A complete GRC platform, modular and built for Canada
CapRISK, CapCOM, CapAUDIT, CapPROSEC, CapTRISK and CapPRP: everything you need to steer risk, compliance, audits, projects, third parties and privacy. Start where you are, expand as you grow.
The 6 CapGRC modules
Each module stands alone, and together they form a coherent, governable, audit-ready GRC program.
How it works
Initial setup
We set up your CapGRC workspace with your frameworks, entities and users so you start fast, with less friction.
Data import
Import existing risks, controls and evidence via Excel templates or API, then consolidate the rest over time.
Daily work
Your team works in CapGRC: assessments, evidence, action plans, diligence and privacy follow-up.
Reporting & oversight
Give leadership clear dashboards and arrive at audits with a documented trail.
Built for enterprise requirements
High-level security
- AES-256 encryption in transit and at rest
- MFA available, mandatory for administrators
- Granular RBAC per module and data
- Complete access logging
Canadian hosting
- Data exclusively in Canada
- Aligned with Law 25 data sovereignty
- Infrastructure hosted with trusted providers
- No transfer to foreign servers
Integrations & API
- Documented REST API (access on request)
- SSO / SAML for enterprise authentication
- Jira connectors (beta), Azure DevOps
- Automations and webhooks as needed
Integrations
Connect CapGRC to your existing tools: Jira, Azure DevOps, enterprise SSO.
Learn moreSecurity & hosting
Everything about our security architecture, Canadian hosting and certifications.
Learn moreRoadmap
Discover the features in development and those planned for upcoming quarters.
Learn moreReady to modernize your GRC program?
Request a free demo and discover how CapGRC can transform your approach to governance, risk and compliance.
