✍️Writing & Content26🎨Image Generation34🎬Video & Animation68🎵Audio & Music50💬Chatbots & Assistants39💻Coding & Development178📈Marketing & SEO60Productivity156🎯Design & UI/UX57📊Data & Analytics43📚Education & Research27💼Business & Finance56🏥Healthcare & Wellness18🔍Search & Knowledge14🤖AI Agent Infrastructure49🛡️AI Security & Testing3🧊3D & Spatial19🔎SEO Tools8🏡Real Estate4🗃️Data Extraction3🧠ADHD & Focus Tools9
Part of 1067+ curated AI tools on AISO
heygrc logo

heygrc

GitHub App that reviews every pull request for compliance across 91 frameworks, citing the specific control

freemiumEvery install starts with 14 days of unlimited private reviews, no credit card, then drops to Free automatically. Free is $0/month with 25 private reviews per month as a hard cap; public repositories are always free. Starter is $19 per org/month for 100 private reviews. Pro is $99 per org/month for 500. Business is $249 per org/month for 2,000. There are no seat fees. Past the included allotment reviews stop unless you enable on-demand at $0.49 each or upgrade. Review depth is identical on every tier.View full pricing →

Visit heygrc

https://heygrc.com

About heygrc

heygrc is compliance review that runs in the pull request rather than in the audit six months later. It installs as a GitHub App with no CI config or YAML to maintain, you select the frameworks your company must meet and add company context during a sub-two-minute onboarding, and from the next PR onward it posts a review with inline comments and a check status you can require in branch protection. The findings are grounded in specific clauses rather than generic warnings — the worked example on the homepage catches a one-line change dropping `AUDIT_LOG_RETENTION_DAYS` from 365 to 30 and cites ISO 27001:2022 A.8.15 and SOC 2 CC7.2, noting that monitoring evidence typically needs at least 90 days. Coverage spans 91 frameworks including ISO 27001, SOC 1 and 2, GDPR, DORA, NIS 2, ISO 42001, the EU AI Act, PCI DSS, HIPAA, the ISO 277xx privacy series, NIST CSF and 800-53/800-171, CMMC, FedRAMP, CCPA/CPRA, Cyber Essentials, TISAX, ISO 22301, SOX, and CIS Controls, with the live catalog exposed at an API endpoint. Reviews are scoped to your sector, data types, and hosting region rather than a generic checklist. The explicit target is teams heading into a first SOC 2 or ISO 27001 audit, and the framing is that AI agents now ship code faster than any human can compliance-check it — so it reviews PRs from Claude Code, Cursor, Copilot, Codex, and humans alike. It is built by ISMS Copilot.

Key Features

GitHub App install with no CI config or YAML
91 frameworks including ISO 27001, SOC 2, GDPR, DORA, NIS 2, EU AI Act, HIPAA, FedRAMP
Every finding cites a specific clause, e.g. ISO 27001:2022 A.8.15 or SOC 2 CC6.1
Reviews scoped to your sector, data types, and hosting region
GitHub check status you can require in branch protection
Reviews PRs from Claude Code, Cursor, Copilot, Codex, and humans alike

Tags

soc 2iso 27001gdprcode reviewgithub appeu ai act
🏷️

Is this your tool?

Claim your listing to get a Featured badge, edit your description, and stand out from competitors. All plans include a permanent dofollow backlink to your site.

Claim Now →

ChatGPT already recommends heygrc. Does it recommend yours?

If you're building in soc 2, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

📬 Get the best new AI tools delivered weekly

One concise email with fresh launches, trending picks, and featured standouts.

Alternatives to heygrc

View all heygrc alternatives →

Agent connectivity: not yet verified