GRCS
GRCS Inc. is a Tokyo-based provider of proprietary cloud-based GRC and cybersecurity software (ERMT, SRMT, CSIRT MT.mss, 脆弱性TODAY), complemented by professional consulting and BPaaS services, serving 200+ Japanese enterprise and financial-sector clients through direct sales and technology partnerships.
- Company typePrivate
- Founded2018
- HeadquartersTokyo, Japan
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What GRCS does
GRCS Inc. (株式会社GRCS) is a Tokyo-headquartered provider of GRC (Governance, Risk, Compliance) and cybersecurity software and consulting services, incorporated in 2018 with a predecessor entity (NANAROQ) operating since 2017. The company sells a portfolio of proprietary domestically-developed cloud platforms — Enterprise Risk MT (ERMT, ISO31000-compliant), Supplier Risk MT (SRMT) for third-party risk management, CSIRT MT.mss for incident response and vulnerability management, and 脆弱性TODAY for daily Japanese-translated vulnerability intelligence — supplemented by resell arrangements for third-party products (Netskope, HENNGE ONE, Bromium, Imperva, RidgeBot, OneTrust, SOCRadar, and others). Recent platform enhancements integrate Salesforce Agentforce and Data Cloud to add generative-AI-driven incident report drafting and semantic similarity search.
The business model combines subscription software licensing for the proprietary platforms with a broad portfolio of professional services — ERM consulting, cloud security, penetration testing, PCI DSS / NIST SP800-171 compliance, generative AI security risk management, supply chain cybersecurity evaluation support, and purple-team training — plus a recently launched BPaaS offering (GRCS BPO MT). Distribution is direct enterprise sales in Japan, with technology partner co-selling (Xceptor, SecurityScorecard, FASTALERT), supplemented by a free-trial funnel for SRMT targeting mid-market. GRCS claims 200+ corporate clients across financial services (Nippon Life Insurance case study) and general enterprise, supported by visible logos including NRI, NTT Comware, Seven-Eleven, Shionogi, Teijin, Anicom, NSSOL, and SNK. The company is operationally headquartered at Palace Building 5F, Marunouchi, Chiyoda-ku, Tokyo; maintains a full investor-relations function; and in April 2026 established GRCS Technologies Inc. as a wholly-owned professional-services subsidiary.
GRCS firmographics
Firmographics- Name
- GRCS
- Legal name
- 株式会社GRCS
- Website
- https://grcs.co.jp
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- GRCS Inc. is a Tokyo-based provider of proprietary cloud-based GRC and cybersecurity software (ERMT, SRMT, CSIRT MT.mss, 脆弱性TODAY), complemented by professional consulting and BPaaS services, serving 200+ Japanese enterprise and financial-sector clients through direct sales and technology partnerships.
- Ownership category
- akta.pro rank
GRCS industry classification
Industry- Product category
- GRC and Cybersecurity Software
- NAICS
- Computer Systems Design and Related Services (5415), Security Systems Services (56162), Custom Computer Programming Services (541511)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA)
- akta.pro secondary industries
- Third-Party Risk, Vendor Due Diligence & Supply Chain Compliance (BPAEAPAG), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH), Privacy, Consent & Data Protection Management (BPAEAPAF), Governance, Risk & Compliance (GRC) Managed Services (BPAEADAJ), Risk, Controls & Governance (GRC) Platforms (FSAFAOAG)
Keywords
Where GRCS is headquartered
LocationHeadquarters
- HQ city
- Tokyo
- HQ country
- Japan
- HQ region
- Asia
Offices1 record
Markets served
GRCS business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- GRC Platform Subscriptions (ERMT, SRMT, CSIRT MT.mss): GRCS generates recurring subscription revenue from its proprietary cloud-based GRC and security platforms (ERMT, SRMT, CSIRT MT.mss). These are licensed on a per-organization/per-user basis, with tiers for different team sizes and feature sets. Consulting and implementation services are provided alongside to drive adoption.
- Security Consulting Services: GRCS provides a broad portfolio of cybersecurity and GRC consulting services including ERM consulting, cloud security, penetration testing, PCI DSS compliance, generative AI security risk management, NIST SP 800-171 compliance, and third-party cyber risk assessment services.
- GRCS BPO MT (Business Process as a Service): BPaaS offering combining AI technology with expert human resources to handle risk management operations on behalf of clients, representing an outsourcing/managed services revenue stream.
- GRCS Technologies Consulting Services: GRCS Technologies (subsidiary, established April 2026) provides GRC consulting, training services, and system engineering services.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels4 records
GRCS product offering
Product offeringCore offering
GRCS develops and sells a suite of cloud-based GRC (Governance, Risk, Compliance) and cybersecurity software platforms — Enterprise Risk MT (ERMT) for ISO 31000-compliant enterprise risk management, Supplier Risk MT (SRMT) for third-party/supplier risk management, and CSIRT MT.mss for integrated security incident and vulnerability management — alongside complementary consulting services in cloud security, penetration testing, PCI DSS, NIST SP 800-171, and AI security risk management for Japanese enterprises.
Product overview
GRCS offers a unified GRC and cybersecurity product portfolio centered on proprietary cloud applications, complemented by a broad range of third-party security products resold through partnerships. The core proprietary suite includes Enterprise Risk MT (ERMT) — an ISO31000-compliant ERM tool for enterprise-wide risk identification, assessment, response, and monitoring; Supplier Risk MT (SRMT) — a supplier/third-party risk management platform for security, compliance, and contract data centralization; and CSIRT MT.mss — a multi-tenant integrated security management tool for CSIRT/SOC incident and vulnerability management. The proprietary tools are supplemented by add-on modules including 脆弱性TODAY (daily vulnerability intelligence delivery), SOCRadar (Extended Threat Intelligence / ASM+CTI+BP), OneTrust (privacy/GRC), シンプラR, and Connected Risk GRC audit module. In the security product line, GRCS resells/distributes Netskope (CASB/cloud security), HENNGE ONE (email security), HP Sure Click Enterprise / Bromium (endpoint application isolation/micro-VM), SecureCube Access Check, Imperva App Protect (WAF), Privilege Management for Windows (least-privilege access), RidgeBot (automated pen testing), Internal Risk Intelligence, and GOOSEC. GRCS also offers consulting services spanning ERM consulting and training, management system operations, sustainability, RPA, cloud security, next-gen endpoint security, PCI DSS compliance, generative AI security risk management, penetration testing, AI service risk screening, purple team training, ransomware incident readiness, vishing training, and the SCS (Supply Chain Security) evaluation system support. The company also operates GRCSテクノロジーズ, a professional services subsidiary offering GRC/security consulting, training, and systems engineering.
Differentiator
Problem solved
Functional benefit
Brands
- GRCSテクノロジーズ (GRCS Technologies): GRC and security professional services subsidiary offering consulting, training, and system engineering services.
Products and services
- Enterprise Risk MT (ERMT) Cloud-based Enterprise Risk Management tool compliant with ISO 31000, supporting risk identification, assessment, response, and monitoring through a centralized dashboard with risk matrix analysis, hierarchical risk management, risk map, cross-tabulation, and audit trail logging. Optional FASTALERT integration provides AI-powered global risk information from news and social media. Targeted at Japanese enterprises seeking to replace manual Excel-based ERM processes.
- Supplier Risk MT (SRMT) Cloud-based external supplier/third-party risk management tool that centralizes supplier security, compliance, and contract information. Provides questionnaire-based self-assessment, risk score calculation, priority ranking, automated reminder notifications, tree-view visualization of subcontracting relationships, and integrated analysis with SecurityScorecard for real-time cyber risk scores. Confirmed deployed by Nippon Life Insurance with approximately 30% workload reduction.
- CSIRT MT.mss Multi-tenant integrated security management tool for CSIRT/SOC operations covering incident response and vulnerability management. Includes automated response action recommendations, incident similarity search, playbook auto-generation, and AI-powered executive report generation using Salesforce Agentforce and Data Cloud. Supports SBOM functionality for software supply chain risk visibility.
- 脆弱性TODAY (Vulnerability TODAY / Z-Today) Daily vulnerability information distribution service that aggregates vulnerability data from 30+ domestic and international sources, delivers Japanese-translated vulnerability alerts by 6 AM daily, and provides CVE/CVSS/attack condition details in CSV and API formats for system integration.
- GRCS BPO MT BPaaS (Business Process as a Service) risk management outsourcing service that combines AI technology with expert human resources to perform risk management operations on behalf of clients, delivering both operational efficiency and effective risk management.
- SOCRadar Extended Threat Intelligence Extended Threat Intelligence (XTI) platform combining attack surface management (ASM), cyber threat intelligence (CTI), and brand protection (BP) in a cloud-based all-in-one security threat intelligence solution, supporting threat actor and TTP analysis for defensive posture improvement.
- OneTrust Privacy Operations & GRC Privacy operations, GRC, and data governance platform for centralized management, visualization, and automation of personal data, offered by GRCS as a partner/reseller product.
- GRCS Technologies Consulting Services Professional services subsidiary offering GRC and Security consulting (ERM高度化支援コンサルティング), training services (ERM全社的リスク管理研修, governance, risk management, security training), and system engineering services (IT infrastructure and system implementation). Established April 2026, headquartered at Palace Building 5F, Tokyo.
- GRC Consulting Services Portfolio of GRC consulting services including ERM高度化支援コンサルティング (ERM advancement consulting), ERM(全社的リスク管理)研修サービス (enterprise risk management training), マネジメントシステム運用改善サービス (management system operational improvement), サステナビリティ支援サービス (sustainability support), and RPAサービス (RPA services). Targeted at enterprises seeking to mature their GRC capabilities.
- Security Consulting Services Portfolio of cybersecurity consulting services including クラウドセキュリティ対策 (cloud security), 次世代型セキュリティ製品導入・運用支援 (next-gen security product implementation and operations support), PCI DSS 準拠支援 (PCI DSS compliance), 生成AIセキュリティリスクマネジメント支援 (generative AI security risk management), NIST SP800-171 準拠 (NIST SP 800-171 compliance), ペネトレーションテスト (penetration testing), 物理ペネトレーションテスト (physical penetration testing), AI活用サービスリスク検診 (AI service risk screening), パープルチームトレーニング (purple team training), ランサムウェアインシデント態勢診断 (ransomware incident readiness assessment), ボイスフィッシング訓練 (vishing training), and セキュリティ対策評価制度 対応支援サービス (METI supply chain security evaluation制度 support).
Quantifiable outcome
- 約30%的业务量削減 (Approx. 30% workload reduction)
- +1 more outcomes
Companies that use GRCS
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
GRCS technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability9 records
Feature4 records
GRCS partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- XceptorcoreXceptor partnered with GRCS to deploy its intelligent data automation platform across Japan's financial sector, marking the first full-scale deployment of the technology in Japan. GRCS leads implementation and provides operational support to banks and securities firms struggling with inefficiencies from legacy systems like Excel and Access. The partnership represents a milestone in Xceptor's global expansion strategy while addressing operational and compliance challenges facing Japanese financial institutions.
- SecurityScorecardcoreGRCS integrated SecurityScorecard's real-time cybersecurity ratings and risk assessment data into SRMT (Supplier Risk MT). Through this integration, SRMT users can seamlessly access SecurityScorecard's security scores, receive score change notifications, and combine external security ratings with internal supplier data for risk-based analysis and monitoring. The partnership enables third-party risk evaluation alongside centralized supplier management.
- Salesforce (Agentforce / Data Cloud)coreGRCS's CSIRT MT.mss leverages Salesforce's Agentforce AI platform and Data Cloud for automated incident response and report generation. Agentforce aggregates comments, emails, logs, and attachments to generate executive summaries, timeline histories, and recurrence prevention recommendations. Data Cloud enables contextual similarity search across historical incident records.
Scale indicators1 record
Recent moves7 records
Expansion highlights6 records
GRCS competitors and assessment
Company assessmentEmerging players
- LogicGate: LogicGate provides a flexible, no-code GRC workflow platform (Risk Cloud) for enterprise risk, third-party risk, and compliance use cases. Emerging competitor with growing enterprise traction that overlaps with GRCS's ERMT/SRMT positioning.
- Riskonnect: Riskonnect offers integrated risk management, third-party risk, and claims software to mid-market and enterprise customers. Competes with GRCS in ERM and supplier risk management categories, particularly for organizations seeking broader risk consolidation.
- NAVEX Global: NAVEX Global offers GRC, ethics & compliance, and third-party risk management software. Comparable to GRCS's SRMT and ERMT for compliance-driven enterprise buyers, with growing overlap in third-party risk and policy management.
Broad incumbents
- ServiceNow: ServiceNow's Integrated Risk Management (IRM) module competes directly with GRCS's ERMT and SRMT, offering enterprise-wide GRC on a global platform. Much larger scale and broader workflow automation, but historically less localized for Japanese regulatory frameworks.
- RSA Archer: RSA Archer is one of the most established enterprise GRC platforms globally, used by large financial institutions and corporations. Competes with GRCS's ERMT and SRMT in multinational and financial services accounts where IT risk and compliance are priorities.
- SAP GRC: SAP's GRC and compliance solutions (Process Control, Risk Management, Access Control) are widely deployed at large multinationals. SAP competes with GRCS in financial controls, access governance, and audit use cases where customers standardize on SAP ERP.
Direct peers
- Diligent (Galvanize / ACL): Diligent's Galvanize platform provides enterprise GRC, audit, and risk management solutions with similar scope to GRCS's ERMT and Connected Risk audit module. Targets large enterprises and is often compared to GRCS in board, audit, and risk use cases.
- OneTrust: OneTrust is a leading privacy, GRC, and data governance platform that GRCS resells in Japan. As a vendor, OneTrust competes directly with GRCS's privacy and consent capabilities while GRCS differentiates through deeper Japanese regulatory localization.
- MetricStream: MetricStream is a long-standing pure-play GRC platform vendor offering ERM, third-party risk, regulatory compliance, and IT GRC capabilities. Closely comparable to GRCS's product scope (ERMT/SRMT/CSIRT MT.mss) and a direct competitor for global enterprise GRC deals.
Regional players
- NTT Data (GRC-related services): NTT Data, a major Japanese system integrator, provides GRC, risk management, and compliance consulting and platform services domestically. Although a GRCS customer/partner ecosystem participant, it competes in adjacent GRC advisory and system integration work for large Japanese enterprises.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
GRCS social profiles
Digital presenceGRCS compliance and trust
Trust signalCompliance3 records
GRCS financial estimates
Financial estimateRevenue estimate
Valuation estimate
GRCS leadership team
Management profileNumber of profiles
Profiles1 record
GRCS subsidiaries and ownership
Company hierarchySubsidiaries1 record
GRCS funding detail
Funding detailFunding overview
Funding rounds4 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GRCS M&A and investment
M&A and investmentM&A2 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GRCS
What does GRCS do?
GRCS develops and sells a suite of cloud-based GRC (Governance, Risk, Compliance) and cybersecurity software platforms — Enterprise Risk MT (ERMT) for ISO 31000-compliant enterprise risk management, Supplier Risk MT (SRMT) for third-party/supplier risk management, and CSIRT MT.mss for integrated security incident and vulnerability management — alongside complementary consulting services in cloud security, penetration testing, PCI DSS, NIST SP 800-171, and AI security risk management for Japanese enterprises.
Is GRCS a public or private company?
GRCS is a private company. It is classified as venture growth investor backed and is currently operating.
When was GRCS founded?
GRCS was founded in 2018. It employs 51 to 100 people.
Where is GRCS based?
GRCS is headquartered in Tokyo, Japan, in the Asia region.
How does GRCS make money?
Four revenue lines are on record. GRC Platform Subscriptions (ERMT, SRMT, CSIRT MT.mss) is the primary driver. The others are security Consulting Services, GRCS BPO MT (Business Process as a Service) and GRCS Technologies Consulting Services.
Who are GRCS's main competitors?
Emerging players on record are LogicGate, Riskonnect and NAVEX Global. Broad incumbents are ServiceNow, RSA Archer and SAP GRC. Direct peers are Diligent (Galvanize / ACL), OneTrust and MetricStream. NTT Data (GRC-related services) is listed as a regional player.
Does GRCS have an API?
No public API is recorded for GRCS.
What industry is GRCS in?
GRCS's product category is GRC and Cybersecurity Software. Its primary akta.pro industry code is BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms, with a secondary code of BPAEAPAG, Third-Party Risk, Vendor Due Diligence & Supply Chain Compliance. Its NAICS code is 5415 and its SIC code is 7370.