Product overview
Your compliance program. Open to your AI.
Compliancy exposes tasks to you only when we need you involved. MCP lets you bring an AI that already “knows you” and your organization to support the compliance work — everything from evidence to policies.
Your organization’s AI
- Gemini
- ChatGPT
- Claude
- Grok
- Kimi
Native
MCP layer
Scoped access, fully audited

Platform
- Controls & frameworks
- Policies & versions
- Risks & treatments
- Evidence, with dates
Evidence this period
1,204
Automated collection
63%
Overdue items
4
AI-assisted, not AI-owned
The same data, whichever assistant you use.
Connect Claude, ChatGPT, Gemini, Kimi, Copilot or an internal agent over MCP. Access is scoped per user, every action is written back with an audit trail, and nothing leaves the platform unless you allow it.
Core product areas
Controls
Every control has an owner, an operating frequency and the frameworks it satisfies.
Policies
Policies are versioned, reviewed on a cycle and linked to the controls they support.
Risks
A risk register with owners, treatment decisions and the controls that reduce each risk.
Evidence
Evidence is stored with dates and attached to the control it demonstrates.
Assessments
Run internal assessments, DPIAs and readiness reviews, and keep the outcomes connected.
Vendors
Track vendors, agreements, data processed and review dates.
Frameworks
Map controls to SOC 2, ISO 27001, GDPR, HIPAA and CCPA at the same time.
Reporting
Report current readiness, coverage gaps and outstanding work by framework or owner.
Automation
Recurring control activity, review reminders and evidence requests run on schedule.
Inside the product
Policies and risks, exactly as your team works on them.
Policies
Create, manage and review all compliance policies.
| Policy name | Owner | Status | Version | Last reviewed |
|---|---|---|---|---|
| Data Retention Policy | Sarah Johnson | Active | 2.1 | May 10, 2024 |
| Information Security Policy | Mark Williams | Active | 3.0 | Apr 28, 2024 |
| Access Control Policy | Rachel Lee | In review | 1.4 | May 5, 2024 |
| Vendor Management Policy | James Brown | Draft | 1.0 | — |
| Incident Response Policy | Sarah Johnson | Active | 1.8 | Apr 15, 2024 |
| Acceptable Use Policy | Mark Williams | Active | 2.3 | Mar 30, 2024 |
Acknowledge POC Policy
Step: Perform Task
Workflow progress
Control procedure
Policy Acknowledgement
Go to the “Policies” tab. Review the policy and acknowledge that you have read it by certifying and submitting the task.
Resources
CCPA policy Rev 2.docx11/3/2022
Response
This looks very good! Go ahead.
Attachments
UploadControls mapped across frameworks
Reporting that reflects reality
Readiness is calculated from control state and evidence, not from a manually updated status column. When a control lapses, the affected frameworks show it.
See it with your own program.
A demo walks through controls, evidence and framework mapping using examples close to your setup.