Your whole security programme, on your own servers.
HouseGRC keeps your frameworks and controls, risk register, evidence, policies, audits, vendors, incidents and board reporting in one encrypted application that you run yourself. Your open risks and control gaps never sit in someone else's cloud.
Runs anywhere Docker runs · no account or card needed for the trial · your data stays on your servers · made in Canada
For teams that would rather keep their risk record at home
A GRC system holds the most sensitive picture an organisation has of itself: what is weak, what is late, and what went wrong. HouseGRC lets you keep that picture inside your own boundary.
Security and compliance leads
Run the programme from one place: frameworks, risks, evidence, audits and the board pack, with owners and dates on every action.
Virtual CISOs and consultancies
Keep each client in its own organisation, fully separated, and produce the same reporting for every one of them.
Regulated organisations
Meet data-residency and confidentiality expectations by keeping the record on infrastructure you already govern.
First audits and certifications
Turn a standard into a project plan, collect evidence against it, and see how ready you are before the auditor arrives.
From a blank server to a running programme
Install it
One Docker Compose file on a Linux server or VM. The database, its key and your evidence stay on volumes you control and back up.
Choose your standards
Adopt the frameworks and regulations that apply to you. Controls are cross-mapped, so one piece of work counts everywhere it applies.
Run the programme
Risks, controls, evidence, vendors and incidents turn into owned, dated actions in each person's work queue and on a shared calendar.
Satisfy a requirement once, get credit everywhere
A curated catalogue of security standards, privacy laws and sector regulations sits on one shared controls library. Evidence collected for a control counts for every framework that depends on it, and each framework becomes a project plan with implementation guidance.
- Audit readiness per framework, with its blockers and a daily trend
- Continuous control checks that open and close findings on their own
- Evidence freshness: stale evidence is chased before an auditor finds it
A risk register the board can follow
Inherent and residual scoring, appetite bands per category with two-person acceptance, key risk indicators with history and breach alerts, and one severity scale across risks, audit findings and exceptions. The board pack is generated with your own branding.
- Promote a finding or an assessment result straight into the register
- Business objectives with a risk coverage roll-up
- Separation of duties on every approval: nobody approves their own work
Know which vendors you cannot do without
Vendor tiering with its reasoning shown, criticality worked out from the business processes that depend on each vendor, security questionnaires a vendor can answer without an account, and renewal tracking that warns you before an auto-renewal locks in.
- Concentration and single-point-of-failure view
- An offboarding checklist built from everything a vendor touches
- Software and assets linked to the vendors behind them
Never miss a notification deadline
When an incident involves personal, health or payment data, HouseGRC works out which reporting obligations it triggers in which jurisdictions and counts down to each deadline. Business impact analysis, continuity, recovery and response plans live alongside, with role-tagged steps.
- On-call rota, corrective actions and post-incident reviews
- Incidents linked to the risks they realised
- Recurring reviews of every plan, on the calendar
Standards, laws and regulations in the catalogue
Adopt only the ones that apply to you. Each comes cross-mapped to the shared controls library.
Security standards
Privacy and sector regulation
Security is the product, not a wrapper around it
HouseGRC holds your weaknesses, so it is built on the assumption that someone will try to read them.
Encrypted twice
The database is encrypted at rest as a whole, and secrets and the most sensitive fields are encrypted again with authenticated encryption. The key stays on your server.
Separated by design
Organisations are separated below the application code: a request with no organisation sees nothing at all, so a business unit or a client can never see another's records.
Accountable
Single sign-on (SAML), multi-factor sign-in with authenticator apps or passkeys, role-based access, and an audit trail in which editing any entry breaks the chain.
Questions people ask first
Do you host it for us?
Not at the moment: HouseGRC runs on your own server or virtual machine, on premises or in your own cloud account, so your data never reaches us. If you would like a hosted option, tell us; it helps us decide when to offer one.
What do we need to run it?
A 64-bit Linux server or VM with Docker, 4 CPU cores, 8 GB of memory and 40 GB of disk is enough for most organisations. See the system requirements.
Where does our data go?
Nowhere. Everything you record stays in the encrypted database on your server. HouseGRC never sends it to us, and licence keys are checked on your server without contacting anyone. AI features are optional and send data only to the AI provider you configure, with your own account.
Is it a subscription?
It is a yearly licence that never renews by itself. When the year ends you keep the right to use every version released while your licence was active; newer versions need a current licence.
What happens when the trial ends?
HouseGRC becomes read-only until you add a licence. You can still sign in, view and export everything: your records are never locked away.
Keep your risk record where it belongs
Every feature, free for 30 days for up to 5 users. Then from $1,490 CAD a year for your whole organisation.