Openlane

Support

Frequently asked questions

General

What is Openlane?

Openlane is an open-source security and compliance platform. You define the controls your team operates, connect the policies and evidence behind them, and reuse that program across unlimited frameworks. Pricing is published, and the code is on GitHub.

Who is Openlane for?

Growing companies that need SOC 2, ISO 27001, or another framework to close deals and enter new markets, and the consultants who run programs for them. Founders, operations leads, and engineers use it without a dedicated compliance team.

How is Openlane different?

You write the control language your organization runs rather than adopting a vendor's template. The code is open source, module prices are public, and SSO, 2FA, and unlimited users are included in every plan.

Features

Which frameworks do you support?

12+ frameworks, including SOC 2, ISO 27001, ISO 27002, ISO 42001, HIPAA, PCI DSS, GDPR, NIST CSF, NIST 800-53, and NIST 800-171. You can also define a custom framework from any set of controls, and adding a framework carries no extra charge.

Does it connect to my tools?

Yes. Integrations cover GitHub, Slack, Google Workspace, AWS, Microsoft Entra ID, Okta, and others, and configurable expressions let you filter which records each integration sends into Openlane. The GraphQL API and scoped organization tokens cover the rest.

Can I customize?

Yes. Controls, subcontrols, policies, procedures, and frameworks are yours to define. Templates are a starting point, not a boundary.

What is continuous compliance?

Operating your controls all year and keeping the proof current, instead of assembling it in the weeks before an audit. In Openlane, renewal dates, recurring reviews, and control history do the reminding.

Do I have to do continuous compliance to use Openlane?

No. You decide which integrations to connect and which evidence to upload yourself. Either way, each artifact stays tied to the control it demonstrates.

Security & Data

Is my data secure?

Yes. Data is encrypted in transit and at rest and isolated per organization. Openlane's own trust center at trust.theopenlane.io publishes our security posture and controls.

What if I leave?

Download your data and evidence from Openlane and take it with you.

Pricing & Access

Is it open source?

Yes. The source is on GitHub, and you can run the open-source project yourself. The managed service adds hosting, support, and access to licensed framework content.

Do I need a credit card to start?

No. The 30-day free trial starts without a credit card, and the module prices on the pricing page are the prices you pay.

How long does onboarding take?

You can sign up, create your organization, and start defining controls the same day. The rest depends on the scope of your program; the docs and our team cover setup.

Switching from another GRC tool?

You can bring your existing controls, policies, and evidence into Openlane without rebuilding the program, and we offer migration support to help with the move.

Audits

Will it help me pass SOC 2?

Openlane keeps evidence tied to the controls it proves, so the audit reviews the program you run. You still operate the controls; the platform keeps the record straight.

Can I share with my auditor?

Yes. A read-only Auditor role gives your auditor direct access to the controls and evidence in scope, and you control what they see. You can also export evidence if they prefer files.

Support

Do you offer support?

Yes. Community help is free on Discord, and paid support plans put the Openlane team on call, including 1:1 Slack support with the Compliance module.

Is there a community?

Yes. The Openlane Discord is where customers, contributors, and the team compare notes, and the source is developed in the open on GitHub.