Catalog
One agent, every framework.
Two ways to start an engagement — and both end the same way: a testable program of controls and tests the agent runs against your evidence.
Pick a framework
Choose a shipped catalog below — SOX ITGC, SOC 2, ISO 27001, Cloud Security and more. Every control and test is already in place; the agent starts testing the moment your evidence lands.
Browse the catalogs ↓ 02Start from a template and customise
Take a catalog as your starting point — toggle what’s relevant, add your own controls and tests to match your methodology. Or skip the template entirely: upload the program you already run and the agent parses it into controls and tests.
How importing works →Shipped catalogs
ITGC
IT General Controls · SOX LiveThe IT general controls that underpin a SOX audit: access management, change management, IT operations & resilience, incident & security monitoring, data protection, and third-party management.
- 6
- domains
- 81
- controls
- 258
- tests
Cloud Security
AWS · Azure · OCI LiveIAM, logging, networking, data protection, and key management across AWS, Azure, and OCI — each control paired with a read-only command you can run yourself.
- 4
- domains
- 145
- controls
- 145
- tests
SOC 2
AICPA Trust Services Criteria LiveThe Common Criteria that appear in every SOC 2, plus Availability, Confidentiality, Processing Integrity and Privacy where you commit to them. Tests are split into suitability of design and operating effectiveness for Type II.
- 9
- domains
- 61
- controls
- 116
- tests
ISO 27001
ISO/IEC 27001:2022 · ISMS LiveManagement clauses 4–10 plus the four Annex A themes — organizational, people, physical, and technological controls — assessed against the evidence you upload.
- 5
- domains
- 123
- controls
- 269
- tests
ISO 42001
ISO/IEC 42001:2023 · AI management LiveThe AI management system standard: clauses 4–10 plus all 38 Annex A controls, from AI policy and impact assessment through the system life cycle, data provenance, and third-party responsibility.
- 9
- domains
- 64
- controls
- 143
- tests
MAS TRM
Monetary Authority of Singapore LiveTechnology Risk Management review for MAS-regulated institutions — governance, access, change, resilience, and the Cyber Hygiene measures.
- 9
- domains
- 71
- controls
- 71
- tests
DPT Platform
MAS PSA · Digital Payment Token LivePlatform audit for MAS-regulated Digital Payment Token service providers — custody, deposit and withdrawal, and the PSA compliance obligations.
- 10
- domains
- 26
- controls
- 26
- tests
Roadmap
Coming next
PCI DSS — Cardholder data
The payment-card security requirements for handling cardholder data.
Join the waitlist →NIST CSF — Govern · Identify · Protect
The cybersecurity framework core functions.
Join the waitlist →