Velocity Engine · Layer 1

Org Compass

The discovery layer. Before anything is collected or assessed, the Compass maps your compliance landscape — entities, frameworks, scope boundaries, organizational profile, and readiness state. You can't assess what you haven't mapped.

12 Scoping Domains
78+ Frameworks
360° Entity View
AI Guided Scoping

Organizational Profiling

12 domains. Complete organizational context.

Before the Velocity Engine runs, it needs to understand your organization. Org Scoping guides you through 12 compliance domains — giving the AI the context it needs for accurate, relevant assessments.

Each domain has guided questions. Answer them once — the Compass remembers and uses this context across all assessments, evidence collection, and artifact generation.

Infrastructure

Data Governance

Workforce & Access

Third Parties

Operations

Technical Controls

Business Context

Governance Maturity

Prior Audits

Evidence Readiness

System Boundaries

Compensating Controls

Entity 360 — 9 views per entity

Overview Documents Scoping Readiness Action Plans Compliance Compliance Scans Graph Activity

Each entity is a complete compliance unit — with its own frameworks, documents, assessment history, cloud accounts, and compliance posture.

Entity 360

Single pane of glass per entity.

Every application, business unit, or system gets a complete 360-degree view. See frameworks assigned, documents uploaded, scoping progress, readiness state, assessments run, and compliance posture — all in one place.

  • Frameworks assigned and tracked per entity
  • Document library with ingestion status
  • Per-entity scope governance
  • Assessment history and compliance scores
  • Cloud account connections and scan results
  • Full activity timeline

Framework Hub

78+ frameworks. Assign, map, track.

All your compliance standards in one place. Assign frameworks to entities, track coverage across controls, and leverage cross-framework mapping so shared evidence satisfies multiple standards at once.

  • SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, DORA, NIS2, and 70+ more
  • Cross-framework control mapping (shared evidence reuse)
  • Per-entity framework assignment
  • Coverage tracking and gap visibility
  • Custom framework support
See all 78+ frameworks →

SOC 2

ISO 27001

HIPAA

PCI-DSS

GDPR

DORA

NIS2

NIST

+70

Org profile complete
Frameworks assigned
Documents uploaded (5+)
Cloud account connected
Scope governance complete
Readiness 60%

Readiness Checks

Are you ready for assessment?

Before the Compliance Cortex runs, Readiness Checks validate that you have enough data for a meaningful assessment — org profile, documents, cloud accounts, and scope boundaries.

  • Pre-flight checks before assessment launches
  • Clear checklist: what's done, what's missing
  • Readiness percentage per entity
  • Actionable guidance to reach 100%

What Comes Next

Once the Compass has mapped your landscape...

The Velocity Engine takes over. Evidence Fabric captures proof. Compliance Cortex scores every control. Assurance Loom weaves the artifacts. All informed by the context the Compass provides.

Compass Fabric Cortex Loom