Self-hosted governance, risk and compliance

Your whole security programme, on your own servers.

HouseGRC keeps your frameworks and controls, risk register, evidence, policies, audits, vendors, incidents and board reporting in one encrypted application that you run yourself. Your open risks and control gaps never sit in someone else's cloud.

Runs anywhere Docker runs · no account or card needed for the trial · your data stays on your servers · made in Canada

Self-hostedOne Docker image on your own server. Nothing you record is ever sent to us.
EncryptedThe whole database encrypted at rest, with the most sensitive fields encrypted again
Tamper-evidentEvery change is recorded in a hash-chained audit trail
Priced per organisationFrom $1,490 CAD a year for up to 10 users
Who it is for

For teams that would rather keep their risk record at home

A GRC system holds the most sensitive picture an organisation has of itself: what is weak, what is late, and what went wrong. HouseGRC lets you keep that picture inside your own boundary.

Security and compliance leads

Run the programme from one place: frameworks, risks, evidence, audits and the board pack, with owners and dates on every action.

Virtual CISOs and consultancies

Keep each client in its own organisation, fully separated, and produce the same reporting for every one of them.

Regulated organisations

Meet data-residency and confidentiality expectations by keeping the record on infrastructure you already govern.

First audits and certifications

Turn a standard into a project plan, collect evidence against it, and see how ready you are before the auditor arrives.

How it works

From a blank server to a running programme

Install it

One Docker Compose file on a Linux server or VM. The database, its key and your evidence stay on volumes you control and back up.

Choose your standards

Adopt the frameworks and regulations that apply to you. Controls are cross-mapped, so one piece of work counts everywhere it applies.

Run the programme

Risks, controls, evidence, vendors and incidents turn into owned, dated actions in each person's work queue and on a shared calendar.

Frameworks and controls

Satisfy a requirement once, get credit everywhere

A curated catalogue of security standards, privacy laws and sector regulations sits on one shared controls library. Evidence collected for a control counts for every framework that depends on it, and each framework becomes a project plan with implementation guidance.

  • Audit readiness per framework, with its blockers and a daily trend
  • Continuous control checks that open and close findings on their own
  • Evidence freshness: stale evidence is chased before an auditor finds it
Risk and governance

A risk register the board can follow

Inherent and residual scoring, appetite bands per category with two-person acceptance, key risk indicators with history and breach alerts, and one severity scale across risks, audit findings and exceptions. The board pack is generated with your own branding.

  • Promote a finding or an assessment result straight into the register
  • Business objectives with a risk coverage roll-up
  • Separation of duties on every approval: nobody approves their own work
Third parties

Know which vendors you cannot do without

Vendor tiering with its reasoning shown, criticality worked out from the business processes that depend on each vendor, security questionnaires a vendor can answer without an account, and renewal tracking that warns you before an auto-renewal locks in.

  • Concentration and single-point-of-failure view
  • An offboarding checklist built from everything a vendor touches
  • Software and assets linked to the vendors behind them
Incidents and resilience

Never miss a notification deadline

When an incident involves personal, health or payment data, HouseGRC works out which reporting obligations it triggers in which jurisdictions and counts down to each deadline. Business impact analysis, continuity, recovery and response plans live alongside, with role-tagged steps.

  • On-call rota, corrective actions and post-incident reviews
  • Incidents linked to the risks they realised
  • Recurring reviews of every plan, on the calendar
Coverage

Standards, laws and regulations in the catalogue

Adopt only the ones that apply to you. Each comes cross-mapped to the shared controls library.

Security standards

ISO/IEC 27001SOC 2NIST CSF 2.0NIST SP 800-53NIST SP 800-171PCI DSSCMMC 2.0FedRAMP ModerateCyber EssentialsEssential EightISO/IEC 42001NIST AI RMF

Privacy and sector regulation

PIPEDAGDPRCCPA/CPRAHIPAALGPDPOPIANIS2DORAEU AI ActMAS TRM
Built to hold sensitive data

Security is the product, not a wrapper around it

HouseGRC holds your weaknesses, so it is built on the assumption that someone will try to read them.

Encrypted twice

The database is encrypted at rest as a whole, and secrets and the most sensitive fields are encrypted again with authenticated encryption. The key stays on your server.

Separated by design

Organisations are separated below the application code: a request with no organisation sees nothing at all, so a business unit or a client can never see another's records.

Accountable

Single sign-on (SAML), multi-factor sign-in with authenticator apps or passkeys, role-based access, and an audit trail in which editing any entry breaks the chain.

How HouseGRC protects your data

Questions people ask first

Do you host it for us?

Not at the moment: HouseGRC runs on your own server or virtual machine, on premises or in your own cloud account, so your data never reaches us. If you would like a hosted option, tell us; it helps us decide when to offer one.

What do we need to run it?

A 64-bit Linux server or VM with Docker, 4 CPU cores, 8 GB of memory and 40 GB of disk is enough for most organisations. See the system requirements.

Where does our data go?

Nowhere. Everything you record stays in the encrypted database on your server. HouseGRC never sends it to us, and licence keys are checked on your server without contacting anyone. AI features are optional and send data only to the AI provider you configure, with your own account.

Is it a subscription?

It is a yearly licence that never renews by itself. When the year ends you keep the right to use every version released while your licence was active; newer versions need a current licence.

What happens when the trial ends?

HouseGRC becomes read-only until you add a licence. You can still sign in, view and export everything: your records are never locked away.

Keep your risk record where it belongs

Every feature, free for 30 days for up to 5 users. Then from $1,490 CAD a year for your whole organisation.