Talk to us
by IruTechBag Intel Page

Iru Compliance Automation

Your biggest customer wants a SOC 2 report. A shared drive of screenshots won’t get you there — Iru Compliance Automation drafts controls for SOC 2, ISO 27001 and nine more frameworks, collects the evidence, and shares a platform with Iru’s device and identity products — hosted in the US or EU, not India.

11 frameworks, SOC 2 to CMMCAI-tailored controls and evidenceUS or EU tenant; quote-only

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Licensed per framework plus seats on an annual term; reached only through a demo
Quote
Frameworks
SOC 2 and three ISO standards through to HIPAA, NIST 800-171 and CMMC; none Indian
11 listed
Analysts
No Gartner Magic Quadrant placement is announced by Iru for this compliance product
None announced
India
Tenants run on AWS in the United States or Germany; there is no Indian hosting region
US or EU

Quick answer

Iru Compliance Automation, launched in October 2025 by Iru (formerly Kandji), prepares a company for audits against 11 frameworks, from SOC 2 and ISO 27001 to HIPAA and CMMC, with AI-tailored controls and automated evidence collection. It is not an audit firm. It is licensed per framework plus seats, quote-only on an annual contract after a demo, and tenants sit in the US or EU. No Indian framework or region is offered. Read more ↓ Show less ↑
Part 01 · Orient

The Iru platform family

This page covers Iru Compliance Automation — audit readiness, licensed per framework. The rest:

Quick facts

30-second orientation
Product
Audit-readiness software: AI-tailored controls, automated evidence and policy management
Maker
Iru, Inc., US-based (Miami and San Diego); CEO Adam Pettit; founded 2018
Status
Launched October 2025; Adaptive Compliance (June 2026) and policy management (July 2026) since
Price
Quote-only; annual contracts billed annually; demo first, no self-serve trial
Licence
Per framework plus seats; Trust Center is a separate line on Iru’s Billing page
Frameworks
SOC 2, ISO 27001/27701/42001, Cyber Essentials, GDPR, HIPAA, NIST 800-53/800-171/CSF 2.0, CMMC
Auditor
Not an audit firm and no auditor network mentioned; you engage the auditor yourself
India
No CERT-In, DPDP, RBI or SEBI framework and no India region; tenants in the US or EU
Support
24/5 by chat, portal and email; free onboarding; 99.9% availability commitment
In India via
TechBag — framework scoping, demo set-up, quote in INR with GST
Part 02 · Learn

Understand compliance automation before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is compliance automation?

Software that keeps controls, evidence and policies for an audit in one place, so a SOC 2 or ISO 27001 audit stops being a scramble.

Screenshots in a shared drive vs automated audit prep — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionScreenshots and spreadsheetsIru Compliance Automation
Where controls come fromA downloaded template, edited by handAI-generated controls tailored to you
How evidence is gatheredScreenshots requested over chatConnectors collect it from your systems
Matching proof to controlsA spreadsheet tab per frameworkThe Adaptive Evidence Map links them
Written policiesWord files in a shared drivePolicy management in the same product
Suppliers involvedMDM, GRC tool and trust page apartOne Iru contract, modules licensed apart
What it is NOT—An audit firm, or a tool for Indian rules

The cheapest test is the demo itself: bring one customer security questionnaire and see how much of it the generated controls already answer.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What you are measured against

Frameworks

Licensed framework library

You license the frameworks you need, such as SOC 2 or ISO 27001, and Iru generates controls tailored to your company for each, which become the spine of the audit programme.

02
Where the proof comes from

Connectors

Evidence connectors

Connectors to cloud, monitoring, HR, password and identity tools, AWS, Datadog, Workday, 1Password and JumpCloud among them, collect evidence without a request to each owner.

03
How proof meets controls

Evidence Map

Adaptive Evidence Map

Collected evidence is mapped onto the controls it supports; Adaptive Compliance and policy management, both added in mid-2026, extend the same workspace towards audit day.

04
Where the records live

Tenant

Iru tenant, US or EU

Compliance records sit in the same Iru tenant as the rest of the platform, hosted on AWS in the United States or Germany; no Indian region and no on-premises edition exist.

Frameworks licensed one by one — controls drafted by AI, evidence pulled from your systems, all inside a US or EU tenant.

Part 03 · Evaluate

Nine capabilities. Map, collect, prove.

Iru Compliance Automation turns your connected systems into audit evidence, mapped to controls written for your company.

Map
Frameworks

Eleven frameworks on one list

SOC 2, ISO 27001, ISO 27701, ISO 42001, Cyber Essentials, GDPR, HIPAA, three NIST sets and CMMC appear on the product page.

Map
AI controls

Controls drafted for your company

Iru uses AI to generate controls tailored to the organisation instead of handing every customer one identical stock library.

Map
Adaptive

Adaptive Compliance, June 2026

Shipped in June 2026 with its own launch video; ask in the demo how it changes controls when your audit scope shifts.

Collect
Evidence

Evidence gathered automatically

Connectors pull evidence from systems you already run, so screenshots and exported spreadsheets stop being the audit artefact.

Collect
Evidence Map

Proof matched to controls

What Iru calls the Adaptive Evidence Map places each collected artefact against the controls it supports, rather than by hand.

Collect
Connectors

Sources beyond the device fleet

Documented sources include AWS services, Datadog, 1Password, Intercom, Sentry, JumpCloud, Workday and Snowflake, among others.

Prove
Policies

Policy management, July 2026

Policy management arrived in July 2026, putting the written policies auditors request beside the controls and the evidence.

Prove
Trust Center

A public portal, licensed apart

Iru Trust Center shows certifications and reports to customers; it is its own Billing line, not part of the framework licence.

Prove
Platform

Next to endpoint and identity

Compliance Automation shares the Iru platform with Endpoint Management, EDR, Vulnerability Management and Workforce Identity.

See it, don’t just read it

Watch Iru Compliance Automation in action

The 2025 product overview, then the two 2026 launches: Adaptive Compliance and policy management.

Iru (official)·Overview, 2025

Iru Compliance Automation

The launch overview from October 2025: frameworks, AI-tailored controls and automated evidence in one tour.

Iru (official)·Launch, 2026

Introducing Adaptive Compliance from Iru

Iru’s own introduction to Adaptive Compliance, the June 2026 addition to the product.

Iru (official)·Launch, 2026

Introducing Policy Management in Iru Compliance Automation

How written policies joined the controls and evidence inside Compliance Automation in July 2026.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Iru Compliance Automation

Every enterprise deal now arrives with a security questionnaire. Iru collects the answers from systems you already run.

Where it earns a shortlist place — and the gaps an Indian buyer has to plan around.

01

One vendor for the laptops and the audit

Iru sells Compliance Automation on the same platform as its endpoint, EDR, vulnerability and identity products. A company already running Iru on its Macs adds audit preparation as one more module on the same contract and support desk, instead of onboarding a separate GRC supplier.

02

Controls written for you, evidence gathered for you

Instead of a stock control library, Iru generates controls tailored to the company, then places automatically collected evidence against them through its Adaptive Evidence Map. Connectors reach AWS, Datadog, 1Password, Workday and Snowflake, cutting the screenshot-hunting of a first SOC 2.

03

The frameworks overseas customers ask about

The list follows export demand: SOC 2 and ISO 27001 for SaaS deals, ISO 27701 for privacy, ISO 42001 for AI, HIPAA for US health data, Cyber Essentials for UK buyers, and NIST 800-171 with CMMC for US defence supply chains. Indian exporters to those markets fit best.

04

Where it stops

It is about a year old, quoted only after a demo, and it lists no Indian framework: no CERT-In directions, DPDP Act, RBI or SEBI CSCRF mapping. It is not an audit firm and names no auditor network, so the auditor is yours to find and pay. Tenants live in the US or EU only.

The idea
Audit prep on the device platform
The residency
US or EU tenant; no India region
The price
Quoted per framework plus seats
Proof, not promises

The numbers behind the platform

11 frameworks
listed on the product page, from SOC 2 and ISO 27001 to NIST CSF 2.0 and CMMC
— Vendor
2025
the year, in October, that Compliance Automation launched with the new Iru name
— Vendor
0 Indian frameworks
CERT-In, the DPDP Act, RBI and SEBI CSCRF are all absent from the framework list
— TechBag
24/5 support
chat, portal and email from Sunday 22:30 to Saturday 01:00 UTC, on every plan
— Vendor
6000+ teams
using Iru across its products, by the count on Iru’s own About page (2026)
— Vendor
$100M
Series D in July 2024 at an $850M valuation, the latest funding round found
— Vendor

What your Iru Compliance Automation rollout looks like

Week 1Model

List the frameworks buyers demand

Collect security questionnaires and contract clauses from your largest customers and decide which frameworks the quote covers.

Week 2Decide

Book the demo and price it

There is no self-serve trial, so bring your framework list and headcount to the demo and ask for an itemised annual quote.

Week 3Pilot

Connect the evidence sources

Link cloud, HR, identity and password tools such as AWS, Workday, JumpCloud and 1Password, then review the generated controls.

Month 2Prove

Close gaps and publish policies

Work through failing controls, publish policies in the policy module, and track Indian duties like CERT-In reporting elsewhere.

Month 3Commit

Bring in the auditor

Engage an independent audit firm, give it the mapped evidence, and decide afterwards whether a Trust Center licence is worth adding.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
24+ reviews*
78% would recommend
Framework coverage4.0
Evidence automation4.2
Ease of setup4.1
India fit2.9
Value for money3.7
5★
38%
4★
38%
3★
16%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
SaaS
“Every Mac we own already ran Iru, so the SOC 2 module was one more line on the renewal, not one more vendor review.”
Head of IT
SaaS
Fintech
“The AI-drafted controls were a fair first cut, but our auditor still had us reword about a third into plainer language.”
Security Lead
Fintech
Software
“Workday and 1Password evidence now arrives on its own. Exporting those reports used to cost our HR team two days.”
People Operations Manager
Software
Healthtech
“We sell to US hospitals, so HIPAA beside ISO 27001 in one workspace beat the tools that centred only on SOC 2.”
CTO
Healthtech
IT Services
“There is no DPDP or CERT-In mapping, so our Indian regulatory tracker still sits in a spreadsheet beside it.”
Compliance Manager
IT Services
E-commerce
“Demo-only buying slowed us down. We wanted to click through a trial workspace before giving sales an hour.”
Engineering Manager
E-commerce
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the compliance automation market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Compliance Automation Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Iru Compliance AutomationThis page

A year old; quoted per framework plus seats.

Grid 02 · The architecture

India Readiness × Framework Breadth

The grid nobody publishes — how ready a tool is for Indian rules and Indian hosting vs how many frameworks and connectors it brings.

Global-framework platformsIndia-ready breadthBundled startersLocal specialists
Iru Compliance AutomationThis page

11 frameworks, none Indian; US or EU tenants.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Iru Compliance Automation vs the compliance automation field

Against Vanta, Drata, Secureframe, Sprinto and OneTrust Tech Risk & Compliance — on frameworks, Indian rules, price, evidence, auditors and hosting.

DimensionIru Compliance AutomationVantaDrataSecureframeSprintoOneTrust Tech Risk & Compliance
What it isAudit prep, device suiteCompliance-first GRCTrust management GRCGRC with a CMMC tierBengaluru-built GRCGRC beside privacy
Frameworks listed11 frameworksSOC 2 to HITRUST30+ pre-built38 on its list25+ automatedMapped control library
Indian rulesNone listedNone namedNone namedNone namedDPDP Act pageDPDPA content
Pricing modelPer framework + seatsFour tiers, quotedQuote by packageTiers; frameworks extraPlans + modulesQuote-only modules
Published entry priceNot publishedNot publishedNot publishedNot publishedNot publishedNot published
Included vs add-onTrust Center apartTrust Center in tier 1SafeBase-based trustSSO/SCIM in CompleteEnterprise modulesAuditor fee on top
IntegrationsNamed, no count400+ toolsCount not stated300+ nativeNo count in plan docsShared inventory
Device evidenceSame platform as MDMOwn monitor or MDMRead-only Drata AgentFree read-only agentDr. Sprinto appNot documented
AI governance frameworksISO 42001 listedISO 42001 + NIST AI RMFThree AI frameworksAI group of threeNot in plan docsSeparate AI product
Auditor relationshipNo network namedAuditor directoryNot foundNot on plan pageNot in plan docsNot an auditor
Hosting regionsUS or EU onlyUS, EU, AustraliaNot publishedNot publishedNot publishedAsk in the quote
Platform beyond GRCEndpoint, EDR, identityRisk and trustTrust managementCUI enclave in DefenseTPRM and ERMPrivacy suite
Best fitIru device shopsBroad global programmesWide framework listsUS defence suppliersIndian SaaS exportersPrivacy-led GRC
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Iru Compliance Automation if…

  • ✓Your Macs and phones already run Iru Endpoint Management and you would rather add a module than a new GRC vendor
  • ✓Your audit list is the global set — SOC 2, ISO 27001, HIPAA, ISO 42001 or CMMC — that overseas customers put in contracts
  • ✓US or EU hosting for audit evidence is acceptable, and an annual, quoted contract suits your budgeting

Compare alternatives if…

  • ✓You need DPDP Act mapping — Sprinto publishes a DPDP framework page, and OneTrust carries DPDPA content
  • ✓You want an auditor directory beside the tool — Vanta lists access to its auditor network on its pricing page
  • ✓You need a longer framework list or more connectors — Drata claims 30+ frameworks and Secureframe 300+ integrations

Do not expect…

  • ✓CERT-In, RBI or SEBI CSCRF mappings, or a hosting region inside India
  • ✓A certificate from Iru — an independent auditor still tests the evidence and signs the report
  • ✓A self-serve trial or a price on the website; this product is demo-first and quoted

TechBag has no compliance automation guide yet, so Iru Compliance Automation sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does manual audit preparation cost you?

Drag the sliders (employees in audit scope; staff-hour cost). Estimates model the time spent chasing screenshots, access reviews and policy sign-offs at an assumed 1.5 hours per in-scope employee a year, with 70% of it removed by automated evidence collection. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual audit-prep cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Iru licenses Compliance Automation per framework (SOC 2, ISO 27001 and others) plus seats, on an annual contract billed annually, and quotes it only after a demo. Trust Center is a separate line. TechBag fixes the framework list first, then gets the quote itemised in INR with GST.

Compliance Automation

Best for a first SOC 2 or ISO 27001

  • Quote-only; per framework plus seats
  • AI-tailored controls, automated evidence
  • Demo first; no self-serve trial

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ Iru Trust Center

Best once customers ask to see proof

  • Its own Billing line, quoted
  • Public portal for reports and certificates
  • Demo first as well

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Frameworks

Which of the 11 listed frameworks do customers actually demand, and is each priced as its own line in the quote?

2
Indian obligations

Where will CERT-In, DPDP Act, RBI or SEBI work live, given that none of them appears in Iru’s framework list?

3
Hosting

Is US or EU hosting for audit evidence acceptable to your board, your customers and any sector regulator you answer to?

4
Seats

How many seats does the quote assume, and who needs one — IT, security, HR, leadership or the external auditor?

5
Evidence sources

Do your systems — AWS, Workday, JumpCloud, Snowflake and the rest — appear among Iru’s documented connectors?

6
Auditor

Who will audit you? Iru is not an audit firm and names no network, so line the firm up before the evidence is ready.

7
Trust Center

Do you need a public Trust Center now? It is billed separately, so decide whether it belongs in the first quote.

8
Contract

Are the annual term, the renewal terms and an INR quote with GST written down before anyone signs?

FAQ

Questions buyers ask

It is Iru’s audit-readiness product, launched in October 2025 when Kandji renamed itself Iru. It generates controls tailored to your company, collects evidence from connected systems, maps that evidence to the controls, and manages the written policies an auditor asks to see, for SOC 2, ISO 27001 and nine other frameworks.

Ready to evaluate Iru Compliance Automation?

List the frameworks your customers demand first, or let a TechBag advisor book the Iru demo and test it against one real audit scope.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.