Org Compass
The discovery layer. Before anything is collected or assessed, the Compass maps your compliance landscape — entities, frameworks, scope boundaries, organizational profile, and readiness state. You can't assess what you haven't mapped.
Organizational Profiling
12 domains. Complete organizational context.
Before the Velocity Engine runs, it needs to understand your organization. Org Scoping guides you through 12 compliance domains — giving the AI the context it needs for accurate, relevant assessments.
Each domain has guided questions. Answer them once — the Compass remembers and uses this context across all assessments, evidence collection, and artifact generation.
Infrastructure
Data Governance
Workforce & Access
Third Parties
Operations
Technical Controls
Business Context
Governance Maturity
Prior Audits
Evidence Readiness
System Boundaries
Compensating Controls
Entity 360 — 9 views per entity
Each entity is a complete compliance unit — with its own frameworks, documents, assessment history, cloud accounts, and compliance posture.
Entity 360
Single pane of glass per entity.
Every application, business unit, or system gets a complete 360-degree view. See frameworks assigned, documents uploaded, scoping progress, readiness state, assessments run, and compliance posture — all in one place.
- ✓ Frameworks assigned and tracked per entity
- ✓ Document library with ingestion status
- ✓ Per-entity scope governance
- ✓ Assessment history and compliance scores
- ✓ Cloud account connections and scan results
- ✓ Full activity timeline
Framework Hub
78+ frameworks. Assign, map, track.
All your compliance standards in one place. Assign frameworks to entities, track coverage across controls, and leverage cross-framework mapping so shared evidence satisfies multiple standards at once.
- ✓ SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, DORA, NIS2, and 70+ more
- ✓ Cross-framework control mapping (shared evidence reuse)
- ✓ Per-entity framework assignment
- ✓ Coverage tracking and gap visibility
- ✓ Custom framework support
SOC 2
ISO 27001
HIPAA
PCI-DSS
GDPR
DORA
NIS2
NIST
+70
Readiness Checks
Are you ready for assessment?
Before the Compliance Cortex runs, Readiness Checks validate that you have enough data for a meaningful assessment — org profile, documents, cloud accounts, and scope boundaries.
- ✓ Pre-flight checks before assessment launches
- ✓ Clear checklist: what's done, what's missing
- ✓ Readiness percentage per entity
- ✓ Actionable guidance to reach 100%
What Comes Next
Once the Compass has mapped your landscape...
The Velocity Engine takes over. Evidence Fabric captures proof. Compliance Cortex scores every control. Assurance Loom weaves the artifacts. All informed by the context the Compass provides.