heygrc
Frameworks in code

What compliance looks like inside a pull request.

Most controls in a framework never touch code. A few do, and those are the ones a review can catch. These pages take a framework apart and show the controls that surface in a diff, the change that trips each one, and the exact clause heygrc cites.

Deep dives

One framework at a time, at the grain of a code change.

We are writing these in order. ISO 27001 is up first; the rest are in progress.

The full set

76 frameworks, one reviewer.

A deep dive exists for a few of these today and more land over time. heygrc is in early access; once you are onboarded it reviews against whichever ones your company must meet.

ISO 27001SOC 2SOC 1GDPRDORANIS 2ISO 42001EU AI ActPCI DSSHIPAAISO 27701ISO 27017ISO 27018NIST CSFNIST 800-53NIST 800-171CMMCFedRAMPCCPA / CPRACyber EssentialsTISAXISO 22301SOXCIS Controls+ 52 more