Software stack audit for SMBs

Find duplicate SaaS tools and evidence gaps before your next audit.

Upload a software inventory CSV. StackGaps flags overlapping tools, missing vendor evidence, and the next actions your team can take before renewals or customer security reviews.

OKNo credit cardOKNo integrations requiredOKPDF report included

Sample scan

Q3 software inventory.csv

Complete

Overlap candidates

4

Zoom, Meet, Teams, and Webex in one stack

Evidence coverage

78

Published vendor evidence, scored out of 100

Missing documents

11

DPA, BAA, SOC 2, and ISO evidence to request

ToolIssueNext step
ZoomOverlapReview Meet
DropboxSOC 2 partialRequest report
LastPassRisk reviewAssign owner

Framework coverage

GDPR84/100
SOC 271/100
SOX66/100

Built for

20-250 employee teams

Input

Any clean software CSV

Checks

Overlap and evidence posture

Output

Dashboard, PDF, and share link

What StackGaps improves

A serious review workflow, not a flashy dashboard.

The first scan should answer three useful questions: what are we paying for twice, which vendors need evidence, and what should we do next?

Duplicate software detection

Find the tools doing the same job.

Industry-wide, roughly half of purchased software licenses go unused — StackGaps groups your inventory by category and vendor so IT, finance, and operators can review overlap candidates and see your own stack's estimated cost before renewals turn into automatic waste.

  • Collaboration, storage, identity, HR, CRM, security, and more
  • Vendor-normalized names from messy CSV exports
  • Plain-English overlap reasons for non-technical reviewers
ZoomVideo meetingsGoogle Meet
DropboxCloud storageOneDrive
AsanaProject trackingJira

Compliance evidence gaps

See which vendors need follow-up.

The score is a coverage signal, not a legal opinion. It helps your team identify which vendors have published evidence and which ones need a document request before an audit or customer review.

  • GDPR, SOC 2, ISO 27001, SOX, and FedRAMP signals
  • Confidence and unknown states kept visible
  • Vendor email drafts for document requests

Okta

SOC 2

Documented

HubSpot

DPA

Needs request

Figma

ISO 27001

Unknown

Audit-ready reporting

Turn a CSV into a decision packet.

Download a PDF, share a read-only scan link, and keep the next action visible so the review does not disappear into a spreadsheet thread.

  • PDF report included on every plan
  • Action Center for owners and next steps
  • Shareable scan workspace for stakeholders

PDF report

Executive summary

Pricing

Start with one review. Upgrade when the workflow becomes routine.

Plans stay aligned with the product limits in the app. Paid checkout is available through the upgrade flow when billing is enabled.

Free

$0

Forever free

Evaluate the full workflow with your own inventory.

  • Yes1 scan per month
  • Yes1 compliance framework per scan
  • YesOverlap candidate detection
  • YesPDF report download
  • YesScan history
  • NoAll 5 frameworks in one scan
  • NoUnlimited scans
  • NoTeam seats (single user only)
Start scanning

Starter

Most popular

$99

per month

Unlimited scans with every framework covered.

  • YesUnlimited scans
  • YesAll 5 frameworks per scan (GDPR, SOC 2, ISO 27001, SOX, FedRAMP)
  • YesOverlap candidate detection
  • YesFull PDF report download
  • YesComplete scan history
  • YesAction Center with prioritized tasks
  • Yes3 team seats
  • NoRenewal calendar & Readiness Score
  • NoPriority support
Choose Starter

Pro

$249

per month

For teams that assign owners and track decisions together.

  • YesEverything in Starter
  • Yes10 team seats & member management
  • YesGovernance & ownership tracking
  • YesRenewal calendar & Readiness Score (included)
  • YesFramework readiness guides
  • YesReferral program access
  • YesPriority support
  • YesEarly access to new frameworks
Choose Pro

Want help setting up your register?

Send your software list and get a founder-assisted cleanup with owners, renewals, overlap findings, and vendor evidence gaps.

Software Stack Cleanup Audit

FAQ

Clear claims for a compliance product.

StackGaps helps your team organize evidence and decisions. It does not replace legal review, an audit, or vendor contract diligence.

Is my software inventory stored securely?+

Yes. Data is encrypted in transit and at rest, and organization data is isolated so one customer cannot access another customer's scans.

What counts as a scan?+

One CSV upload analyzed end to end counts as one scan. Free includes 1 scan per month; Starter and Pro are unlimited.

Which frameworks do you check?+

GDPR, SOC 2, ISO 27001, SOX, FedRAMP readiness signals. StackGaps surfaces vendor evidence coverage and unknowns, not legal advice or certification.

Do I need integrations?+

No. Phase 1 works from a CSV export so you can get a useful first review without agents, admin permissions, or long setup.

Turn your next software export into an action list.

Start with a CSV, then review overlaps, evidence gaps, owners, and report exports from one workspace.