Cloud Compliance Tools - Page 9

How Many Cloud Compliance Software Products Does G2 Track?

Total Products under this Category: 160

Category Stats (Sep 2026)

  • Average Rating: 4.56/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: CrowdStrike Falcon Cloud Security (+0.73%) - Among all products in this category, CrowdStrike Falcon Cloud Security recorded the largest rating increase compared to last month

Last updated: September 26, 2026

How Does G2 Rank Cloud Compliance Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 16,400+ Authentic Reviews
  • 160+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Cloud Compliance Software

G2 Grid® for Cloud Compliance Software plotting products by satisfaction and market presence

Highlighted products: Vanta, Sprinto, Wiz, Drata, Microsoft Defender for Cloud, Scrut Automation, Scytale, and Secureframe.

Underlying data: [Grid® JSON](https://www.g2.com/categories/cloud-compliance/grids.json?focus%5B%5D=vanta&focus%5B%5D=sprinto-inc&focus%5B%5D=wiz-wiz&focus%5B%5D=drata&focus%5B%5D=microsoft-defender-for-cloud&focus%5B%5D=scrut-automation&focus%5B%5D=scytale-g2&focus%5B%5D=secureframe)

Continuum GRC

Continuum GRC ITAM SaaS platform - We offer the leading solution for PCI, FedRAMP, CMMC, HIPAA, NIST, CJIS , DFARS , SOC 1, SOC 2, ISO 27001, NERC CIP, SOX 404, and others. We speed and simplify audit and compliance, removing much of the expense and effort associated with these essential tasks.

Who Is the Company Behind Continuum GRC?

cp.Discover

cp.Discover installs quickly and is pre-configured to find credit card numbers, patient information, and personally identifiable information (PII) used in several countries. Users can also create custom sensitive data types, a feature useful for locating intellectual property and other sensitive data types specific to your business. A single installation of cp.Discover is able to search for information in local and remote file shares, Microsoft SharePoint, and Office 365 without any additional software. cp.Discover uses keywords, regular expressions (patterns), and post-processing (for example, the Luhn Algorithm) to identify sensitive and regulated information. Our classification capability automatically tags and categorizes unstructured data across data centres and clouds. Our solution employs multiple techniques to accurately classify information without compromising system performance or user productivity. - Metadata matching is used to categorize information based on attributes/properties like file type, location, and file owner - Pattern matching is used to find recognizable data such as credit card numbers, medical record numbers, and personally identifiable information - Machine learning (artificial intelligence) is used for information that can be pre-categorised cp.Discover can analyse information on a schedule or be used in-line with existing business process/workflows via an API. It can also be used to automate governance requirements associated with archival and eDiscovery, and enable cloud migrations.

Who Is the Company Behind cp.Discover?

  • Seller: Cipherpoint
  • HQ Location: N/A
  • Twitter: @Covata
    353 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®
  • Ownership: ASX: CPT

CPDone

As a cloud based compliance management software, CPDone was designed to work across a global workforce, allowing businesses to monitor various aspects of different compliance initiatives. The platform provides board to front line visibility on policy & professional development initiatives. A comprehensive and constantly updated view of weaknesses and program status. Information that is readily available enables businesses to make an informed decision.

Who Is the Company Behind CPDone?

Frontline Hardened Virtual Machines

Frontline builds and maintains hardened, compliance-focused virtual machines for AWS. Frontline empowers engineers to launch hardened servers quickly and easily. Using industry standard hardening techniques and frameworks, our system images save you time and money. Included with every Frontline virtual machine is a team of dedicated, passionate world-class support. Whatever your cloud budget may be, we can make it work. Each Frontline VM is built to be affordable and hardened for any environment.

Who Is the Company Behind Frontline Hardened Virtual Machines?

GORICO

Solving the compliance and certification challenge is only the first step. GoRICO empowers organizations to understand, attain and sustain true security.

Who Is the Company Behind GORICO?

  • Seller: Accorian
  • Year Founded: 2019
  • HQ Location: East Brunswick, New Jersey, United States
  • LinkedIn® Page: www.linkedin.com
    146 employees on LinkedIn®

Govplane

Govplane is a governance layer that allows teams to control application behavior at runtime — without redeploying services or modifying code. Instead of hardcoding business rules across your system, Govplane lets you define policies that are centrally managed and instantly enforced across your applications. These policies can allow or deny actions, apply rate limits, trigger kill switches, or adapt behavior based on real-time context. Policies are compiled into a signed bundle and evaluated locally within your services. This ensures deterministic outcomes, zero added latency, and continued operation even without network connectivity. Govplane is designed for systems where behavior needs to evolve continuously. Teams can respond to incidents, adjust rules, or roll out changes instantly — without introducing deployment risk or coordination overhead. Key capabilities include: • Centralized policy management with version control • Local evaluation with no runtime network dependency • Deterministic and predictable decision-making • Secure distribution through signed policy bundles • Support for conditional logic and context-aware rules • SDKs for Node.js, Java, PHP, and Python Govplane helps teams move faster while maintaining control, consistency, and security across their systems.

Who Is the Company Behind Govplane?

HackZero

HackZero is a security and compliance platform in the same category as Vanta, Drata and Secureframe, with the two things they leave you to buy separately already in the package: a real, continuous penetration test, and an independent CPA who issues the attestation. The usual path to SOC 2 Type 2 is three vendors. A compliance platform for the paperwork, a separate firm for the pentest, and an auditor at the end, wired together by you. HackZero runs all three as one motion. The platform collects and maps your evidence to the SOC 2 Trust Services Criteria itself, so you do not need Vanta, Drata or Secureframe alongside it. If you already run one, our pentest report drops straight in as evidence there. The penetration test is not a separate purchase: we test your live app continuously with AI agents, and hackers in the loop confirm every finding actually exploits, with each one pre-mapped to the control it satisfies. The same evidence is formatted for HIPAA, PCI DSS 4.0 and ISO 27001:2022 when you need those. We do not sell the audit. An independent AICPA-member CPA issues the SOC 2 opinion and you pay them directly, which is what keeps the attestation independent and keeps us out of the audit-mill category. A first SOC 2 Type 2 lands around $6,000 all-in, against the $30,000 to $45,000 a separate platform, pentest and auditor cost. Our pricing is public, our benchmark results are public, and our vulnerability research is public and credited, including a critical RCE in velocity.js (CVSS 9.8) and a Function-constructor escape in JSONPath-Plus, so our claim of real security depth is one you can verify.

Average Rating: 4.8/5.0

Total Reviews: 2

How Do G2 Users Rate HackZero?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.3/10)

Who Is the Company Behind HackZero?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of HackZero?

Hardened Microsoft Windows Server 2012 R2

The Hardened Microsoft Windows Server 2012 R2 is a fortified version of Microsoft's server operating system, designed to provide enhanced security and performance for enterprise environments. This hardened edition incorporates critical security updates and configurations to protect against unauthorized access and potential vulnerabilities, ensuring a robust and reliable server infrastructure. Key Features and Functionality: - Enhanced Security Measures: Pre-configured with the latest security patches and settings to mitigate common threats and attacks. - Optimized Performance: Fine-tuned system configurations to deliver improved efficiency and responsiveness for demanding workloads. - Comprehensive Compliance: Aligns with industry standards and best practices to meet regulatory requirements and organizational security policies. - Simplified Deployment: Ready-to-use image that reduces setup time and complexity, allowing for quick integration into existing IT infrastructures. Primary Value and Problem Solved: The Hardened Microsoft Windows Server 2012 R2 addresses the critical need for a secure and stable server environment in enterprise settings. By providing a pre-hardened operating system, it alleviates the burden on IT teams to manually implement security configurations and updates, thereby reducing the risk of misconfigurations and potential breaches. This solution ensures that organizations can maintain high levels of security and compliance while focusing on their core business operations.

Who Is the Company Behind Hardened Microsoft Windows Server 2012 R2?

Havoc Shield

An all-in-one cybersecurity program for startups and small businesses with limited internal security teams to meet stringent security requirements, mitigate increasing cyber threats and complete security questionnaires. No security pros required, all in one place, ready right now. Founded in 2019, we are a small team that caters to other small businesses and startups who may feel left behind by larger cybersecurity providers while still receiving enterprise-level preventative security modules to win more business and keep their business safe. To win new business through security questionnaire help and preventative cybersecurity programs catered to small business, choose Havoc Shield.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Havoc Shield?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.3/10)

Who Is the Company Behind Havoc Shield?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Havoc Shield?

HighGround.io.

Under pressure from the board to make the business safe from Cyber threats, but without enough budget to do so? HighGround enables you to take control of your security experience with a range of security management capabilities. Get access to everything you require to manage all elements of your cyber security based on what you need and when you need it. Key features include Cyber Score, Integrations, Cyber Compliance Manager and ROI tools to help justify security investment and allow you to be subject matter experts. Feel like a Cyber superhero and in turn, sleep that little bit better.

Who Is the Company Behind HighGround.io.?

HyTrust Cloud Advisor

HyTrust CloudAdvisor for Data enables you to define policies to automatically discover the data that’s valuable to you, detect anomalous user access behaviors, and defend your organization against careless exposure, data loss, malicious users, and regulatory noncompliance.

Who Is the Company Behind HyTrust Cloud Advisor?

  • Seller: HyTrust
  • HQ Location: Minneapolis, Minnesota, United States
  • Twitter: @HyTrust
    1,578 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,742 employees on LinkedIn®

iCompaas – Compliance, Covered from Start to Finish

iCompaas is an AI-powered GRC automation platform for organizations that want compliance covered from start to finish. It brings together readiness, policy management, evidence collection, remediation, VAPT coordination, auditor coordination, and continuous audit readiness in one system. With one platform, one partner, and a single invoice for the full journey, iCompaas helps customers reduce manual work, simplify vendor management, and accelerate certification across leading frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, NIST, CIS, C5, and ISO 42001, with additional compliance frameworks continually being added.

Who Is the Company Behind iCompaas – Compliance, Covered from Start to Finish?

  • Seller: iCompaas
  • Year Founded: 2019
  • HQ Location: Santa Clara, US
  • LinkedIn® Page: www.linkedin.com
    42 employees on LinkedIn®

Kalos by Stratus10

An AI-driven cloud management platform for AWS, Kalos helps you reduce spend, strengthen security compliance, and maintain efficient performance. Leverage AI and automation to drastically reduce time spent analyzing reports and help you prioritize cost and security optimizations. Reclaim control of your AWS environment and make data-driven decisions that increase efficiency, compliance, and savings.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Kalos by Stratus10?

  • Seller: Stratus10
  • Year Founded: 2017
  • HQ Location: San Diego, US
  • Twitter: @Stratus_10
    272 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    9 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About Kalos by Stratus10?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the easy visibility of compliance and costs in Kalos, streamlining their AWS infrastructure management.
  • Users appreciate the ease of use of Kalos, enabling quick access to AWS infrastructure and compliance details.
  • Users appreciate the security compliance features of Kalos, ensuring easy oversight of AWS infrastructure and costs.
  • Users value the visibility of Kalos, enabling easy access to AWS infrastructure, costs, and compliance information.

What Are Recent G2 Reviews of Kalos by Stratus10?

Kordon.app

Kordon is a governance, risk, and compliance platform designed to keep you audit-ready and help you achieve your information security goals.

Who Is the Company Behind Kordon.app?

Letsbloom

Letsbloom empowers organisations by simplifying compliance audit processes. Whether an early stage startup, SMB or an enterprise, our compliance automation platform can help you accelerate your compliance journey 10x faster. The platform provides continuous real-time observability and risk management, AI-enabled actionable guidance and insights for faster remediation, comprehensive compliance coverage for technical and process controls, across all frameworks (such as SOC2, ISO 27001 etc.), regulatory standards and custom internal policies. Letsbloom platforms can seamlessly integrate with all major cloud environments and a wide range of services and technologies. We help companies stay compliant, build trust, increase revenues and scale faster.

Who Is the Company Behind Letsbloom?

  • Seller: Letsbloom
  • Year Founded: 2020
  • HQ Location: Singapore , SG
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®
Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024