Our customers are audit, risk and security professionals, so this page is written the way we would want a vendor to write it for us: specific about what we do, and explicit about what we do not claim.
The GrcAI Assistant downloads its AI model to your browser and runs it on your device. Content you analyse is processed locally rather than sent to us. For teams handling confidential audit evidence, this narrows the data boundary to the machine you are already trusting.
Not every feature is local, and we would rather say so:
We hold no security certification at this time. We are not claiming SOC 2, ISO 27001 or any equivalent attestation, and you should not treat this page as one.
On-device processing narrows where your data goes. It does not remove your own responsibilities for device security, browser hygiene, access control and your organisation's acceptable-use policy.
If you believe you have found a security issue, please tell us through our contact page with enough detail to reproduce it. We will acknowledge your report and work with you on it. Please give us a reasonable opportunity to address the issue before disclosing it publicly.
Security questionnaires and due-diligence requests are welcome through the contact page.