# Compliance automation privacy ratings

Tools for SOC 2, ISO 27001 and other compliance programs.

**Our pick:** [Comp AI](https://privacyratings.com/compliance-automation/comp-ai/): Open-source compliance automation for SOC 2, ISO 27001, HIPAA and GDPR, with evidence collection, policies and control tracking. Most of the code is AGPL-3.0, and it can be self-hosted, so compliance data does not have to live with a closed vendor.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Comp AI](https://privacyratings.com/compliance-automation/comp-ai/) (our pick) | F (38/100) | United States (Five Eyes) | Open-source compliance automation platform that helps companies prepare for SOC 2, ISO 27001, HIPAA and GDPR audits by collecting evidence, managing policies and tracking controls. It is offered as a hosted service or can be self-hosted. |
| [Probo](https://privacyratings.com/compliance-automation/probo/) | D (50/100) | United States (Five Eyes) | Open-source governance, risk and compliance platform for SOC 2, ISO 27001 and similar programs, covering risks, controls, vendors, access reviews and documents. It can be self-hosted, used as Probo Cloud, or paired with a managed compliance officer service. |
| [Vanta](https://privacyratings.com/compliance-automation/vanta/) | D (41/100) | United States (Five Eyes) | Hosted compliance automation platform that connects to a company's cloud, identity and HR tools to collect evidence and monitor controls for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks. It also offers vendor risk management and public trust center pages. |
| [Scrut Automation](https://privacyratings.com/compliance-automation/scrut/) | F (34/100) | India | Hosted governance, risk and compliance platform that monitors cloud and SaaS systems and collects evidence for SOC 2, ISO 27001, GDPR, HIPAA and other frameworks, with vendor risk management and trust center pages. |
| [Hyperproof](https://privacyratings.com/compliance-automation/hyperproof/) | F (31/100) | United States (Five Eyes) | Hosted compliance and risk management platform that maps controls across frameworks such as SOC 2, ISO 27001, NIST and FedRAMP, collects evidence from connected tools and manages audits. |
| [Drata](https://privacyratings.com/compliance-automation/drata/) | F (28/100) | United States (Five Eyes) | Hosted compliance automation platform that monitors controls and collects evidence from connected cloud and business tools for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks, with AI agents for questionnaires and risk management. |
| [Secureframe](https://privacyratings.com/compliance-automation/secureframe/) | F (28/100) | United States (Five Eyes) | Hosted compliance automation platform that integrates with cloud, identity and HR systems to monitor controls and collect evidence for SOC 2, ISO 27001, FedRAMP, CMMC, HIPAA and other frameworks, with AI tools for questionnaires and risk management. |
| [Eramba](https://privacyratings.com/compliance-automation/eramba/) | F (25/100) | United Kingdom (Five Eyes) | Governance, risk and compliance software for managing risks, controls, policies, audits and frameworks such as ISO 27001, SOC 2, NIS2 and GDPR. A free Community edition and a paid Enterprise edition run on premises, and Enterprise is also offered as SaaS. |
| [Sprinto](https://privacyratings.com/compliance-automation/sprinto/) | F (25/100) | United States (Five Eyes) | Hosted compliance automation platform that monitors cloud, identity and SaaS systems and collects evidence for SOC 2, ISO 27001, HIPAA, GDPR and many other frameworks, with vendor risk management and AI governance features. |
| [Strike Graph](https://privacyratings.com/compliance-automation/strike-graph/) | F (25/100) | United States (Five Eyes) | Hosted compliance platform that builds security programs, collects evidence and runs audits for SOC 2, ISO 27001, HIPAA, CMMC and other frameworks. |
| [Thoropass](https://privacyratings.com/compliance-automation/thoropass/) | F (22/100) | United States (Five Eyes) | Compliance platform and audit firm that combines compliance automation software with in-house SOC 2, ISO 27001, HITRUST, PCI DSS and other audits, plus penetration testing, in one service. Formerly known as Laika. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?
- **Transparency report** (weight 2): Does the provider regularly publish how many government and legal requests it receives and how it responds?
- **Tells users about requests** (weight 1): Does the provider promise to tell users about requests for their data, unless a court forbids it?
- **TLS configuration** (weight 2, automated): Does the website pass the Qualys SSL Labs test with a grade of A or better?
- **Security headers** (weight 1, automated): Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
- **Modern web standards** (weight 1, automated): Does the website score 90% or higher on the Internet.nl website test?

Source: https://privacyratings.com/compliance-automation/
