Enterprise

Hyperproof, a compliance and risk management startup, raises $40M

Comment

Cityscape with abstract light particles
Image Credits: Hiroshi Watanabe / Getty Images

Hyperproof, a software-as-a-service risk and compliance management company, today announced that it raised $40 million in a funding round led by Riverwood Capital with participation from Toba Capital, an early-stage VC firm.

The tranche brings Hyperproof’s total raised to $66.5 million and “doubles” the company’s valuation from nine months ago, according to co-founder and CEO Craig Unger.

“Although there’s been an economic slowdown, the pace of regulatory agencies passing new laws and ratifying new compliance regimes has only accelerated,” Unger told TechCrunch in an email interview. “For that reason, the compliance industry remains one of the more resilient industries in the tech space and is capturing significant investment and driving important innovation.”

To Unger’s point, there’s been a growing interest from the corporate sector in compliance as a service as new regulations — particularly data privacy regulations — come into force.

At least 25 U.S. states and Puerto Rico introduced or considered around 140 consumer privacy bills in 2023, according to the National Conference of State Legislatures. Meanwhile, the EU recently adopted the Cybersecurity Act, which imposes stricter requirements on businesses storing private data, and the U.S. Securities and Exchange Commission released new regulatory disclosure rules.

Most enterprises are attempting to build a culture of compliance in response. But they’re encountering roadblocks along the way. In a Deloitte survey, 61% of internal compliance teams said that recent increases in the level of regulatory change had had an adverse impact on their ability to perform their role effectively.

Unger, who previously worked for Microsoft developing Windows Live ID, the predecessor to Microsoft Accounts, said that he was inspired to found Hyperproof after dealing with “disruptive” audits that frequently halted his product development efforts. After Microsoft, Unger co-founded Azuqua, a small cloud integration and workflow startup, where he faced similar compliance issues: audits with spreadsheets containing hundreds of security and privacy questions that took hours to complete.

“Here were two contrasting companies — Microsoft, a powerhouse in the technology space, and Azuqua, a small startup — both facing the same error-prone, challenging processes that were universally reviled,” Unger said. “I thought, ‘How could we make compliance efforts simpler and faster?’”

So in 2018, Unger launched Hyperproof, which provides a system of record for compliance data coupled with a collaboration and work management system. Hyperproof seeks to automate “non-strategic” compliance tasks for around 85 compliance and governance frameworks, including FedRAMP, the U.S. federal government-wide compliance program for cloud services and products.

Hyperproof
Hyperproof’s compliance and policy monitoring dashboard. Image Credits: Hyperproof

In addition to controls that can be customized for individual frameworks, Hyperproof hosts several software modules designed to support different types of risk and compliance management work.

A risk management module enables teams to monitor risks in a central place, while a compliance operations module allows team members to automate the collection of evidence (i.e., documentation of compliance processes and outcomes) and to view which risks to mitigate issues. Another module, an audit management module, gives teams visibility into audit prep statuses and helps them map evidence from existing controls to audit requests. And a vendor risk management module automatically assesses third-party vendors’ risk profiles and potential impacts.

Hyperproof, which integrates with platforms such as AWS, Google Cloud, GitHub and Cloudflare as well as task management apps like Jira, Asana and ServiceNow, also leverages heuristics and AI to scale compliance and risk workflows, Unger says. Hyperproof’s algorithms and rules try to prevent duplicative work while “creating novel connections between the user data and compliance regimes that require this data,” he explained — ostensibly saving teams time and money.

“Enterprises in the past have taken two distinct paths,” Unger said. “The first is leveraging legacy solutions that are expensive, complex and take a year or longer to implement. The second is using a complex web of existing processes and infrastructure (on-prem or hybrid) along with massive spreadsheets that become impossible to manage. Both paths lead to siloed teams, taxing workflows and no true real-time visibility into an organization’s risk posture. That’s why companies are increasingly adopting flexible and scalable software-as-a-service platforms like Hyperproof that can scale to meet their diverse needs while increasing collaboration between teams and visibility across the organization.”

Now, Hyperproof isn’t the only player in the compliance software solutions market. Far from it. Analysts at Allied Market Research expect that the segment will be worth $3.06 billion by 2027, growing 15.7% from 2020.

It makes sense. A 2018 report from Globalscape revealed that the cost of not being compliant has risen by 45% from 2011 to 2018, with a dizzying average cost of $14.22 million for organizations that experience problems. The same report estimated that the cost of being compliant by using the right tools and training was actually 2.71 times the cost of being noncompliant.

Hyperproof’s rivals include Cypago, which offers tools to automate governance, compliance and risk workflows, and Osano, a data privacy management platform. There’s also Symmetry, which recently raised $18 million for its platform to bolster companies’ data security programs.

But the competition doesn’t appear to have slowed Hyperproof’s growth. The company’s customer base is 130% bigger than it was this time last year, driving its revenue to climb 260% year-over-year. Unger claims that “hundreds” of companies now use Hyperproof to optimize their risk and compliance workflows and mitigate risk, including Motorola, Nutanix and 3M.

“Hyperproof believes audits are crucial but to prepare appropriately, compliance and risk operations need to be implemented throughout the year so that controls are properly managed and tested well before audit time,” Unger said. “Organizations are concluding that their compliance work can be leveraged more broadly to understand and address the risk profiles of their businesses. . . . Hyperproof is a critical piece of a company’s infrastructure, enabling top-down visibility into organizations compliance commitments, progress, and communications.”

Unger says that the proceeds from the most recent tranche will be put toward expanding Hyperproof’s platform and growing its 100-person team, focusing on the areas of product development, customer success, marketing and engineering. On the business side, Hyperproof intends to expand its go-to-market activities into new verticals and locales and “amplify” its partnership efforts.

More TechCrunch

Google said today it’s adding new AI-powered features such as a writing assistant and a wallpaper creator and providing easy access to Gemini chatbot to its Chromebook Plus line of…

Google adds AI-powered features to Chromebook

The dynamic duo behind the Grammy Award–winning music group the Chainsmokers, Alex Pall and Drew Taggart, are set to bring their entrepreneurial expertise to TechCrunch Disrupt 2024. Known for their…

The Chainsmokers light up Disrupt 2024

Big news today for LumApps, the French startup that has described itself as an “intranet superapp” with a platform for building and provisioning internal communications and apps for workforces. The…

LumApps, the French ‘intranet superapp,’ sells majority stake to Bridgepoint in a $650M deal

Featured Article

More neobanks are becoming mobile networks — and Nubank wants a piece of the action

Nubank is taking its first tentative steps into the mobile network realm, as the NYSE-traded Brazilian neobank rolls out an eSIM (embedded SIM) service for travelers. The service will give customers access to 10GB of free roaming internet in more than 40 countries without having to switch out their own existing physical SIM card or…

4 hours ago
More neobanks are becoming mobile networks — and Nubank wants a piece of the action

Infra.Market, an Indian startup that helps construction and real estate firms procure materials, has raised $50M from MARS Unicorn Fund.

MARS doubles down on India’s Infra.Market with new $50M investment

Small operations can lose customers by not offering financing, something the Berlin-based startup wants to change.

Cloover wants to speed solar adoption by helping installers finance new sales

India’s Adani Group is in discussions to venture into digital payments and e-commerce, according to a report.

Adani looks to battle Reliance, Walmart in India’s e-commerce, payments race, report says

Ledger, a French startup mostly known for its secure crypto hardware wallets, has started shipping new wallets nearly 18 months after announcing the latest Ledger Stax devices. The updated wallet…

Ledger starts shipping its high-end hardware crypto wallet

A data protection taskforce that’s spent over a year considering how the European Union’s data protection rulebook applies to OpenAI’s viral chatbot, ChatGPT, reported preliminary conclusions Friday. The top-line takeaway…

EU’s ChatGPT taskforce offers first look at detangling the AI chatbot’s privacy compliance

Here’s a shoutout to LatAm early-stage startup founders! We want YOU to apply for the Startup Battlefield 200 at TechCrunch Disrupt 2024. But you’d better hurry — time is running…

LatAm startups: Apply to Startup Battlefield 200

The countdown to early-bird savings for TechCrunch Disrupt, taking place October 28–30 in San Francisco, continues. You have just five days left to save up to $800 on the price…

5 days left to get your early-bird Disrupt passes

Venture investment into Spanish startups also held up quite well, with €2.2 billion raised across some 850 funding rounds.

Spanish startups reached €100 billion in aggregate value last year

Featured Article

Onyx Motorbikes was in trouble — and then its 37-year-old owner died

James Khatiblou, the owner and CEO of Onyx Motorbikes, was watching his e-bike startup fall apart.  Onyx was being evicted from its warehouse in El Segundo, Los Angeles. The company’s unpaid bills were stacking up. His chief operating officer had abruptly resigned. A shipment of around 100 CTY2 dirt bikes from Chinese supplier Suzhou Jindao…

22 hours ago
Onyx Motorbikes was in trouble — and then its 37-year-old owner died

Featured Article

Iyo thinks its gen AI earbuds can succeed where Humane and Rabbit stumbled

Iyo represents a third form factor in the push to deliver standalone generative AI devices: Bluetooth earbuds.

22 hours ago
Iyo thinks its gen AI earbuds can succeed where Humane and Rabbit stumbled

Arati Prabhakar, profiled as part of TechCrunch’s Women in AI series, is director of the White House Office of Science and Technology Policy.

Women in AI: Arati Prabhakar thinks it’s crucial to get AI ‘right’

AniML, the French startup behind a new 3D capture app called Doly, wants to create the PhotoRoom of product videos, sort of. If you’re selling sneakers on an online marketplace…

Doly lets you generate 3D product videos from your iPhone

Elon Musk’s AI startup, xAI, has raised $6 billion in a new funding round, it said today, as Musk shores up capital to aggressively compete with rivals including OpenAI, Microsoft,…

Elon Musk’s xAI raises $6B from Valor, a16z, and Sequoia

Indian startup Zypp Electric plans to use fresh investment from Japanese oil and energy conglomerate ENEOS to take its EV rental service into Southeast Asia early next year, TechCrunch has…

Indian EV startup Zypp Electric secures backing to fund expansion to Southeast Asia

Last month, one of the Bay Area’s better-known early-stage venture capital firms, Uncork Capital, marked its 20th anniversary with a party in a renovated church in San Francisco’s SoMa neighborhood,…

A venture capital firm looks back on changing norms, from board seats to backing rival startups

The families of victims of the shooting at Robb Elementary School in Uvalde, Texas are suing Activision and Meta, as well as gun manufacturer Daniel Defense. The families bringing the…

Families of Uvalde shooting victims sue Activision and Meta

Like most Silicon Valley VCs, what Garry Tan sees is opportunities for new, huge, lucrative businesses.

Y Combinator’s Garry Tan supports some AI regulation but warns against AI monopolies

Everything in society can feel geared toward optimization – whether that’s standardized testing or artificial intelligence algorithms. We’re taught to know what outcome you want to achieve, and find the…

How Maven’s AI-run ‘serendipity network’ can make social media interesting again

Miriam Vogel, profiled as part of TechCrunch’s Women in AI series, is the CEO of the nonprofit responsible AI advocacy organization EqualAI.

Women in AI: Miriam Vogel stresses the need for responsible AI

Google has been taking heat for some of the inaccurate, funny, and downright weird answers that it’s been providing via AI Overviews in search. AI Overviews are the AI-generated search…

What are Google’s AI Overviews good for?

When it comes to the world of venture-backed startups, some issues are universal, and some are very dependent on where the startups and its backers are located. It’s something we…

The ups and downs of investing in Europe, with VCs Saul Klein and Raluca Ragab

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. OpenAI announced this week that…

Scarlett Johansson brought receipts to the OpenAI controversy

Accurate weather forecasts are critical to industries like agriculture, and they’re also important to help prevent and mitigate harm from inclement weather events or natural disasters. But getting forecasts right…

Deal Dive: Can blockchain make weather forecasts better? WeatherXM thinks so

pcTattletale’s website was briefly defaced and contained links containing files from the spyware maker’s servers, before going offline.

Spyware app pcTattletale was hacked and its website defaced

Featured Article

Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Synapse’s bankruptcy shows just how treacherous things are for the often-interdependent fintech world when one key player hits trouble. 

3 days ago
Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Sarah Myers West, profiled as part of TechCrunch’s Women in AI series, is managing director at the AI Now institute.

Women in AI: Sarah Myers West says we should ask, ‘Why build AI at all?’