Three worked studies where every number can be re-queried through the free tools, including the one where we found the error rate in our own mappings was 56 percent.
These are not customer stories, and we do not have any yet
Every funded competitor in this market has named customer case studies. We have none. What we could do is write something shaped like one, about a leading financial services organisation that reduced audit preparation by some percentage, and that would be a fabricated record on a site whose whole argument is that its claims are checkable.
So this is what we can stand behind instead. A customer story appears here when a customer agrees to be named and to have the numbers checked, and not before.
We re-judged 23,000 of our own mappings and 56% failed
Seventy-two released crosswalks rested on mappings from one automated path. We pulled all seventy-two off sale and re-judged every mapping behind them. 12,944 of 23,003 did not survive, and some of the failures were high confidence on pairs that had already been sold.
23,003
mappings re-judged
56%
did not survive
4,015
still tagged with that reason, and readable
The failures had one shape: topic similarity rather than evidence transfer. The most common single error was the policy magnet, a control requiring you to issue a policy being satisfied by a control that implements the thing, or the reverse.
A framework whose control titles read right and meant something else
C5, the German cloud standard, had descriptions that were the criterion label restated inside boilerplate. It looked complete to every count-based check and it was a source in dozens of released pairs.
121
controls, rebuilt from the issued standard
3,193
outgoing mappings re-judged, not sampled
30
pairs from C5 released after the rebuild
The control that made the case: IDM-07, titled "Access to cloud customer data", does not restrict access at all. It is a 72 hour notification duty. It had attracted restrict-access mappings from eight different frameworks, because a title that reads like a familiar control is the most expensive kind of wrong.
We ran ourselves through our own product and published the result
We hold no certification. Rather than leave it there, we assessed The Art of Service against all 93 ISO 27001 Annex A controls using the graph this platform sells, and published every verdict.
20
met
15
not met, listed by name
41
partial, mostly meaning no evidence an auditor would accept
Including 5.35, independent review of information security, which we record as not met because nobody independent has checked any of this. No competitor in this market publishes theirs, and having written ours we understand why.
Across the estate: 594 signed-off framework pairs, 59,565 mappings that survived a pass which argued against them, and 42,246 that did not and were kept anyway.
Since we cannot yet show you a customer, we have written out ten situations the platform is built for, in full. They are labelled illustrative and no organisation in them is a specific one, because a fabricated record would cost more than the gap it papers over. The capabilities they describe are live and checkable.
What we can show you is who has bought the material. That is a sales record rather than a customer story, and it is named and countable: 659 organisations across 11 years.