Evidence & fieldwork · Pro
Control testing
Test a control over an observation window and produce a workpaper that survives questioning: a population frozen with a digest when drawn, a sample anyone can re-derive from the stored seed, and sign-off by somebody who did not perform the test.
Evidence & fieldwork · Pro
Recurring evidence collection
A standing evidence requirement on a cadence: one task per period, assigned to a named person, chased before it is due and escalated when missed. The coverage grid shows every period, including the empty cells.
Evidence & fieldwork · Pro
SOC 2 Type II testing pack
61 criteria with 305 test procedures, per-criterion population and sampling guidance, common exceptions, and complementary user-entity controls on 42 of them. Read directly by the control-testing runtime rather than sitting in a PDF.
Evidence & fieldwork · Pro
Policy acknowledgement
Ask everyone to read and sign the current version of a policy, pinned to the exact document version and its digest. The record is append-only and carries the typed name, statement, timestamp and address, which is what an auditor asks for.
Evidence & fieldwork · Pro
Security-awareness training
Assign training, track completion, and keep the attestation records auditors ask for under CC1.4, ISO 27001 A.6.3, PCI DSS 12.6, NIST AT-2 and HIPAA §164.308(a)(5). Three starter courses included, or author your own.
Documents · Pro
Personal-data detection
Finds personal data in uploaded evidence: Luhn-checked payment cards, SSN with the invalid-range rules, IBAN mod-97, NINO, SIN, keys and tokens, and flags it. Detect and warn: the original file is never modified.
Documents · Pro
Masked derivatives
Generate a masked copy for the audit package, keeping the original intact and recording honestly in the manifest what was disclosed, so the package is defensible rather than quietly redacted.
Documents · Pro
E-signature
Send a policy for signature; the executed copy and its completion certificate are filed automatically as a new version, which is exactly the evidence an auditor asks for. DocuSign, Dropbox Sign, or a manual flow that needs no vendor contract at all.
Documents · Pro
Contract auto-extract
Upload a signed contract; it proposes the vendor record, the standards the counterparty is held to, and the expiry that feeds the review clock. Nothing is written until a person confirms it, and every field carries the passage it came from.
Governance · Pro
Board and executive reporting
Scheduled reporting packs with the numbers frozen at generation, so a pack re-read next year shows what the board actually saw. Shareable with a director by an expiring, revocable link that reaches nothing but that one pack.
Governance · Pro
Meeting scheduler
Create the real Teams or Google Meet invite from the governance cadence tracker, and reconcile cancellations made in the calendar. Uses the customer's own OAuth application, not ours.
Content · Pro
Policy and register seed pack
30 policies, plans, standards and procedures pre-mapped to every shipped framework, plus 12 registers: risk register, asset and vendor inventories, incident log with the statutory clocks, access-review workbook, control test schedule, DPIA, AI impact assessment, business impact analysis, ISO 27001 Statement of Applicability, GDPR Article 30 records of processing and continuity exercise records. Markdown, CSV, JSON and XLSX.
Content · Pro
Custom framework builder
Define your own controls and categories, import from CSV or XLSX, crosswalk them to the shipped libraries, and export as a portable pack. Everything else (evidence, scoring, packages, the copilot) works on them unchanged.
Multi-client · Enterprise
MSP console and partner role
One login across the whole portfolio, with readiness, overdue reviews, expiring vendor assurance and open evidence requests rolled up per client, plus search and bulk actions across the whole book. Working inside a client's own screens still needs an account on that workspace.
Multi-client · Enterprise
White-label and TPRM Advanced
Your brand on the sign-in page (rendered before anyone has authenticated), the application shell, the sender name and subject line of every message, and the board report packs. TPRM Advanced adds questionnaire scoring, portfolio ranking by exposure, concentration and fourth-party analysis, and the DORA register-of-information export.