Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Paid
Claimed
Optimized for quick response

Strike Graph Reviews & Product Details

Strike Graph Overview

What is Strike Graph?

Strike Graph is the leading compliance management software designed to revolutionize how businesses achieve and maintain security certifications, including CMMC, NIST, ISO 27001, HIPAA, SOC 2, PCI DSS, TISAX, and more. With a mission to help companies efficiently and effectively prove compliance and build trust, Strike Graph transforms compliance from a burdensome expense into a strategic advantage. Traditional security compliance processes are often slow, opaque, and costly, requiring reliance on outdated methods. Strike Graph eliminates these inefficiencies by providing companies with a transparent, objective solution to design, operate, and measure their security programs. Strike Graph’s innovative tools simplify every stage of compliance. It enables users to create customized security programs tailored to their specific risks and operational needs, streamlines evidence collection and testing, and offers in-platform certification options that reduce reliance on third-party auditors. This comprehensive approach not only saves time and money but also ensures continuous compliance monitoring to protect businesses against evolving threats. The platform caters to security leaders in all industries, including SaaS, FinTech, HealthTech, EdTech, and beyond, offering a knowledgeable and approachable partner in compliance management. Strike Graph’s AI-powered features, like Verify AI, enhance accuracy and efficiency while ensuring data security through self-hosted models. By turning compliance into a revenue enabler, Strike Graph helps companies build trust with their customers, partners, and stakeholders, paving the way for sustainable growth and innovation.

Strike Graph Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

Strike Graph is designed to revolutionize how businesses achieve and maintain security compliance. From SOC 2, ISO 27001, and HIPAA to CMMC, NIST, PCI DSS, TISAX, and more. With a mission to help companies efficiently and effectively prove compliance and build trust, Strike Graph transforms compliance from a burdensome expense into a strategic advantage.

How do you position yourself against your competitors?

Strike Graph provides compliance management for startups to enterprise companies, helping them through right-sized compliance postures that adapt to unique and innovative infrastructures while providing robust security and privacy.

Strike Graph’s comprehensive platform and AI-powered technology help streamline the compliance journey, validating evidence in real time so you can confidentially go into an audit without wasting time and resources.


Seller Details
Company Website
Year Founded
2020
HQ Location
Seattle, WA
Twitter
@StrikeGraph
119 Twitter followers
LinkedIn® Page
www.linkedin.com
48 employees on LinkedIn®
Description

Seattle-based Strike Graph is the #1 leader in customizable compliance management software. We empower businesses to streamline achieving and maintaining compliance with a wide range of security certifications including SOC
, CMMC, ISO
7001, ISO
7701, HIPAA, NIST, FedRAMP, PCI DSS, CCPA, GDPR and TISAX.


Katie B.
KB
Overview Provided by:

Recent Strike Graph Reviews

Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.0 out of 5
"Good balance between the platform and consulting services"
The Strikegraph team is really supportive in helping you to achieve your compliance goals. The provided documentation (templates) and the advices p...
Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.5 out of 5
"Wonderful experience in our SOC2 auditing"
Nice web GUI dashboard, and thorough documentation, plenty of template, guided support for any questions, easy follow process for compliance.
Verified User
U
Verified UserSmall-Business (50 or fewer emp.)
5.0 out of 5
"Strike Graph is a huge time saver and having our SOC2 Report has made our life's easier."
Strike Graph has an amazing support team. Obtaining our SOC2 certification seemed like an overwhelming task at first, but our account rep and the r...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

Strike Graph Media

Strike Graph Demo - Verify AI
Rest assured with AI-powered evidence validation ensuring your evidence matches what your business requires.
Strike Graph Demo - Multi-framework mapping
Experience the simplicity of linking controls to multiple frameworks with multi-framework mapping
Strike Graph Demo - Risk Management Dashboard
Effortlessly identify risks and prioritize vulnerabilities with easy-to-understand scores.
Strike Graph Demo - Control monitoring
Easily decipher controls by owner, implementation progress, and status, keeping you up to date with changes to the controls in your compliance program.
Strike Graph Demo - Compliance Dashboard
Complete overview and visibility of an organization's compliance posture from control snapshots and evidence expiring soon to comment activity and framework satisfaction.
Strike Graph Demo - Integrations Manager
Low-code integrations automatically collect and update evidence ahead of the expiration date, and notify your team, so you can put your security and compliance program on autopilot.
Play Strike Graph Video
Play Strike Graph Video

Official Downloads

Answer a few questions to help the Strike Graph community
Have you used Strike Graph before?
Yes

144 Strike Graph Reviews

4.7 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
144 Strike Graph Reviews
4.7 out of 5
144 Strike Graph Reviews
4.7 out of 5

Strike Graph Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for Strike GraphQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
RZ
Sr. Director, IT - Global Infrastructure and Operations
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Strike Graph?

Strike Graph was the right GRC (Governance, Risk and Compliance) tool we needed at the right time for the right cost. Strike Graph doesnt have a monolithic GRC tool that does everything and cost six figures. It had enough to support our needs for TISAX and ISO27001 without having to pay for features and functionality we didnt need. In addition to a SaaS tool they have available very helpful and responsive support that goes beyond "tech support." They have resources that can help with low level compliance questions and access to currated content like policies and procesdures. The tool was easy to implement (self implementation) and use. StrikeGraph even took feedback and incorporated that feedback. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

Its not a dislike, but to be clear, its not for all organzations depending on need. It currently doesnt have workflow/approval management of Polciy and Procedures, for example. Reporting is limited, but effective for what we needed. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

We didnt have internal expertise on TISAX (European focused security framework in the automative vertical) and they had the famework and all its controls built out that we could quickly start working on the compliance to meet our most demanding customers requirements. Review collected by and hosted on G2.com.

Verified User in Telecommunications
AT
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Strike Graph?

Strike Graph makes the compliance process smooth and stress-free. The platform is incredibly intuitive, making it easy to navigate SOC 2, ISO 27001, and other security frameworks without unnecessary complexity. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

The Strike Graph team lacks regular check-ins and outreach. Although the platform is intuitive, quarterly check-ins would help monitor progress and address compliance needs. More engagement would benefit companies navigating compliance for the first time. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

Strike Graph is solving the complexity and inefficiency of managing security compliance, particularly for frameworks like SOC 2 and ISO 27001. Before using Strike Graph, the process felt overwhelming and manual, with scattered documentation and unclear next steps.The platform streamlines everything—automating evidence collection, simplifying risk assessments, and providing a clear roadmap to certification. Review collected by and hosted on G2.com.

SH
Lead BA/IT Specialist
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Strike Graph?

Periodic reminders about expiring evidence is very helpful for staying on top of what needs to be refreshed, when, and how often.

Control- and evidence-assignment makes it simple for different users to look up what has been assigned to them, which controls have been fully/partially satisfied.

The web portal makes it easy to access things from anywhere. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

A lot of the documentation & examples are focused on AWS and particular products/services, which is unfortunate for inexperienced users from organizations that use other options.

Some of the control/evidence descriptions could be made clearer. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

Achieving SOC2 Type 2 compliance, for an organization that has never done that before. Review collected by and hosted on G2.com.

Gitel Y.
GY
SVP Technology
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Strike Graph?

Strike Graph made it relatively easy for us to obtain our SOC2 Type II audit and report. It took us time to get our documentation and evidence ready for audit, but our CSM Stephanie was extremely helpful. She set things up for us at the start of the process in a way that would be best aligned to our business and defined processes. She was super knowledgeable and responsive. The resources and templates available within the platform were invaluable. They saved us time, and gave us confidence that the documentation we provided using the templates met the requirements. When we needed just-in-time clarification, we got quick answers to our questions from the Strike Graph team who made themselves available via the online chat.

Overall, we had a very positive experience. The platform was easy to use and helped streamline the process of preparing for our SOC 2 Type II audit, the Strike Graph team was great to work with, and the actual audit went very smoothly. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

There was somewhat of a learning curve in understanding how to use the tool effectively which is typical of using a new tool.

Two things that were slightly burdensome were:

1. Collaboration with the auditors was done outside the platform, using Google docs which we don't use so it was something we had to work out. It was not a big deal and we worked around it but it would be good if that could be streamlined and incorporated into the platform (i.e. additional evidence needed, draft audit report). 2. We used the same policy document to support several evidence items and when we updated the document, we had to re-upload it for each evidence item. It would be nice if we could upload the document only once, and associate multiple evidence to it. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

We are required to deliver a SOC 2 Type II report to some of our customers. Strike Graph helped us prepare for and complete the audit and get the SOC2 Type II report. Review collected by and hosted on G2.com.

Nate S.
NS
Chief Customer Officer and Head of Operations
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Strike Graph?

Strike Graph does a great job of organizing our controls and evidence and keeping us on the schedule. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

I really like that Strike Graph supports Sign in with Google and allows us to associate files on our Google Drive with Evidence. If there's any way for it to only ask me for my Google credentials once rather than each time I link a file, that would be amazing. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

The process of defining controls and collecting evidence needed to maintain SOC2 Type 2 can be daunting. Strike Graph is like the much needed drumbeat to keep the oars synchronized. Review collected by and hosted on G2.com.

Jasson C.
JC
Co-Founder
Computer Software
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Strike Graph?

Strike Graph's ability to give us insights into our team's progress towards SOC2 compliance is pretty awesome! Their reporting and monitoring features let us keep a close eye on our compliance efforts, spot any hurdles, and measure how far we've come. It's been a real game-changer for managing our compliance projects, making smart decisions based on data, and staying on the right track to get our SOC2 type 2. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

We had a great experience with Strike Graph, and there was nothing we disliked about their service. Throughout the process, their team was incredibly supportive, providing assistance and guidance every step of the way. Their commitment to our success made the entire journey smooth and enjoyable. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

Strike Graph is solving the problems of simplifying compliance efforts, providing real-time insights, supporting various compliance frameworks, fostering efficient team collaboration, and enabling data-driven decision-making. These benefits have greatly improved our cybersecurity posture and made the compliance process much smoother for our organization. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Strike Graph?

The Compliance Dashboard and the Control Monitoring dashboards are the best feature that StrikeGraph offers in my opinion as it gives you high-level review of the status of risks, controls and evidence.

The Help Centre is also an incredibly helpful tool given it contains sample templates and documentation for most of controls. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

The UI at times is unresponsive and glitchy. In my 2+ years of using StrikeGraph, I've notcied the UI at times fights with the user especially when I try using filters in the control library or evidence respository tabs.

Additionally, the inability to upload more than 1 file at a time for evidence does become frustrating at times especially if you have to upload 50+ onboarding checklists. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

StrikeGraph has made it easier for our internal audit teams to monitor SOC2 Type 2 & GDPR compliance. The control library makes it easy for any user to upload evidence requirements without having to understand all the details and nuancs of the secuirty frameworks.

It's helped make it easy and quick to onboard new members onto the audit team as there's a need for minimal knowledge transfer on the framework requirements Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Strike Graph?

Having the ability to upload evidence throughout the year is a huge benefit of Strike Graph. Typically, an audit kicks off and you start collecting evidence at that time. Strike Graph allows us to upload evidence as it expires which spreads the effort over the year instead of doing it all within 1-3 months. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

There are very few dowsides. Being a younger product, there are some features/functionality I would like to see implemented. However, Strike Graph is one of the few vendors we've used that actually implemented a feature that we requested which is great. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

I am currently the only resource dedicated to security & compliance in our organization. We currently perform two SOC 1 Type 2 audits, PCI DSS, HIPAA, SOC 2 Type 2, and are in the process of moving one of our SOC 1 audits to Strike Graph. The main benefit is being able to chip away at evidence collection to avoid it hitting all at once, when we may have multiple overlapping audits in flight. The ability to set expiration dates and assignments on evidence is also a plus, as it sets expectations with everyone invovled. They know what they're going to be responsible for, and when it's required of them. Review collected by and hosted on G2.com.

Matt L.
ML
Chief Information Security Officer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Strike Graph?

Working with Kevron from Strike Graph has been like having an extension of my team, assisting with compliance guidance, documentation, audit prep, and open conversation about initiatives across our business. The compliance dashboard, document templates, and resources available make enhancing a security and compliance program a breeze. I have been thrilled with the progress and process of interacting with Strike Graph as a whole, but certainly with Kevron in particular. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

I have not experienced any downsides in working with Strike Graph. My situation may be pretty simple, but I have been offered resources above what I even need and have really only scratched the surface of the offerings available through the compliance dashboard. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

Strike Graph is helping me get a handle on compliance audit, assisting with advice, templates, structure, and guardrails for ensuring I have covered all items necessary to remain compliant. Review collected by and hosted on G2.com.

Verified User in Marketing and Advertising
UM
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Strike Graph?

Strike Graph has an amazing support team. Obtaining our SOC2 certification seemed like an overwhelming task at first, but our account rep and the rest of the support team were always available to help us and guide us through it. Review collected by and hosted on G2.com.

What do you dislike about Strike Graph?

Their Security Questionnaires feature, while helpful, could use some improvements. Review collected by and hosted on G2.com.

What problems is Strike Graph solving and how is that benefiting you?

Because of the type of services we provide, almost all of our customers require a SOC2 certification which Strike Graph helped our organization obtain, which in turn has allowed us to expand our business. Review collected by and hosted on G2.com.