Studies of our own data

Three worked studies where every number can be re-queried through the free tools, including the one where we found the error rate in our own mappings was 56 percent.

These are not customer stories, and we do not have any yet

Every funded competitor in this market has named customer case studies. We have none. What we could do is write something shaped like one, about a leading financial services organisation that reduced audit preparation by some percentage, and that would be a fabricated record on a site whose whole argument is that its claims are checkable.

So this is what we can stand behind instead. A customer story appears here when a customer agrees to be named and to have the numbers checked, and not before.

We re-judged 23,000 of our own mappings and 56% failed

Seventy-two released crosswalks rested on mappings from one automated path. We pulled all seventy-two off sale and re-judged every mapping behind them. 12,944 of 23,003 did not survive, and some of the failures were high confidence on pairs that had already been sold.

23,003
mappings re-judged
56%
did not survive
4,015
still tagged with that reason, and readable

The failures had one shape: topic similarity rather than evidence transfer. The most common single error was the policy magnet, a control requiring you to issue a policy being satisfied by a control that implements the thing, or the reverse.

Read the full teardown

A framework whose control titles read right and meant something else

C5, the German cloud standard, had descriptions that were the criterion label restated inside boilerplate. It looked complete to every count-based check and it was a source in dozens of released pairs.

121
controls, rebuilt from the issued standard
3,193
outgoing mappings re-judged, not sampled
30
pairs from C5 released after the rebuild

The control that made the case: IDM-07, titled "Access to cloud customer data", does not restrict access at all. It is a 72 hour notification duty. It had attracted restrict-access mappings from eight different frameworks, because a title that reads like a familiar control is the most expensive kind of wrong.

See the pairs built from it

We ran ourselves through our own product and published the result

We hold no certification. Rather than leave it there, we assessed The Art of Service against all 93 ISO 27001 Annex A controls using the graph this platform sells, and published every verdict.

20
met
15
not met, listed by name
41
partial, mostly meaning no evidence an auditor would accept

Including 5.35, independent review of information security, which we record as not met because nobody independent has checked any of this. No competitor in this market publishes theirs, and having written ours we understand why.

Read our own gap report

Across the estate: 595 signed-off framework pairs, 59,123 mappings that survived a pass which argued against them, and 29,347 that did not and were kept anyway.

Check any single claim end to end