Your weaknesses, kept to yourself
A GRC system holds your open risks, control gaps, incidents and response plans. HouseGRC is built so that nobody else ever holds them: not us, not a cloud provider you did not choose.
Nothing comes to us
HouseGRC runs on your server. It never sends your records, users or usage to us, and it does not need to reach us at all: licence keys are signed files that it checks on its own.
Encrypted at rest
Each database is encrypted as a whole, with a key generated on your server when HouseGRC first starts. Secrets such as integration credentials and multi-factor seeds are encrypted again, field by field, with authenticated encryption.
Organisations kept apart
Every query is limited to the organisation of the person asking, below the application code. When no organisation is known, the answer is nothing: the boundary fails closed.
Sign-in
Single sign-on with SAML and role mapping, user provisioning with SCIM, multi-factor sign-in with authenticator apps or passkeys, sign-in alerts from new addresses, and limits on concurrent sessions.
Least privilege
Roles and groups with fine-grained permissions, time-limited and just-in-time access, recorded break-glass sessions, and separation of duties: nobody can approve their own work.
Tamper-evident audit trail
Every change is recorded with who made it. Each entry includes a hash of the one before it, so editing or deleting any entry breaks the chain, and the chain can be verified at any time.
Careful with the outside world
Every outbound request (connectors, webhooks, document fetches) goes through one checkpoint that refuses internal, link-local and cloud-metadata addresses, so HouseGRC cannot be turned against your own network.
AI on your terms
AI features are off until an administrator configures a provider, with your organisation's own account. Text from outside, such as vendor answers and uploaded documents, is treated as data and screened before any model sees it. The assistant can read; it cannot change anything.
Hardened container
The application runs as an unprivileged user with dropped capabilities and no privilege escalation. Your data, your evidence and the database key live on separate volumes that you back up and control.
What is yours to look after
Because HouseGRC runs on your infrastructure, some security is in your hands: keep the server and Docker up to date, put HouseGRC behind your organisation's TLS and network controls, and back up the data, evidence and key volumes together. A backup without the key cannot be read, and the key without a backup is no use: keep them apart, and keep both. The installation guide and upgrades and backups explain how.
What we hold about you
Only what selling you a licence needs: the name, email address and organisation on your licence, and the record of your purchase. Paddle.com, our reseller, handles the payment. See the privacy notice.
Reporting a vulnerability
If you find a security problem in HouseGRC, please write to [email protected] with the details, and give us a reasonable time to fix it before you tell anyone else. We will acknowledge your report and tell you what we do about it.