Ten scenarios this is built for

Ten situations the platform exists to answer, written out in full so you can recognise your own position in one. Evidence reuse for a second certification, an assistant that stopped inventing control references, a tender due Monday, and the case where the honest answer was no.

These are illustrative scenarios, not customer stories.

No customer is named on this page because we have no published customer stories yet, and we say so plainly on /case-studies, which instead carries three studies of our own data where every number can be re-queried through the free tools. The scenarios below describe what the platform does, in situations it was built for. The capabilities are real and checkable. The organisations are not specific ones. When a customer agrees to be named, their story replaces the matching scenario and moves to /case-studies.

Illustrative scenario 1Evidence reuseB2B SaaS, 84 employees

They held SOC 2. The deal required ISO 27001, in 41 days.

A European enterprise prospect made ISO 27001 a condition of a three-year agreement. A consultancy proposed a six-week readiness assessment before remediation could even begin.

What changed. Running the existing SOC 2 programme against ISO 27001 produced a control-by-control view: where existing evidence supported the requirement, where the relationship was partial, and where no defensible mapping existed. The most useful part was not the coverage figure. It was the rejected mappings, where controls that looked similar by wording were not treated as equivalent because the underlying requirements differed.
What happened. The plan changed from "assess everything" to a defined set of evidence gaps in four working days. The readiness assessment was cancelled and remediation was scoped directly.
We were not looking for software to tell us SOC 2 and ISO 27001 are similar. We needed to know exactly where we could reuse evidence and, more importantly, where we could not.
Head of Security, illustrative

What it cost. A crosswalk report against a quoted five-figure readiness assessment.

Illustrative scenario 2Consulting productivityCybersecurity consultancy, 31 employees

The mapping was the cheap part. Senior judgement was being spent on it anyway.

A client wanted an Essential Eight programme mapped against ISO 27001 before a board risk committee. The previous comparable exercise had consumed 13.5 billable hours of a senior consultant opening two standards and building a spreadsheet.

What changed. The graph supplied the starting hypothesis instead of an empty spreadsheet. The consultant reviewed the proposed relationships, inspected provenance on the uncertain ones, and spent professional judgement on the exceptions rather than on discovering the obvious relationships.
What happened. A usable first mapping in well under an hour, then review, client context and the board narrative. The firm still billed for analysis. It stopped billing for lookup.
The graph does not make the judgement for me. It gets me to the part where my judgement is actually worth something.
Principal Consultant, illustrative

What it cost. An API subscription, against senior consultant hours.

Illustrative scenario 3AI groundingCompliance software vendor, 46 employees

The assistant sounded authoritative when it was wrong.

An AI assistant answered well on ISO 27001, SOC 2 and NIST, and degraded on anything less common. A 120-question internal evaluation across twelve frameworks found several answers citing control identifiers that do not exist in the issued framework.

What changed. Framework and control questions were required to retrieve source data before generating an answer, with mappings returned carrying provenance rather than inferred from model memory. The same 120 questions were then re-run.
What happened. Fabricated control references went to zero. A handful of answers remained wrong, mostly interpretation rather than retrieval, and those stayed in the benchmark rather than being quietly removed. The UI changed so a user can inspect the underlying control reference instead of receiving an unsupported natural-language answer.
The biggest improvement was not that the model knew more. It was that we could finally distinguish something the model knew from something it merely sounded as though it knew.
VP Engineering, illustrative

What it cost. An API licence and roughly two engineering days for the first integration.

Illustrative scenario 4The answer was noPayments technology, 112 employees

Management assumed PCI DSS meant ISO 27001 was mostly handled. It did not.

Mature controls existed around the cardholder-data environment, and an eight-week certification timeline had been budgeted on the assumption that ISO 27001 was largely an administrative extension of work already done.

What changed. The mapping contradicted the assumption. PCI DSS gave strong evidence in specific technical areas, while governance, organisational responsibilities, broader asset scope and several management-system requirements sat outside the PCI programme entirely. Superficially plausible relationships were rejected where the evidence did not carry.
What happened. The eight-week target was withdrawn before it was communicated externally, and replaced with a realistic multi-month programme with owners assigned to the uncovered domains. No failed audit had to teach the same lesson.
I wanted the report to tell me we were nearly there. It did not. That was considerably more useful than getting the answer I wanted.
Compliance Manager, illustrative

What it cost. Avoided committing publicly to a certification date the evidence could not support.

Illustrative scenario 5Document mappingHealthcare provider, 420 employees

Policies everywhere. Nobody knew which requirements they evidenced.

More than seventy policies and procedures had accumulated across a document repository. The team believed most required evidence already existed, but proving it meant opening documents individually. A consultant estimated three weeks of review and indexing.

What changed. Core security and privacy documents were mapped against the target control set, each requirement classified as supported, partial or gap. The exercise exposed a distinction that matters: several controls had a policy describing what should happen and no evidence that it did.
What happened. A proposed whole-library policy rewrite became targeted work on the genuine documentation gaps, with the "policy exists but operation is unevidenced" items tracked separately as remediation rather than counted as covered.
Our problem was not mainly missing policies. It was knowing what the policies we already had could actually prove.
Governance and Risk Manager, illustrative

What it cost. Days rather than the estimated weeks of document review.

Illustrative scenario 6Tender responseCritical-infrastructure supplier, 265 employees

A tender referenced 63 requirements from a framework they did not hold.

A government infrastructure tender was due Monday. The security schedule drew on a framework the company had never implemented directly, though it did hold ISO 27001 and ran an Essential Eight programme. A deadline extension was refused.

What changed. The schedule was split three ways against the two existing programmes: requirements with candidate reusable evidence, requirements needing additional narrative, and genuine gaps. The bid team answered the residual rather than all 63 from scratch.
What happened. Submitted on time, with most requirements evidenced, some needing scope clarification, and the remainder disclosed as gaps with proposed remediation. The gaps were not marked compliant. The submission progressed through security evaluation.
The value was not producing 63 green boxes. It was being able to say which are evidenced, which need explanation, and which genuinely are not done.
Bid Director, illustrative

What it cost. No emergency external mapping engagement, and no overstated compliance position.

Illustrative scenario 7Multinational governanceLogistics technology, 1,850 employees

Four regional teams had mapped the same control four different ways.

Regions across three continents each maintained their own spreadsheets connecting corporate controls to local and customer-specific requirements. An internal review found the same access-control requirement mapped four different ways, with no way to identify the approved interpretation.

What changed. The graph became a common reference layer. Teams could still disagree, but every proposed relationship now had an identifiable source control, target control and reasoning trail. A mapping had to be accepted, rejected or escalated, rather than inherited from a spreadsheet nobody owned.
What happened. Contradictory mappings were surfaced and resolved against the underlying requirements, with the genuinely ambiguous ones escalated to counsel rather than settled by whoever edited the spreadsheet last. One approved interpretation replaced four undocumented ones.
We did not need another spreadsheet. We needed a common object everyone could argue about and eventually agree on.
Global CISO, illustrative

What it cost. Four regional mapping processes became one governed process.

Illustrative scenario 8Agent integrationProcurement intelligence software, 67 employees

Their agent could read supplier documents. It could not reason across frameworks.

Customers asked things like "this vendor holds ISO 27001, how much does that help with our procurement security standard". Answering it meant either hard-coded rules or letting the model infer framework relationships. Neither was acceptable to the product team.

What changed. The agent was connected over MCP, discovering the compliance tools, requesting coverage and gaps, and inspecting provenance where a mapping affected a recommendation. One rule was added: the agent may summarise a cross-framework relationship, never invent one.
What happened. Instead of "ISO 27001 broadly aligns with your requirements", reviews distinguished requirements with supporting mappings from those with no defensible carry-over. Cases where the agent found insufficient evidence were escalated, and the team treated those escalations as the feature working rather than failing.
The feature we wanted was not an AI that always answered. It was an AI that knew when the graph did not support the answer.
Chief Product Officer, illustrative

What it cost. One MCP integration, and no framework database of their own to build and maintain.

Illustrative scenario 9Avoided spendAdvanced manufacturing, 540 employees

Sales wanted a certification. Customers wanted evidence.

Three automotive prospects had started asking security questions, and the commercial team was pushing a six-figure, nine-month certification programme. Before approving it the CISO asked a more basic question: are customers asking for the certificate, or for controls we may already evidence?

What changed. The requested requirements were mapped against the existing programme and the actual customer questionnaires. Overlap was substantial but not complete, and only one prospect contractually required the certificate. The graph could settle the control relationships. It could not settle the commercial question, which stayed a management decision.
What happened. The certification programme was deferred rather than approved on an assumption. Identified gaps were closed and an evidence pack produced for the customers who did not require the certificate. The one that did was qualified separately.
We were about to solve the phrase "customers are asking about this" with a six-figure certification programme. Mapping the actual requirements forced a much better question.
CISO, illustrative

What it cost. A six-figure programme deferred rather than approved on an assumption.

Illustrative scenario 10Board reportingManaged technology services, 310 employees

The board kept asking how compliant they were and getting four answers.

SOC 2, ISO 27001, privacy obligations and customer-specific requirements each reported separately. Directors received audit status, open findings and spreadsheet counts, none of which answered what they meant: where can existing evidence be relied on, and what material obligation remains uncovered.

What changed. Frameworks, cross-framework relationships and remediation were presented as common evidence domains with framework-specific gaps, rather than as separate programmes. Management could finally separate three things previously collapsed into "compliant": having a policy, implementing a control, and evidencing that the control operated.
What happened. The quarterly pack shrank substantially. Reporting concentrated on the control domains where remediation improved the position against several obligations at once, and two planned projects merged because they addressed the same underlying evidence requirement.
It did not give the board a magic compliance percentage. It gave us a defensible explanation of why fixing one thing sometimes satisfies five obligations, and why sometimes it does not.
Chief Risk Officer, illustrative

What it cost. Investment shifted from framework-by-framework projects to shared control requirements.

Check the capabilities yourself

Everything the scenarios describe is live and most of it needs no account. The coverage reports name every rejected mapping, and the benchmark publishes where the graph barely helps as well as where it does.