Watch it check a policy, before you give us anything
A real information security policy, read against two frameworks, control by control, with the evidence behind every verdict. No account, no upload, no email.
This is a recording, made on 2026-08-21 by the same analyser the paid path uses. It is not run live, because that would put an LLM call behind an open endpoint and let any visitor spend our credits. The numbers are whatever it produced, including the ones that do not flatter us.
The document
Northwind Analytics Information Security Policy v2.1, 2,872 characters. A fictional company's policy, written for this demo. Real in shape: eleven sections, the things a small engineering company actually writes down, and the things it usually leaves out.
Read the whole policy firstPublished so you can disagree with a verdict rather than take it.
Against SOC 2
47%28 of 60 controls addressed. Strongest: access control and change management. Weakest: privacy and detailed risk management.
The policy provides a solid foundation for security and availability, covering access control, data protection, change management, incident response, and governance, but lacks detailed evidence for several SOC 2 controls especially around risk assessment, privacy notices, and detailed backup testing.
Gaps it found (32)
Include a data disposal procedure for media and backups.
Define metrics and reporting mechanisms for security performance.
Include a risk assessment policy that defines risk identification and objectives.
Document risk analysis methodology and mitigation mapping.
Add fraud risk considerations and controls (e.g., segregation of duties).
Establish periodic internal audit schedule for control effectiveness.
26 more gaps in the full report.
Controls it judged addressed, with the evidence (28)
Section 8 states production runs across two availability zones.
Section 4 mentions encrypted volumes and nightly backups; Section 8 mentions backups tested annually.
Section 8 notes restore testing at least once a year.
Section 3 enforces least-privilege access; Section 4 encrypts data in transit and at rest.
Policy approved by the Board and signed by the CTO.
Section 11 states annual review and Board approval.
22 more in the full report.
Against ISO 27001:2022
37%22 of 60 controls addressed. Strongest: access control and incident response. Weakest: asset management, classification, and physical security.
The policy provides a solid foundation for information security, covering many high-level ISO 27001:2022 controls such as access control, incident response, supplier management and training, but it lacks detail on asset handling, classification, legal requirements, and physical security.
Gaps it found (38)
Add a clause describing the process for returning or securely wiping company assets when staff leave or change roles.
Introduce a classification scheme (e.g., public, internal, confidential, restricted) and assign responsibilities.
Specify labelling requirements aligned with the classification levels.
Define secure methods for transferring data (e.g., encrypted email, SFTP) and approval processes.
Add requirements for supply-chain risk assessments and periodic security audits of suppliers.
Include a process for ongoing monitoring of supplier performance and security posture.
32 more gaps in the full report.
Controls it judged addressed, with the evidence (22)
Section 1 defines the purpose and scope of the Information Security Policy and Section 11 states the policy is reviewed annually.
Section 9 outlines acceptable use of company laptops and restrictions on software and network connections.
Section 3 details least-privilege provisioning, quarterly reviews, and revocation on termination.
Section 3 requires unique named accounts and prohibits shared logins.
Section 3 mandates multi-factor authentication for critical systems.
Section 3 includes quarterly review of access rights and removal of unnecessary accounts.
16 more in the full report.
Any rewrite produced from a report like this is a draft. It is written against the gaps this analysis found, in language grounded in the framework controls. It has not been read by a practitioner, writing a commitment into a policy is not the same as operating it, and whether an assessor accepts it is a judgement only a person can make. Read it before you adopt it.
Run it on your own policy
Same analyser, your document, every control rather than the sample shown here, and a redraft written against the gaps it finds.