Skip to content
Product · Radiatus GRC

Governance, Risk & Compliance, Organised

One place for risk assessments, policies, evidence, vendors, incidents and training, so your HIPAA, ISO 27001 or SOC 2 programme is always ready for the next audit.

Signing a compliance document — GRC Platform
At a glance
  • 8 modulesin one platform
  • HIPAA · ISO · SOC 2frameworks covered
  • Web-basednothing to install

Replace the spreadsheets, shared drives and reminder emails

Most compliance programmes start in spreadsheets: a risk list here, policies in a shared drive, evidence in email threads. That works until the auditor asks who approved a policy, when a control was last tested or which vendors handle sensitive data.

Radiatus GRC puts that work in one web-based platform. Run a guided risk assessment, keep a living risk register, publish policies, store evidence with version history, track vendors and BAAs, log incidents and assign training, then report on all of it from one dashboard.

  • Built around HIPAA, ISO 27001 and SOC 2 programmes
  • Evidence organised for audit, with version control and access controls
  • Backed by the Radiatus security & compliance team when you need hands-on help
Signing a compliance document
Platform modules

What's Inside Radiatus GRC

The building blocks of a compliance programme, connected so evidence collected once can support every framework you report against.

Security risk assessment

A guided assessment wizard with industry-specific questions, automated risk scoring and a generated action plan.

Risk register & scoring

One living register of risks with likelihood and impact scoring, owners and treatment decisions.

Policy & control management

Write, publish and track policies and the controls they map to, so you can show what is in place and who owns it.

Evidence management

Secure storage for compliance evidence with version control and access controls, organised for audit.

Vendor management

Third-party risk assessments, vendor documentation and Business Associate Agreement (BAA) tracking.

Incident response

Report incidents, run response workflows and keep guidance on regulatory notifications alongside the record.

Training & education

Compliance training modules with progress tracking and completion certificates for your staff.

Reporting & dashboards

Real-time dashboards, custom reports and exports for leadership updates and auditor requests.

How it works

From First Assessment to Audit-Ready

A typical path for a team starting its first structured programme.

Assess

Answer the guided risk assessment. The platform scores your risks and produces an action plan.

Plan & assign

Turn the action plan into owned tasks: policies to write, controls to implement, vendors to review.

Collect evidence

Upload and version evidence against each control as work is done, instead of scrambling before the audit.

Monitor & report

Track incidents, training completion and open risks on dashboards, and export reports for leadership and auditors.

Frameworks

Frameworks Your Programme Can Track

The platform organises your work; an independent auditor still issues the certificate or report. We will tell you plainly if your framework is not a good fit.

HIPAA Security & Privacy Rules ISO/IEC 27001 SOC 2 NIST guidance
Security engineers reviewing controls on screen
Software plus people

Need help running the programme?

A platform only helps if someone owns the work. Radiatus is an engineering company as well as the team behind this product, so we can do the parts most teams find hardest:

New to this? Read what actually gets you ISO 27001 certified or our guide to HIPAA-aligned workloads on AWS.

Pricing

Plans for Startups to Enterprises

Monthly plans that scale with the number of frameworks and the depth of risk and vendor management you need, plus custom enterprise terms.

Compare GRC plans Start the free assessment

FAQ

GRC Platform Questions

No software can certify you. Certification for ISO 27001 or a SOC 2 report is issued by an independent auditor. Radiatus GRC organises your risk assessments, policies, evidence and vendors so you are ready for that audit and can stay ready afterwards.

The platform is built around HIPAA, ISO 27001 and SOC 2, with HIPAA control and NIST guidance material available in the platform. If you need a different framework, ask us before you sign up so we can tell you honestly how well it fits.

You can create an account at grc.radiatus.com or start with the free assessment to see where you stand. Plans and what each includes are listed on the GRC pricing page.

Yes. Our security and compliance team can run the gap assessment, write policies, implement technical controls and prepare you for audit, using the platform as the system of record. See our ISO 27001 and HIPAA, GDPR and SOC 2 services.

Organisations that need a structured compliance programme without an enterprise GRC budget: healthcare providers and health-tech companies working towards HIPAA, and SaaS or service businesses preparing for ISO 27001 or SOC 2.

See Radiatus GRC on your own programme

Book a walkthrough with our team, or create an account and start with the free assessment.

Request a Demo