{
 "sym": "Cm",
 "updated": "2026-08-06",
 "verdict": "Vanta, and it isn't close anymore \u2014 $300M ARR by April 2026 (+69% YoY), 16,000+ customers, a $4.15B valuation, and an AI agent now baked into every tier including the cheapest. Drata is the mandatory bake-off: deeper mid-market GRC, the SafeBase trust center it bought for $250M, and an Agent Governance product Vanta doesn't match. Secureframe wins when CMMC or federal work is on the roadmap; Sprinto when you're cost-sensitive or non-US and need obscure frameworks; Oneleet when you want to actually get secure \u2014 pentest, vCISO, MDM bundled \u2014 not just collect the badge. The category's cautionary tale is Delve: $300M valuation in July 2025, expelled from YC's directory by April 2026 over fake-compliance allegations. Automation speeds up evidence; it cannot replace it.",
 "top5": [
  {
   "rank": 1,
   "name": "Vanta",
   "maker": "Vanta",
   "url": "https://www.vanta.com",
   "docs": "https://developer.vanta.com",
   "pricing": "Quote-only \u00b7 4 tiers (Essentials \u2192 Plus \u2192 Professional \u2192 Enterprise) \u00b7 AI Agent included in all tiers \u00b7 questionnaire automation metered by tier (25/yr Plus, 144/yr Professional)",
   "best_for": "The default: fastest path from zero to SOC 2 for a startup, with enough GRC, vendor-risk, and AI-governance modules to not outgrow it.",
   "why": "The category leader by every measure that matters: $300M ARR by April 2026, up 69% YoY, across 16,000+ customers from seed startups to Snowflake and Atlassian. Its AI Agent \u2014 agentic evidence checks, policy drafting, questionnaire answers \u2014 ships in every tier, and the developer surface (API, MCP server, webhooks) is the deepest in the category. 35+ frameworks, 400+ integrations, and customers report 20% faster deal cycles.",
   "watch": "Quote-only pricing with real sticker shock at renewal \u2014 no tier prices published anywhere. A June 2025 bug briefly exposed customer data to other customers (TechCrunch), an ironic wound for a trust company. Per-questionnaire metering pushes growing teams up-tier fast.",
   "evidence": [
    {
     "stat": "$300M ARR (Apr 2026), +69% YoY; 16,000 customers; ~$19K implied ACV",
     "src": "https://sacra.com/c/vanta/"
    },
    {
     "stat": "$4.15B valuation, Series D Jul 2025; $504M total raised",
     "src": "https://sacra.com/c/vanta/"
    },
    {
     "stat": "AI Agent in every tier incl. entry Essentials; 35+ frameworks, 400+ integrations (Aug 2026)",
     "src": "https://www.vanta.com/pricing"
    }
   ],
   "tile_note": "the compliance default"
  },
  {
   "rank": 2,
   "name": "Drata",
   "maker": "Drata",
   "url": "https://drata.com",
   "docs": "https://developers.drata.com",
   "pricing": "Quote-only \u00b7 packages by framework count and modules \u00b7 SafeBase Trust Center and Agent Governance sold as add-on products",
   "best_for": "The bake-off contender \u2014 mid-market and enterprise teams juggling multiple frameworks who want deeper GRC workflows and the best trust-center product.",
   "why": "The clear #2 with 8,500+ customers (OpenAI and Notion among them) and the most aggressive M&A in the category: SafeBase for $250M (Feb 2025) plus oak9 and Harmonize. Claims 75% shorter SOC 2 audits and cross-framework control mapping in two hours; its new Agent Governance product \u2014 discover and police the AI agents running in your own environment \u2014 is a genuinely differentiated bet on where compliance is going.",
   "watch": "Growth has visibly lagged Vanta's: ~$98M ARR in Jan 2025 vs Vanta's $250M at the same moment, after a 9% layoff in Sep 2024. Valuation still marked at Dec 2022's $2B. No fresher primary financials surfaced \u2014 assume the gap widened, not narrowed.",
   "evidence": [
    {
     "stat": "8,500+ customers, 4.8/5 G2 (Aug 2026)",
     "src": "https://drata.com/"
    },
    {
     "stat": "Acquired SafeBase for $250M (Feb 12, 2025)",
     "src": "https://techcrunch.com/tag/drata/"
    },
    {
     "stat": "~$98M ARR (Jan 2025); $2B valuation (Dec 2022, Series C)",
     "src": "https://sacra.com/c/drata/"
    }
   ],
   "tile_note": "the bake-off contender"
  },
  {
   "rank": 3,
   "name": "Secureframe",
   "maker": "Secureframe",
   "url": "https://secureframe.com",
   "docs": "https://developer.secureframe.com",
   "pricing": "Quote-only \u00b7 3 packages: Fundamentals \u00b7 Complete \u00b7 Defense (CMMC) \u00b7 Comply AI included across tiers",
   "best_for": "Startups that will ever touch US federal or defense work \u2014 the only top-tier platform with a purpose-built CMMC package (SSPs, POA&M, managed CUI).",
   "why": "6,000+ customers and the strongest defense/federal story in the category: its Defense tier ships System Security Plans, POA&M, and managed CUI environments that generalist rivals bolt on later. Comply AI handles policy generation and remediation, and the three-product split (Comply, Defense, Trust) keeps scope honest.",
   "watch": "Squeezed in the middle \u2014 less ecosystem gravity than Vanta, less GRC depth than Drata, and no public customer-growth or ARR disclosures since its 2022 raise. The CMMC Phase 2 pause (flagged on its own homepage) delays the tailwind its Defense bet depends on.",
   "evidence": [
    {
     "stat": "6,000+ customers (Aug 2026)",
     "src": "https://secureframe.com/"
    },
    {
     "stat": "Dedicated Defense tier for CMMC: SSP, POA&M, managed CUI (Aug 2026)",
     "src": "https://secureframe.com/pricing"
    }
   ],
   "tile_note": "the cmmc specialist"
  },
  {
   "rank": 4,
   "name": "Sprinto",
   "maker": "Sprinto",
   "url": "https://sprinto.com",
   "docs": "https://docs.sprinto.com",
   "pricing": "Quote-only (demo-gated) \u00b7 widely reported as the value option vs US rivals (unverified \u2014 no published tiers) \u00b7 $1 Trust Center promo running Aug 2026",
   "best_for": "Cost-sensitive and non-US startups needing breadth \u2014 200+ frameworks including TISAX, DORA, ISO 42001 \u2014 with autonomous remediation rather than alert noise.",
   "why": "3,000+ customers and the widest framework library of any major platform (200+, vs Vanta's 35+), with upload-your-own-regulation translation into controls. Its 'autonomous trust' positioning \u2014 the platform executes compliance actions instead of just flagging them \u2014 plus shadow-AI detection mapped to ISO 42001/NIST AI RMF makes it more than a budget clone.",
   "watch": "The value reputation rests on third-party chatter, not published pricing. Smallest of the top five by customer count; US enterprise brand recognition and auditor network still trail. Site aggressively bot-blocks (pricing page 403s), which is a small irony for a trust company.",
   "evidence": [
    {
     "stat": "3,000+ companies; 200+ frameworks incl. ISO 42001, TISAX, DORA (Aug 2026)",
     "src": "https://sprinto.com/"
    },
    {
     "stat": "Shadow-AI detection with live registries mapped to ISO 42001 / NIST AI RMF (Aug 2026)",
     "src": "https://sprinto.com/"
    }
   ],
   "tile_note": "frameworks at startup prices"
  },
  {
   "rank": 5,
   "name": "Oneleet",
   "maker": "Oneleet",
   "url": "https://www.oneleet.com",
   "docs": "https://docs.oneleet.com",
   "pricing": "Quote-only \u00b7 bundles compliance automation with pentest, code/attack-surface scanning, MDM, security training, and vCISO in one contract",
   "best_for": "Founders who want the SOC 2 badge to mean something \u2014 real security (pentest, hardening, vCISO) and the certificate from one integrated platform.",
   "why": "The security-first insurgent: $33M Series A led by Dawn Capital (Oct 2025) with Frank Slootman and YC behind it, on $9M ARR and a claim that a large share of recent YC cohorts are customers. Its thesis \u2014 rival platforms are 'evidence-collection tools' while security should come first and the badge second \u2014 is the sharpest critique of this category, and post-Delve it reads prophetic.",
   "watch": "An order of magnitude smaller than Vanta/Drata ($9M vs $300M ARR); the all-in-one bundle means trusting one young vendor for pentest, tooling, and compliance at once. Enterprise features and auditor network still maturing.",
   "evidence": [
    {
     "stat": "$33M Series A (Dawn Capital, Oct 2, 2025); $35M total raised",
     "src": "https://techcrunch.com/2025/10/02/oneleet-raises-33m-to-shake-up-the-world-of-security-compliance/"
    },
    {
     "stat": "$9M ARR (Oct 2025); ~two-thirds of YC S22 cohort reported as clients",
     "src": "https://techcrunch.com/2025/10/02/oneleet-raises-33m-to-shake-up-the-world-of-security-compliance/"
    }
   ],
   "tile_note": "security first, badge second"
  }
 ],
 "matrix": {
  "cols": [
   "Pricing",
   "Audit in-house?",
   "Frameworks",
   "AI depth",
   "Traction (latest)",
   "Sweet spot"
  ],
  "rows": [
   [
    "Vanta",
    "Quote-only, 4 tiers",
    "No \u2014 auditor marketplace",
    "35+",
    "AI Agent all tiers \u00b7 MCP \u00b7 API",
    "16,000+ customers, $300M ARR (Apr 2026)",
    "Default, seed \u2192 enterprise"
   ],
   [
    "Drata",
    "Quote-only",
    "No \u2014 auditor network",
    "20+ incl. custom",
    "AI agents \u00b7 Agent Governance \u00b7 MCP",
    "8,500+ customers (Aug 2026)",
    "Mid-market GRC depth"
   ],
   [
    "Secureframe",
    "Quote-only, 3 packages",
    "No",
    "SOC 2 \u2192 CMMC 2.0",
    "Comply AI (policy, remediation)",
    "6,000+ customers (Aug 2026)",
    "Federal / defense track"
   ],
   [
    "Sprinto",
    "Quote-only, demo-gated",
    "No",
    "200+",
    "Autonomous actions \u00b7 shadow-AI registry",
    "3,000+ customers (Aug 2026)",
    "Global, cost-sensitive"
   ],
   [
    "Oneleet",
    "Quote-only bundle",
    "No \u2014 but pentest in-house",
    "SOC 2, ISO, HIPAA, DORA+",
    "Automation + real security stack",
    "$9M ARR (Oct 2025)",
    "YC-stage, security-first"
   ],
   [
    "Thoropass",
    "Quote incl. audit fees",
    "Yes \u2014 auditor + software",
    "Major frameworks",
    "Thoropass AI (controls, gaps)",
    "500+ audits/yr (Aug 2026)",
    "One-vendor audit + tooling"
   ],
   [
    "Scrut",
    "Quote-only",
    "No",
    "70+",
    "Agent 'Teammates' \u00b7 MCP into Claude/Cursor",
    "2,500+ customers (Aug 2026)",
    "Agentic GRC, global"
   ],
   [
    "Hyperproof",
    "Quote-only",
    "No",
    "160+",
    "AI-assisted, control dedup",
    "G2 Enterprise Leader (2026)",
    "Enterprise multi-framework"
   ]
  ]
 },
 "rules": [
  {
   "if": "A real customer just asked for SOC 2 and you want the fastest, safest default",
   "then": "Vanta \u2014 biggest ecosystem, AI Agent even on the entry tier, and the 16,000-customer path your auditor already knows. Budget for the renewal conversation."
  },
  {
   "if": "You're past ~50 people with multiple frameworks and a security-review pipeline",
   "then": "Run the Vanta\u2013Drata bake-off. Drata's SafeBase trust center and cross-framework mapping win real deals; both are quote-only, so competing quotes is the only price lever you have."
  },
  {
   "if": "US federal, defense, or CMMC is anywhere on your roadmap",
   "then": "Secureframe Defense \u2014 SSPs, POA&M, and managed CUI are painful to retrofit onto a generalist platform later."
  },
  {
   "if": "You're outside the US, price-sensitive, or need an obscure framework (TISAX, DORA, ISO 42001)",
   "then": "Sprinto \u2014 200+ frameworks and upload-your-own-regulation beat every rival's library."
  },
  {
   "if": "You're tempted by any vendor promising 'compliance in days' with minimal evidence work",
   "then": "Remember Delve: $300M valuation July 2025, out of YC's directory April 2026 over fabricated-compliance allegations. Ask who the auditor of record is and how evidence is collected \u2014 or pick Oneleet/Thoropass, which put the security or the audit itself in-house."
  }
 ],
 "field": [
  {
   "name": "Thoropass",
   "maker": "Thoropass (ex-Laika)",
   "note": "The auditor-and-software-in-one play: 500+ audits/yr, 50+ Fortune 500 accept its reports; Bain Capital Ventures / JP Morgan backed \u2014 the near-miss for the top 5",
   "url": "https://thoropass.com",
   "oss": false,
   "entry": "quote incl. audit",
   "status": "active"
  },
  {
   "name": "Scrut Automation",
   "maker": "Scrut",
   "note": "2,500+ customers; agent 'Teammates' (policy, evidence, vendor risk) plus an MCP concierge that surfaces compliance inside Claude and Cursor",
   "url": "https://www.scrut.io",
   "oss": false,
   "entry": "quote-only",
   "status": "active"
  },
  {
   "name": "Scytale",
   "maker": "Scytale",
   "note": "1,000+ companies (Monday.com, Deel, Fiverr); 80+ frameworks with a multi-agent suite and human expert layer",
   "url": "https://scytale.ai",
   "oss": false,
   "entry": "quote-only",
   "status": "active"
  },
  {
   "name": "Hyperproof",
   "maker": "Hyperproof",
   "note": "Enterprise GRC with 160+ frameworks, control deduplication, and a FedRAMP-certified gov environment; G2 Enterprise Leader 2026",
   "url": "https://hyperproof.io",
   "oss": false,
   "entry": "quote-only",
   "status": "active"
  },
  {
   "name": "Anecdotes",
   "maker": "Anecdotes",
   "note": "Enterprise agentic GRC \u2014 Agent Studio, Agent Library, ChatGRC \u2014 over 230+ integrations; aimed at multi-entity regulated orgs, not startups",
   "url": "https://www.anecdotes.ai",
   "oss": false,
   "entry": "quote-only",
   "status": "active"
  },
  {
   "name": "Strike Graph",
   "maker": "Strike Graph",
   "note": "Verify AI on fine-tuned small language models \u2014 the cost-efficient-AI angle on compliance automation",
   "url": "https://www.strikegraph.com",
   "oss": false,
   "entry": "quote-only",
   "status": "active"
  },
  {
   "name": "TrustCloud",
   "maker": "TrustCloud (ex-Kintent)",
   "note": "CISO-oriented 'hallucination-free' agentic GRC; claims 85% questionnaire pre-fill automation",
   "url": "https://www.trustcloud.ai",
   "oss": false,
   "entry": "quote-only",
   "status": "active"
  },
  {
   "name": "Comp AI",
   "maker": "Comp AI",
   "note": "The open-source challenger \u2014 fully OSS codebase, 580+ integrations, open-source device agents; claims 1,000+ companies",
   "url": "https://trycomp.ai",
   "oss": true,
   "entry": "free (self-host) \u00b7 paid cloud",
   "status": "active"
  },
  {
   "name": "A-LIGN",
   "maker": "A-LIGN",
   "note": "The audit side of the equation: 36,000+ audits across 45+ standards plus its A-SCEND platform \u2014 pairs with any automation tool above",
   "url": "https://www.a-lign.com",
   "oss": false,
   "entry": "audit fees",
   "status": "active"
  },
  {
   "name": "AuditBoard",
   "maker": "AuditBoard / Hg",
   "note": "Enterprise audit-and-risk suite acquired by Hg for ~$3B (2024) \u2014 where compliance graduates when the GRC team outnumbers your startup",
   "url": "https://auditboard.com",
   "oss": false,
   "entry": "enterprise quote",
   "status": "acquired"
  },
  {
   "name": "Complyance",
   "maker": "Complyance",
   "note": "Raised $20M (Feb 2026) for risk-and-compliance management \u2014 the funding wave continues post-Delve",
   "url": "https://techcrunch.com/tag/compliance/",
   "oss": false,
   "entry": "quote-only",
   "status": "active"
  },
  {
   "name": "Delve",
   "maker": "Delve",
   "note": "The integrity lesson: $32M at $300M (Insight, Jul 2025) \u2192 whistleblower 'fake compliance' receipts (Mar 2026) \u2192 removed from YC's directory (Apr 4, 2026) \u2192 customer security incidents through Apr 2026. Site still live, claims 1,500+ customers; trust is the product, and it broke",
   "url": "https://delve.co",
   "oss": false,
   "entry": "\u2014",
   "status": "fading"
  },
  {
   "name": "Laika",
   "maker": "\u2192 Thoropass",
   "note": "Rebranded to Thoropass in 2023 as it leaned into in-house audit delivery",
   "url": "https://thoropass.com/about/",
   "oss": false,
   "entry": "\u2014",
   "status": "renamed"
  },
  {
   "name": "Kintent",
   "maker": "\u2192 TrustCloud",
   "note": "Renamed TrustCloud in 2023, pivoting from checklist compliance to programmatic trust assurance",
   "url": "https://www.trustcloud.ai",
   "oss": false,
   "entry": "\u2014",
   "status": "renamed"
  },
  {
   "name": "Tugboat Logic",
   "maker": "\u2192 OneTrust",
   "note": "Early SOC 2 automation pioneer acquired by OneTrust (Oct 2021); brand absorbed into OneTrust Certification Automation",
   "url": "https://www.onetrust.com",
   "oss": false,
   "entry": "\u2014",
   "status": "acquired"
  },
  {
   "name": "Aptible Comply",
   "maker": "Aptible",
   "note": "One of the first compliance-automation products; sunset as Aptible refocused on its hosting PaaS \u2014 proof the category predates the 2021 boom",
   "url": "https://www.aptible.com",
   "oss": false,
   "entry": "\u2014",
   "status": "dead"
  }
 ],
 "signals": [
  {
   "fact": "Enterprise GRC market: $23.6B (2026) \u2192 $42.2B (2031), 12.3% CAGR, with DORA and AI-regulation demand called out as accelerants",
   "src": "https://www.mordorintelligence.com/industry-reports/enterprise-governance-risk-and-compliance-market"
  },
  {
   "fact": "Vanta: $300M ARR (Apr 2026, +69% YoY), 16,000 customers, $4.15B valuation \u2014 pulling away from Drata's ~$98M ARR (Jan 2025)",
   "src": "https://sacra.com/c/vanta/"
  },
  {
   "fact": "The Delve scandal: whistleblower 'fake compliance' allegations (Mar 22, 2026) \u2192 YC directory removal (Apr 4, 2026) \u2192 continued customer security incidents (Apr 23, 2026) \u2014 the category's first integrity crisis",
   "src": "https://techcrunch.com/2026/04/04/embattled-startup-delve-has-parted-ways-with-y-combinator/"
  },
  {
   "fact": "Consolidation wave: Drata bought SafeBase for $250M (Feb 2025) after oak9 and Harmonize; AuditBoard went to Hg for ~$3B (2024); Tugboat Logic into OneTrust (2021)",
   "src": "https://techcrunch.com/tag/drata/"
  },
  {
   "fact": "Security-first challengers funded: Oneleet $33M Series A on $9M ARR (Oct 2025) explicitly attacking incumbents as 'evidence-collection tools'",
   "src": "https://techcrunch.com/2025/10/02/oneleet-raises-33m-to-shake-up-the-world-of-security-compliance/"
  },
  {
   "fact": "2026 structural shift: every major platform now ships agentic AI plus an MCP server (Vanta MCP, Drata MCP, Scrut's Claude/Cursor concierge) \u2014 compliance is becoming a surface your coding agent queries",
   "src": "https://developer.vanta.com/"
  }
 ],
 "notes": "Pricing opacity is the category's defining consumer problem: all five top picks are quote-only \u2014 verified on each vendor's own pricing page Aug 2026 \u2014 so third-party '$10k\u201350k/yr' estimates circulate but none met our sourcing bar and were excluded. Conflicts resolved: Vanta valuation reported as '$4B' (Forbes, Jul 2025) vs $4.15B (Sacra) \u2014 we cite $4.15B as the precise figure consistent with the $2.45B Series C lineage; Drata's ARR is stale (Sacra, Jan 2025, ~$98M) with no fresher primary figure found, noted plainly in its entry; no evidence surfaced of any SailPoint\u2013Drata deal (SailPoint's Aug 2026 press archive shows none) \u2014 Drata remains independent. Sprinto's pricing page 403s bot traffic; homepage claims verified instead. Delve is listed 'fading' not 'dead': the company still operates and disputes the allegations as a smear campaign, but the YC removal and customer incidents are documented. Adjacent elements: ISO 42001 / NIST AI RMF / EU-AI-Act readiness overlaps element Ai \u00b7 AI-Act Readiness \u2014 the platforms here now sell AI-governance modules into that job; LLM evals and observability belong to Ev; agent runtime policy to Gd. Auditor selection (A-LIGN, Johanson, Prescient et al.) is a service decision downstream of this element \u2014 Thoropass and Oneleet are the two picks that internalize parts of it.",
 "sources": [
  "https://www.vanta.com/pricing",
  "https://www.vanta.com/",
  "https://sacra.com/c/vanta/",
  "https://www.vanta.com/company/press",
  "https://developer.vanta.com/",
  "https://drata.com/pricing",
  "https://drata.com/",
  "https://developers.drata.com/",
  "https://sacra.com/c/drata/",
  "https://techcrunch.com/tag/drata/",
  "https://techcrunch.com/tag/delve/",
  "https://techcrunch.com/2026/04/04/embattled-startup-delve-has-parted-ways-with-y-combinator/",
  "https://techcrunch.com/tag/compliance/",
  "https://techcrunch.com/2025/10/02/oneleet-raises-33m-to-shake-up-the-world-of-security-compliance/",
  "https://www.oneleet.com/pricing",
  "https://docs.oneleet.com/",
  "https://secureframe.com/pricing",
  "https://secureframe.com/",
  "https://sprinto.com/",
  "https://docs.sprinto.com/",
  "https://thoropass.com/pricing/",
  "https://thoropass.com/about/",
  "https://www.mordorintelligence.com/industry-reports/enterprise-governance-risk-and-compliance-market",
  "https://www.scrut.io/",
  "https://scytale.ai/",
  "https://hyperproof.io/",
  "https://www.anecdotes.ai/",
  "https://www.strikegraph.com/",
  "https://www.trustcloud.ai/",
  "https://trycomp.ai/",
  "https://www.a-lign.com/",
  "https://delve.co/"
 ],
 "element": {
  "number": 48,
  "name": "Compliance",
  "group": "Trust & Compliance",
  "essential": true,
  "edition": "v2026.Q3",
  "revision": "r7",
  "license": "CC BY 4.0 \u2014 cite elems.ai",
  "url": "https://elems.ai/e/cm.html"
 }
}