The same review, tuned to your situation.
heygrc is built to review pull requests against the frameworks your company must meet. What that means in practice depends on who you are: a fast-moving engineering team, an outnumbered security engineer, a US SaaS heading into SOC 2 or HIPAA, an EU SaaS carrying several regimes, or a startup heading into a first audit.
- Engineering teams
For engineering teams who want to ship fast without compliance becoming a quarterly emergency. Catch control-relevant changes in the review you already do.
- Security engineers
For security engineers who cannot personally review every change against every obligation. A framework-grounded second set of eyes on the diff.
- EU SaaS
For EU SaaS teams carrying overlapping regulatory duties. The data-protection and resilience obligations that show up in a diff, named at the clause.
- Startups
For startups heading into a first SOC 2 or ISO 27001. Get the framework awareness of a larger company without hiring for it.
- Fintech
For fintech and payments teams whose regulators moved into the repository: card-data handling, operational resilience, and vendor risk all change one diff at a time.
- Healthtech
For healthtech teams handling patient data. HIPAA's technical safeguards and GDPR's data duties show up in ordinary changes: a log line, a storage config, a dropped check.
- AI startups
For AI-native startups facing the EU AI Act's engineering duties (logging, data governance) alongside the SOC 2 and GDPR asks every customer already makes.
- Shipping with AI agents
For engineering teams where Claude Code, Cursor, Copilot, or Codex open a growing share of pull requests. The compliance reading has to keep pace with the code, not with how many people you have to read it.
- US SaaS
For US SaaS teams whose customers ask for SOC 2, HIPAA, NIST, CMMC, or CCPA. The controls that actually show up in a diff, named at the clause.
- Open source
Compliance review on the pull request, for maintainers who keep the repository public. No application. No license check.