Mycroft
Security and compliance platform whose AI agents draft policies and SSPs, collect evidence and track controls across SOC 2, ISO 27001, HIPAA, CMMC, FedRAMP and more, through read only integrations with remediation tickets and Slack alerts, backed by security experts.
Mycroft is a Toronto security and compliance platform that combines a GRC platform, AI agents and its own security experts. Its agents scope compliance boundaries, generate policies, risk registers, system descriptions, SSPs and POA&Ms, implement controls and collect audit evidence across frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, CMMC, FedRAMP, CPCSC, CPRA/CCPA and PIPEDA. Around the GRC core, plans add a cloud native application protection platform, security awareness training, 24/7 threat intelligence and monitoring, a trust center, and on higher tiers penetration testing, third party risk management and a dedicated CISO.
Mycroft connects to 24 systems, including AWS, GCP, Azure, GitHub, GitLab, Okta, Google Workspace, Microsoft Entra ID, HR systems, Jamf and 1Password, and states that every integration is read only by default: it reads configuration, identity and metadata and cannot change resources, credentials or policy. Integrations continuously test the controls that depend on each system and store dated evidence; the only writes are remediation tickets in one Jira, Linear or Asana project the customer nominates and notifications in Slack channels it is invited to.
Mycroft's own trust center lists SOC 2 Type 2, ISO 27001, ISO 27701 and ISO 42001 and FedRAMP 20x Class A, with hosting on GCP in Canada and the US. Plans are Platform, Scale and Managed, with basic, expanded and customized agentic workflows by tier and no published prices. It fits fast growing companies, especially fintechs, that want audit readiness across several frameworks with evidence collected continuously and experts on call; it does not operate the customer's security stack, since its integrations are read only.
Vendor details
Canonical URL
https://www.mycroft.io
Category
Security / SOC agent
Funding status
Seed round of 3.5 million dollars (September 2025, out of stealth) led by Luge Capital, with Brightspark Ventures, Graphite Ventures, Ripple Ventures, Developer Capital, Antler, BoxOne Ventures, and strategic angels. Toronto based, co founded by Mike Kim (CEO) with Jonathan Mendes (Head of Product and Design) and Jan Jedrasik (Head of Engineering), a team with over 30 years of combined security and compliance experience. Signed more than 50 customers, many of them fintechs, within its first six months.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
24 read only integrations: AWS, GCP, Azure, Cloudflare, Heroku, Vercel, GitHub, GitLab, Bitbucket, Azure DevOps, Okta, Google Workspace, Microsoft Entra ID, Deel, Employment Hero, BambooHR, Zoho People, Jira, Asana, Linear, ServiceNow, Slack, 1Password and Jamf. The only writes are remediation tickets in one nominated Jira, Linear or Asana project and Slack notifications.
In practice
A defense contractor needs CMMC to keep bidding on contracts. Mycroft's agents scope the compliance boundary and draft the SSP and POA&Ms, and its experts handle each required change on the way to the audit.
A startup's first enterprise deal needs a SOC 2 report fast. Mycroft connects read only to systems like AWS, GitHub and Okta, collects evidence automatically and coordinates with the auditor; Weave went from zero to SOC 2 in under 30 days.
A security lead worries a compliance tool will change production. Every Mycroft integration is read only by default, and its only writes are tickets in one nominated Jira, Linear or Asana project and posts in invited Slack channels.
Sources & related URLs
Agentic Index coverage score
6.5 / 14 capabilities · 46%
| Integrations & Tool Calling | Full |
|---|---|
|
Mycroft lists 24 integrations across clouds (AWS, Google Cloud, Azure, Cloudflare, Heroku, Vercel), code hosts (GitHub, GitLab, Bitbucket, Azure DevOps), identity (Okta, Entra ID, Google Workspace, 1Password), devices (Jamf), HR (Deel, Employment Hero, BambooHR, Zoho People) and work tools (Jira, Asana, Linear, ServiceNow, Slack), all read only by default. The two scoped write paths are "creating remediation tickets in one project you nominate in Jira, Linear or Asana, and posting notifications to Slack channels you invite it to". Those are the only places Mycroft acts in outside systems. SourceMycroft, mycroft.io/integrationsread 2026-10-06 |
|
| Workflow Orchestration | Partial |
|
AI agents scope compliance boundaries, generate policies, risk registers, SSPs and POA&Ms, implement controls, configure the security stack and collect evidence. Plans carry Basic, Expanded and Customized agentic AI workflows, and the customized ones are delivered by Mycroft's own team, with a dedicated CISO on the Managed plan. No flow the customer configures, branching or coordinating agents is documented. SourceMycroft, mycroft.io and /pricingread 2026-10-06 |
|
| Knowledge Grounding & RAG | Full |
|
Integrations continuously test the controls that depend on each system and "store the results as dated evidence", from daily checks of encryption, logging and IAM configuration to the account inventory and the pull request approval behind every production change. The agents draft policies, system descriptions and SSPs from that evidence and the framework requirements. How the agents retrieve from it is not described. SourceMycroft, mycroft.io/integrationsread 2026-10-06 |
|
| Human Oversight & Guardrails | Partial |
|
Every integration is read only by default, and Mycroft "cannot create, modify or delete resources, reset credentials or change policy". Its only writes go to one ticket project the customer nominates and to Slack channels it is invited to, and the customer decides both. Mycroft's experts handle every required change, and no approval step for agent actions is documented. SourceMycroft, mycroft.io/integrations and mycroft.ioread 2026-10-06 |
|
| Security, Identity & Governance | Full |
|
The trust center lists SOC 2 Type 2, ISO 27001, ISO 27701 and ISO 42001 (certificates dated 31 Aug 2026) and FedRAMP 20x Class A. Application authentication, role based access and user segregation are among the controls it lists for the platform. Sourcetrust.mycroft.ioread 2026-09-28 |
|
| Observability & Auditability | Not documented |
|
Integrations test controls on a schedule, such as encryption, logging and IAM configuration daily, and store the results as dated evidence, and every plan includes 24/7/365 threat intelligence and monitoring. Those report on the customer's estate, and no log or trace of what Mycroft's agents did is documented. SourceMycroft, mycroft.io/integrations and /pricingread 2026-10-06 |
|
| Memory & State Persistence | Not documented |
|
Mycroft keeps dated control evidence for each customer, but describes no memory its agents keep, what it would hold or for how long. SourceMycroft, mycroft.io and /integrationsread 2026-10-06 |
|
| Deployment & Data Residency | Partial |
|
Mycroft is SaaS hosted primarily on GCP in Canada and the US, per its trust center. No customer choice of region and no customer environment option is documented. Sourcetrust.mycroft.ioread 2026-09-28 |
|
| Prebuilt Agents / Templates / Packs | Full |
|
The agents work from named framework packs for CMMC, FedRAMP, CPCSC, SOC 2, GDPR, ISO 27001, ISO 42001, HIPAA, CPRA/CCPA and PIPEDA, and generate policies, risk registers, SSPs and POA&Ms. The agents themselves are not named. Every plan adds a full GRC platform, a CNAPP, security, AI and privacy awareness training and a trust center, Scale adds penetration testing and continuous third party risk management, and Managed adds customized frameworks. SourceMycroft, mycroft.io and /pricingread 2026-10-06 |
|
| Triggers & Channel Coverage | Full |
|
Integrations "continuously test the controls" on their own schedule, daily for infrastructure settings, and failures open remediation tickets and Slack notifications without a user starting a run. Every plan includes 24/7/365 threat intelligence and monitoring. SourceMycroft, mycroft.io/integrations and /pricingread 2026-10-06 |
|
| Model Flexibility & Routing | Not documented |
|
No model behind the agents is named and no customer choice of model is documented. The trust center's subprocessor list names no LLM provider. Sourcetrust.mycroft.ioread 2026-09-28 |
|
| APIs / SDKs / MCP Extensibility | Not documented |
|
No API, SDK or MCP server is documented. Integrations pull data into Mycroft rather than exposing Mycroft to other systems, using read only credentials on systems the customer already runs. SourceMycroft, mycroft.io/integrationsread 2026-10-06 |
|
| Testing, Debugging & Optimization | Not documented |
|
Continuous control testing and penetration testing on the Scale plan test the customer's estate, and Mycroft documents no harness, scored test cases or quality gate for its own agents. Customers report results such as Weave going from zero to SOC 2 in under 30 days and Unified cutting its SOC 2 time by 90%. SourceMycroft, mycroft.io/pricing and mycroft.ioread 2026-10-06 |
|
| Browser / Computer-use | Not documented |
|
Mycroft works through read only API integrations. No agent operating a browser or desktop is documented. SourceMycroft, mycroft.io/integrationsread 2026-10-06 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Not public; three plans (Platform, Scale, Managed) without published prices
plan tier; prices not published
What is public
Plan names and inclusions for Platform, Scale and Managed; no prices, billing period or free tier on the pricing page.
Cost watchouts
Penetration testing, third party risk management and a dedicated CISO sit in higher plans, so expanding scope moves you up a tier.
Variable cost rationale
Inference, not stated by the vendor: cost likely scales with company size, connected systems and frameworks in scope, on top of the plan tier.
Sales call required
Mixed (some tiers require a call)
Free / trial
No free tier shown on the pricing page; Platform has a Get started path
Key ambiguities
No prices or plan limits are published for Platform, Scale or Managed. Platform starts from a Get started path, Scale is sold by demo and Managed goes through sales.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Mycroft
The closest documented capability profiles to Mycroft among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Anvilogic8.5 / 14Adds documented Observability & Auditability and APIs, SDKs & MCP Extensibility
- Abnormal AI9.0 / 14Adds documented Observability & Auditability and Memory & State Persistence, among others
- AirMDR6.0 / 14Adds documented Observability & Auditability
- Clutch Security6.0 / 14Adds documented Observability & Auditability and APIs, SDKs & MCP Extensibility
- Pi6.0 / 14Adds documented Observability & Auditability and Memory & State Persistence
- PRE Security6.0 / 14Fuller documented coverage on Workflow Orchestration and Deployment & Data Residency
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded