Three worked studies where every number can be re-queried through the free tools, including the one where we found the error rate in our own mappings was 56 percent.
These are not customer stories, and we do not have any yet
Every funded competitor in this market has named customer case studies. We have none. What we could do is write something shaped like one, about a leading financial services organisation that reduced audit preparation by some percentage, and that would be a fabricated record on a site whose whole argument is that its claims are checkable.
So this is what we can stand behind instead. A customer story appears here when a customer agrees to be named and to have the numbers checked, and not before.
We re-judged 23,000 of our own mappings and 56% failed
Seventy-two released crosswalks rested on mappings from one automated path. We pulled all seventy-two off sale and re-judged every mapping behind them. 12,944 of 23,003 did not survive, and some of the failures were high confidence on pairs that had already been sold.
23,003
mappings re-judged
56%
did not survive
4,015
still tagged with that reason, and readable
The failures had one shape: topic similarity rather than evidence transfer. The most common single error was the policy magnet, a control requiring you to issue a policy being satisfied by a control that implements the thing, or the reverse.
A framework whose control titles read right and meant something else
C5, the German cloud standard, had descriptions that were the criterion label restated inside boilerplate. It looked complete to every count-based check and it was a source in dozens of released pairs.
121
controls, rebuilt from the issued standard
3,193
outgoing mappings re-judged, not sampled
30
pairs from C5 released after the rebuild
The control that made the case: IDM-07, titled "Access to cloud customer data", does not restrict access at all. It is a 72 hour notification duty. It had attracted restrict-access mappings from eight different frameworks, because a title that reads like a familiar control is the most expensive kind of wrong.
We ran ourselves through our own product and published the result
We hold no certification. Rather than leave it there, we assessed The Art of Service against all 93 ISO 27001 Annex A controls using the graph this platform sells, and published every verdict.
20
met
15
not met, listed by name
41
partial, mostly meaning no evidence an auditor would accept
Including 5.35, independent review of information security, which we record as not met because nobody independent has checked any of this. No competitor in this market publishes theirs, and having written ours we understand why.
Across the estate: 595 signed-off framework pairs, 59,123 mappings that survived a pass which argued against them, and 29,347 that did not and were kept anyway.