heygrc
Framework-in-code verkenner

Één wijziging kan meerdere frameworks raken.

Dezelfde gewone codewijziging raakt vaak een control in meer dan één framework tegelijk. Kies hieronder een veelvoorkomende wijziging en zie welke clausules deze meestal raakt, elk met een link naar hoe heygrc dat framework in een pull request leest. Het draait volledig in je browser en is een illustratie, geen compliance-oordeel.

Kies een wijziging

Controls die het meestal raakt

Een debug- of auditlog begint meer persoonsgegevens vast te leggen dan de functionaliteit nodig heeft.

Een illustratie van het framework-in-code idee, geen compliance-oordeel. Welke verplichtingen daadwerkelijk gelden, hangt af van de frameworks die je bedrijf hanteert.

Free tool

Generate a starter .heygrc.md

heyGRC can read a repo-root .heygrc.md as company context for reviews (self-described scope, data types, controls to emphasize). Build a starter file here, download it, commit it, then install the GitHub App so reviews cite your own context. Runs entirely in your browser. No account required.

Frameworks in scope

Company context (optional)

Not a certificate or compliance attestation. Keep secrets out of the file. Public repos make this file public.

Preview

<!-- heygrc_context_version: 1 -->
<!-- Generated on 2026-08-12 from the free heygrc.com starter tool.
     Commit as `.heygrc.md` at the repository root.
     Self-described company context only (no secrets). In a PUBLIC repo this file is public. -->

# heyGRC compliance context

Self-described context about this company so heyGRC's pull-request reviews can reference your own
systems, data, and controls. This is context for review, not a compliance attestation.

## Frameworks in scope for review
- SOC 2
- GDPR

## Self-described company context
- (fill the form fields, or edit this section after download)

## Systems and controls to emphasize
<!-- Add your specific systems and control IDs so reviews can cite them. For example:
       - The billing service handles cardholder data; control DS-LOG-03 forbids logging it.
       - Access control: control AC-MFA-01 requires MFA for all human access. -->

Commit the file at the repository root, open a PR that does not only add the file (the first PR that adds it is reviewed without it, by design), then install heygrc so later PRs can use the context.

Install heygrc on GitHub
Van illustratie naar review

Dit is de koppeling die heygrc op elke PR uitvoert.

Deze verkenner is een statische, handgemaakte kaart van veelvoorkomende patronen. heygrc is gebouwd om hetzelfde soort redenering uit te voeren op de daadwerkelijke diff: elke wijziging lezen aan de hand van de frameworks die je bedrijf heeft geselecteerd en de specifieke control die het raakt citeren, als een review-opmerking. Het certificeert je niet of voert je audit niet uit.