See where you stand, continuously
Connect your environment once and let the platform gather the evidence. What can be established automatically should not be established by hand.
Connected environments
Eight integrations into the systems you already work with.
You connect your cloud environment, your code platform and your HR system through the vendor's own sign-in screen. You grant permission to look along there, and nobody shares a password with us. From that moment your environment is checked continuously and every finding shows which setting is off and which requirement it sits under. Revoking permission happens at the vendor, at any time, and you do not have to ask us for it.
The access we request is read-only. We never change anything in your environment, because that is not what this product is for. It also saves the conversation with your own administrator about what a compliance tool is allowed to do in production.
Statement of Applicability
The document your auditor starts with, and the most expensive one to maintain by hand.
The Statement of Applicability walks all one hundred requirements of ISO 27001:2022 and records per requirement whether it applies. Exclude one and the screen asks for the justification, which you can link to the risk that warrants it. Every requirement that does apply shows where its evidence comes from, either the measurement of your environment or an approved document of your own, and what is still missing.
Who made the decision and when is recorded alongside it, as is the edition of the standard that decision was made against. That last part sounds like a detail until a standard is revised. An auditor assesses you against the edition in force when your audit period started, and a statement with no edition attached cannot answer that question. The same setup applies to NIS2, DORA, NEN 7510 and GDPR.
Policy library
Which mandatory policies you actually have, and which exist on paper only.
The library names the policies the standards genuinely require, from the information security policy to the access control policy, and shows per policy whether a document is attached and whether that document is approved. A document that exists but is still a draft does not count as evidence, and you see that here before your auditor does.
Every policy carries a version and a review date. Once that date passes the document loses its standing as evidence and your coverage drops. That is intentional. A policy untouched for three years that still shows green is exactly the kind of paper compliance an audit sees through.
