RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Visitor log + physical-security assessment + compliance evidence in one tenant.
Summary
RiskWatch ships a risk-and-compliance platform built around pre-mapped control libraries for 40+ frameworks. The visitor-management workflow is one module inside the platform: visitor sign-in, photo capture, NDA acceptance, host notification, badge print, escort tracking, watchlist screening, and evacuation muster reporting are tied to the same tenant as the SOC 2 CC6.4 Physical Access evidence, ISO 27001 A.7 physical-controls assessment, HIPAA 164.310 facility access controls, and ITAR 22 CFR 120-130 visitor-log retention. Customers include state governments in all 50 US states, healthcare networks, defence contractors, and financial-services holding companies. Single-tenant deployment with customer-owned data residency makes it the fit for ITAR + CMMC + HSPD-12-shaped regulated facilities that need a 5-year-plus visitor-log retention term.
Strengths
- Visitor log lives inside the same tenant as SOC 2 CC6.4 Physical Access evidence, ISO 27001 A.7 physical-controls assessment, HIPAA 164.310 facility access controls, and ITAR 22 CFR 120-130 deemed-export visitor screening; auditors see one source of truth
- Pre-mapped frameworks include SOC 2 + ISO 27001 + HIPAA + ITAR + EAR + NIST 800-53 (PE family) + NIST 800-171 r3 + CMMC 2.0 + NERC CIP + FFIEC + 30 more; the same evidence satisfies multiple physical-security audits
- Evacuation muster reporting ships as a first-class feature: one-tap export of every person on site with last-known location, defensible under OSHA General Duty Clause and ASIS WVPI 2020
- Single-tenant deployment with customer-owned data residency and configurable retention (5 years for ITAR, 6 years for HIPAA, custom for SOC 2); SaaS-first vendors default to 12-month log purges that fail ITAR audits
- Escort tracking + dual-control workflow for ITAR-controlled areas and HIPAA-restricted zones; visitor badge ties to the host's responsibility chain
- 33-year operating history with federal customers (US Department of Defense, VA, DOJ, NSA per public press); the visitor-log chain-of-custody survives federal audit
- Watchlist screening against OFAC SDN, denied-parties lists, and customer-uploaded persona-non-grata lists at sign-in
Weaknesses
- Not a kiosk-first iPad experience at Envoy or The Receptionist polish; the visitor sign-in flow works but does not match the Apple-Wallet-badge consumer aesthetic that office-experience leads expect
- Pure-play VMS competitors (Envoy, Sine, Greetly, iLobby) still win on workflow polish and out-of-the-box integration count for the office-HQ use case; RiskWatch is the right pick when visitor management is one of several compliance workflows, not when it is the only one
- Public pricing is partial above Professional (we publish Standard $99/month and Professional $36K/year; Enterprise is quote-only)
- Brand awareness on G2 / Capterra in the visitor-management cohort specifically is lower than Envoy or iLobby; total third-party review volume in this category sits below 100
- Smaller native-integration count than Envoy or Proxyclick for collaboration tools (Slack, Microsoft Teams, Apple Wallet); slack and Teams integrate via REST and Zapier rather than first-class apps
- Mobile pre-registration UX is functional but not a polished consumer app at Envoy or Proxyclick standard
Regulated mid-market and enterprise facilities (ITAR contractors, SOC 2 SaaS, HIPAA hospitals, federal contractors, utilities under NERC CIP) that need visitor compliance plus the broader physical-security and compliance platform in one tenant.
Office-HQ buyers whose only brief is a polished iPad kiosk with Slack pings and Apple Wallet badge; Envoy or The Receptionist fits that brief better.
Key features
- Visitor sign-in with photo capture, NDA acceptance, host notification, and badge print
- Evacuation muster reporting with one-tap export of every person on site
- Escort tracking and dual-control workflow for ITAR + HIPAA restricted zones
- Watchlist screening (OFAC SDN + denied-parties + customer persona-non-grata)
- Pre-mapped frameworks: SOC 2 CC6.4 + ISO 27001 A.7 + HIPAA 164.310 + ITAR + EAR + NIST 800-53 PE + CMMC 2.0 + NERC CIP
- Contractor pre-registration and induction workflow
- Vehicle visitor screening with plate capture
- Configurable retention (5+ years for ITAR, 6 years for HIPAA)
- Single-tenant deployment with customer-owned data residency
- Audit-ready export to PDF + CSV with chain-of-custody
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU