, with a citation on every value
NEW
🧭Exception Triage
Deviation → severity call, root cause and a 5 C’s finding write-up
NEW
📣Proposal Builder
Five questions in — a drafted proposal, a PDF and an editable PowerPoint out
NEW
🔮Universal Intelligence
Any question, or load your files and interrogate them — with the page, sheet or slide behind every answer
NEW
🔒DPDP Assessment
Privacy evidence in — exceptions, contradictions and a 20-column workpaper out
🛡️SOD Analysis
ERP extracts scored against a licensed rule engine — SAP, Oracle EBS, Fusion
📊Data Analysis
Ticket exports → a SOX ITGC workpaper with PCAOB statistical sampling
PCAOB explained
Bridging letters
ITGC → COBIT mapping
SOX §302 vs §404

Pick a model above and click ⚡ Load in browser to start — or ⬇ Download & run offline to keep working with no internet at all.
Use + below to attach an ERP extract or a document, and ⚖️ 2 responses to get two independent answers and pick the better one. The Engine switch stays on Private / On-device until you change it yourself.

Two independent answers per prompt — compare and choose
📝 AI Document Analyzer PCAOB & ISA Multi-File Deep Analysis On-Device
Upload one or more SOC reports, policies, or procedures (PDF · DOCX · TXT · CSV · XLSX). Summarize them, or run a deep standards analysis that maps controls, exceptions and gaps against PCAOB auditing standards and IAASB ISA requirements — all on your device.
🧾 Writing a memo from this report rather than reading it? Workpaper Composer takes the report as evidence, a memo you have already completed as the shape to follow, and your blank template — and returns it filled, with the source quoted against every value.
1 — Upload Documents (optional — or paste below)
📂 Drop files or click — multiple supported SOC reports · Policies · PDF · DOCX · TXT · CSV · XLSX
Document Type
Output Format ✨ Premium
Paste Text (or rely on uploaded files above)
🔬 2 — Deep Standards Analysis
Map the uploaded document(s) against professional standards. The AI assesses control design, testing coverage, exceptions, complementary user-entity controls (CUECs) and gaps — and cites the specific standard paragraphs.
Standards to assess against (select any)
⚖️ PCAOB — AS 2201 · 2110 · 1215
🌐 IAASB ISA — 315 · 330 · 402 · 500
🛡️ SOC / SSAE 18 · ISAE 3402
🏛️ COSO 2013
Analysis Focus
Tip: for multi-document, long-context analysis, load GrcAI Max (Llama 3.1 8B) or GrcAI Pro (Phi-3.5) above for best results.
🎯 IT Risk Assessment CVSS · FAIR ScoringCOSO · COBIT · NIST
Complete the form below. Generates a scored risk report with CVSS/FAIR likelihood-impact matrix, findings, and COSO/COBIT/NIST compliance mapping.
📄 Asset Details
Asset Name *
Asset Type *
⚠️ Threat & Vulnerability
Threat Description *
Vulnerability *
Existing Controls (optional)
🔴 Impact Classification
Business Impact *
Data Classification *
Users / Systems Affected *
🏗️ IT Application Risk Profile
Click a level for each of the 15 factors below. This drives the likelihood score.
◇ Not Evaluated (0/15 factors)
📋 Notes / Rationale
Live Risk Score
--
/25
--
Complete fields to calculate
🎨 Image Generation
Diagrams, SAP screens and enterprise visuals render instantly. Photographic and illustrative images use a local image model that runs on your own device.
Image generation now lives in the GrcAI Visual Intelligence Studio just below. Pick a template on the left, or describe what you need.

For a photographic or illustrative image, open General Creative → Create an Image. The first use offers a one-time licensed model download; after that it runs offline on your device.
OR analyze an existing image
🔍 Image → Data Extraction & Vision No GPU NeededAny Browser100% On-Device
Upload any image and Extract Data from Image — pick an extraction mode (Invoice, Audit evidence, SAP/Access log, Ticket, Table→JSON, Key–Value) and GrcAI reads the text and pulls out structured fields with a Trust Layer (OCR confidence %, low-read warnings, time taken) — deterministic, so it never hallucinates. 100% on-device: the image never leaves your browser. Or load GrcAI Vision Lite to ask questions about an image.
📁
Click to upload or drag & drop
PNG · JPG · GIF · WEBP
Preview
📊 Data Analysis SOX ITGC WorkpaperPCAOB Sampling
Upload ServiceNow / JIRA ticket exports to auto-generate SOX ITGC workpapers with PCAOB statistical sampling. Also supports CSV, JSON, XLSX, TXT, PDF for general analysis.
Upload Files
📂 Drop files or click — multiple supported CSV · JSON · XLSX · TXT · PDF
✅ Ticket data detected SOX ITGC analysis available — enter population below
⚖️
SOX ITGC Analysis — PCAOB Statistical Sampling
Validates every ticket, determines sample adequacy, generates SOX documentation with exception detail
Total User Population *
Total requests/users for the period — not just the uploaded sample. Used for PCAOB sample size calculation.
PCAOB Required Sample
—
Enter population to calculate
or paste directly
Question
High-risk exceptions?
Pass rate?
Most exceptions?
Trends?
Risk posture?
💻 Code Review & Generator 15 Languages On-Device Security Scan
✨ Generate Code — describe what you need
💡 Best for code: — purpose-built for code, never stalls on reasoning. Reasoning models (Ultra/Ultra+) can be slow here.
▶ Run & Test
stdin / test input:
Click ▶ Run Code to compile and execute.
Ready
🔍 Review & Debug Code
🖼 Long program? Select all screenshots at once (in page order) — or upload a Word/PowerPoint document and every embedded screenshot is extracted in document order. Everything is read on-device, stitched in order, and repeated lines from scrolling are removed automatically.
⚠️ Potential Credential Leaks Detected
Never hardcode secrets. Use environment variables or a secrets manager.
▶ Run & Test
stdin / test input:
Click ▶ Run Code to compile and execute.
Ready
⚡
SAP Dev · Security & Compliance AI SAP-Native Rules SOX · SOD · ITGC On-Device
ABAP · Fiori/UI5 · BTP · HANA SQL · Integration Suite — authority checks, SOD conflicts, hardcoded credentials
SAP Technology — auto-detected, change to override
🖼 SE38 / SE80 program longer than one screen? Select all screenshots at once (in page order), or upload a Word document containing them — every embedded image is extracted in document order. Read on-device, stitched in order, repeated lines removed, and SAP GUI status-bar text after the final ENDFORM. / ENDMETHOD. stripped.
Run:
Paste code or upload — up to 6,000 chars scanned
Scan Results
▶ Run & Test
stdin / test input:
Click ▶ Run Code to compile and execute.
Ready
📊
Power BI Dashboard Generator On-Device Export Ready
Upload CSV / XLSX / JSON → AI generates insights, KPI cards & charts → export Power Query M code, DAX measures & clean CSV directly into Power BI Desktop
Upload Data Files — multiple files supported for joining tables
📂
Drop files or click to upload
CSV · XLSX · XLS · JSON  ·  Multiple files for join/append
Dashboard Focus (optional — leave blank for auto-analysis)
📊
Upload data to generate your dashboard
The AI will create KPI cards, bar charts, trend lines and pie charts
then generate ready-to-paste Power Query M code and DAX measures
⚔️ Audit Prep AI Red Team 7 Frameworks Unique to GrcAI
The AI impersonates a Big 4 external auditor and stress-tests your control before real auditors do. Surfaces deficiency risks, missing evidence, and a hardening roadmap — no other AI assistant offers this.
1 — Select Compliance Framework
SOX §404
SOC 2
ISO 27001
NIST CSF
COBIT 2019
GDPR
PCI DSS
2 — Auditor Perspective
⚔️ External Auditor
🔍 Internal Auditor
⚖️ Regulator
3 — Describe Your Control, Policy, or Process
📂 Workpaper Autopilot AI Audit Manager ToD + ToE Unique to GrcAI 🏷 build 2026-07-08.6
Describe one control — the AI performs a senior manager's planning-stage work: a PBC evidence-request list, separate ToD and ToE procedures with audit reasoning & pass/fail decision rules, an evidence-traceability matrix, contradiction detection, honest planning-confidence scoring, and a PCAOB inspection-readiness check. Conclusions stay ⏳ pending until evidence is evaluated — the workpaper never claims testing it hasn't done.
1 — Compliance Framework
SOX §404
SOC 2
ISO 27001
NIST CSF
COBIT 2019
ITGC
PCI DSS
2 — Control Frequency
3 — Testing Phase
🔬 Both
📐 Design
⚙️ Operating
4 — Describe the Control to Test
🧾 Workpaper Composer Evidence → Working Paper Unique to GrcAI
Give it the blank document, a completed example of the same document for a different subject, and the evidence. It reads the evidence, fills the blanks in the template’s own file — every sheet, every section — and cites the evidence behind each value. The completed example is used for shape and phrasing only: its names, dates and findings belong to another engagement, and anything that leaks from it is caught and held back. Gaps stay gaps. Nothing is uploaded.
1 — The blank document to fill (.xlsx or .docx fills in place; .txt / .md export as Markdown)
2 — A completed example of the same document (optional, strongly recommended)
3 — Evidence (PDF, Word, Excel, CSV, text — as many as you have)
4 — What is this document about? (the subject, so a leaked name is obvious)
Run this on the machine that fails — it says exactly which stage breaks.
No files to hand? Try it with these. Fictional, and built so the leak check has something real to catch — the completed example is a different client.
SOC 1 memo (Excel): 1 · blank template  ·  2 · completed example  ·  3 · evidence
ITGC workpaper (Word): 1 · blank template  ·  2 · completed example  ·  3 · sampling note  ·  3 · ticket export
Structured workbook (dropdowns, comments, formulas, named ranges): 1 · blank template  ·  2 · last year, completed  ·  3 · this year's evidence
Use this set to see the template's own rules being honoured — the Result cell is a Pass/Fail/N/A dropdown, Coverage % is a formula that must not be overwritten, and last year's answers are shown as shape, never copied.
🧭 Exception Triage Deviation → Finding 5 C's + Severity Unique to GrcAI
You found an exception in testing — now what? The AI classifies its severity (deficiency / significant deficiency / material weakness), reasons through root cause, drafts the finding in Condition–Criteria–Cause–Effect–Recommendation form, and proposes remediation, compensating controls, a management-response template and the ICFR aggregation impact. The finding write-up a senior spends an afternoon on — in seconds.
1 — Compliance Framework
SOX §404
SOC 2
ISO 27001
NIST CSF
COBIT 2019
ITGC
Internal Audit
2 — Quantify the Deviation (optional — sharpens the severity call)
3 — Control Being Tested
4 — What Went Wrong (the exception you observed)
📣 Proposal Builder Nothing invented
Answer five short questions and GrcAI drafts a full business proposal — executive summary, approach, scope, team, timeline and next steps — with illustrations, ready to print as a PDF. Every figure and credential in the draft is checked against what you supplied; anything the model added on its own is flagged for you to verify before you send it.
🔐 DPDP Compliance Assessment On-Device Evidence-Grounded Deterministic Controls
Assess an organisation against India's Digital Personal Data Protection regime from its own evidence. Conclusions are produced by deterministic predicates, not by a language model: the same evidence gives the same result every time, and every result cites the evidence fact behind it. Read the scope limitation before using the output. The DPDP Rules text could not be retrieved from an official source, so no statutory obligation can currently be tested — controls whose standard is a statute report NOT TESTED, never a pass. What this does test today is internal consistency: whether the notice matches what is collected, whether withdrawal stopped processing, whether retention matches policy.
Statutory testing activates by importing the official instruments. Use Import legal instrument below to supply the Gazette PDF text for the DPDP Act, the DPDP Rules and their commencement notifications. Each import is hashed, and a named person must attest that they compared it against the official source before it becomes law inside this tool — the system cannot verify its own legal sources, because everything it could compare them against is the same document. Once verified, the AI can propose obligations from the text; each one still needs a person to accept it.
▶ Run an assessment
The worked example contains no real personal data.
⚖ Legal pack
⚖ Obligation review bench
The AI reads a verified instrument and proposes obligations. It never activates one. Every proposal must quote the instrument verbatim — a quotation that is not literally in the source is rejected automatically — and every acceptance records a named person, the URL they opened and what they checked. A verified document does not make a model's reading of it correct: source authority and obligation interpretation are verified separately.
📜 The 23 controls — what this assessment tests, and what each one needs ▾
Loading the control register…
🔮 Universal Intelligence
checking… Evidence-grounded On-device by default

Ask anything. Bring anything.

Any subject — science, law, finance, code, SAP, audit, privacy — or load your own files and interrogate them. Conclusions that rest on your evidence carry the page, sheet or slide they came from, figures are computed from the actual cells rather than written by the model, and a reference that does not resolve to a file you loaded is marked as unverified instead of being left to look real.

Open question
Significant deficiency vs material weakness — who decides?
With evidence
Summarise my files and name the top three concerns
Across files
Does the evidence comply with the policy?
Computed
Percentages, breakdowns and duplicates from a sheet
Gaps
What is missing from my evidence?
Code
Security review, line by line
Evidence Drag files here — PDF, Word, Excel, PowerPoint, CSV, JSON, images, code
Engine Answer Enter to send · Shift+Enter for a new line
🛡️ AI Segregation-of-Duties Analysis 100+ Rule Engine SAP & Oracle Transactional Conflict AI
Upload your ERP security extracts. Your private backend runs a secure server-side rule engine (198 licensed SOD rules across SAP, Oracle EBS R12 and Oracle Cloud) to find access-level conflicts — the rule book and matching logic stay on the server and are never exposed to the browser. Your extracts are parsed in the page into a user→entitlement map, evaluated in memory on the server (not stored), and only the violations are returned. The on-device LLM then writes the risk narrative & remediation. Finally, upload your transaction/change logs to confirm which access conflicts became real transactional violations — same vendor created and paid, same document posted and approved, etc.
1 — Select ERP System
🟦 SAP ECC / S&4HANA
🟥 Oracle EBS R12
🟧 Oracle Cloud (Fusion)
2 — Upload SAP Security Extracts (CSV / TXT — comma, semicolon, tab or pipe delimited)
👤 USR02
User master list — column BNAME
No file
🧩 AGR_USERS
User→role — UNAME + AGR_NAME
No file
🔑 AGR_1251
Role auth data — AGR_NAME,OBJECT,LOW
No file
The SOD rule engine is deterministic and runs securely on your private backend — the proprietary rule book is never sent to the browser. Loading an AI model (above) adds an executive risk narrative & remediation plan on top of the detected conflicts.
🧠
Loading AI Model
Preparing…
0%
Importing engine…
Model weights download once and cache in your browser.
Nothing is sent to any external server.