Centraleyes

Primary category: enterprise-grc. Also listed in vendor-risk.

One-liner — A lightweight, no-code cyber-risk-and-compliance platform aimed at firms that need a real risk register and framework coverage but have no appetite for a GRC implementation project.

What it does — SaaS GRC built around three linked things: a control/framework library with automated mapping across many regulatory and standards frameworks, a cyber risk register with quantification and executive dashboards, and third-party/vendor risk assessment in the same platform. The pitch is deployment speed — no-code configuration and onboarding measured in days rather than the months a servicenow or archer rollout takes — plus automated collection of assessment data instead of chasing spreadsheets.

Naming / provenance — Founded July 2016 by Yair Solow, originally as CyGov; rebranded to Centraleyes. Legal entities exist in both New York and Israel. Older records and databases still index it under CyGov.

Ownership & viabilityindependent, founder-led, privately held. This page’s largest caveat: publicly reported funding is only about $2.8M across three rounds, with the latest a seed round dated 2019-05-18. Either the company has been capital-efficient and bootstrapped from revenue since, or later rounds are undisclosed — the available sources do not distinguish these. That is a material diligence question for a buyer placing its compliance system of record with a small vendor. verify_after: 2027-02-26.

Note (soft): the disclosed-funding figure and the company’s marketed enterprise positioning are hard to reconcile. Treat funding as unconfirmed-low rather than known-low, and ask the vendor directly.

Positioning & differentiators

  • Time-to-value is the whole pitch. Directly aimed at the buyer who was quoted a six-figure implementation by an incumbent.
  • Cyber-risk quantification and board-level dashboards are foregrounded more than audit-evidence collection — the opposite emphasis from vanta/drata, and closer to logicgate in intent at a smaller scale.
  • TPRM included, overlapping vendor-risk.
  • A large share of its search visibility comes from its own content marketing — the “best GRC tools” listicles that surface it are published by Centraleyes itself. Discount accordingly; this is not third-party validation.

Who should choose them / anti-fit — Fits a small-to-mid firm (a sub-$5B manager, a small RIA) that needs a defensible risk register and framework coverage for investor and regulator diligence, staffed by one or two people. Anti-fit: any firm large enough to need a system of record with deep workflow customisation, or one whose vendor-diligence standards would flag a small, thinly-funded supplier holding its complete control environment.

Known weaknesses / gotchas — Small vendor; funding and scale unverified (above). Third-party analyst coverage is thin compared with logicgate, hyperproof or the incumbents. AI-governance module coverage is unverified.

Deployment & data handling — SaaS. Data residency, retention, and whether an EU/UK region exists are unverified — relevant given the split US/Israel operation.

Integrations & partnerships — Automated data collection from cloud and security tooling is claimed; the actual connector list is unverified.

Compliance & FS tractionUnverified. No named financial-services customers found; certifications held not confirmed.

Commercial — Not public; listed on software marketplaces (Capterra) without published pricing.

Open questions

  • Actual funding and headcount. Is the ~$2.8M figure current, or are later rounds undisclosed? Revenue-funded?
  • Certifications actually held (SOC 2 Type II, ISO 27001) — table stakes for a compliance vendor and worth confirming.
  • Data residency options; where customer control data is stored.
  • Whether an AI-risk framework module exists.
  • Named customers of any kind, and any financial-services references.

Sources

History

  • [2026-08-26] Page created via wiki-create + researched same day. Sourced from the 2026-08-25 competitor scan (Tier A, score 10 — the strongest co-mention signal in the scan, surfaced by Credo AI, Drata, Holistic AI and Onspring).