Product
One system for the whole compliance monitoring cycle.
Four modules on one record. Every policy, control, test, piece of evidence and finding links back to the requirement it serves, and every change is kept.
Compendium
Every obligation, in one versioned library.
Every requirement from the rulebooks that apply to you, versioned and maintained centrally. Mark applicability per entity and licence, with reasons.
Monitoring
A monitoring plan that runs on time.
A monitoring plan per entity and year, with every test linked to controls and requirements. Calendar, reminders, escalation and a signed period report.
Registers
Policies, controls and findings, all linked.
Policy library, control library, and findings and actions. Mandatory fields, configurable approvals, requirement links and full history on every row.
Evidence
Evidence you can prove, not just find.
One vault for every file. SHA-256 hashed, never overwritten, and searchable by record, date, uploader, hash or content.
Underneath every module
- Audit log. Every change is an append-only event with actor, time in UTC, action, and the state before and after. Each record has a history view you can export to CSV and PDF.
- Any date, reproduced. Every register, report and dashboard can be shown as it stood at any date and time.
- Nothing is deleted. Deleting a record sets a status and a reason. The record stays visible in historical views.
- Approval is evidence. Approval workflows are configured per register. The approval chain is stored with the record and printed on every export.
- Configurable, not custom. Your admin adds fields, sets workflow steps and schedules reminders through admin screens. There is no custom code per customer.
- Regulator-ready exports. Everything exports to PDF with its approval chain and a hash footer, and to CSV. A regulator pack bundles records and evidence into one ZIP file with an index PDF.