Two ways to run the same core.
Neither is the "real" TruSecure and the other a lesser version — the same core, aimed at two different operating models.
The actual difference: who operates it
Community Edition is for organizations whose operating model is "we run it": your infrastructure, your inference endpoint, your upgrade cadence, your people on call for it. TruSecure GRC is for organizations whose operating model is "it runs": TruSecure operates the platform, maintains the private inference layer, updates the packs as regulations move, and carries the SLA. The core workflows — the control library, the mapping, the evidence, the audit trail — are the same artifacts in both.
That is also why the path between them is a change of operating model rather than a migration: the control model you built self-hosted describes the same reality under management. What changes is who does the operational work — and what the accountability table above shows is exactly which responsibilities move with it.
How to choose in one paragraph
If you have the platform capability and the data-control requirements to match, self-host — the real core ships, and nothing in it phones home. If your constraint is people rather than perimeter, or your buyers require a managed service with dedicated SLAs and board-grade accountability reporting, TruSecure GRC is the fit. And if you start on one and the answer changes, the other side is a conversation, not a rebuild.
| Feature | Community Edition | TruSecure GRC |
|---|---|---|
| Core workflows | Included — the real thing | Same core, plus continuous updates |
| AI inference | You choose the provider | Proprietary private inference |
| Hosting | Self-hosted | Fully managed SaaS |
| Support | Community / Paid Enterprise | Dedicated SLAs |
| Board accountability | Not included | Included |