For Audit and certification firms
Every claim shows its working, and the claims that failed review are published beside the ones that held.
The job: Accept or reject a client assertion that evidence for one standard satisfies a control in another, and be able to say why.
For any released pair you can read the individual mappings: source control, target control, reasoning, source document, verification date, and whether the claim survived a pass whose job was to refute it.
Inspect the recordRejected mappings are kept in the graph rather than deleted, each with the reason it failed. A crosswalk that never rejects anything has not been judged, and that is a test you can apply to any vendor.
Pick a pair and read its rejectsWe hold no certification of our own and say so. Our own position on all 93 ISO 27001 Annex A controls is published, including the fifteen we do not meet.
Read our own gap reportThis is not an attestation and does not substitute for one. It is a documented judgement about requirement overlap that you are free to disagree with, row by row.
Claude Code, with a second pass whose job was to argue against each claim. No practitioner has read every pair line by line, which is stated on every report and in every tool response rather than in a footnote.
Each control carries the document it was verified against and the date. Where we do not hold a licensed copy of a standard we return no requirement text at all and label it, rather than paraphrasing something we cannot source.
The graph holds 686 frameworks and 59,123 judged cross-framework mappings, with 29,347 more that were judged and rejected and kept where you can read them.