Conformiti
ProductEditionsPricing ConsultingSelf-hostDocs Security GitHub Book a demo

Product tour

Every screen, and what
you actually do on it.

Nothing below is a concept render. These are screenshots of the shipping build with the demo dataset loaded, the same dataset you get from SEED_DEMO_DATA=true on the first boot. Click any image to enlarge it.

01 · Frameworks and controls

The register everything else hangs off.

Three complete control libraries ship pre-loaded and seed themselves on first boot: SOC 2 (61), ISO/IEC 27001:2022 (93) and PCI DSS v4.0.1 (63). Each control carries a category, an objective, a status, an owner and the evidence linked to it.

On this screen you can

  • Filter by framework and status, or search by reference or title
  • Expand a row for the objective, the status and owner selects, and the linked evidence
  • Attach evidence to many controls at once: the bulk action reports anything it skipped and why
  • Unlink a document where you hold edit rights on its folder
  • Export CSV of the whole register, filtered as you see it
Readiness is arithmetic, not opinion. It is implemented ÷ applicable, per framework, recalculated as statuses change. Marking a control not applicable removes it from the denominator, and who did it, when, and which field they changed is recorded in the audit trail, which is precisely what an assessor will ask for.
grc.yourcompany.com/controls

Cross-framework crosswalk

Twenty cross-framework themes ship with the libraries, each naming the SOC 2, ISO and PCI controls that address the same requirement. CC6.1, A.5.15 and 7.1 are one theme, so a single policy is evidence for all three. Read through /api/crosswalk/; no screen yet.

Evidence links go both ways

The control ↔ document relationship is many-to-many and editable from either side. Add a policy from the Controls screen, or map controls from the Documents screen. It is the same link, and unlinking from one place unlinks it everywhere.

Owners are real accounts

A control owner is a person with a login, not a text field. That is what makes ownership coverage meaningful, routes the reminder, and lets an owner answer a PBC line without seeing the rest of the package.

02 · Documents and evidence

A folder tree generated from the standards.

Not an empty drive you have to organise. The tree is created from the control libraries (framework, then category, then control) on disk and mirrored in the app, with your own subfolders wherever you want them.

grc.yourcompany.com/documents
grc.yourcompany.com/documents · viewer
Lifecycle

Versions, not overwrites

Version archives the current file and increments; the old bytes stay retrievable, which matters when an auditor asks what the policy said during the window. Rename, Move and Mark reviewed are separate permissions, each an audit-log entry.

Reminders

The clock that runs itself

Set a cadence from monthly to biennial and the next review date is derived. Owners and the compliance address are emailed at 30, 14, 7 and 1 days out, and once when it goes overdue. Each window fires exactly once and is recorded, so a restart does not re-send yesterday's mail.

Access

Grants that inherit

Permissions are per folder, granted to a role or a user at view, edit or manage, and inherited by every subfolder. Effective access resolves server-side. Auditor roles are capped at view whatever they are granted.

Open in browser

Reviewing evidence should not require downloading it.

Downloading evidence to look at it is how copies of your policies end up in Downloads folders on laptops you do not control. The viewer renders in place, and the way it renders is deliberately conservative.

  • PDFs are drawn by pdf.js onto canvases, no plugin frame, no embedded scripting from the file
  • Images stream inline only after a magic-byte check on the actual content, never on the extension
  • Word and Excel are parsed on the server and returned as structured JSON, then rendered as structure. The file's own markup is never injected into the page
  • Anything else offers a download rather than guessing
  • The wrapper shows the version, the controls satisfied, and a SHA-256 computed in your browser with WebCrypto: the same digest a sealed package records, so a reviewer can compare by eye

03 · Dashboard and analytics

Numbers with a provenance.

A readiness snapshot is recorded daily. The trend line and the month-over-month delta come from that history, so the figure you show your board is reproducible rather than re-derived each time.

grc.yourcompany.com/dashboard

Dashboard. The calendar merges review dates, audit milestones and tasks; filter by type, click a day for detail.

grc.yourcompany.com/analytics

Analytics. Ownership coverage across controls, documents and risks: usually the most useful number on the page.

Reviews coming up

The next reviews due, with Mark reviewed inline for managers and owners with edit access. Clearing the queue takes one pass, not a tour of the folder tree.

Evidence coverage

What share of controls have at least one document linked. The gap between “implemented” and “evidenced” is where audits go wrong, so it gets its own tile.

Risk posture

Open risks, how many are being mitigated, how many accepted, and how many are past their due date: linked straight into the register.

Notification tray

Computed per person: your documents and risks that are due, tasks assigned to you, cadences you own that are behind. A manager's tray widens to the organisation. The emailed digest is off by default; turn on daily or weekly in Settings.

grc.yourcompany.com/risks

04 · Risk register

Five by five, with a paper trail.

Likelihood × impact on the 5×5 grid auditors expect, producing low, moderate, high or critical. Each entry carries status, treatment, owner, an optional control and Jira key, a due date and a note trail.

Import that survives contact with reality

  • Reads CSV and XLSX, and recognises the column names people actually use: Title/Risk, Likelihood/Probability, Impact/Severity, Owner, Control, Due date, Status, Notes
  • Understands word scales as well as numbers: High, Likely, Almost certain
  • Skips duplicates by title rather than creating a second copy of a risk you already track
  • Downloadable template, and a CSV export that round-trips

Managers create and edit; the risk's owner can edit theirs; anyone with access can add notes. An auditor's exception can be pushed into the register in one click, arriving with the package and control referenced.

05 · Access reviews and the audit trail

Two screens that answer most of the questions.

Two of them: the periodic user access review, and the append-only record of every change that happened. Between them they cover a surprising share of what an assessor asks for in the first week.

grc.yourcompany.com/user-audit

Access reviews

Start new review snapshots every account as it stands, so the grid does not shift under you. Record a decision and a note per row, export the CSV, then complete it. The API refuses to complete while any row is pending, and a completed review is read-only evidence.

grc.yourcompany.com/audit-log

Audit trail

Middleware records the top-level field names of every mutating request, never the values, dropping password, token and code keys outright. Sign-ins, failures with the reason, and sign-outs are written explicitly. There is no API to edit or delete an entry.

06 · Vendors and shared responsibility

Third-party risk, computed rather than asserted.

grc.yourcompany.com/vendors

The register, with assurance and its expiry visible before it lapses.

grc.yourcompany.com/responsibilities

RACI per control, across people and vendors.

Assurance on file

SOC 2 reports, ISO certificates, PCI AOCs, penetration tests and DPAs, each with an expiry date. Posture and risk rating are derived from what is on file and how close it is to lapsing. A bridge-letter reminder fires when a SOC report lapses with nothing newer behind it.

The matrix importer

Vendors send their matrix in whatever shape their template happens to be. The importer scores headers to find the columns, promotes a mark column by its values, and never guesses at prose it does not recognise. Nothing is written until you confirm what it read.

The questionnaire, sent out

One click emails the vendor's contact a personal link, valid 14 days by default and 90 at most, one live link per vendor with a revoke button. They answer in a browser with no account, the token is stored hashed, and the submission returns as a pending assessment for you to accept or reject.

RACI, with the obvious inferred. A control's owner is implicitly Accountable; a vendor that owns a row in its shared responsibility matrix is implicitly Responsible. Exactly one Accountable per control is enforced at the API, not merely discouraged in the interface, and the controls with no Accountable at all are counted and shown, because that count is the point.

07 · Audit packages

The feature the rest of
the product exists to feed.

A sealed, hash-pinned package whose canonical manifest (every control snapshot and the SHA-256 of every evidence file) carries a detached Ed25519 signature, issued to named auditors for a fixed window, and verified offline without us.

grc.yourcompany.com/packages

What sealing does

  • Snapshots every row (control reference, text, status, owner, document name, version, size and SHA-256) into a canonical manifest with its own digest
  • Signs that manifest with a detached Ed25519 signature from a key held in a file outside the database (SIGNING_KEY_FILE), never in a table
  • Freezes the package: no row edited, no evidence added, removed or re-pointed. If a pinned document is replaced afterwards, every file is re-hashed at export and the mismatch is named in INTEGRITY.txt. The seal detects a substitution rather than preventing one.
  • Writes a seal entry to the audit trail, which is the timestamped record that binds the digest to a moment
  • Publishes the key fingerprint under Settings and at /api/signing-keys/, so the auditor can compare it against the bundle. One key signs the whole installation, so the manifest names the organisation inside the signed bytes.

What the auditor receives

  • A grant that opens the pinned artefacts and the attachments answering the request list: the one deliberate bypass of folder permissions, bounded by the grant and recorded before each byte leaves. Scope the workspace, not just the grant.
  • A design and an operating conclusion per control that the API will not let the assessed organisation edit. The Django admin is an operator tool outside those rules, so put it behind a VPN or an allow-list
  • Per-sample pass / exception / not tested, with a mandatory note on an exception
  • A ZIP that checks itself: manifest.json with its digest in MANIFEST.sha256, manifest.sig, signing-key.pub, SHA256SUMS, controls.csv, evidence.csv, samples.csv, trail.csv, INTEGRITY.txt, a README.txt, the evidence itself, and a stdlib-only verify.py that checks the manifest signature and every listed digest with nothing installed
  • Access that expires, or is withdrawn in one click, while the record of what was disclosed, to whom, and which files were opened, is permanent

Sampling

The organisation states population size, source and sampling method while the package is a draft, and may list items. Those are sealed into the manifest. Afterwards the auditor adds selections and records a verdict per item.

Roll-forward

Next year's package from last year's: the same controls re-snapshotted with today's evidence, the predecessor named in the manifest, and a year-over-year panel showing scope changes, replaced evidence and last year's still-open exceptions.

PBC request list

The auditor raises lines from inside the package, or you transcribe the ones they emailed. Each is assigned, dated and chased in the tray, by email and in Slack or Teams, then answered by attaching documents and marking it provided.

What the auditor runs, on their own machine
$ unzip conformiti-package-fy26-soc2.zip && cd conformiti-package-fy26-soc2
$ sha256sum -c SHA256SUMS
evidence/access-control-policy-v4.pdf: OK
evidence/user-access-review-2026-Q1.csv: OK

$ python3 verify.py
manifest digest   d41f0e…9ab2   OK
signature        Ed25519       OK  (key 8c:1a:…:e7)
files            214/214       OK
# no network, no dependencies, no vendor involvement

08 · The rest of the governance calendar

Meetings, groups and the ticket board.

The unglamorous evidence that a programme is being run by people, on a cadence, with minutes.

Meetings

Series with a required cadence per year: steering committee quarterly, risk review semi-annually. The badge compares minutes recorded this year against what the calendar demands so far, so a series is not marked behind in January for a meeting due in November.

Champion groups

Who represents which part of the business in the programme, with an accountable owner per group and members tagged by department. Useful evidence for the “security is governed across the organisation” questions, and useful in practice for knowing who to ask.

Jira optional

An administrator connects an Atlassian site, with the token stored server-side and never sent to the browser, and tracks boards by id. Everyone reads those boards without a Jira seat. The integration is read-only, https and public hosts only, redirects refused, hardened against SSRF.

09 · Identity, roles and settings

Five roles, folder grants,
and an API that means it.

Capabilities are enforced by the API. The interface only shows write controls where the API would accept them, which is the opposite of the common arrangement, where a hidden button is the whole security model.

  • TOTP on the standard library alone, checked against the RFC 4226/6238 vectors: a setup key or otpauth:// URI for any authenticator, plus ten single-use backup codes owned by the account rather than the authenticator.
  • Passkeys and security keys (WebAuthn) satisfying the second step instead of a code, with a counter-regression check that disables a key that looks cloned and refuses the sign-in rather than falling back to password-only
  • OIDC and SAML 2.0 configured from the environment only, with verified-email linking that never attaches to an administrator, a domain allow-list, and auto-provisioning off by default. One identity provider per installation, not per workspace.
  • Step-up MFA on SSO logins when the provider asserted no second factor: off, if-enrolled or required, defaulting to if-enrolled
  • Administrators can reset a person's second factor; the API refuses self-lockout and will never leave an organisation with no active administrator
Built-in roles and their capabilities
RoleManage usersManage frameworks Manage documentsManage folders View allAuditor
AdministratorNo
Compliance ManagerNoNo
Control OwnerNoNogranted foldersNoNoNo
AuditorNoNoNoNoregisters read-only; documents by grant
ViewerNoNoNoNoNoNo

Custom roles come from the same capability flags. Folder grants are inherited by every subfolder, and effective access resolves to the highest of superuser, view-all, ownership and the strongest grant on the folder or any ancestor. Auditor roles are then capped at view.

Since v0.9.0 · isolation hardened in v0.9.2

10 · Workspaces

One installation, several organisations.

Every organisation-owned row: frameworks and controls, folders and documents, risks, vendors, packages and their request lists, reviews, meetings, groups, the calendar, Jira, readiness history, the audit trail, roles and people: belongs to a workspace.

Scoping is applied at the ORM, not the view layer: a queryset carries its workspace filter every time it is chained, so a view that forgets to scope still returns only the active workspace's rows.

  • A superuser creates workspaces, switches between them (X-Workspace: <slug>, remembered by the SPA) and archives one, which refuses its people at sign-in, ends their sessions, and drops it from every scheduled job. Nothing is deleted.
  • Scheduled work runs once per workspace: review, vendor and auditor-request scans, readiness snapshots. There is one Slack or Teams webhook per installation, so every workspace posts to the same channel.
  • An existing single-organisation install becomes one workspace named Default holding everything it already had, and never notices.
  • Names that were once unique installation-wide (role, framework key, vendor, meeting series, group, Jira board) are now unique per workspace.

Who this is for

MSPs and consultanciesOne deployment holding each client's programme, scoped in the database. The compliance mailbox and the Slack or Teams channel are still one per installation, so every client's reminders and daily summary land in the same place. A channel per organisation is the next item on the roadmap.
Groups and holding companiesSeveral regulated entities, separate scopes and separate auditors, one operations burden.
Separate certificationsA payments subsidiary in PCI scope kept apart from the rest of the group's ISO programme.
Staging and productionA workspace to rehearse a framework rollout in, without a second deployment to maintain.
Not tenant-scoped, deliberately: the workspace list itself, per-person authentication state (passkeys, TOTP, backup codes, SSO identities), the signing-key registry, the scanner status row, notification receipts and webhook deliveries. Single sign-on and the Slack or Teams webhook are installation-wide too: one identity provider and one channel for the whole deployment, with per-workspace versions of both on the roadmap. These belong to the installation or to the individual, not to an organisation.

Editions

Everything above is
the free build.

Every screen on this page ships in Core under the MIT licence, with nothing switched off. The copilot, the trust page and the multi-client console are the paid editions, installed on top.

Pro

A compliance copilot that drafts from your own control objectives on your own model key, a public trust centre, a custom framework builder, PII redaction and e-signature.

Enterprise

One console across every client organisation, a partner role that is not a superuser, white-label and TPRM at portfolio scale.

Next

Read the code, or run it.

Both take about a minute. Everything on this page is in the MIT-licensed build. There is no “request access” gate between you and the product.