Skip to main content

How it works

Runs inside your boundary. Reads what you already collect. Explains itself.

AlloyGRC is a packaged platform installed in your environment. Your data, your tools, models on your own hardware. Nothing leaves.

The data path

From the sources you already have to answers you can act on

There is no page per data source. A source is described once, and every feature reads it by the role its fields play.

01

Your sources

Scan data from the scanners you already run, identity state, the policies and evidence you upload, and the ATIP threat corpus refreshed daily.

Raw collections

02

Dataset Builder

Profiles a source, asks you to confirm what its fields mean (which one is the severity, which one joins to a system), and publishes it once.

Dataset roles

03

Every feature

Vulnerability views, sprint boards, dashboards, Ask Alloy and the ATO workflow all ask for a role, never a column name. A new source needs no release.

Ranked, scoped views

04

AI on top

Ask Alloy, GenAI Dashboards, AVISSAA, PolicyForge and evidence analysis read the same roles and run on local models. The model writes prose and picks shapes; code produces every number.

Answers, boards, drafts

Sovereign AI

Every model AlloyGRC uses runs on hardware inside your boundary. No prompt, finding, evidence file or policy is ever sent to an external inference service.

Local models

Control advisory, evidence analysis, dashboard design and remediation narratives all run on GPUs you control.

Deterministic where it counts

Rankings, counts and scores are computed in code. Models write prose, pick chart shapes and explain results. They never produce a number.

Priced, not preached

The LLM Infrastructure ROI dashboard shows what local inference saves against cloud GPUs and per token pricing.

Tested on Qwen and Gemma. Want to know whether it works on your model of choice? Ask us

Deployment

Packaged. Installed by Avint. Yours to run.

See what each role gets
  • Where it runs

    On premises or in your own cloud, as containers. Never hosted by Avint.

  • Who installs it

    Avint engineers install and configure it today. A fully automated Ansible install is in development so that no Avint engineer ever has to touch your data.

  • Who gets in

    Role gated seats for the Authorizing Official, ISSO, ISSM, ISSE, System Owner, Security Control Assessor, administrators and IT support, with the authorization workflow being made configurable to your agency's practice. Every view is scoped to the systems a person is cleared for, enforced by the server.

  • What is recorded

    Consequential actions, approvals and overrides are written to an activity ledger you can export to the SIEM you already run.

Integrate, do not replace

Connects to what you already run.

Nobody rips out a working stack for a new platform. AlloyGRC reads from your tools and hands work back to them.

SourceWhat it doesStatus
Tenable Security Center and Qualys Vulnerabilities, compliance results and assets, ingested and ranked by AREA Today
ATIP threat corpus Enriched CVE intelligence, refreshed daily by the Avint pipeline Today
Jira Send a sprint or a group of findings to Jira as tickets, opt in per send Today
MidPoint identity Live account, role and entitlement state for Access Control assessment Today
Active Directory Sign in and role resolution from your directory Today
CrowdStrike Falcon Endpoint detections beside the findings on the same asset In development
Microsoft Intune Hand remediation to endpoint management Planned
ATIP API Query the threat corpus from outside AlloyGRC Planned
Existing ATO import Bring an authorized system straight into continuous monitoring Planned
Every connector, what it pulls

See it installed, not hosted.

We demo on synthetic data so you see everything without exposing anything. Then we install it against your own sources.