Watch it check a policy, before you give us anything

A real information security policy, read against two frameworks, control by control, with the evidence behind every verdict. No account, no upload, no email.

This is a recording, made on 2026-08-21 by the same analyser the paid path uses. It is not run live, because that would put an LLM call behind an open endpoint and let any visitor spend our credits. The numbers are whatever it produced, including the ones that do not flatter us.

The document

Northwind Analytics Information Security Policy v2.1, 2,872 characters. A fictional company's policy, written for this demo. Real in shape: eleven sections, the things a small engineering company actually writes down, and the things it usually leaves out.

Read the whole policy first

Published so you can disagree with a verdict rather than take it.

Against SOC 2

47%

28 of 60 controls addressed. Strongest: access control and change management. Weakest: privacy and detailed risk management.

The policy provides a solid foundation for security and availability, covering access control, data protection, change management, incident response, and governance, but lacks detailed evidence for several SOC 2 controls especially around risk assessment, privacy notices, and detailed backup testing.

Gaps it found (32)

SOC2-C1.2Confidential information is disposed of securely

Include a data disposal procedure for media and backups.

SOC2-CC2.1COSO principle 13: Obtains and generates relevant, quality information

Define metrics and reporting mechanisms for security performance.

SOC2-CC3.1COSO principle 6: Specifies objectives to identify and assess risks

Include a risk assessment policy that defines risk identification and objectives.

SOC2-CC3.2COSO principle 7: Identifies risks and analyzes to determine how managed

Document risk analysis methodology and mitigation mapping.

SOC2-CC3.3COSO principle 8: Considers potential for fraud

Add fraud risk considerations and controls (e.g., segregation of duties).

SOC2-CC4.1COSO principle 16: Selects and develops ongoing and separate evaluations

Establish periodic internal audit schedule for control effectiveness.

26 more gaps in the full report.

Controls it judged addressed, with the evidence (28)

SOC2-A1.1Maintains capacity to meet availability commitmentsconfidence 80

Section 8 states production runs across two availability zones.

SOC2-A1.2Environmental protections, data backups, and recovery infrastructure support availabilityconfidence 75

Section 4 mentions encrypted volumes and nightly backups; Section 8 mentions backups tested annually.

SOC2-A1.3Recovery plan procedures support system recovery from failuresconfidence 70

Section 8 notes restore testing at least once a year.

SOC2-C1.1Confidential information is identified and protected during receipt, processing, storageconfidence 85

Section 3 enforces least-privilege access; Section 4 encrypts data in transit and at rest.

SOC2-CC1.1COSO principle 1: Demonstrates commitment to integrity and ethical valuesconfidence 80

Policy approved by the Board and signed by the CTO.

SOC2-CC1.2COSO principle 2: Board exercises oversight responsibilityconfidence 75

Section 11 states annual review and Board approval.

22 more in the full report.

Against ISO 27001:2022

37%

22 of 60 controls addressed. Strongest: access control and incident response. Weakest: asset management, classification, and physical security.

The policy provides a solid foundation for information security, covering many high-level ISO 27001:2022 controls such as access control, incident response, supplier management and training, but it lacks detail on asset handling, classification, legal requirements, and physical security.

Gaps it found (38)

5.11Return of assets

Add a clause describing the process for returning or securely wiping company assets when staff leave or change roles.

5.12Classification of information

Introduce a classification scheme (e.g., public, internal, confidential, restricted) and assign responsibilities.

5.13Labelling of information

Specify labelling requirements aligned with the classification levels.

5.14Information transfer

Define secure methods for transferring data (e.g., encrypted email, SFTP) and approval processes.

5.21Managing information security in the ICT supply chain

Add requirements for supply-chain risk assessments and periodic security audits of suppliers.

5.22Monitoring, review and change management of supplier services

Include a process for ongoing monitoring of supplier performance and security posture.

32 more gaps in the full report.

Controls it judged addressed, with the evidence (22)

5.1Policies for information securityconfidence 90

Section 1 defines the purpose and scope of the Information Security Policy and Section 11 states the policy is reviewed annually.

5.10Acceptable use of information and other associated assetsconfidence 85

Section 9 outlines acceptable use of company laptops and restrictions on software and network connections.

5.15Access controlconfidence 92

Section 3 details least-privilege provisioning, quarterly reviews, and revocation on termination.

5.16Identity managementconfidence 88

Section 3 requires unique named accounts and prohibits shared logins.

5.17Authentication informationconfidence 85

Section 3 mandates multi-factor authentication for critical systems.

5.18Access rightsconfidence 90

Section 3 includes quarterly review of access rights and removal of unnecessary accounts.

16 more in the full report.

Any rewrite produced from a report like this is a draft. It is written against the gaps this analysis found, in language grounded in the framework controls. It has not been read by a practitioner, writing a commitment into a policy is not the same as operating it, and whether an assessor accepts it is a judgement only a person can make. Read it before you adopt it.

Run it on your own policy

Same analyser, your document, every control rather than the sample shown here, and a redraft written against the gaps it finds.