Sentrix
Sentrix Inc. is a Montréal-based GRC automation software company that helps regulated mid-market and enterprise organisations manage compliance across 20+ frameworks (SOC 2, ISO 27001, Law 25, CPCSC, DORA, HIPAA, etc.) on a single platform hosted in Canada, selling annual subscriptions through direct sales and audit/MSSP partner channels.
- Company typePrivate
- Founded2024
- HeadquartersMontréal, Canada
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Sentrix does
Sentrix Inc. is a Montréal-headquartered software company that builds a unified Governance, Risk, and Compliance (GRC) automation platform for regulated mid-market and enterprise organisations. The platform ingests evidence through 80+ read-only OAuth connectors across cloud, identity, devops, HR, and endpoint systems, then maps a single configured control to 20+ frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIS2, DORA, NIST CSF, CMMC, Law 25, CPCSC, TGV, CAN/DGSI 104, ISO 42001, and others) using a proprietary crosswalk engine. Five modules compose the platform: Compliance Automation, Third-Party Risk Management, Policy Management, License Optimizer, and Integrations, supported by professional services for ISO 27001, TGV, CPCSC, and CAN/DGSI 104 certification preparation. All customer data resides on AWS ca-central-1 in Montréal by default, with bilingual EN/FR interface, and Sentrix itself holds SOC 2 Type II (Grant Thornton) and ISO 27001:2022 (Bureau Veritas) certifications with annual penetration testing by Bishop Fox.
The company sells through a direct enterprise field sales motion targeting CISOs, VP Security, and GRC leads, complemented by an inside sales function and a three-track partner program covering audit firms, GRC consultancies/MSSPs, and Canadian VARs. Pricing is annual subscription based on framework count and modules, with mid-market customers typically landing between $30K and $80K per year and enterprise contracts on a multi-year basis. A distinctive commercial claim is the License Optimizer module, which the company says identifies an average of $180K in recoverable SaaS/GRC tool spend per customer within 90 days, creating a self-funding ROI dynamic. Sentrix is privately held, describes itself as "profitable-path," and discloses no institutional venture capital funding. William Georges Khouri (CISSP, CISM, ITIL) is President and Founder, supported by a leadership team of approximately three named executives with a total headcount near 80 employees.
Sentrix firmographics
Firmographics- Name
- Sentrix
- Legal name
- Sentrix Inc.
- Website
- https://sentrix.ca
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Sentrix Inc. is a Montréal-based GRC automation software company that helps regulated mid-market and enterprise organisations manage compliance across 20+ frameworks (SOC 2, ISO 27001, Law 25, CPCSC, DORA, HIPAA, etc.) on a single platform hosted in Canada, selling annual subscriptions through direct sales and audit/MSSP partner channels.
- Ownership category
- akta.pro rank
Sentrix industry classification
Industry- Product category
- GRC Automation Software
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- GRC Platforms & Workflow Automation (HDADAIAA)
- akta.pro secondary industries
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK), Compliance, GRC Workflow & Audit Automation Platforms (HDAEAHAL), Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA), Model Governance, Risk & Compliance (GRC) Platforms (HDAAAKAA)
Keywords
Where Sentrix is headquartered
LocationHeadquarters
- HQ city
- Montréal
- HQ country
- Canada
- HQ region
- North America
Offices2 records
Markets served
Sentrix business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Platform subscription (compliance automation, third-party risk, policy management, license optimizer, integrations): Annual subscription-based pricing with tiering based on framework count and modules selected. Most mid-market customers land between $30K-$80K per year. Professional services for certification support (ISO 27001, TGV, CPCSC, CAN/DGSI 104) offered as separate engagements. License optimizer module delivers ROI within days by identifying recoverable spend from redundant tool contracts.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Growth plan covering full platform with all modules for mid-market enterprises |
| Subscription | Annual | Sentrix Growth contract example |
| Subscription | Multi-year contract | Enterprise tier |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Sentrix product offering
Product offeringCore offering
Sentrix sells a cloud-based GRC (Governance, Risk, and Compliance) automation platform that continuously ingests compliance evidence from cloud, identity, devops, HR, and endpoint systems via read-only OAuth integrations and maps each control across 20+ frameworks simultaneously. The platform is delivered as five integrated modules — Compliance Automation, Third-Party Risk Management, Policy Management, License Optimizer, and Integrations — plus professional certification support services for ISO 27001, TGV, CPCSC, and CAN/DGSI 104. All customer data is stored exclusively in AWS ca-central-1 (Montreal) by default, with bilingual EN/FR interface and documentation.
Product overview
Sentrix is a unified GRC (Governance, Risk, and Compliance) automation platform built in Canada. The platform consists of five interconnected modules: Compliance Automation (core module for multi-framework evidence collection and control mapping), Third-Party Risk Management (continuous vendor monitoring and questionnaire automation), Policy Management (50+ pre-built policy templates with automated attestation), License Optimizer (SaaS tool overlap analysis and spend recovery), and Integrations (80+ native OAuth connectors plus REST API). Supporting these modules, Sentrix offers professional certification support services for ISO 27001, TGV (Quebec health network), CPCSC (Canadian defence suppliers), and CAN/DGSI 104 (CyberSecure Canada). A public Trust Center documents the platform's own security posture. The architecture centers on a single evidence layer where controls are configured once and mapped automatically across every supported framework.
Differentiator
Problem solved
Functional benefit
Products and services
- Compliance Automation Core platform module that automates compliance evidence collection and maps controls across 20+ frameworks simultaneously. Continuous evidence ingestion from cloud, identity, devops, HR, and ticketing systems with pre-built crosswalks between standards. Targets security and compliance leads at regulated mid-market and enterprise organizations.
- Third-Party Risk Management Vendor risk management module providing continuous vendor monitoring, automated security questionnaires (SIG Lite, CAIQ, NIST), SOC 2/ISO 27001 certification tracking, drift detection alerts, concentration risk analysis, and risk-tiered vendor onboarding. Vendor onboarding completes in under 5 minutes with unlimited vendor seats.
- Policy Management Policy lifecycle management module with 50+ pre-built enterprise policy templates pre-mapped to all supported frameworks, automated version control, multi-tier approval workflows, immutable version history with reviewer sign-off, and employee acknowledgment tracking with cryptographically signed audit evidence. Includes automated annual re-acknowledgment and policy exception management.
- License Optimizer SaaS license governance module that surfaces GRC tool overlap, dormant seats, and redundant contracts across 5+ tool stacks. Includes renewal calendar with 90-day advance alerts, dormant seat detection, and CFO-ready savings reports comparing current spend versus Sentrix cost. Identifies average $180K in recoverable spend within first 90 days.
- Integrations Native connector library providing 80+ read-only OAuth integrations across cloud (AWS, Azure, GCP), identity (Okta, Azure AD, Google Workspace, JumpCloud), devops (GitHub, GitLab, Jira), HR (Workday, BambooHR, Rippling), endpoint (Jamf, CrowdStrike, SentinelOne, Intune), and security tool categories. Includes REST API with OpenAPI documentation, sandbox environment, and webhook support for custom evidence ingestion.
- ISO 27001 Certification Support Hands-on certification preparation service for ISO 27001:2022 covering gap analysis, ISMS scope definition, Statement of Applicability generation, control implementation, internal audit, and certification audit support. Sold as a separate professional services engagement.
- TGV Certification Support Specialized certification support for Quebec health network technology products and services. Covers security, personal information protection, performance, and technology domains with penetration test coordination and BCH filing support. Sold as a separate professional services engagement.
- CPCSC Certification Support Certification readiness service for Canadian defence suppliers covering CPCSC Levels 1-3. Includes gap analysis against ITSP.10.171, control implementation, documentation, POA&M development, and assessment preparation. Sold as a separate professional services engagement.
- CAN/DGSI 104 Certification Support CyberSecure Canada certification preparation service for SMEs covering Level 1 and Level 2 requirements. Includes gap analysis, control implementation, internal audit, evidence file preparation, and SCC-accredited certification body audit support. Sold as a separate professional services engagement.
- Trust Center Public-facing trust portal documenting Sentrix's own security posture, including SOC 2 Type II certification, ISO 27001:2022 certification, annual penetration test results (Bishop Fox), data residency commitments, sub-processor list, and pre-completed SIG Lite and CAIQ security questionnaires for prospective customers conducting vendor security reviews.
Quantifiable outcome
- Average $180K in recoverable GRC spend identified per customer in first 90 days via license optimizer
- +11 more outcomes
Companies that use Sentrix
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles1 record
Sentrix technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration40 records
Feature7 records
Sentrix partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- Grant Thornton LLPcoreIndependent auditor performing annual SOC 2 Type II attestation against AICPA Trust Services Criteria for Security, Availability, and Confidentiality. Audit performed annually with report available under NDA to qualified prospects and customers.
- Bureau VeritascoreAccredited certification body issuing ISO/IEC 27001:2022 certification with three-year certification cycle and annual surveillance audits. Certificate publicly available to Sentrix customers.
- Bishop FoxcoreSpecialized offensive security firm conducting annual comprehensive penetration testing of the Sentrix application and underlying infrastructure. Scope includes OWASP Top 10 web application testing, API endpoint enumeration and fuzzing, network segmentation validation, and tenant isolation control testing.
- Audit firm partners (CPA firms)coreAccounting and audit firms that perform SOC 2, ISO 27001, HIPAA, and PCI assessments for their client organizations. Sentrix provides auditor workspace with read-only access to client evidence, pre-formatted audit packages reducing fieldwork preparation time, and referral revenue for clients introduced to Sentrix.
- GRC consultancy and MSSP partnerscoreSecurity consultancies and managed service providers running GRC programs for clients. Sentrix provides multi-tenant partner portal for managing all client environments, white-label reporting options for client deliverables, co-sell and referral revenue with preferred pricing.
- Value-added reseller and technology integrator partnersminorValue-added resellers and technology integrators in Canada including Sentrix in their security practice. Benefits include preferred reseller pricing with margin protection, joint go-to-market and co-sell support for qualified opportunities, and integration co-development for client-specific connector requirements.
- AWS (ca-central-1)coreAmazon Web Services ca-central-1 region (Montreal) hosts all Sentrix production infrastructure. All customer compliance data — including uploaded evidence, control assessments, audit trails, and user records — stored and processed exclusively within Canada. No data replicated to US-East, EU, or other AWS regions as part of normal operations.
- AWS Key Management ServicecoreEncryption keys managed through AWS KMS with annual rotation schedules and strict separation between tenant environments. Per-tenant key separation available on Enterprise tier.
Scale indicators14 records
Recent moves6 records
Expansion highlights6 records
Sentrix competitors and assessment
Company assessmentDirect peers
- Drata: Drata is the US-based leader in automated compliance for SOC 2, ISO 27001, HIPAA, etc. Direct competitor to Sentrix on compliance automation and continuous evidence collection, but lacks Sentrix's native Canadian framework support (Law 25, CPCSC, TGV) and Canadian data residency by default.
- Vanta: Vanta is the largest US-based automated compliance/trust management platform. Competes head-to-head with Sentrix on multi-framework automation, integrations, and trust center capabilities; differentiates on broader integrations and scale.
- Secureframe: Secureframe is a compliance automation platform targeting SOC 2, ISO 27001, HIPAA and similar frameworks. Directly comparable technology and GTM motion to Sentrix, but US-headquartered without Canadian data residency or French/English localization.
- Sprinto: Sprinto is a compliance automation platform focused on SaaS/cloud companies with continuous control monitoring. Direct competitor on framework automation for SOC 2/ISO 27001/HIPAA, comparable in mid-market GTM but again US-centric.
Emerging players
- LogicGate Risk Cloud: LogicGate is a no-code GRC platform focused on risk and compliance workflow automation for mid-market. More configurability-heavy than Sentrix but similar target buyer profile; competing sales cycles overlap.
- Hyperproof: Hyperproof is a compliance operations platform with continuous control monitoring and multi-framework support. Direct overlap with Sentrix's compliance automation module and similar mid-market focus.
- Tugboat Logic (now part of OneTrust): Tugboat Logic was a SOC 2 compliance automation platform for SaaS companies, now consolidated under OneTrust. Comparable technology positioning to Sentrix for SaaS audit readiness, validating the compliance-automation category.
Broad incumbents
- OneTrust: OneTrust is a broad privacy/GRC platform with modules covering third-party risk, ethics, ESG, and compliance. It overlaps with Sentrix on TPRM and consent but is much larger and broader-focused; customer testimonials indicate Sentrix has won competitive displacements against OneTrust.
- AuditBoard: AuditBoard is an enterprise GRC/risk platform focused on internal audit, SOX, and risk management. Overlaps with Sentrix in audit-ready reporting and control mapping, but targets larger enterprises and lacks Sentrix's automation-first mid-market positioning.
- Diligent (Galvanize/GRC): Diligent's GRC unit (Galvanize) is an enterprise-grade governance, risk, and compliance suite. Addresses similar compliance, vendor risk, and audit use cases at large enterprises; competing on Canadian-framework coverage is unlikely to be a strategic priority.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Sentrix social profiles
Digital presenceSentrix compliance and trust
Trust signalCompliance22 records
Sentrix financial estimates
Financial estimateRevenue estimate
Valuation estimate
Sentrix leadership team
Management profileNumber of profiles
Profiles3 records
Sentrix funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Sentrix M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Sentrix
What does Sentrix do?
Sentrix sells a cloud-based GRC (Governance, Risk, and Compliance) automation platform that continuously ingests compliance evidence from cloud, identity, devops, HR, and endpoint systems via read-only OAuth integrations and maps each control across 20+ frameworks simultaneously. The platform is delivered as five integrated modules — Compliance Automation, Third-Party Risk Management, Policy Management, License Optimizer, and Integrations — plus professional certification support services for ISO 27001, TGV, CPCSC, and CAN/DGSI 104. All customer data is stored exclusively in AWS ca-central-1 (Montreal) by default, with bilingual EN/FR interface and documentation.
Is Sentrix a public or private company?
Sentrix is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Sentrix founded?
Sentrix was founded in 2024. It employs 1 to 10 people.
Where is Sentrix based?
Sentrix is headquartered in Montréal, Canada, in the North America region.
How does Sentrix make money?
One revenue line is on record: platform subscription (compliance automation, third-party risk, policy management, license optimizer, integrations).
Who are Sentrix's main competitors?
Direct peers on record are Drata, Vanta, Secureframe and Sprinto. Emerging players are LogicGate Risk Cloud, Hyperproof and Tugboat Logic (now part of OneTrust). Broad incumbents are OneTrust, AuditBoard and Diligent (Galvanize/GRC).
Does Sentrix have an API?
Yes. Sentrix offers a REST API with full OpenAPI documentation and sandbox environment. The API enables custom evidence ingestion from internal systems, custom SIEM events, and internal audit logs. Webhook support is available for real-time evidence push from custom systems. Custom evidence schema builder allows mapping any data structure to any control. Enterprise customers receive dedicated integration support during onboarding. Developer documentation is at sentrix.ca/Platform-Integrations.
What industry is Sentrix in?
Sentrix's product category is GRC Automation Software. Its primary akta.pro industry code is HDADAIAA, GRC Platforms & Workflow Automation, with a secondary code of HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms. Its NAICS code is 5182 and its SIC code is 7372.