Included with Professional

Judge a policy once. Answer every framework.

Upload an information security policy and have it read against the framework you name. The result is kept. From then on any of the 686 frameworks in the graph can be answered from that same evidence, because the mappings between their controls already exist.

Every other tool that reads your policy forgets it. Ask about a second standard and you pay to have the same document read a second time. That is the part this changes.

How it works

1

Name one framework

The one you are certified against, or the one you know best. Your policy is read against its controls and the passage that satisfies each one is recorded.

2

The binding is kept

Not the answer to a question, but which control each part of your evidence satisfies, and why. That is the asset, and it survives the session.

3

Ask about any other

Coverage of a second framework is worked out by following mappings between controls. No second reading of your document, so no second charge for it.

A worked example

This is our own sample policy, not a customer. Nine clauses covering access control, cryptography, logging, supplier security, incident management, change management, backup, asset management and awareness training. It was judged once against ISO 27001:2022 and bound to 18 controls. Everything below followed from that single reading, with no further analysis.

FrameworkControls reachedOf total
HIPAA Security Rule
34.3%
23 of 67
APRA CPS 234
33.3%
8 of 24
NIST Cybersecurity Framework 2.0
29.2%
31 of 106
DORA
26.9%
7 of 26
SOC 2
23%
14 of 61
NIS2 Directive
21.4%
6 of 28
CMMC 2.0
18.2%
20 of 110

Measured 26 August 2026. Coverage of this shape is inherited, meaning it was carried across a mapping rather than read directly, and every row of it is labelled that way in the product. A nine-clause policy is a small document. A real one reaches further, and a thin one reaches less.

Four answers, never added together

A single percentage hides the difference between evidence somebody read and a claim derived from a mapping. Each control gets one of four answers, and they are reported separately.

Direct

A document of yours was read against that control, and the passage that satisfies it is quoted back to you.

Inherited

A control you do have evidence for maps to this one. The row names which control it came from and in which framework, so you can check it. It is a lead to verify, not an audited finding.

Gap

Read against your evidence and not found. This is the list worth working through.

Not assessed

Nothing has looked at it yet. Counting these as gaps would inflate the number of problems you appear to have, so they are kept separate.

What is allowed to carry across

The graph holds 310K+ cross-framework mappings. Evidence is only carried across the ones judged and not rejected, which is 59,197 of them. The other 42,246 were examined, argued against and kept in the graph as refuted rather than quietly deleted. Within the judged set, only the high confidence ones carry evidence.

Direction is respected. If a control you have evidence for satisfies one in another standard, your evidence carries. The reverse does not follow, and the product does not pretend it does.

Your document is not kept

What is stored is the binding: which control each part of your evidence satisfies, a short quoted excerpt as the citation, and a hash of the file so a re-upload replaces the old judgement rather than counting twice. The document itself is not retained. You can delete any of it, and deleting a document removes every binding it created. The full security position sets out what is held and where.

What this does not do

  • It does not make an organisation compliant, and it does not replace an auditor. It tells you where your own evidence already reaches and where it does not.
  • Inherited coverage is not an audited finding. An auditor will want to see the evidence against their standard, and the product shows you which control to take to them.
  • A scanned image with no text layer cannot be read. It is refused rather than guessed at.
  • One pass reads a bounded set of controls. The rest are reported as not assessed until you point a document at them.

Start with the policy you already have

One document, one framework. Then look at what it already does for the 686 others, across 21,696+ controls.

Create an account