Iru SOC 2 compliance software
Iru is Kandji's October 2025 expansion into an integrated IT and security platform. Compliance Automation covers controls, tasks, policies, evidence, auditor roles, and Trust Center—not just endpoint telemetry—but it had less than a year of public production history as of this review.
Rebranded from Kandji to Iru on October 22, 2025 (company newsroom).
By Peter Korpak, Lead Editor · independently researched · Methodology
- Pricing
- Quote-based
- Source-checked frameworks
- 11
- Integrations
- Unknown is not zero. Connector usefulness depends on the artifacts, permissions, source retention, and collection interval for the buyer's stack.
- G2 (2026-09-18)
- 4.7 · 853 reviews
Native Iru Endpoint and Workforce Identity telemetry is the main SOC 2 evidence differentiator. Expert Insights found no native vendor-risk, supplier-assessment, or risk-scoring workflow as of September 2026, and Iru's public Compliance lineup does not advertise one. The visible G2/Capterra corpus is dominated by endpoint/MDM experiences rather than Compliance Automation.
In July 2024, Kandji announced $100M in financing—$50M Series D equity plus $50M in go-to-market financing—at an $850M valuation. Total funding is reported at roughly $288M including that round.
What Iru does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Iru says Adaptive integrations collect artifacts, validate relevance and staleness, and map evidence to controls. Native Iru endpoint and identity telemetry can also supply evidence. Source |
| Auditor workspace | Yes | Auditor and Compliance Auditor are restricted roles: they can generate automated artifacts, assess artifact relevance, and create, edit, or delete comments, but they cannot edit controls, connect sources, or upload or delete artifacts. Iru's access-level copy still labels them read-only for audit and review. Source |
| Trust center | Yes | Trust Center publishes certifications, reports, FAQs, and security posture, with private document access and NDA workflows. Source |
| Security questionnaire answering | Yes | Trust Center accepts uploaded security questionnaires and drafts answers from the Adaptive Evidence Map. Human review remains necessary before a customer response is sent. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Partial | The compliance product documents granular tenant and compliance-only RBAC. The reviewed public evidence does not establish the directory's complete SSO, SCIM, and RBAC bundle for Compliance. Source |
| SCIM 2.0 provisioning | Not established | Workforce Identity includes lifecycle functions, but the reviewed public Compliance evidence did not establish SCIM 2.0 provisioning for this product scope. |
| Continuous control testing | Yes | Iru says it continuously collects evidence and checks daily for technology or policy changes that may require control updates. Collection intervals can vary by source. Source |
| Native multi-framework support | Partial | Iru provides named framework libraries and reuses controls and evidence across programs. Public evidence reviewed here does not establish independent native tests for every listed framework. Source |
11 frameworks checked individually, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Iru documents tailored controls, tasks, automated evidence, and native endpoint and identity telemetry for SOC 2. An independent CPA still performs the examination and issues the report. Source |
| ISO 27001 | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| ISO 27701 | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| ISO 42001 | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| GDPR | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| HIPAA | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| NIST 800-53 | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| NIST 800-171 | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| NIST CSF | Vendor-claimed | Iru lists NIST CSF 2.0 in its current Compliance Automation framework catalog. Source |
| CMMC | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
| Cyber Essentials | Vendor-claimed | Listed in Iru's current Compliance Automation framework catalog. Source |
Iru uses quote-based pricing.
Getting a direct number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.
- Disclosure model
- Quote-based
- Sourced annual price
- None found
- Basis
- Estimate, 2026-09-18
Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.
Who actually issues the report.
Iru provides restricted Auditor and Compliance Auditor roles, control-linked evidence, lineage, timestamps, policy acknowledgements, and evidence export. Those roles can generate automated artifacts, assess relevance, and comment, but they cannot edit controls or upload or delete artifacts. Iru is the readiness and evidence system, not the licensed CPA firm that performs the examination and signs the SOC 2 report. Buyers should have their intended auditor test a representative evidence package before signing.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Iru is for, and who it is not.
Good fit
Mac-heavy or existing Iru environments where endpoint and identity telemetry should flow directly into SOC 2 controls and evidence without a separate MDM or IdP integration for that proof.
Poor fit
Organizations that need native vendor-risk management, supplier assessments, risk scoring, a long compliance-specific customer track record, public pricing, a self-service Compliance trial, or Windows feature parity with Mac, including behavioral EDR.
Typical buyer: Lean IT, security, or compliance teams—often existing Iru customers or Mac-heavy shops—that want endpoint management, workforce identity, compliance workflow, and customer assurance from one vendor..
Compare Iru with three alternatives.
- Comp AI Sponsored
An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.
-
Startups running one or two frameworks (e.g. SOC 2 plus HIPAA or ISO 27001) that want the fastest guided path to a first audit without per-user pricing or a large software bill.
-
A growing SaaS company that wants deep, well-documented connectors on a mainstream stack, values interface polish and G2-rated support experience, and plans to run more than one framework over time.
Sources
If a claim on this page is out of date, this is the list to re-check.
| Establishes | Source | Retrieved |
|---|---|---|
| $100M from General Catalyst ($50M equity + $50M debt); total funding over $288M including debt; valuation $850M (Jul 17, 2024). | TechCrunch Press | |
| Company wire: $100M from General Catalyst; $50M equity Series D and $50M go-to-market investment; valuation $850M. | GlobeNewswire / Kandji Press | |
| Kandji raised $100 million from General Catalyst on July 17, 2024: $50 million Series D equity and $50 million go-to-market investment, at an $850 million valuation. | Iru / Kandji Vendor docs | |
| Adaptive Compliance runs on a daily schedule, proposes control and action wording in a side-by-side diff, and applies nothing until an Admin or Compliance Admin approves. Approvals and rejections are recorded. | Iru product documentation Vendor docs | |
| Kandji is now Iru (Oct 22, 2025, Miami). Unifies identity, endpoint, compliance automation, and Trust Center. | Iru Vendor docs | |
| Independent coverage of Kandji→Iru rebrand and expansion to Windows/Android MDM (Oct 22, 2025). | Computerworld Press | |
| Dedicated SOC 2 compliance automation product page. | Iru Vendor docs | |
| Dedicated ISO 27001 compliance automation product page. | Iru Vendor docs | |
| Iru’s comparison page positions itself as unified endpoint, identity, and compliance versus Drata as a compliance-primary platform. | Iru Vendor docs | |
| Current Compliance Automation scope: tailored controls, tasks, Adaptive integrations, artifact relevance, daily Adaptive Compliance suggestions, policies and acknowledgements, auditor validation, Trust Center publishing, and the current framework catalog. | Iru Vendor docs | |
| Permission matrix for Compliance Admin, Collaborator, Employee, Auditor, and Compliance Auditor. Auditor and Compliance Auditor can generate automated artifacts, assess relevance, and comment, but cannot edit controls, connect sources, or upload or delete artifacts. | Iru product documentation Vendor docs | |
| Trust Center publishing, private document and NDA flows, and AI-assisted security-questionnaire drafting from the evidence map. | Iru Vendor docs | |
| Quote-based annual billing, included onboarding and migration support, and demo-only evaluation for Compliance rather than the standard self-service trial. | Iru Vendor docs | |
| Independent September 2026 hands-on evaluation of Endpoint, Identity, and Compliance. Reports fewer Windows management options; Windows behavioral EDR, automatic quarantine, and device isolation planned for early 2027; no native vendor-risk, supplier-assessment, or risk-scoring workflow; an Iru-wide 50-license minimum in blocks of 25; and Compliance under $15,000 per year. Confirm pricing in Iru's written quote. | Expert Insights Editorial | |
| 4.7 out of 5; 853 reviews captured on the seller page on 2026-09-18 (another G2 surface showed 854). The visible corpus is dominated by endpoint/MDM/EDR experience, with little public review evidence isolating Compliance Automation. | G2 Review platform | |
| 4.9 out of 5 across 493 reviews, primarily establishing broader Iru/Kandji endpoint usability, support, and Mac-management experience rather than Compliance Automation maturity. | Capterra Review platform | |
| Iru states that its own service holds SOC 2 Type 2 (the security page also uses the heading SOC 2 Type II) and ISO 27001 assurance; buyers can request the current reports under NDA. | Iru Vendor docs | |
| Current subprocessor disclosure includes AWS and AI providers OpenAI, Anthropic, xAI, and Arize; public disclosure alone does not establish feature-level retention, training, or residency terms. | Iru Vendor docs |
← All SOC 2 compliance software · Iru review · How we verify
2 facts on this page we could not establish.
Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Iru, send us the sources and we will fill them.
Verification is free and always will be. It does not change where Iru appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the sources list above alongside the date.