Loading AuditFlow…
For startups and scaling teams
Answer the security questions a buyer asks — and keep the answers true after the deal closes.
Framework readiness across 35 frameworks — SOC 2, ISO 27001, the DPDP Act, GDPR, ISO 42001 and more — computed from your own records, with the evidence, the Statement of Applicability, the Trust Center and the questionnaire library beside it. It is the compliance and audit layer. It is not a security tool, and the page says what that means below.
Where you are
Each stage below names modules that ship today, and the plan each one is on.
The first enterprise prospect sends a security questionnaire and asks for your policies. There is no security team; there is a founder with a deadline.
A deal is conditional on SOC 2 or ISO 27001. You need to know what is missing, hold the evidence in one place, and give an auditor something to work from.
Personal data in more than one jurisdiction, AI in the product, more vendors than anyone can name, and access that has grown by accretion.
An illustrative plan
Steps the product supports, in the order teams usually take them. It is not a promise of a certificate on a date — whether and when a report or certificate is issued is your auditor's decision, and a SOC 2 Type II report covers an observation period you agree with them.
Weeks 1–2
Adopt the frameworks a buyer has asked for. Readiness lists every requirement and resolves each one from what your workspace already holds; the rest is the gap, by name.
Growth and above
Weeks 2–4
Scope, context, interested parties, roles and objectives, then a decision and a justification for each Annex A control on the Statement of Applicability.
Growth and above
Weeks 3–6
Each policy keeps its version history, and each member's acknowledgement is recorded with who and when. Training completions sit beside it.
Every plan
Weeks 4–8
Upload the artefact — the access review export, the backup test, the penetration-test report you commissioned — and link it to every control it evidences. It stops counting on the date it stops being evidence.
Growth and above
Weeks 6–10
Each of the 35 frameworks ships an internal-audit questionnaire with every question carrying the clause it evidences. A failed answer becomes an action item with an owner and a due date.
Every plan
Weeks 8–12
Review against the inputs the standard requires and record the decisions. Then open an engagement for your external auditor, who raises requests on the prepared-by-client list and you answer them against the evidence you already hold.
Growth / Scale
What you get
A plan label is the cheapest plan that includes the module; every plan above it includes it too.
35 frameworks, including SOC 2 (61 criteria), ISO 27001 (93 Annex A controls), DPDP Act (19), GDPR (61), ISO 42001, NIST CSF 2.0 (106), CIS v8.1 (153) and PCI DSS (248). If any part of the figure could not be read, the percentage is withheld rather than shown low.
1642 crosswalk links between frameworks. A related control is shown as a labelled signal with its basis printed — it is never marked met on your behalf.
All 93 Annex A controls, each with a decision, a justification in both directions and an implementation state. It refuses to export while a decision is missing.
Scope, context, interested parties, roles, objectives and management review — held as records.
One artefact linked to every control it evidences, with a validity window, so stale evidence shows as stale.
14 checks. 12 read your workspace's own records; 2 read GitHub with a credential you supply, and read “not connected” until you do — never “pass”.
A public page on its own revocable token link, plus requests for the documents you will not publish: a buyer asks, you approve, they get a link that expires.
Answer from an approved library. An AI draft is grounded in that library, refused when it is empty, and saved as an unapproved draft marked as AI-written — a person approves what goes to the buyer.
Vendors tiered from what they touch and how badly their outage hurts, with a review cadence and a signed record.
Campaigns per system, each line decided by a named reviewer, and a campaign that will not close half-done.
Every AI system you use, in one of the EU AI Act's four bands, with the duties that band carries — between 1 and 10 — each citing its article or clause. We suggest a band; you decide it.
Article 30 records, DPIAs, cross-border transfers and data subject requests on a stored statutory clock.
Inherent and residual scores, appetite and tolerance, and acceptance above appetite that needs a written reason.
A period, a lead auditor, a scope statement and a prepared-by-client list the auditor raises and you answer.
Policies with version history and a per-member acknowledgement record, and training completions per person.
An internal-audit questionnaire for each of the 35 frameworks; a failed answer becomes an action item with an owner and a due date. Essentials installs 3 templates.
An org admin can download the workspace as CSVs from Settings. The archive is refused rather than shipped short.
What those tools and services PRODUCE still has somewhere to land. A penetration-test report or a scanner export goes in the document vault (every plan) and into the evidence library linked to the controls it evidences (Growth), and each finding you accept becomes an action item with an owner and a due date.
Questions
The workspace is yours from the moment you pay, and it does not run out. Run your first audit this week.