Compliance frameworks, connected
Import the standards you answer to, map them to the controls you already run, and read your coverage straight from live data — no spreadsheet to rebuild before every audit.
Start free trialYour obligations, mapped to your controls
A compliance framework is any external standard, regulation, or internal policy you measure controls against. Bring those frameworks into the platform, map each requirement to the controls that address it, record how completely each one is covered, and your compliance posture becomes a live view drawn from current data — not a document someone rebuilds by hand the week before an audit.
Import a framework, don't build one
Frameworks come in by CSV — there's no requirement-by-requirement construction to grind through. Pick from a launch library of freely available standards — PCI DSS, NIST CSF, NIST 800-53, CIS Controls, Cyber Essentials, GDPR, and DORA — or upload your own file in the same format for anything else you hold a licence to, including ISO 27001, SOC 2, or your internal policies.
An imported framework is usable immediately — no activation step. Where a standard has multiple editions, they live side by side as separate frameworks, and you can hold more than one instance of the same standard under different names where that suits how you're structured.

The standard's words, plus yours
Requirements are displayed in a structured, grouped view — requirement group, sub-requirement, reference code, and title — so a long standard stays navigable. The imported text is immutable: what the standard says stays exactly as the standard says it, which is what an auditor expects to see.
Against each requirement you can record your own tenant interpretation — internal guidance that tells first-line users how you read it and what you expect a mapping to demonstrate. The source stays clean; your context sits alongside it.

Map to controls, with honest coverage
Map your controls to the requirements they address — a control can answer requirements across several frameworks, and a requirement can draw on several controls. Each mapping records a coverage level: full, partial, or planned, with optional notes to explain a gap. Coverage that is honest about "partial" and "planned" tells you far more than a binary tick.
Mapping is built for real catalogues: bulk-map many controls to one requirement, or one control to many requirements, in a single operation. Every mapping records who made it.

See your gaps, and report your position
Because coverage is structured data, the platform can show you exactly where you stand: which requirements have full coverage, which have only partial or planned coverage, and which have no mapped controls at all. An unmapped-requirements worklist gives compliance managers a clear list to work through instead of scanning a standard line by line.
From the same live mappings you generate a Statement of Applicability — coverage by level, control status, the lot — current the moment you run it. The audit answer comes from the data you already maintain, not a parallel document that drifts out of date.
Obligations in context
Controls
Mappings run on the controls you already maintain — their effectiveness and evidence are what your coverage claims rest on.
ControlsReporting
Coverage summaries and the Statement of Applicability turn your mappings into the report an auditor or a board asks for.
ReportingRisks
The same controls that satisfy your obligations are the ones mitigating your risks — one control library, two questions answered.
RisksOrganised by category, governed by permission
Frameworks live in a hierarchical category structure with role-based permissions. Framework-read governs who can view frameworks, requirements, and mappings; framework-write governs who can import, delete, map, and edit interpretations. Permissions inherit down the category tree, so a grant on a parent applies to everything beneath it.
There's no separate sign-off workflow to slow you down — governance comes from those category permissions, framework naming you control, and an audit trail that records who imported each framework, from what source, and when.