Hicomply
Hicomply is a UK-based SaaS provider of an integrated compliance management platform that automates ISO 27001, SOC 2, GDPR, and 16+ other frameworks for startups, mid-market firms, and enterprises via AI-assisted drafting, cross-framework control mapping, and automated evidence collection across 75+ integrations.
- Company typePrivate
- Founded2020
- HeadquartersDurham, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Hicomply does
Hicomply is a UK-headquartered SaaS company that operates a compliance management platform purpose-built to automate information security and broader Governance, Risk, and Compliance (GRC) workflows. The platform supports 16+ frameworks including ISO 27001, SOC 2, GDPR, HIPAA, NIST CSF, NIST 800-53, PCI DSS, DORA, CAF, NHS DSPT, ISO 9001, ISO 14001, ISO 45001, ISO 27701, and ISO 42001, and targets startups, mid-market firms, and enterprises with differentiated offerings for GRC, InfoSec, and IT personas. Core technology consists of a real-time dashboard layer, cross-framework control mapping, automated evidence collection via 75+ native integrations (Jira, Azure DevOps, Slack, Zendesk, GitLab, Asana, UKG, Azure AD and others), and 'Hicomply AI' — an AI copilot that drafts compliance documents, maps controls, and performs automated checks across frameworks. Supporting modules cover policy management, risk management, task management, controls monitoring, information asset management, a public-facing Trust Centre, and a privacy operations module (GDPR/CCPA).
The company monetises through a three-tier annual SaaS subscription (Essentials, Professional, Enterprise), with additional frameworks and workspaces sold separately. Distribution is primarily demo-led direct sales, supplemented by a partner/reseller program, and self-serve for smaller customers. Hicomply is a private limited company registered in England & Wales (Hicomply Ltd., company number 12364000), founded in 2020, with offices in North Shields (global HQ), Manchester, and Denver, Colorado (the latter opened in 2025 to anchor US expansion). It is backed by BGF (£3M, September 2021) and the North East Fund (January 2021); named customers include Siemens AG, Balfour Beatty, Birketts LLP, Access Credit Union, ERM, Cofense, and DX Delivery.
Hicomply firmographics
Firmographics- Name
- Hicomply
- Legal name
- Hicomply Ltd.
- Website
- https://hicomply.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Hicomply is a UK-based SaaS provider of an integrated compliance management platform that automates ISO 27001, SOC 2, GDPR, and 16+ other frameworks for startups, mid-market firms, and enterprises via AI-assisted drafting, cross-framework control mapping, and automated evidence collection across 75+ integrations.
- Ownership category
- akta.pro rank
Hicomply industry classification
Industry- Product category
- Compliance Management Software
- NAICS
- Software Publishers (513210), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
- akta.pro secondary industry
- Data Privacy, Consent & Compliance Management (HDAEADAG)
Keywords
Where Hicomply is headquartered
LocationHeadquarters
- HQ city
- Durham
- HQ country
- United Kingdom
- HQ region
- Europe
Offices4 records
Markets served
Hicomply business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Subscription: Hicomply operates as a SaaS compliance platform with three subscription tiers (Essentials, Professional, Enterprise). Subscriptions are annual by default with auto-renewal. Additional workspaces can be purchased separately. Revenue is primarily recurring subscription-based.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Essentials, Professional, and Enterprise tiers available with base features and framework access per tier. |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
Hicomply product offering
Product offeringCore offering
Hicomply sells a SaaS-based compliance management platform that helps organisations automate their Information Security Management System (ISMS) and achieve and maintain compliance with frameworks such as ISO 27001, SOC 2, GDPR, HIPAA, NIST, PCI DSS and DORA. The platform provides real-time dashboards, automated evidence collection from 75+ integrations, AI-assisted drafting and mapping of policies and controls, and a public Trust Centre for sharing compliance posture with customers and auditors.
Product overview
Hicomply is a SaaS-based compliance management platform built around a three-tier subscription model (Essentials, Professional, Enterprise). The core offering consists of the Hicomply Platform (providing real-time dashboards, automated evidence collection, and cross-framework control mapping) together with Hicomply AI (an AI copilot for drafting, mapping, and checking documents) and Hicomply Integrations (connecting 75+ tools for automated evidence pull). Supporting modules include Policy Management, Risk Management, Task Management, Controls Monitor, Information Asset Management, Trust Centre, and Hicomply Privacy — each addressing a distinct phase of the compliance lifecycle from policy authoring through to public audit reporting. The platform supports over 16 compliance frameworks including ISO 27001, SOC 2, GDPR, HIPAA, NIST CSF, NIST 800-53, PCI DSS, DORA, and ISO 42001.
Differentiator
Problem solved
Functional benefit
Products and services
- Hicomply Platform Central compliance management platform providing real-time dashboards, automated evidence collection, and cross-framework control mapping across all supported standards. For GRC, InfoSec, and IT teams at startups, mid-market, and enterprise organisations.
- Hicomply AI AI copilot that drafts compliance documents, maps controls across frameworks, and performs automated checks for users. Aimed at compliance, IT, and InfoSec teams building policies, procedures, and reports.
- Hicomply Integrations Integration library connecting the platform to 75+ third-party tools (including Jira, Azure, Slack, HR systems) for automated evidence collection and data syncing across the compliance stack.
- ISMS Scoping Tool that defines and documents an Information Security Management System (ISMS) in minutes, supporting initial scoping and continuous maintenance for ISO 27001 and other ISMS-based frameworks.
Companies that use Hicomply
Customer profileNamed customers14 records
Segments6 records
Ideal customer profiles3 records
Hicomply technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability4 records
Feature9 records
Hicomply partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core and minor.
- A-LIGNcorePartnership with A-LIGN to expand compliance support across EMEA region. Joint workshops and webinars such as 'From Audit Panic to Audit Advantage' to support compliance certification journeys.
- DrummondcorePartnership with Drummond to support North American compliance validation, enabling Hicomply customers to validate their compliance posture against US standards.
- WaterstonsminorStrategic partnership to strengthen North East cyber defences, combining Hicomply's compliance platform with Waterstons' cyber expertise.
- Prescient SecurityminorPartnership with leading name in cyber resilience to offer combined compliance and security services.
- NEBRC MarketplaceminorHicomply joined NEBRC (North East Business Resilience Centre) marketplace to offer compliance solutions to member businesses.
- Cyber Bridge ProgrammeminorMembership in innovative Cyber Bridge programme supporting regional cyber resilience initiatives.
- Dynamo North EastminorMembership in Dynamo North East business network supporting regional technology and growth initiatives.
- Cyber ExchangeminorPartnership with Cyber Exchange, a UK cyber security community and resource platform.
- HM Government G-Cloud SupplierminorApproved supplier on HM Government G-Cloud framework for public sector procurement.
Scale indicators2 records
Recent moves7 records
Expansion highlights6 records
Hicomply competitors and assessment
Company assessmentDirect peers
- Sprinto: Sprinto provides compliance automation for SOC 2, ISO 27001, GDPR, and HIPAA, focused primarily on SaaS companies. Direct competitor with similar GTM emphasis on SaaS startups and mid-market cloud companies.
- Secureframe: Secureframe automates SOC 2, ISO 27001, HIPAA, PCI DSS, and other compliance frameworks with continuous monitoring and audit-readiness tooling. Direct competitor with comparable feature set, integrations, and target customers.
- Vanta: Vanta is the leading automated compliance and trust management platform for SOC 2, ISO 27001, HIPAA, and other frameworks. Direct competitor with overlapping framework coverage, AI-assisted compliance, and an extensive integration marketplace; serves startups through enterprise.
- Drata: Drata offers continuous compliance automation across SOC 2, ISO 27001, HIPAA, GDPR, and additional frameworks, with auditor marketplace and automated evidence collection. Closest direct competitor to Hicomply across mid-market and enterprise customer segments.
- ISMS.online: ISMS.online is a UK-based information security management system platform supporting ISO 27001, ISO 22301, GDPR, and related standards. Direct UK/EMEA competitor with overlapping ISMS focus and comparable customer base.
- Delve: Delve offers AI-driven compliance automation for SOC 2 and ISO 27001, positioning strongly on automation and AI agent capabilities. Emerging direct peer with overlapping product positioning and target customer profile.
- Thoropass: Thoropass (formerly Laika) combines compliance automation with in-house audit services for SOC 2, ISO 27001, HITRUST, and PCI. Direct competitor bundling software with audit, similar to Hicomply's partnership approach with A-LIGN and Drummond.
Broad incumbents
- AuditBoard: AuditBoard is a broader GRC platform covering audit, risk, and compliance management for enterprise customers. Overlaps with Hicomply in compliance workflows but serves a larger enterprise market with a wider portfolio of GRC modules.
- OneTrust: OneTrust is a broad trust intelligence platform covering privacy, GRC, ethics, and ESG. Overlaps with Hicomply's compliance and privacy (GDPR/CCPA) modules as part of a much larger product portfolio targeting enterprise buyers.
Emerging players
- LogicGate: LogicGate offers a flexible GRC workflow platform with Risk Cloud and compliance automation capabilities. Comparable to Hicomply in automating compliance workflows but more enterprise-focused and configurable.
Market position
Strengths5 records
Weaknesses1 record
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Hicomply social profiles
Digital presenceHicomply compliance and trust
Trust signalCompliance12 records
Hicomply financial estimates
Financial estimateRevenue estimate
Valuation estimate
Hicomply leadership team
Management profileNumber of profiles
Profiles5 records
Hicomply funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Hicomply M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Hicomply
What does Hicomply do?
Hicomply sells a SaaS-based compliance management platform that helps organisations automate their Information Security Management System (ISMS) and achieve and maintain compliance with frameworks such as ISO 27001, SOC 2, GDPR, HIPAA, NIST, PCI DSS and DORA. The platform provides real-time dashboards, automated evidence collection from 75+ integrations, AI-assisted drafting and mapping of policies and controls, and a public Trust Centre for sharing compliance posture with customers and auditors.
Is Hicomply a public or private company?
Hicomply is a private company. It is classified as venture growth investor backed and is currently operating.
When was Hicomply founded?
Hicomply was founded in 2020. It employs 11 to 50 people.
Where is Hicomply based?
Hicomply is headquartered in Durham, United Kingdom, in the Europe region.
How does Hicomply make money?
One revenue line is on record: saaS Subscription.
Who are Hicomply's main competitors?
Direct peers on record are Sprinto, Secureframe, Vanta, Drata, ISMS.online, Delve and Thoropass. Broad incumbents are AuditBoard and OneTrust. LogicGate is listed as an emerging player.
Does Hicomply have an API?
Yes. Hicomply offers API access enabling customers to connect to hundreds of applications and send data directly via API. The platform's integration capabilities allow automated evidence collection and data syncing with third-party tools. Specific API type (REST/GraphQL), authentication method, rate limits, and versioning details are not explicitly stated in the available source material.
What industry is Hicomply in?
Hicomply's product category is Compliance Management Software. Its primary akta.pro industry code is HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms, with a secondary code of HDAEADAG, Data Privacy, Consent & Compliance Management. Its NAICS code is 513210 and its SIC code is 7372.