Skip to content

Compliance

The Compliance module functions as the central hub and repository for cybersecurity governance artifacts and program documentation. In addition to the Risk Assessment Management Procedure (RAMP) and the Cyber Incident Response Procedure (CIRP), it generates dynamic strategy documents, policies, and governance materials that evidence program maturity during ISO, SOC 2, and similar framework-based attestations—without thick generic templates that can bury an organization in hidden commitments and audit traps. It enables you to meet compliance standards with precise, durable processes that reflect real operating practices and incorporate platform data for end-to-end auditability.

The page is split into Governance and Program Documentation, with Program Documentation grouping Procedures and Policies. Each area has its own guide:

The Governance section generates an on-demand compliance report from live operational data — an editable PPTX covering a configurable reporting period and scope, with slides for the threat profile, remediation agility, incident detection and containment, the risk and incident flows, and a References appendix linking every cited figure back to the register. Reports generate in the background and land on the Generated Reports shelf.

See Governance Reports for configuring a report and what each slide shows.

The Cybersecurity and Privacy Governance (CyberGov) Committee oversees management’s implementation of the cybersecurity and privacy risk programs. The platform generates the committee’s charter and the reporting that anchors its meetings.

See CyberGov for the charter and running the committee.

The platform maintains your organization’s procedures — the RAMP for risk management and the CIRP for incident response, which also serve as the embeddings behind AI scoring — and its policies: the Corporate Information Security Policy (CISP), the Generative AI Acceptable Usage Policy (AIUP), and the Bug Bounty Program Scope (BBP). Every document is authored directly in the platform’s document viewer, changes take effect through a proposal-and-approval step, and each document carries calendar-based versioning with opt-in adoption of new versions.

See Program Documentation for the catalog and the document lifecycle.

Your organization’s own content can be attached to specific sections of any compliance document — rendered in place on screen and included in the downloaded Word copy, under the same approval workflow as other document edits.

See Organizational Supplements.