1. Self-serve compliance automation. Sign up, connect AWS, Google Workspace, Okta, GitHub and Slack, and 100+ tests run continuously for SOC 2, ISO 27001, HIPAA, PCI DSS and more. 2. No per-framework fees 3. 14-day free trial, no credit card 4. Built by a data-security company, so it also finds the AI apps and agents in your workspace and maps them to the customer data they can reach 5. Run it from the dashboard or Claude Code via MCP 6. Platform $4,995/yr. Audit, vCISO and pen test tiers above
Before Strac, I spent 11 years at Amazon building payment security systems. For the last four years, we’ve been building data security for SaaS, cloud, and GenAI.
We’ve also been a compliance customer the entire time.
And every year, the same thing happened: the audit ends, tests quietly drift, and by the next audit cycle we’re collecting evidence almost from scratch again. Compliance somehow gets slower instead of faster.
At the same time, auditors started asking questions that traditional compliance tooling wasn’t designed around:
Which AI tools are employees using?
Which agents can access customer data?
Where is sensitive data actually flowing?
We already had the underlying visibility and controls in Strac.
So we built Strac Comply — security-first compliance for the AI era.
• Continuous tests against your real stack, so you stay audit-ready after the audit • 100+ automated checks and evidence collection from day one • Shadow AI and AI governance as real controls, not just policy documents • SOC 2, ISO 27001, HIPAA, PCI, and GDPR with no per-framework fees • Run compliance from the dashboard — or from Claude Code, Cursor, Codex, and other agents through MCP
And we wanted the buying experience to be different too:
No sales call. Starts at $4,995/year. 14-day free trial. No credit card.
You can sign up tonight and start running checks immediately.
Would love feedback from anyone who has been through SOC 2 or another audit:
What was the most painful part — and what broke after the first audit was over?
I’ll be here answering questions all day. 👋
About Strac Comply on Product Hunt
“Get SOC 2 without the sales call”
Strac Comply launched on Product Hunt on October 8th, 2026 and earned 70 upvotes and 5 comments, placing #31 on the daily leaderboard. 1. Self-serve compliance automation. Sign up, connect AWS, Google Workspace, Okta, GitHub and Slack, and 100+ tests run continuously for SOC 2, ISO 27001, HIPAA, PCI DSS and more. 2. No per-framework fees 3. 14-day free trial, no credit card 4. Built by a data-security company, so it also finds the AI apps and agents in your workspace and maps them to the customer data they can reach 5. Run it from the dashboard or Claude Code via MCP 6. Platform $4,995/yr. Audit, vCISO and pen test tiers above
On the analytics side, Strac Comply competes within Developer Tools, Artificial Intelligence and Security — topics that collectively have 1M followers on Product Hunt. The dashboard above tracks how Strac Comply performed against the three products that launched closest to it on the same day.
Who hunted Strac Comply?
Strac Comply was hunted by Garry Tan. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
For a complete overview of Strac Comply including community comment highlights and product details, visit the product overview.
Hey Product Hunt 👋 I’m Aatish, founder of Strac (YC W22).
Before Strac, I spent 11 years at Amazon building payment security systems. For the last four years, we’ve been building data security for SaaS, cloud, and GenAI.
We’ve also been a compliance customer the entire time.
And every year, the same thing happened: the audit ends, tests quietly drift, and by the next audit cycle we’re collecting evidence almost from scratch again. Compliance somehow gets slower instead of faster.
At the same time, auditors started asking questions that traditional compliance tooling wasn’t designed around:
Which AI tools are employees using?
Which agents can access customer data?
Where is sensitive data actually flowing?
We already had the underlying visibility and controls in Strac.
So we built Strac Comply — security-first compliance for the AI era.
• Continuous tests against your real stack, so you stay audit-ready after the audit
• 100+ automated checks and evidence collection from day one
• Shadow AI and AI governance as real controls, not just policy documents
• SOC 2, ISO 27001, HIPAA, PCI, and GDPR with no per-framework fees
• Run compliance from the dashboard — or from Claude Code, Cursor, Codex, and other agents through MCP
And we wanted the buying experience to be different too:
No sales call. Starts at $4,995/year. 14-day free trial. No credit card.
You can sign up tonight and start running checks immediately.
Would love feedback from anyone who has been through SOC 2 or another audit:
What was the most painful part — and what broke after the first audit was over?
I’ll be here answering questions all day. 👋