Skip to content

Allgress

Allgress provides an integrated IT governance, risk, and compliance platform that helps organizations map controls, manage risk assessments, and track regulatory compliance in one system.

Visit Website ↗ + Add to Compare
42/100Emerging / Unranked

Overview

Allgress builds an integrated governance, risk, and compliance (GRC) platform focused on giving organizations a business-context view of IT risk rather than a purely technical, control-by-control checklist. The platform centralizes risk assessments, control mapping across multiple regulatory and framework requirements (NIST, ISO, PCI, HIPAA, and similar), policy management, and vendor/third-party risk tracking, aimed at compliance and risk teams that need to reconcile overlapping framework requirements without maintaining separate spreadsheets or point tools for each one.

Founded by Jeff Bennett and Gordon Shevlin, with sources placing incorporation between 2006 and 2008, Allgress is headquartered in Dublin, California, in the San Francisco Bay Area. Bennett previously founded SiegeWorks and SiegeWorks International, which were acquired by FishNet Security in 2006. Allgress has operated as a privately held, self-funded company for most of its history, with no material outside venture funding disclosed, and remains a small vendor by headcount relative to larger, well-funded GRC platforms.

GRC is a mature, crowded category dominated by larger platforms (ServiceNow GRC, Archer, MetricStream, and others) with far greater scale and integration ecosystems. Allgress’s niche has historically been mid-market organizations that need practical, business-context IT risk management without the implementation overhead of enterprise-scale GRC suites, but its small size and lack of disclosed recent funding or major public product news limit how much independent evidence exists of current market traction.

Innovation Matrix Assessment

Innovation Velocity 3/10

Limited recent, independently verifiable public product-release news was found, consistent with a small, self-funded vendor that iterates quietly rather than publicizing a fast release cadence.

Operational Value 5/10

As an established, nearly two-decade-old platform, it has had time to mature its control-mapping and risk-assessment workflows, though as a small vendor its integration ecosystem is narrower than larger GRC suites.

Market Momentum 3/10

No material outside venture funding or recent high-profile customer wins were found in independent sources, indicating limited visible growth momentum relative to funded GRC competitors.

Category Disruption 3/10

Multi-framework IT GRC platforms are a well-established product category going back over a decade; Allgress's business-context approach to IT risk is a reasonable design choice rather than a novel technical or architectural departure from category norms.

Real-World Efficacy 5/10

Long operating tenure (nearly two decades) without disclosed major incidents or public customer complaints is a weak but real proxy for baseline reliability; no independent, named-customer outcome studies were found to substantiate specific efficacy claims.

Enduring Relevance 6/10

Organizations still need to reconcile overlapping compliance frameworks and manage IT risk in business terms, so the core GRC problem Allgress addresses remains relevant, even as larger platforms increasingly dominate enterprise budgets.

Why CISOs Should Care

Offers mid-market organizations a way to manage overlapping regulatory and framework requirements in one system and translate technical risk into business terms for leadership, without the cost and implementation overhead of enterprise-scale GRC suites.

What Makes It Different

Positions on translating IT risk into business context for a mid-market audience, rather than competing on the breadth of integrations and modules offered by large enterprise GRC platforms.

The Matrix Verdict

42/100 — EMERGING / UNRANKED

A long-tenured, self-funded niche GRC platform serving mid-market IT risk needs; it lacks the visible funding, scale, or independently reported momentum to be considered a category leader, but continues to operate in a segment still underserved by enterprise-focused competitors.

Editorial Note: Claims vs. Verified Findings

Founding details (with some source disagreement on the exact year), leadership background, and headquarters are independently reported (GRC 20/20 Research, Silicon Review, Crunchbase); no independently verified customer-outcome or funding data beyond these sources was found, so momentum and efficacy assessments rely on company tenure rather than quantified evidence.

Sources