We turn the compliance spreadsheet into evidence that carries a date.
Your client answers to a regulator, and the answer has to be in a document someone signs. 93 ISO/IEC 27001:2022 controls, 47 SOC 2 criteria and 90 OWASP SAMM v2 activities come loaded in the product. Those are catalogues, not certifications — we hold neither ISO 27001 nor SOC 2, and there is no certification process open.
Three behaviours that change the number your client reads
None of the three is a feature name. Each is a behaviour that moves a figure someone will be audited on.
- 93ISO/IEC 27001:2022A compliance catalogue included in the product — not a certification we hold.
- 47SOC 2Audit-ready control coverage to work against. There is no auditor report to attach.
- 90OWASP SAMM v2Maturity assessment built in.
Those are catalogues, not certifications — we hold neither ISO 27001 nor SOC 2, and there is no certification process open.
The part of compliance that lives in a spreadsheet today
I need the framework already loaded
ISO/IEC 27001:2022 with 93 controls, SOC 2 with 47 criteria and OWASP SAMM v2 with 90 activities come in the product. These are catalogues to work against, not certifications we hold.
I need each client separate, with their own history
One record per client company, each with its own assessment history, score and reports. The questionnaire changes with the client profile, and the score is computed in code.
I need the report without writing it from scratch
The executive report comes out drafted, in six fixed sections: summary, risks by impact, what is in good shape, and a 90-day plan, as a PDF. You review, correct and sign — you do not write it from zero.
Measured against your process today, not against a competitor
| Step | Your process today | With the platform |
|---|---|---|
| Collecting evidence | By hand, file by file, before every audit | Collected from the scan and the hardening, with an expiry date |
| Linking a technical finding to a control | Someone decides from memory, and the decision is not written down | Suggested by keyword with the confidence recorded; you confirm or reject |
| Evidence past its validity | Stays in the spreadsheet as if it still counted | Stops supporting the control |
| Saying how compliant the client is | One percentage, mixing assessed with compliant | Two separate numbers on the screen |
| The final report | Written from scratch, every time | Already drafted; you review and sign |
What we do not do
Every limit below was read in the code before it was written here, and it is in writing before the proposal, not after it.
Three catalogues were checked. Three others were not.
ISO/IEC 27001:2022, SOC 2 and OWASP SAMM v2 were counted item by item. CIS, CSA and NIST CSF exist in the code with fewer items than their own documentation promises, so they are not on this page. A control map for a local data-protection law or a banking regulation has not been checked in the source — when it has, it will appear here with the number.
We organise and evidence. We do not certify.
The platform does not guarantee compliance and does not "meet a requirement". The match between finding and control is by keyword, with the confidence recorded: it suggests, it does not classify. The opinion is signed by you.
White label does not exist
The report carries our brand in the header and footer of every page. Changing it takes a code change and a rebuild.
PDF only, and no portal for your client
No Word, no Excel. And there is no portal where the company you assess logs in to see its own risk: what it gets is the document you send.
The platform is not live yet
Infrastructure is being rebuilt. There is no signup, no trial and no billing.
Tell us which framework your client is audited against and we will tell you what is loaded.
If the answer is a catalogue that has not been counted yet, we will say so in the conversation.