# Korinza > Korinza is an AI-powered GRC (Governance, Risk, and Compliance) platform built for mid-market companies and PE-backed businesses. It finds, quantifies, and tracks risks end-to-end — without requiring a dedicated risk team. A company can look fine financially while legal filings, tax issues, insurance gaps, regulatory notices, cyber exposure, vendor disruptions, missed filings, and compliance failures are building in the background. Korinza surfaces those risks earlier, organizes the evidence, assigns accountability, and gives CFOs and PE sponsors visibility before they appear in the financial statements. ## Product - **Website**: [Korinza](https://korinza.com) - **Features**: [Features](https://korinza.com/features) - **Pricing**: [Pricing](https://korinza.com/pricing) - **Use Cases**: [Use Cases](https://korinza.com/use-cases) - **Trust Center**: [Trust Center](https://korinza.com/trust) - **Platform Overview**: [Platform Overview](https://korinza.com/platform-overview) - **Glossary**: [GRC Glossary](https://korinza.com/glossary) - **Blog**: [Blog](https://korinza.com/blog) - **Contact / Demo**: [Request a Demo](https://korinza.com) ## Blog Articles - [CMMC Phase II Suspended: What Contractors Should Do](https://korinza.com/blog/cmmc-phase-2-suspended-what-defense-contractors-should-do) — The Pentagon suspended CMMC Phase II third-party assessments and opened a 60-day review. Here is what changed, what did not, and what contractors should do now. *(Cybersecurity & Compliance, updated 2026-07-19)* - [Tariff Volatility Is a Supply Chain Compliance Risk](https://korinza.com/blog/tariff-volatility-supply-chain-compliance-risk-2026) — Manufacturing tariffs doubled in 2025. See how tariff volatility creates supply chain compliance risk — vendor concentration, export controls, and more. *(Risk & Compliance, updated 2026-07-19)* - [AI Governance Is a GRC Problem — Most Companies Are Behind](https://korinza.com/blog/ai-governance-grc-risk-2026) — Only 26% of companies align governance with AI deployment pace. With EU AI Act Annex III high-risk obligations now scheduled for December 2027 (deferred from August 2026), the accountability gap is a material GRC risk — and the window to prepare is open. *(AI & Emerging Risk, updated 2026-07-22)* - [How to Build a Vendor Risk Register in a Day](https://korinza.com/blog/vendor-risk-register-guide) — Acquirers and auditors ask for vendor risk registers first. Most companies lack one. Build a complete, defensible vendor risk register in a single day. *(Vendor Risk, updated 2026-07-19)* - [Risk Management for CEOs and CFOs Without a Risk Team](https://korinza.com/blog/risk-management-for-ceos-cfos-without-risk-team) — Identify where your business is exposed, estimate financial impact, and assign ownership — a practical risk guide for CEOs and CFOs without a risk team. *(Risk Management, updated 2026-07-19)* - [What Is Risk Management?](https://korinza.com/blog/what-is-risk-management) — A practical explanation of risk management — what it is, why it matters, how it works, and how mid-market companies can build an effective program. *(Risk Management, updated 2026-07-19)* - [Best GRC Software for Mid-Market Companies in 2026](https://korinza.com/blog/best-grc-software-mid-market-2026) — Compare 10 GRC platforms — Korinza, Sprinto, AuditBoard, LogicGate, and more. A practical buyers guide for CFOs, compliance managers, and PE sponsors. *(Risk & Compliance, updated 2026-07-19)* - [GRC for PE-Backed Manufacturers: Exit Readiness](https://korinza.com/blog/grc-pe-backed-manufacturing-exit) — PE-backed manufacturers face hidden GRC gaps that surface at exit. Learn what to track — risk registers, controls, vendor compliance — before the sale. *(Risk & Compliance, updated 2026-07-19)* ## Who Korinza Is For **Private Equity Sponsors:** PE firms managing multiple portfolio companies need cross-portfolio risk visibility without requiring each portco to hire a dedicated compliance team. Korinza gives sponsors a single dashboard showing risk counts, compliance posture, open findings, and vendor exposure across every company in the portfolio. The PE Edition white-label add-on lets firms deploy Korinza under their own brand. **CFOs and Finance Teams:** CFOs need to see what is building in the business before it surfaces in the P&L or during a sale process. Korinza gives finance leaders a structured view of operational, regulatory, and vendor risks with owners, due dates, and treatment plans. **Operations Leads:** Portfolio operations teams managing multiple companies need a consistent framework for tracking risks and compliance obligations across the portfolio without reinventing the wheel at each company. **Compliance and Risk Managers:** Teams responsible for regulatory compliance, vendor risk, and audit readiness need a platform that maps internal controls to compliance frameworks, tracks evidence, and surfaces gaps before auditors do. ## Core Modules (All Available) 1. **Risk Register** — Centralized risk inventory with owner assignment, severity scoring (likelihood × impact matrix), treatment plans, due dates, risk aging indicators, and full immutable audit trail. Supports custom risk categories and cross-portfolio roll-up. 2. **Compliance Frameworks** — Pre-mapped control libraries for SOC 2 Type 2, ISO 27001, HIPAA, NIST CSF, PCI DSS, ISO 9001, ISO 45001, OSHA, FDA GMP, and AS9100D. One-click framework adoption with live coverage percentage. 3. **Control Mapping** — Maps risks to controls across one or more frameworks. Shows which controls are implemented, missing, or stale. Automated stale control alerts when controls go unreviewed. 4. **Policy Management** — Policy lifecycle management with version history, owner assignment, review schedules, and employee attestation tracking. Supports policy templates and bulk attestation campaigns. 5. **Vendor Risk Management** — Vendor inventory with risk tier classification, due diligence questionnaires, contract expiry tracking, and fourth-party risk visibility. Automated questionnaire dispatch and response collection. 6. **Audit Management** — Structured audit lifecycle from planning through closure. Supports internal audits, external audits, and regulatory inspections. Generates PDF audit reports with findings, corrective actions, and conformance metrics. 7. **Trust Center** — Public-facing trust page per organization showing compliance posture, security certifications, and framework coverage. Shareable with customers, partners, and auditors at korinza.com/trust/{slug}. 8. **Insurance Management** — Insurance policy inventory with coverage type, carrier, premium, expiry, and renewal tracking. Alerts for upcoming renewals and coverage gaps. ## Key Capabilities - AI-powered risk discovery: Upload contracts, vendor lists, insurance policies, compliance docs, and HR/payroll files — Korinza extracts and scores risks automatically. - Dollar-denominated risk scoring: Every risk is quantified in dollars (expected loss = likelihood × financial impact), not just red/yellow/green. - Regulatory signal monitoring: Monitors FRED, EIA, World Bank, and other external data sources for macroeconomic signals that affect risk profiles. - Cross-portfolio dashboard: PE sponsors see risk counts, compliance posture, and open findings across all portfolio companies in one view. - Automated evidence collection: Korinza pulls evidence from connected systems (HR, finance, legal) and attaches it to controls automatically. - Framework auto-mapping: Risks and controls are automatically mapped to applicable compliance frameworks based on category and type. ## Security and Compliance - SOC 2 Type 2 (in progress) - Data encryption: AES-256 at rest, TLS 1.3 in transit - Access control: Role-based (owner, admin, auditor, viewer, contributor, board member) - Audit trail: Immutable activity log for every action across all modules - Backup: Continuous point-in-time recovery with 14-day recovery window - Infrastructure: Serverless, auto-scaling, multi-AZ - Data privacy: GDPR-aware retention policies, data isolation per organization - Trust Center: Public per-organization trust page at https://korinza.com/trust/{slug} ## Public Pages - / — Main landing page (PE-first hero) - /features — Full module and feature breakdown with availability status - /pricing — Pricing tiers and PE Edition contact-us card - /use-cases — Persona-based use case pages (PE sponsor, CFO, compliance team) - /trust — Generic Trust Center landing page - /trust/{slug} — Per-organization public trust page - /platform-overview — Dense AI/crawler-optimized platform description - /glossary — GRC and PE terminology glossary - /grc-software — SEO landing page for GRC software - /risk-management-software — SEO landing page for risk management software - /compliance-management — SEO landing page for compliance management - /vendor-risk-management — SEO landing page for vendor risk management - /pe-portfolio-risk-management — SEO landing page for PE portfolio risk management - /who-we-serve — Audience overview page ## What Problems Korinza Solves - Hidden risks building in the background while the company looks fine financially - No single view of risk across multiple portfolio companies - Compliance obligations tracked in spreadsheets with no accountability or audit trail - Vendor risk managed informally with no scoring or monitoring - Insurance gaps and policy expirations discovered too late - Regulatory notices and missed filings not surfaced until they become material - Audit preparation done reactively rather than continuously - No structured process for assigning risk ownership and tracking resolution - No visibility into macroeconomic signals that affect portfolio company risk profiles - PE sponsors unable to see cross-portfolio risk without burdening portco teams ## Competitive Positioning Korinza is not a large enterprise GRC platform (not Archer, ServiceNow GRC, or MetricStream). It is built for the people accountable for enterprise value at mid-market companies and PE-backed businesses — where the buyer is a CFO or PE sponsor, not a dedicated GRC team. Key differentiators: 1. **PE-native**: Cross-portfolio dashboard, portco onboarding wizard, and white-label PE Edition are built for the PE use case from the ground up. 2. **Risk signals**: Automated external signal monitoring (FRED, EIA, World Bank) links macroeconomic and market data directly to the risk register — no other mid-market GRC tool does this. 3. **Speed to value**: Typical onboarding in one day. Pre-mapped controls for 10+ frameworks. No professional services required. 4. **Accountability layer**: Every risk has an owner, a due date, and an evidence trail. Not just a list. 5. **Audit-ready by default**: Evidence collection, control testing, and audit report generation are built in — not add-ons. 6. **Multi-entity support**: Manage multiple legal entities (EINs) under one account with entity-scoped views. ## Technical Details - Built on React 19, TypeScript, tRPC, Express, and MySQL/TiDB - REST API v1 with API key authentication and rate limiting (100 req/min per key) - Webhook support for risk, control, audit, and policy events - PDF export for audit reports and executive dashboards - Signed JWT session management with full audit trail on all data changes - @dnd-kit for drag-and-drop interactions (Pinned Signals reordering) ## Company Korinza is an early-stage B2B SaaS company in active development with early design partners in the private equity and mid-market space. - [Website](https://korinza.com) - [Request a Demo](https://korinza.com) - [Trust Center](https://korinza.com/trust) - [Platform Overview](https://korinza.com/platform-overview) - [GRC Glossary](https://korinza.com/glossary) - [Blog](https://korinza.com/blog) ## NAICS Integration - Legal entities can be tagged with a 6-digit NAICS code and title (e.g., 621111 — Offices of Physicians, except Mental Health Specialists) - NAICS search is available via `trpc.naics.search({ query })` — fuzzy matches code prefix or title substring, returns up to 10 results - NAICS lookup by code is available via `trpc.naics.getByCode({ code })` — returns a single entry or null - NAICS data is served from a static TypeScript file (`server/naicsData.ts`) covering ~1,000 6-digit codes across all 20 NAICS sectors - The NAICS combobox in OrgSettings (Legal Entities card) allows searching by typing a code prefix (e.g., "621") or industry keyword (e.g., "hospital") - Assigned NAICS codes appear as a blue monospace badge in the entity row and in the expanded detail view - The Regulatory Notices entity dialog also uses the NAICS combobox for the monitored entity NAICS field