Compliance-as-Code for Cloud Infra
Terraform-native ISO controls are table stakes; unclear if reports actually satisfy auditors.

Automates SOC 2 evidence and AI Act compliance so engineers stop answering spreadsheets.
B2B SaaS founders and security teams
Vanta · Drata · Secureframe
Terraform-native ISO controls are table stakes; unclear if reports actually satisfy auditors.
Ambitious but vague: predicts failures with AI, but unclear how it differs from existing AIOps platforms.
ReARM zeroes in on a gritty, enterprise problem: per-release evidence, automated changelogs, and 10+ year retention with product-level bundling and approval workflows. Integrations with Dependency-Track and OWASP TEx are smart moves, but the offering reads like a sensible commercial UX layer on top of existing provenance tools rather than a technical breakthrough.
This is a focused, pragmatic take on turning spreadsheet chaos into audit-ready checklists: locked photos, time/user stamps, reusable templates and one-click PDF export are sensible, usable features. The UI on the landing page telegraphs that they thought about common flows, but the market already has strong incumbents — the product will live or die on integrations, automation hooks, and how well it handles complex recurring workflows.
EU AI Act compliance in your IDE with code never leaving your machine.
HMAC-SHA256 audit chains for EU AI Act Article 12 compliance, pip-installable trust layers for every major agent framework.