About
Compliance evidence should live where the evidence lives.
ComplianceGuard collects, scores, and signs endpoint evidence for SOC 2, ISO 27001, and HIPAA — locally, on the machines being audited.
Why ComplianceGuard exists.
Compliance platforms moved to the cloud, but the evidence didn't. Disk encryption status, firewall configuration, OS patch level, screen-lock policy — the controls auditors actually check live on endpoints, where cloud integrations can't see them.
Cloud-first platforms such as Vanta solve a different problem well: orchestrating SaaS and infrastructure integrations at scale. But they ask teams to ship sensitive evidence to a vendor cloud to get it, and they leave the endpoint layer largely uncovered.
Our founder saw that gap and took the architectural position that defines this product: evidence should be collected, scored, and cryptographically signed on the machine where it originates — a local-first desktop application, not another cloud you hand your infrastructure to.
The result is readiness you can hand to an auditor without handing your infrastructure to anyone else.
What it actually does
- Collects endpoint evidence directly on Windows and macOS
- Scores SOC 2, ISO 27001, and HIPAA in a single pass
- Stores everything locally — no data leaves your network
- Exports a signed PDF evidence pack your auditor can verify
One collection pass · three frameworks · zero telemetry.
By the numbers
Engineering you can verify.
Tests passing across the stack
Controls (SOC 2 · ISO 27001 · HIPAA)
Evidence categories per machine
OSes supported (Windows + macOS)
Green CI workflows on every commit
Bytes uploaded to a vendor cloud
Source-available under BSL 1.1. Version 3.5.1 ships cross-platform — Windows installer plus macOS builds for Intel and Apple silicon.
The product
The dashboard you ship to auditors.
Readiness score
SOC 2 Type II · 54 controls
36 of 54 controls passing.
18 need attention before audit. Estimated 4–6 hours of remediation work, fully documented in your evidence pack.
Principles
Three commitments we build against.
Data sovereignty by default
Evidence, credentials, and reports live in a local database on your machine. Nothing leaves your network unless you explicitly choose to send it.
Evidence you can audit
The collector is source-available under BSL 1.1. You can read every line of the code that reads your systems — and so can your auditor.
Honest scope
ComplianceGuard does endpoint evidence, scoring, and reporting — and does them rigorously. We don't claim integrations or services we don't ship.