Personal Business Look closer How we work How we score Questions Security and trust Talk to us Sign in Book your audit
Regulatory Compliance

Set what we find against the rules that apply to you

Automated compliance mapping against FTC guidelines, CCPA, and state privacy laws. Document your due diligence with evidence-backed assessments.

FTC/CCPA Mapping
Each finding set against the rule it touches
Breach Notification
Whether you have to report it
Insurance Documentation
The file your insurer asks for
Continuous Monitoring
Re-checked each quarter
Capabilities

What We Assess

Automated compliance posture assessment mapped against the regulatory frameworks applicable to your practice's jurisdiction and industry.

FTC/State Law Compliance Mapping
Map security findings to specific regulatory obligations. Covers FTC Act Section 5, CCPA, and state-specific privacy laws.
Do you have to report it
Whether what we found means you are legally required to tell somebody.
What the insurer wants
The file an insurer asks for at application and again at renewal.
Kept current
Checked again each quarter, so you can see when something new has changed where you stand.
Platform

Compliance In Action

How a finding becomes a document you can hand to somebody who asks.

Framework Mapping

Findings set against PIPEDA, SOC 2, ISO 27001 and the other frameworks that reach a practice like yours.

Evidence Collection

The paperwork writes itself from what was found, dated, with the evidence attached.

Gap Analysis

Where you fall short, named against the specific rule that says so.

Audit Readiness

A dated summary an auditor or an insurer will accept.

Regulatory Framework Map3 Gaps Found
PIPEDA, Personal Information ProtectionCompliant
SOC 2, Trust Services Criteria2 Gaps
ISO 27001, Information Security1 Gap
CASL, Anti-Spam LegislationCompliant
PCI DSS, Payment Card IndustryCompliant
15+
Frameworks Mapped
82%
Overall Compliance
3
Open Gaps
Q1
Last Assessment
Evidence Collection LogAuto-Generated
Password check, datedMar 31, 2026
Systems check, evidence attachedMar 31, 2026
Domain and certificate checkMar 30, 2026
Dark web monitoring sweepMar 29, 2026
48
Evidence Items
12
Report Types
PDF
Export Format
Auto
Generation
Control Gap Analysis3 Deficiencies
SOC 2 CC6.1, Logical access controls insufficientCritical
SOC 2 CC7.2, Monitoring incompleteMedium
ISO 27001 A.12.4, Logging gapsMedium
Control Coverage82%
47
Controls Assessed
3
Gaps Identified
Audit Readiness ReportReady
One-page summary, writtenPDF Ready
Rules mapping, writtenPDF Ready
Evidence, gatheredPDF Ready
Insurer file, writtenPDF Ready
Audit Readiness ScoreREADY
5
Report Types
92%
Readiness Score
Process

How It Works

Five steps, and you can see everything your practice is showing.

1
2
3
4
5
Step 01
We Map Your Domain

Everything your practice publishes without meaning to: forgotten subdomains, open services, certificates and DNS.

Coverage

Which rules we cover

Your findings set against the privacy and security rules that actually apply to you.

15+
Frameworks we set findings against
Quarterly
Reassessment cadence
Accepted
By insurers
Industries

Who This Is For

Practices navigating regulatory obligations, insurance requirements, or board-level due diligence expectations.

Healthcare
Map data exposure against HIPAA, state breach notification laws, and FTC health data requirements.
Financial Services
Document compliance posture for GLBA, SEC guidance, and state financial privacy regulations.
Any Regulated Business
What your partners, your auditor and your insurer each need to see.

Look at my practice

One look at your domain, set against the rules you answer to, with the paperwork written for you.

Look at my practice