Skip to main content

Getting started

DSALTA is an AI-native Governance, Risk, and Compliance (GRC) platform that helps organizations manage compliance frameworks, automate evidence collection, track vendor risk, and prepare for audits — all from a single dashboard.
Most organizations complete initial setup in under an hour. The Onboarding Roadmap guides you through four phases. Full audit readiness typically takes 1–4 weeks depending on your organization’s size and framework requirements.
No. DSALTA is designed for compliance teams, not developers. Integrations connect via OAuth (one-click), policies are AI-generated, and controls are automatically mapped. Technical teams may be needed for certain cloud or DevOps integrations.
DSALTA supports 44 frameworks including SOC 2, ISO 27001:2022, GDPR, HIPAA, PCI DSS v4.0.1, NIST CSF v2.0, NIST AI RMF 1.0, CIS v8.1, HITRUST CSF, ISO 9001, ISO 42001:2023, EU AI Act, DORA, and more. Multiple frameworks can be active simultaneously with cross-framework control mapping.
Yes. Activate as many frameworks as needed. DSALTA maps overlapping controls automatically, so satisfying a control for SOC 2 may also count toward ISO 27001 or GDPR.

Account and access

There is no hard limit. Invite as many people as needed and assign them roles (Owner, Admin, Member, or Auditor) with different permission levels.
Yes. Invite your auditor with the Auditor role. It is view-only across most of the workspace, and grants full access to the surfaces an audit runs on — Documents, Incidents, Changes, Code Changes, User Access Reviews, Risk Management, Audit, Vendor Risk overview and Trust questionnaires — so they can record findings and request evidence directly. Review the role against your own engagement terms before you invite an external auditor; see Members for the full permission list.
Yes. DSALTA supports Google Workspace and Microsoft Entra ID for identity provider integration and single sign-on.

Data and security

Yes. All integrations connect with read-only access. DSALTA never makes changes to your connected systems — it only pulls data for evidence collection and monitoring.
Yes. Export evidence lists, policy documents, control mappings, and audit reports from the platform.