03 · Compliance

Evidence ready before the audit.

Everything the platform carries under compliance: self-assessment, the internal audit lifecycle, the evidence behind it, what the regulators change, and incidents.

Request a demo

19 screens in 5 groups, all of it on your own infrastructure.

Self-assessment

  • Self-Assessment

    Assess your controls against any loaded framework, at the pace that suits you.

  • Policy Assessments

    Check that what the policy says is what the controls and the evidence show.

  • Self-Assessment Dashboard

    Coverage, score and gaps per framework and per domain, as they stand today.

Internal audit

  • Audit Plans

    The annual plan: what is audited, when, by whom and on what basis.

  • Audit Projects

    Each engagement with its team, timeline, working papers and status.

  • Scope

    What the audit covers, tied to the controls, assets and processes inside it.

  • Work Programs

    Test steps per control, with the sample, the result and the evidence attached.

  • Findings

    Raised with severity, owner and due date, and the remediation that closes them.

  • Audit Reports

    Drafted from the work itself, in Arabic or English, ready for the committee.

Evidence

  • Evidence Library

    Every artefact in one place, classified and attached to the control it proves.

  • Ask my Evidence

    Ask in your own words; the answer comes from your evidence, with its source.

  • Evidence Coverage

    Which controls are proven, which are not, and what expires next.

  • Evidence Anomalies

    Duplicates, stale documents and evidence that does not match the control it sits on.

  • Awareness Evidence

    Training and awareness completions posted as evidence, with no sheet to upload.

Regulatory & oversight

  • Framework Updates

    When a regulator changes a framework, you see what it touches in your controls.

  • Compliance Calendar

    Submission dates, renewals and review cycles on one calendar.

Incident Command

  • Incident Hub

    One hub from the first report to closure, with tasks, timeline and communications.

  • PDPL 72-Hour Clock

    The breach clock starts with the incident and shows what is due before it runs out.

  • Breach Lineage

    What the incident touched: assets, data, controls, risks and obligations, in one line.

The rest of the platform

One record, three disciplines.

The same record carries governance, risk and compliance. Nothing is re-entered when it crosses from one to the next.

See it in the clear.

Tell us a little about your entity and what you would like to see, and we will arrange a private demonstration on your frameworks, in your language.

Step 1 of 3 · Entity

Start with the country code, for example +966

Prefer WhatsApp? Message us