Dashboard
62 of 209 applicable controls implemented across ISO/IEC 27001, PCI DSS and SOC 2.
ISO/IEC 27001 · PCI DSS · SOC 2
4 due in the next 30 days
22 control-document links.
0 mitigating · 0 accepted
Compliance calendar
3 items in view · 6 this month ● REVIEW● AUDIT ● TASK● OTHER September 2026Controls, documents and live risks with a named owner.
November is where seventeen documents come due at once. Re-cadence before it happens, not after.
Click any row to expand it · one policy commonly satisfies CC6.1, A.5.15 and 7.1 at once
Grants are per folder, by role or by user, at view / edit / manage, and inherited by every subfolder
Columns are likelihood, rows impact. Three live risks.
Import the vendor's own CSV/XLSX matrix. The columns and values are recognised, and nothing is written until you confirm what it read
A control owner is implied Accountable · a vendor that owns a matrix row is implied Responsible · exactly one Accountable is enforced at the API
FY26 SOC 2 Type II
28 controls in scope · 214 evidence files pinned · population and sampling method stated per control
| CC6.1 | Access security | No exceptions |
| CC7.2 | Anomaly monitoring | No exceptions |
| CC8.1 | Change management | Exceptions noted |
| CC9.2 | Vendor risk | Not tested |
Design and operating conclusions are the auditor's: you answer beside them
| Q3 user access review export Assigned to Mia · due 2026-09-12 | PROVIDED |
| Change tickets, sample of 25 Assigned to Owen · due 2026-09-09 | OPEN OVERDUE |
| Backup restore test evidence Assigned to Ada · due 2026-09-18 | OPEN |
A control owner with no package access still sees the lines assigned to them
This screen is not in the demo
It is in the product: users, access reviews, the audit log, meetings, champion groups and Jira all ship in the open-source build. This walkthrough covers eight screens; the real thing covers fifteen.