Stop Scrambling Audit. Start Intelligent, Continuous Compliance.
Orchestrated Compliance Platform
GRACE automates evidence collection, maps one set of controls across 250+ frameworks, quantifies cyber risks, supports 1500 controls across 34 domains, and empowers organizations with continuous compliance readiness.
Explore GRACE
An orchestrated GRC platform from ComplyX that connects to your cloud, identity and code tools, collects audit evidence automatically, and checks your controls every day. GRACE leads to one control library and built-in risk quantification that turns gaps into dollar values, empowering governance leaders to act on.
From Compliance Gaps to Continuous Assurance
Eliminate Compliance Chaos
GRACE brings evidence, controls, assessments and audit workflows into one orchestrated platform. Teams can stop chasing files across spreadsheets, inboxes and disconnected tools and maintain a clear, current source of compliance evidence.
Comply Across Frameworks
GRACE maps common controls and evidence across multiple frameworks, including SOC 2, ISO 27001, PCI DSS and NIST CSF. Reuse relevant evidence instead of repeating the same compliance work every time a new framework enters the picture.
Identify Gaps Before They Become Audit Findings
GRACE enables continuous compliance visibility through self-assessments, control monitoring and evidence tracking. Teams can identify missing or outdated evidence and emerging control gaps before they surface during an audit.
Turn Compliance Data Into Cyber Risk Quantification
GRACE brings Cyber Risk Quantification (CRQ) into compliance, helping organisations translate control gaps and risk exposure into measurable financial impact. Security teams can prioritise remediation based on potential business loss and give leadership clearer data for investment decisions.
One Platform. Multiple Frameworks. Measurable Risk.
Evidence Once. Extend Across Frameworks.
GRACE maps 1,500 controls across 34 domains to 250+ frameworks, helping enterprises reuse controls and evidence across compliance programmes instead of starting from scratch.
Quantify Risk. Strengthen Investment Decisions.
The GRACE Q Engine uses an adaptive FAIR-based approach and Monte Carlo simulations to quantify potential financial exposure, helping security leaders prioritise remediation and justify investments with measurable risk impact.
Unify Compliance Across Your Environment.
Connect cloud, on-premises and hybrid environments through standard and custom integrations. GRACE brings controls, evidence and compliance visibility into one centralised platform.
Frequently Asked Questions
Want to see how this applies to your stack?
GRACE is a compliance automation and GRC platform from Complyx by Ampcus Cyber. It automates evidence collection, monitors controls continuously, maps one control library to 250+ frameworks and quantifies cyber risk in dollars. It suits organizations of any size, from SMEs to large enterprises, that need to stay audit-ready across one or many frameworks.
Each integration needs a read-only API key. Once it is added, GRACE’s scheduler pulls data automatically, daily by default or at a custom frequency. More than 30 standard integrations are available, including AWS, GCP, GitHub and Okta, and custom integrations can be built on request.
GRACE maps 1,500 controls across 34 domains to all 250+ supported frameworks. When you complete one framework, overlapping controls in others are already covered, and a single piece of evidence, such as an MFA policy, can satisfy several frameworks at once. Your team uploads once instead of repeating the work for every audit.
The GRACE Q Engine is an adaptive version of the FAIR model. It combines your revenue and risk appetite, risk scenarios and the controls you have in place, then runs 10,000 to 50,000 Monte Carlo simulations. The output is Annual Loss Expectancy in dollars, with prioritized actions showing how much risk each control removes.
GRACE is hosted on AWS with tenant isolation, and data is encrypted at rest and in transit. Ampcus Cyber has enterprise AI agreements in place, so client data is not used to train models. AI suggestions, such as proposed control status, are proposals your team can review and confirm.
Yes. GRACE supports cloud, on-premises and hybrid environments, so infrastructure outside a single cloud provider can sit in the same compliance view. Custom integrations are available on request for systems that are not on the standard connector list.
See GRACE in your own environment
Book a demo and see how GRACE discovers your infrastructure, maps your controls and puts a dollar value on your risk.