heygrc
Get started

Start reviewing every pull request.

Install heygrc and it reviews your pull requests across ISO 27001, SOC 2, GDPR, and many more frameworks, each finding grounded in the specific control it touches. Claim your install in the console for 14 days unlimited, no credit card.

  1. 01

    Install the GitHub App

    One click. Pick the repositories heygrc should review. Public repositories are always free.

  2. 02

    Choose your frameworks

    ISO 27001, SOC 2, GDPR, and more. heygrc grounds each finding in the specific control it touches, at the diff.

  3. 03

    Every pull request gets reviewed

    Reviews start immediately on the free tier. Claim your install for 14 days unlimited, then free for 25 private reviews a month. Past included limits, reviews pause unless you enable on-demand at $0.49 each.

Install heygrc

Add the GitHub App and reviews start on your next pull request. Claim it in the console for 14 days unlimited, no credit card.

Get started

Then free: 25 private reviews / month. Public repositories always free.

What heygrc catches

The kind of change heygrc catches in a diff.

Not generic findings. heygrc reads the pull request and grounds each one in the specific control it touches.

A pull request broadens an IAM role or opens a new access path.

SOC 2 CC6.1logical access controls

A change removes or quietly weakens an audit log.

ISO 27001:2022 A.8.15logging

A new table starts storing personal data with no retention bound.

GDPR Art. 5(1)(e)storage limitation