Skip to content

About

Compliance evidence should live where the evidence lives.

ComplianceGuard collects, scores, and signs endpoint evidence for SOC 2, ISO 27001, and HIPAA — locally, on the machines being audited.

Why ComplianceGuard exists.

Compliance platforms moved to the cloud, but the evidence didn't. Disk encryption status, firewall configuration, OS patch level, screen-lock policy — the controls auditors actually check live on endpoints, where cloud integrations can't see them.

Cloud-first platforms such as Vanta solve a different problem well: orchestrating SaaS and infrastructure integrations at scale. But they ask teams to ship sensitive evidence to a vendor cloud to get it, and they leave the endpoint layer largely uncovered.

Our founder saw that gap and took the architectural position that defines this product: evidence should be collected, scored, and cryptographically signed on the machine where it originates — a local-first desktop application, not another cloud you hand your infrastructure to.

The result is readiness you can hand to an auditor without handing your infrastructure to anyone else.

What it actually does

  • Collects endpoint evidence directly on Windows and macOS
  • Scores SOC 2, ISO 27001, and HIPAA in a single pass
  • Stores everything locally — no data leaves your network
  • Exports a signed PDF evidence pack your auditor can verify

One collection pass · three frameworks · zero telemetry.

By the numbers

Engineering you can verify.

0+

Tests passing across the stack

0

Controls (SOC 2 · ISO 27001 · HIPAA)

0

Evidence categories per machine

0

OSes supported (Windows + macOS)

0

Green CI workflows on every commit

0

Bytes uploaded to a vendor cloud

Source-available under BSL 1.1. Version 3.5.1 ships cross-platform — Windows installer plus macOS builds for Intel and Apple silicon.

The product

The dashboard you ship to auditors.

ComplianceGuard — SOC 2 readinessv3.3.1

Readiness score

SOC 2 Type II · 54 controls

Scanned 2 min ago
67%

36 of 54 controls passing.

18 need attention before audit. Estimated 4–6 hours of remediation work, fully documented in your evidence pack.

CC6.1 — Logical AccessPass
CC6.5 — Network SecurityPass
CC7.1 — Event LoggingNeeds work
CC7.2 — Vulnerability MgmtPass
C1.2 — Data ProtectionNeeds work
A1.4 — Backup & RecoveryPass

Principles

Three commitments we build against.

Data sovereignty by default

Evidence, credentials, and reports live in a local database on your machine. Nothing leaves your network unless you explicitly choose to send it.

Evidence you can audit

The collector is source-available under BSL 1.1. You can read every line of the code that reads your systems — and so can your auditor.

Honest scope

ComplianceGuard does endpoint evidence, scoring, and reporting — and does them rigorously. We don't claim integrations or services we don't ship.