The platform
Run the whole management system from one place.
Not a document library with a dashboard. A system of record where every requirement has an owner, every piece of evidence has a cadence, and every report is a frozen snapshot an auditor can trust.
The unit of work
A requirement is a row. Everything hangs off it.
Adopt a standard and its clauses, controls and requirements appear. Not a checklist to build, a ledger to fill.
Access control
- Owner
- IT Manager
- Evidence
- Access control policy v3.0 · Quarterly access review 2026-Q2 · Workspace admin export
- Cadence
- Quarterly · next due 2026-10-01
- Also satisfies
- E8 ML2 · Restrict admin privileges · SOC2 CC6.1 to CC6.3
- Documents
- Access control policy · Joiner-mover-leaver procedure
- Actions
- None open · last CAPA closed 2026-05-12
- History
- 14 changes · every one in the audit log
Modules
Sixteen modules. One spine.
Annex SL gives ISO 27001, 9001, 45001 and 14001 the same ten-clause skeleton, so document control, corrective action, internal audit and management review run once and serve every standard you adopt.
Know where you stand
Frameworks & requirements
Every clause and control as a row with an owner and a status.
Assessments
Guided questionnaires per standard; maturity and readiness roll up from answers.
Dashboard
Per-standard posture, what is overdue, what is due next.
Reports
Statements of Applicability, gap reports, dossiers, frozen and hashed.
Prove it
Evidence
Upload, link or generate. Collection cadence, expiry, reuse across standards.
Documents
Policies and procedures with versions, approval, acknowledgement and review dates.
Registers
Assets, risks, legal obligations, interested parties, exceptions, as data, not tabs in a spreadsheet.
Trust centre
A public page that answers questionnaires once.
Run the system
Actions & CAPA
Nonconformities, corrective actions, root cause, verification.
Internal audits
Programme, checklists, findings, follow-up.
Management reviews
Agenda from the standard; minutes as records.
Incidents, hazards & inspections
Safety and security events captured from the field.
People & suppliers
People & training
Competency matrix, acknowledgements, onboarding.
Access reviews
Periodic review of who can reach what.
Vendors
Third-party register with risk and evidence.
MSP & multi-client
One screen across clients; hard isolation between them.
Template library
More than 400 templates, included on every plan.
The toolkits ISO Assist is known for are now a module. Every policy, procedure, register and job safety analysis opens in the editor, adapts to your organisation profile, and lands in document control with a version and an approver.
- ISO 27001
- Policies, procedures, registers, risk and asset templates, SoA
- ISO 45001
- WHS policies, procedures, job safety analyses, inspection and incident forms
- ISO 9001
- Quality manual set, process procedures, nonconformity and CAPA forms
- ISO 14001:2026
- Environmental policy set, aspects and impacts, compliance obligations
- SOC2
- Trust Services Criteria narratives mapped from your 27001 documents
Essential Eight requirements are technical and verified in the Assessments module rather than described in documents. Import your existing .docx policies and keep working in place.
Evidence
Evidence that stays current, from the tools you already use.
Upload it, link it live from Google Workspace or Microsoft 365, or generate it from a register. Set a collection cadence and the platform tells you what is expiring before an auditor does.
Google Workspace and Microsoft 365
Documents linked, not copied. Staleness detected when the source changes or the review date passes.
Reuse across standards
One access-review export satisfies 27001 A.5.18, an Essential Eight ML2 requirement and SOC2 CC6.2, mapped once.
Deterministic upload safety
Magic-byte checks, archive inspection, PDF action scanning. Never executed, always served through signed URLs.
Auditor access
Time-boxed, read-only, scoped to the pack. Every view logged.
AI
Six ways AI does the heavy lifting. Six ways you stay in control.
Compliance state is arithmetic over your records. AI works at these labelled boundaries, every output is validated before it becomes a record, and every call is logged with its cost so you always know what it did and what it spent.
01
Interpret a written answer
Turns a free-text response into a proposed status with its reasoning. You confirm it.
02
Draft a policy or remediation plan
A first draft from your organisation profile and the template, versioned as a draft. A person approves it.
03
Summarise the gaps
A plain-English account of what is missing and what to do first.
04
Map documents to requirements
Suggests which controls a document evidences. You accept or dismiss each suggestion.
05
Review evidence against the standard
An opinion on whether a piece of evidence is sufficient, with the reasoning. Advisory, never a status.
06
Assistant across the workspace
Answers questions from your records and proposes draft changes you confirm.
Your content is treated as data, never as instructions. Uncertain output becomes needs review, never a pass.
Reports
Every report is a frozen, hashed snapshot.
Statement of Applicability, gap report, certification dossier, evidence index, maturity report. Generated from your records, stamped with a SHA-256, reproducible. Archived, never deleted.
A public trust page answers questionnaires once; secure links share a specific report with a specific person for a specific time.
MSPs and consultants
Every client on one screen. Hard walls between them.
Tenant isolation is enforced by the database itself, not by convention in application code. An MSP manager role spans clients; nothing else does.
Switch client and the tenant chip changes. It never hides, so you always know whose data you are looking at. Reports, evidence and registers belong to the client tenant. Your own certification runs in the parent.
Certification consultants get the same model: bring your clients, run their programmes, hand them a system that keeps working after you leave.
Standards
Six standards. One spine.
SECURITY · SUPPORTED
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS).
SECURITY · SUPPORTED
ACSC Essential Eight
The Australian Signals Directorate's eight mitigation strategies, assessed at maturity levels 1–3.
QUALITY · SUPPORTED
ISO 9001:2015
Quality management: consistent processes, measured outcomes, corrective action that sticks.
SAFETY · SUPPORTED
ISO 45001:2018
Occupational health and safety management, aligned to the AU WHS Act and regulations.
ENVIRONMENT · SUPPORTED
ISO 14001:2026
Environmental management on the 2026 edition, with a 36-month transition from 2015.
ASSURANCE · SUPPORTED
SOC2
AICPA Trust Services Criteria for service organisations, run from the same evidence as your ISO 27001 controls.
See the platform run your standard.
14 days free, no card. Or book a demo and we will walk it with you.