How it works
Runs inside your boundary. Reads what you already collect. Explains itself.
AlloyGRC is a packaged platform installed in your environment. Your data, your tools, models on your own hardware. Nothing leaves.
The data path
From the sources you already have to answers you can act on
There is no page per data source. A source is described once, and every feature reads it by the role its fields play.
01
Your sources
Scan data from the scanners you already run, identity state, the policies and evidence you upload, and the ATIP threat corpus refreshed daily.
Raw collections
02
Dataset Builder
Profiles a source, asks you to confirm what its fields mean (which one is the severity, which one joins to a system), and publishes it once.
Dataset roles
03
Every feature
Vulnerability views, sprint boards, dashboards, Ask Alloy and the ATO workflow all ask for a role, never a column name. A new source needs no release.
Ranked, scoped views
04
AI on top
Ask Alloy, GenAI Dashboards, AVISSAA, PolicyForge and evidence analysis read the same roles and run on local models. The model writes prose and picks shapes; code produces every number.
Answers, boards, drafts
What the models do
Five AI features, all inside the boundary
Advisory assistant for ISSOs and ISSEs
AVISSAAAsk what a control requires, what an assessor will expect as evidence, and what the mandatory tasks are at each RMF step. Answers are retrieved from the NIST corpus and cite the publication.
Policies drafted, gap checked and fixed
POLICYFORGEGenerate policies against a control baseline, then run semantic gap analysis over the ones you already have and draft the missing language.
Evidence read against the control
cATOUpload a screenshot, a scan or a config export and get a determination with its reasoning. A human ratifies. Nothing closes on a model verdict alone.
Dashboards from a sentence
GENAI DASHBOARDSType what you want to see. The model picks the shape, the code computes every number, and the board can be pinned as an executive's opening view.
Plain English answers from your data
ASK ALLOYA drawer on every page that navigates, looks up real figures, or explains them, and labels each answer by which of the three it is.
Sovereign AI
Every model AlloyGRC uses runs on hardware inside your boundary. No prompt, finding, evidence file or policy is ever sent to an external inference service.
Tested on Qwen and Gemma. Want to know whether it works on your model of choice? Ask us
-
Where it runs
On premises or in your own cloud, as containers. Never hosted by Avint.
-
Who installs it
Avint engineers install and configure it today. A fully automated Ansible install is in development so that no Avint engineer ever has to touch your data.
-
Who gets in
Role gated seats for the Authorizing Official, ISSO, ISSM, ISSE, System Owner, Security Control Assessor, administrators and IT support, with the authorization workflow being made configurable to your agency's practice. Every view is scoped to the systems a person is cleared for, enforced by the server.
-
What is recorded
Consequential actions, approvals and overrides are written to an activity ledger you can export to the SIEM you already run.
Integrate, do not replace
Connects to what you already run.
Nobody rips out a working stack for a new platform. AlloyGRC reads from your tools and hands work back to them.
| Source | What it does | Status |
|---|---|---|
| Tenable Security Center and Qualys | Vulnerabilities, compliance results and assets, ingested and ranked by AREA | Today |
| ATIP threat corpus | Enriched CVE intelligence, refreshed daily by the Avint pipeline | Today |
| Jira | Send a sprint or a group of findings to Jira as tickets, opt in per send | Today |
| MidPoint identity | Live account, role and entitlement state for Access Control assessment | Today |
| Active Directory | Sign in and role resolution from your directory | Today |
| CrowdStrike Falcon | Endpoint detections beside the findings on the same asset | In development |
| Microsoft Intune | Hand remediation to endpoint management | Planned |
| ATIP API | Query the threat corpus from outside AlloyGRC | Planned |
| Existing ATO import | Bring an authorized system straight into continuous monitoring | Planned |
See it installed, not hosted.
We demo on synthetic data so you see everything without exposing anything. Then we install it against your own sources.