Introducing heyGRC


Hi,

You know ISMS Copilot as the chat where you do ISO 27001, SOC 2 and GDPR.

heyGRC is the other half of that job. It reads your pull requests and flags a compliance problem while the change is still open, not months later in front of an auditor.

ISMS Copilot and heyGRC

If you are on ISMS Copilot Standard, Pro or Business, 100 private heyGRC reviews a month are already part of your plan, on one organization. Your price does not change.

Open it with the same account: https://app.heygrc.com

  1. Sign in with the same email you use for ISMS Copilot.
  2. Install the heyGRC GitHub App on the organization you want reviewed.
  3. Open Plan and click Activate.

Free and Plus do not include those 100 private reviews. heyGRC still has a free plan: 25 private reviews a month. You can still open the same link. Public repositories stay free.

If you already pay for heyGRC, nothing changes. Your heyGRC plan stays as it is.

Full rules: https://docs.ismscopilot.com/docs/account-billing/heygrc-included-with-your-plan

If something is unclear, reply. I read every reply.

Best,
Tristan
ISMS Copilot

Better ISMS

Read more from Better ISMS
ISMS Assistants chat playground

Hi, You already know ISMS Copilot as the chat for GRC work. Introducing the platform: the same knowledge, ready to ship to your customers and your products, without you standing up a training pipeline, model stack, or compliance chatbot from scratch. One console: https://platform.ismscopilot.com For consultants and compliance platforms: Assistants If you advise clients, you already own the relationship. What you often lack is a way to extend support between workshops, or to capture leads with...

December 2025 edition ISMS Copilot latest updates How we made ISMS Copilot a better GRC assistant this month. ISMS Copilot 2.5 is here The biggest update since we launched the new app: Dynamic Framework Knowledge Injection. Ok, the name is a bit scary, but put it simply: When you ask about a standard or a regulation (ISO 27001, GDPR, SOC 2, HIPAA, NIS 2, DORA, CCPA, ISO 42001, or ISO 27701), the framework is automatically detected and relevant knowledge is injected into the AI before it...