Compliance Posture

Progress against ISO 27001, SOC 2, and GDPR with a per-control checklist, versioned evidence, and an audit report in PDF.

Last reviewed:

Compliance evidence is almost never ready on the day a large client asks for it as a condition of sale. This module exists so that day does not catch you off guard.

What it measures

How far you are from meeting the framework being asked of you — ISO 27001, SOC 2, or GDPR — control by control, with the supporting documents attached to each one.

How to set it up

  1. 1

    Activate a framework

    Pick the one being demanded of you. On Starter you can have one active at a time; from Growth on, as many in parallel as you want.

  2. 2

    Work through the checklist

    Each control is marked Not started, In progress, Implemented, or Not applicable, and takes internal notes. Nobody outside your organization sees the notes.

  3. 3

    Attach evidence

    Upload the document backing each control — policy, screenshot, contract, log. Up to 10 MB per file. It is stored with a date and the name of whoever uploaded it.

  4. 4

    Review the evidence

    Every file arrives as *Pending review* and someone on your team approves or rejects it. That is what separates a file repository from a compliance program.

How to read the result

The maturity score is a percentage with a deliberately simple formula:

implemented controls ÷ (total controls − those marked "not applicable") × 100

Marking a control Not applicable removes it from the denominator and therefore raises your score. That is legitimate when the control genuinely does not apply to your operation — a control about your own data center at a company that runs entirely in the cloud, say — but it is the easiest lever to abuse without noticing. Always write why it does not apply in the notes: it is the first thing an auditor will question.

The score recalculates on its own the moment you change any control's status, and stores a daily snapshot. That series is the trend, and it is usually more useful than the number: it shows whether the program is moving or has been parked for three months.

What to do with the result

  • Generate the audit PDF when someone asks you for evidence. It carries the framework, the score, the control table with statuses and notes, and the evidence list with dates — ready to hand over as is.
  • Work the not-started controls before the in-progress ones. The first group tends to be real gaps; the second is work already underway that just needs closing.
  • Revisit old evidence. A policy approved two years ago and never updated is an audit finding, even if the control shows as implemented.
  • Deactivating a framework deletes nothing. The checklist and evidence are kept; it simply stops counting toward your plan limit. That is how you switch frameworks on Starter without losing work.