By the team behind ISMS Copilot.
heygrc is a standalone product, built by the same team as ISMS Copilot, the AI compliance assistant. ISMS Copilot helps compliance teams answer hard questions across frameworks; heygrc takes that same framework knowledge and moves it left, into the pull request, where engineers work.
Same frameworks, a different surface.
ISMS Copilot is a compliance-consultant product: a chat assistant that compliance teams use to reason about controls, policies, and audits across the full framework catalog. heygrc is built for a different audience and a different moment, engineers and security engineers, at the pull request, and it draws on the same underlying framework knowledge so a finding in a diff is grounded in the same control library that powers the assistant.
That shared foundation is the reason heygrc can cite a specific clause on a code change rather than a vague posture note. The expertise is not new; it is the same one, pointed at code review.
Security and legal live in one place.
heygrc does not maintain a separate trust or legal stack. The binding documents (Terms, Privacy, DPA) and the security evidence that govern heygrc live at the shared ISMS Copilot trust center, kept in one place. One coherent story, not two thin ones.
Launched, and honest about what it is.
heygrc is compliance review for pull requests: install the GitHub App and it reviews your pull requests against the frameworks your company selected. As far as we can tell, it is the first compliance reviewer for pull requests (July 2026); if you know an earlier one, tell us and we will say so here. Neither heygrc nor ISMS Copilot holds a SOC 2 or ISO 27001 certification of its own today; what we share is the framework knowledge and the trust center, and we would rather say that plainly than imply a badge we have not earned. When the product reviews your pull requests, it does so as a reviewer that cites the control, not as a certificate.
Who is behind this, asked directly.
Who builds heygrc?
heygrc is built and operated by the team behind ISMS Copilot, the AI compliance assistant. Both products draw on one body of framework knowledge across ISO 27001, SOC 2, GDPR, and more, and share a single public trust center at trust.ismscopilot.com.
Is heygrc itself certified?
heygrc makes no certification claim. Neither heygrc nor ISMS Copilot holds a SOC 2 or ISO 27001 certificate of its own today; the shared security posture is documented plainly at the trust center. We would rather say that than imply a badge we have not earned.