Virtual Auditor
Virtual Auditor (Virtual Auditor, LLC) is a Champaign, Illinois-based compliance platform that delivers a managed security and compliance program via an on-premises VA Appliance with agentless auditing, continuous control monitoring, and audit-ready evidence, serving regulated mid-market healthcare, financial services, municipality/utilities, and MSP/MSSP organizations across HIPAA, PCI DSS, NIST, ISO, SOC 2, and NYDFS frameworks.
- Company typePrivate
- Founded2013
- HeadquartersChampaign, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Virtual Auditor does
Virtual Auditor (VA) is a Champaign, Illinois-based information security and compliance platform provider founded in 2013 by Thomas Barker. The company delivers a fully managed security and compliance program via an on-premises or private cloud appliance (the VA Appliance) that performs agentless auditing of configurations, patch posture, web applications, identities, and endpoints across Windows, macOS, Linux, network devices, databases, virtual hosts, and select OT/SCADA systems, with air-gapped deployment options for high-sensitivity networks. Its VA core program maps controls to HIPAA, PCI DSS 4.0/4.0.1, NIST CSF 2.0, ISO 27001, SOC 2, and NYDFS 23 NYCRR 500, tracks adherence and drift via continuous control monitoring, and produces audit-ready evidence, change diffs, and remediation tickets; the Inventory Manager add-on extends the platform into regulated data inventory, PHI access correlation against HR data, data flow mapping, and log review/activity auditing.
The company primarily serves regulated mid-market organizations across four verticals: healthcare providers and payers (HIPAA/HITECH pressure, OCR readiness), regional and community banks and fintechs (NYDFS 23 NYCRR 500, PCI DSS, GLBA/FFIEC), municipalities/education/utilities/critical services (ransomware, board and insurer reporting), and an indirect channel of MSPs, MSSPs, law firms, compliance advisors, and boutique security firms. Go-to-market combines direct enterprise field sales, evidenced by “Request a Demo” and “Get a Readiness Consult” CTAs and an initial scope of 5–10 critical systems expanding over time, with a multi-tier partner program offering Referral, Co-Delivery/White-Label, and Strategic Alliance structures. Revenue is subscription-based and recurring; pricing is not publicly disclosed.
Virtual Auditor is a privately held LLC (Virtual Auditor, LLC) operating with 11–50 employees, a single disclosed 2017 investment from Serra Ventures, no parent company, and no subsequent institutional funding disclosed. The product is delivered as platform-plus-experts, with vCISO program guidance, quarterly risk reviews, board-ready reporting, and SEC 8-K incident-readiness support supplementing core technical scanning. The company reports 10+ years in business and 200+ audits completed.
Virtual Auditor firmographics
Firmographics- Name
- Virtual Auditor
- Legal name
- Virtual Auditor, LLC
- Website
- https://virtualauditor.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Virtual Auditor (Virtual Auditor, LLC) is a Champaign, Illinois-based compliance platform that delivers a managed security and compliance program via an on-premises VA Appliance with agentless auditing, continuous control monitoring, and audit-ready evidence, serving regulated mid-market healthcare, financial services, municipality/utilities, and MSP/MSSP organizations across HIPAA, PCI DSS, NIST, ISO, SOC 2, and NYDFS frameworks.
- Ownership category
- akta.pro rank
Virtual Auditor industry classification
Industry- Product category
- Compliance & Security Auditing Software
- NAICS
- Security Systems Services (except Locksmiths) (561621), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (51821), Computer Systems Design Services (541512)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI), Compliance, Risk & Audit Management (SOC 2/ISO/PCI) (HDABANAK), Cloud Security Services (Posture Mgmt, Workload Protection) (BPAKAHAK)
Keywords
Where Virtual Auditor is headquartered
LocationHeadquarters
- HQ city
- Champaign
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Virtual Auditor business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Managed Security & Compliance Program: Virtual Auditor is described as a 'fully managed security & compliance program' delivered as a platform + experts. The service includes continuous scanning, prioritized findings, policy/control mapping, and audit-ready evidence. Revenue appears to be subscription-based recurring revenue with engagement scoped around initial application sets (often 5-10 critical systems) that can expand over time.
Go-to-market motion2 records
Distribution channels4 records
Marketing channels3 records
Virtual Auditor product offering
Product offeringCore offering
Virtual Auditor delivers a fully managed information security and compliance program as an on-premises or private cloud appliance (the VA Appliance) combined with expert services. The platform provides continuous, agentless auditing of configurations, patch posture, web applications, identities, and endpoints; maps controls to HIPAA, PCI DSS 4.0/4.0.1, NIST CSF 2.0, ISO 27001, SOC 2, and NYDFS 23 NYCRR 500; and produces audit-ready evidence, dashboards, daily digests, and board-ready reports.
Product overview
Virtual Auditor offers a two-product platform portfolio: Virtual Auditor (VA) serves as the core continuous security and compliance program combining an on-premises or private cloud appliance with managed expert services for risk assessment, control monitoring, and audit-ready evidence. Inventory Manager is an add-on module that goes deeper on application and PHI inventory, providing discovery, user access analysis, ghost account detection, data flow visualization, and log auditing. Both products integrate with common IT service management tools and support compliance with HIPAA, PCI DSS 4.0/4.0.1, NIST CSF 2.0, ISO 27001, SOC 2, and NYDFS 23 NYCRR 500.
Differentiator
Problem solved
Functional benefit
Brands
- Inventory Manager: Application & PHI inventory platform that discovers and catalogs applications in scope for regulated data, correlates user access with HR data, and generates security assessment reports aligned to NIST-style controls.
Products and services
- Virtual Auditor (VA) A fully managed security and compliance program delivered as an on-premises or private cloud appliance combined with embedded expert services. Provides continuous risk assessment, agentless configuration and patch auditing, vulnerability and exposure management, web app assessment, identity/privilege/MFA checks, policy/control mapping, continuous control monitoring with adherence and drift tracking, vCISO program guidance with quarterly reviews, and incident readiness and reporting (including SEC 8-K 4-day disclosure preparation). Targets healthcare providers and payers, regional/community banks and FinTech firms, municipalities, education, utilities, and other regulated mid-market organizations.
- Inventory Manager An application and PHI inventory add-on module for the Virtual Auditor platform. Discovers and catalogs applications handling regulated data, tags those that process, transmit, or store PHI or other regulated data, correlates application user lists against HR and directory data to flag stale and ghost accounts, shared/generic service IDs, and role misalignment, visualizes PHI data flows between servers, databases, and applications in auditor/examiner-understood format, and pulls logs from servers and applications to answer 'who did what, with which patient or customer record, and when.' Generates NIST-style security assessment reports. Targeted at regulated organizations needing deep application, PHI, and access inventory for HIPAA and other compliance requirements.
Quantifiable outcome
- In one deployment, Inventory Manager surfaced 100+ users with unnecessary access in a single clinical application - exposure not previously noticed in prior audits
Companies that use Virtual Auditor
Customer profileSegments4 records
Ideal customer profiles4 records
Virtual Auditor technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability5 records
Feature11 records
Virtual Auditor partnerships and signals
Strategic signalScale indicators2 records
Recent moves6 records
Expansion highlights5 records
Virtual Auditor competitors and assessment
Company assessmentBroad incumbents
- AuditBoard: Enterprise-grade audit, risk and compliance management platform widely adopted by Fortune 1000 internal audit and security teams. Adjacent incumbent that competes for compliance tooling budgets in regulated enterprises, though typically serving larger accounts than VA.
- Tenable: Vulnerability management and cybersecurity platform with strong configuration/compliance auditing capabilities across IT, cloud, and OT environments. Overlaps with VA's agentless auditing and CIS Benchmark assessment functionality, particularly for critical infrastructure and regulated industries.
- Tugboat Logic (OneTrust): Now part of OneTrust, Tugboat Logic offers a SaaS compliance automation product for SOC 2, ISO 27001 and other frameworks. Broad incumbent with overlapping capabilities but embedded in a much larger privacy/GRC suite.
- Tanium: Endpoint and converged endpoint management platform used by large enterprises and government agencies for configuration, patch, and compliance assessment. Comparable to VA's on-prem configuration/patch auditing capabilities, though broader and aimed at much larger deployments.
- Qualys: Cloud-based security and compliance platform offering vulnerability management, policy compliance, and web application scanning across on-prem and cloud environments. Comparable to VA's vulnerability, configuration, and framework correlation features, at a much larger scale.
Direct peers
- Vanta: Leading cloud-native trust management platform that automates SOC 2, ISO 27001, HIPAA, PCI and other compliance audits. Direct competitor to Virtual Auditor in the mid-market compliance automation space, though Vanta is SaaS-only whereas VA offers an on-prem appliance.
- Secureframe: Compliance and security automation platform supporting SOC 2, ISO 27001, HIPAA, PCI DSS and other frameworks with continuous monitoring and audit-ready evidence. Direct competitor in mid-market compliance automation.
- Thoropass (formerly Laika): Compliance platform combining automated evidence collection with integrated audit expertise, covering SOC 2, ISO 27001, HIPAA, PCI and more. Comparable to VA's platform-plus-experts model and overlapping mid-market buyer profile.
- Hyperproof: Compliance operations platform providing continuous control monitoring, evidence collection, and framework mapping across SOC 2, ISO 27001, HIPAA, PCI, NIST and others. Direct mid-market competitor to VA.
- Drata: Compliance automation platform providing continuous control monitoring and automated evidence collection across SOC 2, ISO 27001, HIPAA, PCI DSS and more. Competes head-to-head with VA for mid-market security/compliance buyers, also SaaS-delivered.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Virtual Auditor social profiles
Digital presenceVirtual Auditor financial estimates
Financial estimateRevenue estimate
Valuation estimate
Virtual Auditor leadership team
Management profileNumber of profiles
Profiles1 record
Virtual Auditor funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Virtual Auditor M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Virtual Auditor
What does Virtual Auditor do?
Virtual Auditor delivers a fully managed information security and compliance program as an on-premises or private cloud appliance (the VA Appliance) combined with expert services. The platform provides continuous, agentless auditing of configurations, patch posture, web applications, identities, and endpoints; maps controls to HIPAA, PCI DSS 4.0/4.0.1, NIST CSF 2.0, ISO 27001, SOC 2, and NYDFS 23 NYCRR 500; and produces audit-ready evidence, dashboards, daily digests, and board-ready reports.
Is Virtual Auditor a public or private company?
Virtual Auditor is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Virtual Auditor founded?
Virtual Auditor was founded in 2013. It employs 1 to 10 people.
Where is Virtual Auditor based?
Virtual Auditor is headquartered in Champaign, United States, in the North America region.
How does Virtual Auditor make money?
One revenue line is on record: managed Security & Compliance Program.
Who are Virtual Auditor's main competitors?
Broad incumbents on record are AuditBoard, Tenable, Tugboat Logic (OneTrust), Tanium and Qualys. Direct peers are Vanta, Secureframe, Thoropass (formerly Laika), Hyperproof and Drata.
Does Virtual Auditor have an API?
No public API is recorded for Virtual Auditor.
What industry is Virtual Auditor in?
Virtual Auditor's product category is Compliance & Security Auditing Software. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of HDABAHAI, Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC). Its NAICS code is 561621 and its SIC code is 7372.