On this page
- Iru Pros and Cons for SOC 2
- Is Iru the Same Company as Kandji?
- What Do You Actually Buy With Iru Compliance?
- Where Can Iru Enforce a Control and Produce Its Evidence?
- How Does Iru’s SOC 2 Workflow Work?
- Does Iru Include Vendor Risk Management?
- What Do Iru G2 Reviews Actually Measure?
- How Much Does Iru Compliance Cost?
- Iru vs Vanta, Drata, and Secureframe: Which for SOC 2?
- How Should You Proof Iru Before You Buy?
- Is Iru Worth Shortlisting?
- Frequently Asked Questions About Iru
Our verdict: Iru belongs on a SOC 2 shortlist when endpoint management, identity, and compliance evidence can be one buying decision, especially for a Mac-heavy team or an existing Iru customer. Iru can enforce device and identity controls and attach that state to evidence without polling a separate MDM or IdP for the same proof. G2 and Capterra scores still mostly reflect endpoint products, not Compliance Automation. Skip it when you need a native vendor-risk module, a public Compliance rate card, or a longer compliance-specific review corpus.
Who this is for: Security, IT, and compliance leaders deciding whether to buy endpoint, identity, and SOC 2 evidence from one vendor. This is a SOC 2 product review, not an employer review or a Kandji-only MDM review.
Best alternatives: Vanta or Drata for a longer compliance-specific history, and Secureframe or a broader GRC tool when vendor risk has to live in the same platform. Category context is in the SOC 2 software guide.
Iru is Kandji after the October 22, 2025 rebrand. The Apple endpoint product now sits inside a platform that also includes Workforce Identity, EDR, Vulnerability Management, Compliance Automation, and Trust Center. The SOC 2 workflow is framework, control, task, and evidence, in a console separate from MDM.
Iru Pros and Cons for SOC 2
Iru can enforce endpoint and identity controls and attach the resulting state to SOC 2 evidence. Your team still remediates failures, and an independent CPA still performs the examination.
Key Strengths (Pros)
- Native endpoint and identity evidence: Iru can enforce FileVault, device configuration, access, vulnerability, malware, and incident controls and feed the resulting state into Compliance. A separate platform normally polls another MDM or identity provider for the same proof.
- Evidence stays attached to the control: Iru documents control-linked artifacts, relevance checks, timestamps, lineage, tasks, comments, history, and restricted auditor roles. An auditor can see where an artifact came from and when; a folder of undated screenshots cannot.
- Human-approved control updates: Adaptive Compliance runs on a daily schedule, proposes control and action edits in a side-by-side diff, and records the decision. Iru documents that nothing changes until an Admin or Compliance Admin accepts the proposal.
- Policies, Trust Center, and questionnaires use the same evidence model: Policy drafts, acknowledgements, Trust Center documents, and questionnaire drafts can sit on the same controls and artifacts.
- Mac management has the longer track record: G2, Capterra, and the Kandji product history describe Apple management, usability, and support as strengths.
Key Limitations (Cons)
- Compliance Automation is young: It launched with Iru’s platform expansion on October 22, 2025.
- No advertised vendor-risk workflow: Expert Insights’ September 2026 evaluation found no native vendor-risk, supplier-assessment, or risk-scoring workflow, and Iru’s current public Compliance lineup does not advertise one.
- Windows trails Mac on specific controls: The same independent review found fewer Windows management options. Behavioral EDR, automatic quarantine, and device isolation were not available on Windows and were reported as planned for early 2027.
- G2 and Capterra scores describe endpoint products: The visible corpus is dominated by MDM and endpoint experience. There is little public review evidence that isolates Compliance Automation.
- Price is quote-only and Compliance is demo-led: Iru publishes no Compliance rate card. Several other Iru products get a 14-day trial; Compliance Automation and Trust Center do not.
- Iru does not issue the SOC 2 report: A SOC 2 Type 2 is an examination engagement under AICPA attestation standards. An independent CPA firm still scopes, examines, and signs the report.
Iru at a Glance
- Category and origin: Integrated endpoint, identity, and multi-framework compliance platform. Rebranded from Kandji on October 22, 2025. In July 2024, Kandji announced $100M in financing ($50M Series D equity plus $50M in go-to-market financing) at an $850M valuation. Total funding is reported at roughly $288M including that round.
- Testing: Vendor-claimed continuous evidence collection, with a daily Adaptive Compliance check for technology or policy changes. Collection intervals can vary by source. We did not independently measure those intervals.
- Dated review aggregates: G2 4.7/5 from ~850 reviews and Capterra 4.9/5 from 493 reviews on September 18, 2026. Gartner Peer Insights showed 4.3/5 across 29 ratings in Endpoint Management Tools.
- Plans and spend: Quote-only. Iru says pricing depends on products plus user or device quantities, and contracts are annual. Third-party reported figures are in the pricing section.
- Audit: The subscription does not include a CPA opinion. Iru documents restricted auditor roles and control-linked evidence.
Is Iru the Same Company as Kandji?
Yes. Iru is Kandji after the October 22, 2025 rebrand. The Apple endpoint product continues inside the Iru platform. Compliance Automation is a newer native application, not a rename of Kandji MDM.
That split is why “Iru review” results often describe the MDM product. Endpoint reviews, vendor pages, and employer listings dominate the result set. They tell you whether Iru can manage Macs, not whether Compliance Automation is ready for a SOC 2 program.
What Do You Actually Buy With Iru Compliance?
You buy a compliance workspace that can sit on top of Iru Endpoint, Workforce Identity, EDR, and Vulnerability Management, or collect evidence from external systems. The homepage shows one platform. The quote is a bundle of products, user or device quantities, and a Compliance demo.
| What you need | What Iru can sell | What still sits outside the product |
|---|---|---|
| Mac or mixed-fleet endpoint enforcement | Endpoint Management, EDR, and Vulnerability Management | Windows behavioral EDR, automatic quarantine, and device isolation, which Expert Insights reported as planned for early 2027 |
| Workforce identity and access state | Workforce Identity, with evidence that can flow into Compliance | Native SCIM for the Compliance product remains unknown in the current record |
| SOC 2 controls, tasks, evidence, and auditor review | Compliance Automation, including Adaptive Evidence Map and restricted auditor roles | A native vendor-risk workflow in the current public lineup; the CPA examination |
| Customer-facing assurance | Trust Center publishing and questionnaire drafts | Human review before a customer response is sent |
Sources: Iru product pages and the Iru software record, retrieved September 18, 2026. A product card is not a quoted bundle.
Iru’s pricing FAQ says Compliance Automation can migrate frameworks, requirements, and controls from Vanta, Drata, Sprinto, or Secureframe. Confirm in the demo which historical artifacts, mappings, and exceptions actually move.
Where Can Iru Enforce a Control and Produce Its Evidence?
Iru can skip a separate MDM or IdP poll when it is also the system that enforces the control. Most compliance products sit above the operational stack and pull the same proof from another tool.
| Layer | Examples | What Iru can do | What it does not prove |
|---|---|---|---|
| Native Iru enforcement | Disk encryption, device configuration, identity lifecycle, authentication, vulnerability and endpoint threat controls | Enforce or observe the state and place supporting telemetry in the evidence model | That the control is suitably designed or operated for the whole audit period |
| External evidence sources | AWS, Okta, Entra ID, GitHub, HR, ticketing, monitoring, and data systems | Collect artifacts through configured connectors and map them to controls | Complete API coverage, correct permissions, sufficient retention, or zero collection failures |
| Buyer-owned work | Risk decisions, contracts, board approvals, remediation, incident exercises, and management review | Assign tasks, hold documents, record comments and history, and track completion | That the underlying work was performed well |
| Independent examination | Scope, samples, exceptions, testing, opinion, and signed SOC 2 Type 2 report | Give the CPA a restricted auditor view of evidence and actions | Iru cannot act as the independent service auditor or issue the report |
Sources: Iru's SOC 2 solution page, Compliance Automation page, and current permissions documentation, retrieved September 18, 2026. Capability does not replace CPA judgment.
Consolidating enforcement and evidence also concentrates that data with one provider.
- 01Enforce or connectIru Endpoint or Identity enforces the control, or an external connector collects the artifact.
- 02Map to a controlIru says the Adaptive Evidence Map identifies the artifact, checks relevance or age, and attaches it.
- 03Assign the ownerThe control owner gets the action, due date, comments, and history in a compliance inbox.
- 04Review driftAdaptive Compliance can propose a control edit after a source change; a person accepts or rejects it.
- 05Hand to the CPAA restricted auditor role and export are the input to the examination, not the opinion.
How Does Iru’s SOC 2 Workflow Work?
Iru’s documented workflow starts with a framework and company context, turns controls into owned actions, and attaches evidence from Iru products, connectors, or uploads. Iru AI can draft tailored controls. “AI generated the controls” is a starting point, not audit readiness.
The current product page and Adaptive Compliance docs say Iru AI reviews source and policy changes on a daily schedule, usually within 24 hours of the triggering activity, and proposes control or action wording in a side-by-side diff. Only an Admin or Compliance Admin can approve or reject the proposal. Scope, control owners, evidence periods, and the CPA’s testing plan still need human agreement.
Iru documents Auditor and Compliance Auditor as restricted roles for audit and review. They can generate automated artifacts, assess artifact relevance, and create, edit, or delete comments. They cannot edit controls, connect or disconnect sources, or upload or delete artifacts.
Iru’s connector docs name concrete limits:
- AWS CloudTrail uses a cross-account role and external ID. Standard
LookupEventscoverage is about 90 days; older history may require S3 access (s3:GetObject) and KMS permissions (kms:Decrypt) when trails use customer-managed keys. - Snowflake uses key-pair authentication and reads governance metadata from
ACCOUNT_USAGE; Iru says it does not query customer tables arbitrarily. - Jenkins can use a read-only service account scoped to relevant folders or views.
- Sentry coverage depends on the customer’s plan and permissions. A personal token can also break when its owner leaves.
Ask what artifact each connector collects, how often, with what retention, and how failure is surfaced. A logo count does not answer that.
Does Iru Include Vendor Risk Management?
Expert Insights found no native vendor-risk, supplier-assessment, or risk-scoring workflow as of September 2026, and Iru’s current public Compliance lineup does not advertise one. Trust Center publishes your assurance material for customers. It does not assess your suppliers.
If you need vendor inventory, supplier due diligence, and risk scoring in the same tool, shortlist Vanta, Drata, Secureframe, or a broader GRC product alongside Iru.
If you still buy Iru for native endpoint evidence, keep vendor inventory, diligence, and reassessment in a spreadsheet, a dedicated VRM tool, or another GRC system. Trust Center publishes your posture to customers; it does not run supplier risk.
What Do Iru G2 Reviews Actually Measure?
G2 showed 4.7/5 across ~850 reviews on September 18, 2026. The visible corpus is dominated by endpoint/MDM experience. There is little public review evidence that isolates Compliance Automation. That aggregate is not a SOC 2 product score.
One September 2026 G2 review described using FileVault, recovery-key state, and EDR deployment as audit evidence. G2 labels it seller-invited and incentivized. That is one found example, not a claim that it is the only SOC 2-relevant review. We do not use the 4.7 as a rating for Iru Compliance.
How Much Does Iru Compliance Cost?
Iru does not publish a standard Compliance Automation price. Iru’s pricing page says pricing depends on the products you pick plus user and device quantities. Contracts are annual. Onboarding and migration support are included.
| Reported figure | Scope in that review | How to use it |
|---|---|---|
| Under $15,000 per year | Compliance specifically | Quote context only; confirm applicability in writing |
| 50-license starting minimum, increases in blocks of 25 | Described as an Iru-wide pricing rule, not a Compliance-only rule | Ask whether it applies to the products on your quote |
Source: Expert Insights, September 17, 2026. Iru itself does not publish these figures. Confirm every quantity, increment, and discount in the written quote.
Iru’s pricing FAQ, retrieved the same day, says a free 14-day trial covers Workforce Identity, Endpoint Management, Vulnerability Management, and EDR. Compliance Automation and Trust Center are demo-led.
Request an itemized quote that splits Compliance Automation, Trust Center, frameworks, seats, Endpoint, Workforce Identity, EDR, Vulnerability Management, migration, support, renewal terms, and export rights.
Iru states that its service holds SOC 2 Type 2 and ISO 27001. The same page titles the report “SOC 2 Type II.” Request the current report, a bridge letter if needed, a penetration-test summary, and the ISO certificate rather than relying on the web statement. The current subprocessor list includes AWS and AI providers OpenAI, Anthropic, xAI, and Arize. Put artifact access, retention, training use, and processing region in the contract.
Iru vs Vanta, Drata, and Secureframe: Which for SOC 2?
Iru sells endpoint, identity, and compliance together. Run the same connector and auditor proofs in each product you shortlist.
| Buying situation | Shortlist direction | Reason |
|---|---|---|
| You already use Iru Endpoint, or are replacing Mac MDM and compliance software together | Iru | Native enforcement and evidence can drop a separate MDM or IdP poll for that proof and keep ownership in one place |
| You want a longer public compliance-product history | Vanta or Drata | Their compliance products have longer public histories; prove the exact connector and service differences for your stack |
| Vendor risk and supplier assessment are required in the same platform | Vanta, Drata, Secureframe, or broader GRC tools | Iru's current public Compliance lineup does not advertise those workflows |
| You intentionally separate endpoint enforcement from compliance assurance | Dedicated compliance platform | Keeping MDM and compliance in separate products may be worth the extra integration |
This is a buying-model comparison, not a claim that every competitor has every feature. Confirm current modules, evidence depth, service scope, and price in each quote. For the broader field, use the SOC 2 software guide and the compliance automation comparison.
How Should You Proof Iru Before You Buy?
Run these proofs on controls from your intended audit scope. Start with three to five if time is short. Follow each from the operational system to CPA review and record what stayed manual.
- Endpoint encryption: Show one Mac and, if relevant, one Windows device moving from state to artifact to mapped control.
- Joiner/leaver: Terminate a test identity and show the access state, evidence, owner, timestamp, and exception path.
- Cloud logging: Connect CloudTrail, show the collected configuration, then explain history older than the standard API window.
- Failed source: Revoke a test credential and show alerting, evidence freshness, ownership, and recovery history.
- Stale manual evidence: Upload an expired document and test identification, mapping, and replacement.
- Adaptive Compliance: Change source context and inspect the proposed control edit, approval gate, and audit history.
- Policy acknowledgement: Publish a policy, acknowledge it as an employee, and inspect the timestamped evidence as an auditor.
- CPA handoff: Give your intended auditor a restricted Auditor or Compliance Auditor role and export the complete package they would retain.
- Questionnaire: Upload a real customer questionnaire, inspect source grounding, and confirm that a human approves the response.
- Offboarding: Export controls, mappings, artifacts, tasks, comments, policy history, and Trust Center material in a usable format.
Do this before contract signature. A product-page “auditor validation” claim does not mean your CPA accepts the workflow.
Is Iru Worth Shortlisting?
Yes, when native endpoint and identity enforcement is part of the buy. Iru fits a lean, Mac-heavy team that can replace MDM, identity, or compliance tools it was already buying. Run the proof of concept before you sign.
When Iru Is a Strong Fit
- You already use Iru Endpoint, or you are replacing Mac MDM and compliance software together.
- You want FileVault, device configuration, identity, and EDR evidence in one data model.
- You can live with quote-only Compliance pricing and a demo-led buy.
When to Consider Iru Alternatives
- Compliance software is the only purchase, and you want a longer public compliance-product history: Vanta or Drata.
- Vendor risk and supplier assessment have to live in the same platform: Vanta, Drata, Secureframe, or a broader GRC tool.
- Windows is the dominant fleet. Repeat every required endpoint control on Windows, including behavioral EDR.
When to Skip Iru
- You need a numeric Compliance rate card on the marketing site today. Iru does not publish one.
- Third-party risk has to live in the same platform, and you will not run a second vendor-risk process.
- You expect Iru to issue the SOC 2 report. Iru cannot issue it.
Category context is in the SOC 2 software guide.
Frequently Asked Questions About Iru
Is Iru the same as Kandji?
Yes. Iru is Kandji after the October 22, 2025 rebrand. The Apple endpoint product continues. Compliance Automation is a separate application launched with that expansion, not a new name for MDM.
Do Iru’s G2 scores cover Compliance Automation?
No. G2’s 4.7/5 across ~850 reviews on September 18, 2026 sits on an endpoint-dominated corpus. This review found one seller-invited, incentivized FileVault/EDR review. That is not a Compliance Automation sample.
Does Iru include vendor risk management?
Expert Insights found none as of September 2026, and Iru’s public Compliance lineup does not advertise vendor-risk, supplier-assessment, or risk-scoring workflows. Trust Center publishes your assurance material; it does not assess your suppliers.
How much does Iru Compliance cost?
Iru does not publish a numeric Compliance rate card. Pricing depends on products plus user or device quantities, and contracts are annual. Expert Insights reported Compliance under $15,000 per year and an Iru-wide 50-license minimum in blocks of 25. Confirm both in an itemized quote.
Will an auditor accept Iru evidence?
The auditor decides. Iru’s Auditor and Compliance Auditor roles can generate automated artifacts, assess relevance, and comment, but they cannot edit controls or upload evidence. Invite the intended CPA to inspect a representative export before you sign. Iru cannot issue the SOC 2 report.
Is Iru a good fit for a Windows-heavy company?
Only after a proof of concept. Expert Insights reported fewer Windows management options as of September 2026. Behavioral EDR, automatic quarantine, and device isolation were not available on Windows and were planned for early 2027.
Iru vs Vanta: which for a SOC 2 program?
Iru fits when native endpoint and identity enforcement is part of the buy. Vanta’s dated record has a longer compliance-specific history and a much larger G2 sample.
Is this a review of working at Iru or Kandji?
No. This page reviews Iru Compliance Automation for SOC 2. Employer-review listings for Iru or Kandji are a different search.
More in Compliance Tools