Companies that use ZenGRC

Analyzed and validated by Henley Wing Chiu
All GRC ZenGRC

ZenGRC We detected 112 customers using ZenGRC and 37 companies that churned or ended their trial. The most common industry is Software Development (22%) and the most common company size is 1,001-5,000 employees (40%). Our methodology involves discovering URLs with known URL patterns through web crawling, certificate transparency logs, or modifications to subprocessor lists.

About ZenGRC

ZenGRC provides governance, risk, and compliance software that automates compliance management, streamlines risk assessments, and supports multiple frameworks like ISO, SOC, and HIPAA with flat-fee pricing and integrated features including third-party risk management and vendor oversight.

⏱️ Data is delayed by 1 month. To show real-time data, sign up for a free trial or login
Company Employees Industry Region YoY Headcount Growth Usage Start Date
Accertify, Inc. 501–1,000 Software Development US +32.3% 2025-11-05
Alcami Corporation 501–1,000 Pharmaceutical Manufacturing US N/A 2025-10-16
Siteimprove 201–500 Software Development US -7.8% 2025-09-12
Kinetic 10,001+ Telecommunications US N/A 2025-08-21
Autodesk 10,001+ Software Development US -0.3% 2025-07-15
Regis University 1,001–5,000 Higher Education US N/A 2025-06-13
Zoox 1,001–5,000 Automotive US +21% 2025-06-01
Elemica 201–500 Software Development US -0.2%
JAGGAER 1,001–5,000 Software Development US +4.3%
Kindeva Drug Delivery 1,001–5,000 Pharmaceutical Manufacturing US +7.7%
Knowledge Services 1,001–5,000 IT Services and IT Consulting US N/A
LendingTree 501–1,000 Financial Services US +4%
Foundation Medicine 1,001–5,000 Biotechnology Research US -4.3%
LiveRamp 1,001–5,000 Advertising Services US -3.3%
Long View Systems 1,001–5,000 IT Services and IT Consulting CA +1.8%
MasterClass 201–500 E-Learning Providers US +6.5%
Matterport 501–1,000 Software Development US -10.2%
Tyto Athene, LLC 1,001–5,000 IT Services and IT Consulting US N/A
MODEC 5,001–10,000 Oil and Gas JP +5.7%
MoneyLion 501–1,000 Financial Services US -2.8%
Showing 1-20 of 112

Market Insights

🏢 Top Industries

Software Development 24 (22%)
Financial Services 11 (10%)
Hospitals and Health Care 7 (6%)
IT Services and IT Consulting 7 (6%)
E-Learning Providers 4 (4%)

📏 Company Size Distribution

1,001-5,000 employees 44 (40%)
501-1,000 employees 24 (22%)
201-500 employees 14 (13%)
10,001+ employees 13 (12%)
51-200 employees 8 (7%)

📊 Who in an organization decides to buy or use ZenGRC?

Source: Analysis of 100 job postings that mention ZenGRC

Job titles that mention ZenGRC
i
Job Title
Share
IT/Security Compliance Analyst
47%
Manager, Information Security
7%
Information Security Engineer
7%
Director, Information Security
6%
My analysis shows that ZenGRC is primarily purchased by mid-to-senior level security leadership, with Director and Manager level information security roles representing the key decision makers. These leaders are building GRC programs focused on maintaining multiple compliance frameworks simultaneously including SOC 2, ISO 27001, NIST, FedRAMP, HIPAA, and PCI DSS. They're hiring for capabilities around third-party risk management, policy development, audit coordination, and risk assessment processes, signaling strategic priorities around scalable compliance automation and centralized governance.

The day-to-day users are predominantly IT and Security Compliance Analysts who spend their time managing audit evidence collection, conducting risk assessments, coordinating with internal and external auditors, maintaining control frameworks, and responding to customer security questionnaires. These practitioners are using ZenGRC to track findings, document policies and procedures, monitor controls, and maintain compliance documentation across multiple frameworks from a single platform. They also leverage the tool for third-party vendor assessments and maintaining risk registers.

The recurring pain points center on managing compliance at scale while enabling business growth. Companies are looking to move from manual processes to automation, with phrases like "evidence collection automation," "centralized governance management system," and "drive remediation for critical issues" appearing throughout the postings. Organizations want to "elegantly achieve and maintain key certifications" while fostering a risk-based culture that doesn't slow down innovation. The emphasis on managing multiple frameworks simultaneously and reducing audit burden suggests companies view ZenGRC as a solution for consolidating fragmented compliance activities.

🔧 What other technologies do ZenGRC customers also use?

Source: Analysis of tech stacks from 112 companies that use ZenGRC

Commonly Paired Technologies
i
Technology
Likelihood
3980.5x
3925.9x
3184.4x
1792.8x
1008.8x
596.3x
I noticed that companies using ZenGRC are mature, security-conscious organizations dealing with significant compliance requirements. The presence of Egencia for corporate travel management and Alert Media for emergency communications tells me these are established businesses with distributed workforces and duty-of-care obligations. They're not scrappy startups. They're companies at a scale where governance, risk, and compliance programs become mission-critical.

The combination of Proofpoint Security Training and Lacework FortiCNAPP is particularly revealing. These companies aren't just checking compliance boxes. They're implementing comprehensive security programs that span both human behavior (security awareness training) and technical infrastructure (cloud security posture management). When I see Tines and Monte Carlo Data in the mix, it confirms these teams are automating their security operations and monitoring data quality. This suggests they're handling sensitive customer data at scale and need robust controls to prove compliance to auditors and customers.

My analysis shows these are likely Series B and beyond companies, probably in regulated industries like financial services, healthcare, or technology services where customers demand SOC 2 or ISO certifications. The sophisticated security automation tools suggest dedicated security and compliance teams, not just one person wearing multiple hats. These companies are sales-led, using compliance certifications as competitive differentiators to close enterprise deals. The travel and emergency communication tools indicate they have field teams, distributed offices, or a significant number of employees requiring coordination.

👥 What types of companies is most likely to use ZenGRC?

Source: Analysis of Linkedin bios of 112 companies that use ZenGRC

I noticed that ZenGRC customers span an unusually wide range of industries, but they share a common thread: they operate in highly regulated environments where compliance isn't optional. These companies include pharmaceutical manufacturers developing life-saving drugs, financial services firms managing billions in assets, healthcare organizations processing millions of patient visits, defense contractors handling classified information, and enterprise software companies serving Fortune 500 clients. What unites them is that their business models depend on maintaining rigorous security, safety, and regulatory standards.

These are predominantly mature, established enterprises. My analysis shows that most have between 500 and 5,000 employees, with many exceeding that range significantly. Several are publicly traded with post-IPO funding rounds, while others have private equity backing or have been operating for decades. The presence of companies like Autodesk with 15,000+ employees and Veolia with 50,000+ employees signals that ZenGRC serves organizations operating at serious scale with complex compliance requirements.

Alternatives and Competitors to ZenGRC

Explore vendors that are alternatives in this category

LogicManager LogicManager Archer IRM Archer IRM Auditboard Auditboard Navex One Navex One LogicGate LogicGate Anecdotes.ai Anecdotes.ai Compliatric Compliatric TeamMate Audit Management TeamMate Audit Management

Loading data...