One platform. Not twelve tools.

Beneath every module is a single engine, one connected data model, a curated regulatory catalog, automation that runs your cadence, and the integrations and identity to tie it to your stack. That's what makes CardinalGRC a system, not a folder of apps.

Mapped once. Inherited by every customer.

Frameworks, controls and policy templates are curated centrally and versioned. Adopting one is a reference, not a fork: when a new circular lands, we map it one time and you see the new version through your overlay, adopting it deliberately rather than being silently changed.

Platform-curated

The canonical catalog

40+ frameworks across nine African markets and the international standards: 1,200+ requirements resolved to 132 shared controls through 1,700+ cross-mappings, maintained centrally by our curation team.

A new circular is mapped once, here.
Your overlay

Adoption by reference

Which items you've adopted, your customisations, owners and evidence. A reference to the catalog, never a fork of it.

New versions surface here; you adopt them deliberately.
Your programme

Controls, resolved

Your working controls are the catalog read through your overlay: implement once, and it counts toward every framework it maps to.

The machinery every module shares.

The modules are views onto one connected data model, not separate apps that sync. These systems run underneath all twelve, which is why a control you implement once counts everywhere.

01

Automation that runs itself

A definition-driven scheduler runs your programme's cadence so nothing depends on someone remembering, raising work items when something needs a human.

20+ hourly sweeps · Breach clocks · Recertifications
02

Connect your stack

Read-only collectors auto-evidence controls from systems you already run. A broken connection raises an integration-health issue; it never silently flips a control red.

Google Workspace · GitHub · Integration healthHow evidence works
03

Identity & access

Roles modelled on the Three Lines of Defence, maker/checker enforced per item, one identity to one workspace, and SSO provisioned just-in-time.

Three Lines RBAC · Maker/checker · OIDC + SAML SSO
04

Built for outside parties

Auditors, examiners and vendors work in their own time-boxed workspace, never in your live data. The full story lives in Audit Hub.

External guests · Time-boxed · Provenance projectionsMeet Audit Hub
05

Reporting & your work

Board and Exco rollups, exportable posture reports, a compliance calendar, and a “what needs me” inbox, all reading from the same data the programme runs on.

Board rollups · Posture exports · Compliance calendar

Simple to reason about. Safe to trust.

One deployable, one database, a modular monolith you can fully reason about and defend. The kind of architecture that survives a security review instead of explaining itself away.

The full security architecture, and how it's tested, is written up for your security team to review.

Read the security architecture
Architecture
Modular monolith, one deployable, one database
Data
PostgreSQL 16, forward-only reviewed migrations
Storage
Private object storage, signed URLs only, never a public object
Footprint
Postgres, an object store, one worker, one VM

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.