SaltyCloud
Techstars '20Austin, US · Founded 2017 · 18 employees on LinkedIn · 1 known investors
Find your way into SaltyCloud
SaltyCloud builds Isora, a cloud-based GRC (governance, risk, and compliance) assessment platform designed to simplify risk assessment questionnaires and enable cross-team collaboration on information security and organizational risk.
Also known as Isora · Isora GRC
Investors · 1
How we know: the Techstars portfolio · open dataset · Top 3000 Accelerator Startups (no YC) 2026-08 · Not right? Tell us
Company profile
researched Sep 2026SaltyCloud is an Austin, Texas software company, incorporated as a public benefit company, that develops Isora GRC, which it markets as a "GRC Assessment Platform" for information security teams. The product positions assessments as the core workflow of a governance, risk, and compliance program: structured questionnaires are distributed to departments, system owners, and third-party vendors; contributors collaborate on responses and upload supporting evidence inline; and completed responses are routed for approval and scored.
Isora GRC combines several connected modules in a single workspace: assessment management for distributing and tracking questionnaires across the organization; a prebuilt questionnaire library aligned to established frameworks; scorecards and reporting that compare performance across departments, vendors, and frameworks and allow drill-down to individual responses; inventory management linking vendors, assets, and systems to their assessment history, associated risks, and data classification; exception management for logging policy exceptions with compensating controls, owners, and expiration dates; and a risk register into which assessment findings flow with lineage from questionnaire to control to risk, with assigned owners and remediation tracking.
The company states that Isora supports cybersecurity frameworks including NIST CSF, NIST 800-53, NIST 800-171, CIS Controls and ISO 27001; regulatory requirements including the HIPAA Security Rule, the GLBA Safeguards Rule, CMMC, NYDFS 23 NYCRR 500 and TAC 202; and third-party risk questionnaires including HECVAT, CAIQ and SIG, alongside custom assessments for internal policies.
Founding story
SaltyCloud describes its founding as a group of people who came together in Austin, Texas in 2017 and chose to incorporate as a public benefit company. The name combines "salty" — a reference to salting as a cybersecurity technique for fortifying data, as well as a "salt of the earth" ethos — with "cloud," reflecting delivery of cloud-based technology.
Business model
SaltyCloud sells access to Isora GRC, a cloud-based software platform, to organizations' security and compliance teams. Prospective customers are directed to book a demo and contact sales rather than self-serve sign-up, indicating a sales-led subscription software model.
Traction
The company cites customers including Virginia Tech, whose senior IT compliance manager describes replacing manual document-heavy IT self-assessment processes with automated workflows, dashboards, and gap analyses. A third-party business data profile lists the company in the 11-20 employee range.
▸Full profile — market position, technology, go-to-market, geography, history
Market position
SaltyCloud positions Isora as a distinct category between spreadsheets and two adjacent software categories: enterprise GRC suites, which it characterizes as covering legal, finance, and audit but requiring months of implementation and dedicated administrators, and audit automation tools, which it describes as covering SOC 2 but not ongoing structured risk management. Its stated focus is the operational assessment work performed by information security practitioners.
SaltyCloud differentiates Isora as purpose-built around collaborative, structured assessments rather than broad enterprise GRC governance or SOC 2-focused audit automation, emphasizing faster deployment without dedicated administrators or consultant-driven configuration, evidence captured as work is performed, and connections between assessments, inventories, risks, and reports within one workspace.
Technology
Isora is a cloud-based platform providing assessment distribution and tracking, collaborative multi-contributor questionnaires with inline evidence upload and approval routing, a prebuilt framework-aligned questionnaire library with support for custom assessments, scorecards and exportable audit-ready reports, linked vendor/asset/system inventories with data classification, exception tracking with expiration dates, and a risk register with lineage from questionnaire to control to risk. A HECVAT Uploader imports completed HECVAT spreadsheets and converts them into scored, auditable vendor questionnaires.
Go-to-market
The company markets through its website with demo requests and contact-sales calls to action, customer testimonials, a newsletter (the InfoSec GRC Brief) reaching a stated 1,000+ CISOs, compliance officers and risk managers, and a newsroom publishing product and company announcements.
Information security, risk, and compliance teams at established organizations, including higher education institutions (a customer testimonial comes from a senior IT compliance manager at Virginia Tech) and organizations subject to frameworks such as GLBA, HIPAA, CMMC, NYDFS 23 NYCRR 500 and TAC 202. The company's newsletter is aimed at CISOs, compliance officers, and risk managers.
Geography
Headquartered in Austin, Texas, United States.
History
The team came together in Austin, Texas in 2017 and formed the business as a public benefit company, a structure the company says commits it to considering the interests of customers, employees, investors, society, and the environment. It has since developed and marketed the Isora GRC assessment platform, adding capabilities such as a HECVAT Uploader announced in July 2025, and completed a SOC 2 attestation with partner A-LIGN.
Compiled by commissioned research from 5 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 10
by search overlapCompanies competing with SaltyCloud for the same Google search keywords, organic and paid, via search-intersection analysis.
Non-dilutive funding · 4 SBIR/STTR awards
Federal grants — no equity taken| Agency | Phase | Year | Amount |
|---|---|---|---|
| U.S. Air ForceAir Force | Phase ISTTR | 2021 | $150K |
| U.S. Air ForceAir Force | Phase I | 2021 | $50K |
| U.S. Air ForceAir Force | Phase I | 2019 | $50K |
| U.S. Air ForceAir Force | Phase I | 2019 | $50K |
Source: SBIR.gov award data (U.S. Small Business Administration). SBIR/STTR awards are competitive federal R&D grants and contracts — non-dilutive capital alongside any venture rounds above.
Timeline · 2
launches, deals, and filingsSaltyCloud announced a HECVAT Uploader for Isora GRC, a one-click importer that converts completed HECVAT spreadsheets into scored, auditable vendor questionnaires inside the platform.
The company announced that it passed its SOC 2 attestation, performed by partner A-LIGN.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
▸Research sources · 5
primary sources listed
- SaltyCloudsaltycloud.com · web
5 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does SaltyCloud do?
- SaltyCloud is an Austin-based public benefit company behind Isora GRC, an assessment platform for security teams.
- Who are SaltyCloud's investors?
- SaltyCloud's investors include Techstars.
- Where is SaltyCloud headquartered?
- SaltyCloud is headquartered in Austin, US.









