The Anecdotes Compliance OS Core PackageEverything your team needs to get started with data-powered GRC automation | ||
---|---|---|
Out-of-the-box frameworks | Unlimited | |
Easily automate the management, monitoring, and audits of all of your frameworks. Anecdotes has over 40 pre-mapped frameworks for you to choose from. Thanks to our cross-mapping technology, the work you do in one framework can be leveraged for others—which makes adopting additional frameworks much easier! Have multiple instances of a framework? No problem. Easily create as many as your business needs. | ||
Custom frameworks | Unlimited | |
You shouldn't be punished for having a mature program! Keep using your own, custom frameworks. With just a few simple steps you can upload or configure a custom framework. And don't worry—at Anecdotes, custom frameworks use the same automation and cross-mapping that our out-of-the-box frameworks use, so you will continue to enjoy automated evidence collection. | ||
Gap detection and analysis rules | Unlimited | |
Anecdotes has created rules based on CIS standards to automatically detect gaps within your GRC data. You can also create custom rules based on your policies—no code required! If records in the evidence table match the rule, it will be flagged, so you know exactly where you need to focus your efforts. This will save you valuable time and help you identify gaps you may otherwise miss. | ||
Plugins | Unlimited | |
Data is at the core of everything we do. The more plugins you connect, the more you'll be able to do, and the better visibility you'll have into your GRC posture. All of our 170+ plugins are developed 100% in-house, so you don't have to worry about third parties gaining access to your data. We build them based on the principle of least privilege, so you won't be providing excessive access, either. | ||
CSP accounts | 10* | |
Mature companies often have more than one cloud instance, and you need to see all of them to gain a real understanding of your GRC posture. Anecdotes lets you connect as many as you need. And don't worry, with Anecdotes' granular configurability you will be able to decide which account is in scope for each of your frameworks. | ||
Evidence Lab | ||
With some tools, like Jira or GitHub, you'll want to collect evidence that’s unique to the way your business operates. The Anecdotes Evidence Lab empowers you to craft custom evidence. Once defined, this evidence will be automatically collected and mapped to your entire GRC program. | ||
Policy Manager | ||
Upload your policies to your Anecdotes Compliance OS or choose from our elaborate policy library. You can automatically manage the entire review and approval cycle with ease, using notifications to communicate efficiently with reviewers and approvers. | ||
Playbooks | Unlimited | |
Anecdotes Playbooks is an automated solution for continuously responding to events in your GRC data. Integrate with collaboration tools and predefine a response plan to reduce downtime and risk exposure while addressing events in your data. | ||
Dashboards & reporting | ||
Anecdotes Compliance OS includes dashboards for monitoring the various aspects of your GRC program and demonstrating your ROI. You can filter data to meet your needs and generate reports to demonstrate your progress. | ||
Custom Roles | ||
Don't want all users to have access to all parts of the platform? No problem. With Anecdotes Custom Roles you can easily define and assign roles and permissions to team members according to business needs and limitations. | ||
SSO | ||
Anecdotes supports single sign-on through Google, Microsoft, and other Identity Providers (IdPs). | ||
SCIM | ||
Configure SCIM provisioning of users with OKTA. | ||
User licenses | 5* | |
These are the core users of the platform. User licenses do not apply to external users who are assigned specific tasks, or auditors—those are unlimited. | ||
Robust API | ||
Anecdotes offers a variety of API endpoints for programmatically interacting with key objects in your GRC program, including evidence, requirements, controls, frameworks, and risks. Leverage all of your standardized and structured data evidence in any GRC application. If you need help, our support team is here for you! |
*Additional accounts and users are available for an additional cost.
With the Anecdotes Risk App you can finally embrace a risk-based mindset. Powered by the data pulled from your tech stack—all mapped to the mitigating controls in your risk register—the Anecdotes Risk App delivers unmatched enterprise-level risk management and monitoring capabilities, giving you a broader context for understanding the impact of security and GRC gaps.
When you have a complex tech stack, ensuring employees have access only where and to what is needed is paramount for compliance and risk mitigation. With the Anecdotes UAR App, you can automate review and approval cycles and monitor irregularities in permissions. Besides saving time and resources up front, automating user access reviews eliminates the need to grapple with error-prone manual review cycles.
Put your commitment to security and GRC on display. The Anecdotes Trust Center provides seamless external sharing of your organization's GRC program. Your Trust Center streamlines the security check process and ensures ease and efficiency throughout the sales journey.
Adhere to the highest standards of data ownership and still enjoy robust automation. Anecdotes will serve as a data processor, and your data will remain within your perimeter at all times.
Is part of your tech stack on-prem? No problem! Our team will work with you to customize an On-premises Connector that lets you enjoy automation and data from your on-prem or private cloud infrastructure as well as your SaaS tools.
Your GRC program has a huge impact on the entire organization. Leverage the Connected App to stream the metadata created in the Anecdotes Compliance OS into your chosen database for more personalized analysis and contextualized reporting.