/Companies

SaltyCloud

Techstars '20

Austin, US · Founded 2017 · 18 employees on LinkedIn · 1 known investors

Find your way into SaltyCloud

SaltyCloud builds Isora, a cloud-based GRC (governance, risk, and compliance) assessment platform designed to simplify risk assessment questionnaires and enable cross-team collaboration on information security and organizational risk.

Also known as Isora · Isora GRC

Investors · 1

Techstarslisted by TechstarsBoulder · $220K

How we know: the Techstars portfolio · open dataset · Top 3000 Accelerator Startups (no YC) 2026-08 · Not right? Tell us

Company profile

researched Sep 2026

SaltyCloud is an Austin, Texas software company, incorporated as a public benefit company, that develops Isora GRC, which it markets as a "GRC Assessment Platform" for information security teams. The product positions assessments as the core workflow of a governance, risk, and compliance program: structured questionnaires are distributed to departments, system owners, and third-party vendors; contributors collaborate on responses and upload supporting evidence inline; and completed responses are routed for approval and scored.

Isora GRC combines several connected modules in a single workspace: assessment management for distributing and tracking questionnaires across the organization; a prebuilt questionnaire library aligned to established frameworks; scorecards and reporting that compare performance across departments, vendors, and frameworks and allow drill-down to individual responses; inventory management linking vendors, assets, and systems to their assessment history, associated risks, and data classification; exception management for logging policy exceptions with compensating controls, owners, and expiration dates; and a risk register into which assessment findings flow with lineage from questionnaire to control to risk, with assigned owners and remediation tracking.

The company states that Isora supports cybersecurity frameworks including NIST CSF, NIST 800-53, NIST 800-171, CIS Controls and ISO 27001; regulatory requirements including the HIPAA Security Rule, the GLBA Safeguards Rule, CMMC, NYDFS 23 NYCRR 500 and TAC 202; and third-party risk questionnaires including HECVAT, CAIQ and SIG, alongside custom assessments for internal policies.

Founding story

SaltyCloud describes its founding as a group of people who came together in Austin, Texas in 2017 and chose to incorporate as a public benefit company. The name combines "salty" — a reference to salting as a cybersecurity technique for fortifying data, as well as a "salt of the earth" ethos — with "cloud," reflecting delivery of cloud-based technology.

Business model

SaltyCloud sells access to Isora GRC, a cloud-based software platform, to organizations' security and compliance teams. Prospective customers are directed to book a demo and contact sales rather than self-serve sign-up, indicating a sales-led subscription software model.

Traction

The company cites customers including Virginia Tech, whose senior IT compliance manager describes replacing manual document-heavy IT self-assessment processes with automated workflows, dashboards, and gap analyses. A third-party business data profile lists the company in the 11-20 employee range.

▸Full profile — market position, technology, go-to-market, geography, history

Market position

SaltyCloud positions Isora as a distinct category between spreadsheets and two adjacent software categories: enterprise GRC suites, which it characterizes as covering legal, finance, and audit but requiring months of implementation and dedicated administrators, and audit automation tools, which it describes as covering SOC 2 but not ongoing structured risk management. Its stated focus is the operational assessment work performed by information security practitioners.

SaltyCloud differentiates Isora as purpose-built around collaborative, structured assessments rather than broad enterprise GRC governance or SOC 2-focused audit automation, emphasizing faster deployment without dedicated administrators or consultant-driven configuration, evidence captured as work is performed, and connections between assessments, inventories, risks, and reports within one workspace.

Technology

Isora is a cloud-based platform providing assessment distribution and tracking, collaborative multi-contributor questionnaires with inline evidence upload and approval routing, a prebuilt framework-aligned questionnaire library with support for custom assessments, scorecards and exportable audit-ready reports, linked vendor/asset/system inventories with data classification, exception tracking with expiration dates, and a risk register with lineage from questionnaire to control to risk. A HECVAT Uploader imports completed HECVAT spreadsheets and converts them into scored, auditable vendor questionnaires.

Go-to-market

The company markets through its website with demo requests and contact-sales calls to action, customer testimonials, a newsletter (the InfoSec GRC Brief) reaching a stated 1,000+ CISOs, compliance officers and risk managers, and a newsroom publishing product and company announcements.

Information security, risk, and compliance teams at established organizations, including higher education institutions (a customer testimonial comes from a senior IT compliance manager at Virginia Tech) and organizations subject to frameworks such as GLBA, HIPAA, CMMC, NYDFS 23 NYCRR 500 and TAC 202. The company's newsletter is aimed at CISOs, compliance officers, and risk managers.

Geography

Headquartered in Austin, Texas, United States.

History

The team came together in Austin, Texas in 2017 and formed the business as a public benefit company, a structure the company says commits it to considering the interests of customers, employees, investors, society, and the environment. It has since developed and marketed the Isora GRC assessment platform, adding capabilities such as a HECVAT Uploader announced in July 2025, and completed a SOC 2 attestation with partner A-LIGN.

Compiled by commissioned research from 5 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
EmployeesJan 202611-20
HeadcountAug 202618
Newsletter subscribersJan 20261,000 subscribers

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Competitors · 10

by search overlap
Upguard649 shared keywordsUpGuard provides a platform for managing cybersecurity risk, including third-party vendor and supply chain risk assessment. It is aimed at organizations seeking to evaluate and monitor the security posture of their vendors.
Secureframe624 shared keywordsSecureframe provides a compliance automation platform that helps enterprises maintain security and compliance posture with common controls mapping across multiple frameworks. The platform uses AI and automation to reduce manual compliance work for organizations managing standards like SOC 2, ISO 27001, and HIPAA.
Kiteworks434 shared keywordsKiteworks provides a Private Data Network platform that lets organizations track, govern, and protect sensitive data (such as PII, PHI, and IP) across email, file sharing, managed file transfer, web forms, and APIs, with data governance and compliance controls. It serves enterprises and government agencies, targeting CIOs, CISOs, and Chief Data Privacy Officers, with deployment options including on-premises, private cloud, hybrid, and FedRAMP.
Sprinto428 shared keywordsSprinto is a compliance and governance, risk, and compliance (GRC) platform that automates security compliance across 200+ frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, and PCI DSS. It serves companies from Series A to enterprise, covering compliance, vendor risk, AI governance, and audit preparation through integrations with cloud, identity, HR, and SaaS systems.
Hyperproof416 shared keywordsHyperproof is a governance, risk, and compliance (GRC) platform that automates compliance management and audit workflows for organizations. It serves companies seeking to streamline GRC operations and demonstrate compliance to stakeholders.
CyberSaint Security399 shared keywordsCyberSaint offers CyberStrong, an AI-native platform that automates cybersecurity control assessments and quantifies cyber risk in financial terms for enterprises. It serves CISOs, executives, and boards by harmonizing compliance frameworks (NIST, CIS, ISO), monitoring controls, and modeling risk using methods like FAIR and NIST 800-30.
Security Scorecard380 shared keywordsSecurityScorecard provides third-party risk management (TPRM) software using AI to help organizations identify, monitor, and mitigate cybersecurity risks across their supply chain and vendor networks. The platform serves enterprises managing extended supply chain security risks.
Cynomi368 shared keywordsCynomi offers an AI-driven security program management platform that lets managed service providers and security consultancies run assessments, generate risk registers, remediation roadmaps, policies, and compliance mappings, and manage the full security program lifecycle across their client portfolios. Its "CISO Intelligence" embeds senior security judgment into guided workflows so junior teams can deliver CISO-level program management without a dedicated CISO on each account.
Vanta344 shared keywordsVanta provides a security and compliance platform that helps companies improve their security posture and demonstrate compliance to auditors. The platform serves enterprise customers across industries seeking to manage security controls, governance, and regulatory compliance.
Accountable338 shared keywordsAccountable provides a platform that automates HIPAA compliance tasks including policies, training, risk assessments, vendor management, and incident tracking for small and mid-size healthcare organizations such as dental offices, therapy practices, and health tech startups.

Companies competing with SaltyCloud for the same Google search keywords, organic and paid, via search-intersection analysis.

Non-dilutive funding · 4 SBIR/STTR awards

Federal grants — no equity taken
AgencyPhaseYearAmount
U.S. Air ForceAir ForcePhase ISTTR2021$150K
U.S. Air ForceAir ForcePhase I2021$50K
U.S. Air ForceAir ForcePhase I2019$50K
U.S. Air ForceAir ForcePhase I2019$50K

Source: SBIR.gov award data (U.S. Small Business Administration). SBIR/STTR awards are competitive federal R&D grants and contracts — non-dilutive capital alongside any venture rounds above.

Timeline · 2

launches, deals, and filings
Jul 2025
Isora GRC introduces HECVAT Uploader

SaltyCloud announced a HECVAT Uploader for Isora GRC, a one-click importer that converts completed HECVAT spreadsheets into scored, auditable vendor questionnaires inside the platform.

source ↗

Jan 2025
SaltyCloud completes SOC 2 attestation

The company announced that it passed its SOC 2 attestation, performed by partner A-LIGN.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

▸Research sources · 5

primary sources listed

5 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does SaltyCloud do?
SaltyCloud is an Austin-based public benefit company behind Isora GRC, an assessment platform for security teams.
Who are SaltyCloud's investors?
SaltyCloud's investors include Techstars.
Where is SaltyCloud headquartered?
SaltyCloud is headquartered in Austin, US.