Compliance assessments that actually fit your budget
Governance, risk, and compliance — automated, affordable, and actionable. Explore assessments, evidence and reports free during the open beta. No sales call. No retainer.
Every module is free to use during the open beta. The prices shown are indicative and struck through because checkout is closed — nothing can be bought here yet.
Start with your goal
Choose the work you need to do. You can also go directly to any framework in the catalogue below.
Certification Readiness
Gap assessments against international information security and trust frameworks.
Information security management system readiness — Annex A controls, evidence vault, gap register.
Privacy Information Management System — Controller, Processor, and dual-role readiness. RoPA builder, DPIA trigger evaluation, multi-law gap view across GDPR, DPDP, CCPA, and 5 more jurisdictions.
Trust Services Criteria readiness — Type I design review or Type II continuous operation. Security, Availability, Confidentiality, Processing Integrity, Privacy.
Controls over financial reporting — Type I or Type II. ICFR readiness for service organizations, subservice org coverage, and CPA handoff.
Payment Card Industry Data Security Standard v4.0.1 — SAQ recommendation, critical finding detection, and gap register for merchants and service providers.
India Compliance
Regulatory readiness for Indian data protection, financial sector, and securities compliance obligations.
Digital Personal Data Protection Act 2023 — 31 obligations, penalty exposure register, in-force vs future readiness.
RBI IT Master Directions 2023 — auto-derived supervision tier (T1–T4), 22-control CSITE readiness assessment, critical finding detection, and examination gap register.
SEBI CSCRF 2024 — category derivation, a 15-control sampler drawn from the 65-control CSCRF set, quarterly Score Card preparation, and registration risk detection.
Cyber Standards
Maturity assessments and gap reviews against globally recognised cybersecurity control frameworks.
CSF 2.0 readiness — Govern, Identify, Protect, Detect, Respond, Recover, with an evidence-backed improvement profile.
Implementation Group readiness across 18 control families. Auto-derived IG1/IG2/IG3 with prioritised gap register.
Third-party security questionnaire across 7 domains — risk tier derivation, critical finding detection, and evidence checklist.
Technical & Governance Reviews
Specialist reviews of cloud and infrastructure controls, continuity, and IT governance.
IAM, data security, network controls, logging, misconfiguration, cost anomaly, and compliance posture — AWS, GCP, Azure, OCI.
BIA, recovery plans, test cadence, RTO/RPO validation, supplier dependencies, and crisis communications — 16 controls.
IT strategy, governance structures, ITSM, vendor management, project delivery, risk, and technology refresh — Ad Hoc to Optimised maturity.
Not sure where to start?
Choose a starting point from the work you need to do. If a customer or auditor has named a framework, use that framework and its agreed scope.
Choose a starting point →