High level views power the daily workflow: mapped citations across every framework, live posture metrics per domain, a guided project plan, a Policy Templates downloads centre with 238 policy and templates, and a controls library mapping every obligation to evidence. Audit, Risk, Asset, Exception, Supplier and Issue management all available out of the box and connected dynamically to your Framework obligations.
One list across NIST SP 800-53, NIST CSF 2.0, ISO/IEC 27001, GDPR, NIS2, WCAG 2.2 and the EU AI Act. Filter by framework, status or domain — 238 documents, mandatory vs desirable, fully searchable.

Real-time posture per domain and per framework: Governance, Risk, Asset Management, Access Control, Incident Response and more. Non-compliant items surface immediately so remediation is targeted, not guessed.

A PMP-aligned ISMS implementation plan that takes a complete novice to a fully operational ISMS, ready for external audit. 73 tasks across 7 phases, with framework filters and live progress tracking.

238 policy, procedure and register templates ready to download — every one mapped to the underlying ISO, NIST, GDPR, NIS2, WCAG and EU AI Act controls so auditors can trace evidence in seconds.

202 controls mapped to 33 control objectives with 324 preloaded and connected control tests out of the box. Each control links to its policies, evidence, owner, test method and residual risk — one source of truth for audit.


A glance at the operational surfaces that sit behind the five core views — every register, every feed and every report rendered exactly as your team will see it.

Inherent vs residual scoring, treatments and ownership.

Unified queue for findings, non-conformities and corrective actions.

Approved deviations with mandatory expiry and compensating control.

Live registers — owned, on cadence and linked to controls, tests and evidence.

Curated regulatory, vulnerability, threat and AppSec feeds in one place.

Named individuals mapped to departments, role levels and responsibilities.

Branded PDF assurance reports per framework, ready to download.

Pick sections and registers — filename and scope previewed before export.

Executive summary, dashboard, operating chain and obligations — auditor-ready.
Every template ships fully drafted — purpose, scope, architecture, requirements, references and framework mappings — not a blank shell. Watermarked samples below show the level of detail you get in every .docx.

Covers internal DNS architecture, DNSSEC, DNS-over-TLS and DNS-over-HTTPS controls. Mapped to ISO/IEC 27001:2022 A.8.20, NIST SP 800-53 SC-20/21/22, and the relevant RFCs.

Zero Trust Network Access architecture, legacy VPN controls, device requirements, MFA and third-party access. Mapped to ISO 27001 A.6.7, NIST SP 800-207, NIST CSF 2.0 PR.AA-05 and NIS2 Art. 21(2)(j).
Samples shown are watermarked previews. Unlocked templates are delivered as fully editable .docx files.
Pick one or stack them. Every box below can be enabled immediately from your account after sign-up — no sales calls, no consultancy gating.
Buy individual policy template domains or the full 238-template bundle. Download as .docx, mapped to ISO, NIST, GDPR, NIS2, WCAG and the EU AI Act. No platform subscription required.
Full platform access — mapped citations, posture dashboard, project plan, registers, audits and reports. One Business Unit included; add more on demand. Card-required 14-day free trial.
Stream the immutable audit log to Splunk, Datadog, Elastic or any HTTPS SIEM in near real-time. Stacks on top of any App subscription.