Skip to content

The platform

Run the whole management system from one place.

Not a document library with a dashboard. A system of record where every requirement has an owner, every piece of evidence has a cadence, and every report is a frozen snapshot an auditor can trust.

The unit of work

A requirement is a row. Everything hangs off it.

Adopt a standard and its clauses, controls and requirements appear. Not a checklist to build, a ledger to fill.

A.5.15 · ISO 27001:2022met

Access control

Owner
IT Manager
Evidence
Access control policy v3.0 · Quarterly access review 2026-Q2 · Workspace admin export
Cadence
Quarterly · next due 2026-10-01
Also satisfies
E8 ML2 · Restrict admin privileges · SOC2 CC6.1 to CC6.3
Documents
Access control policy · Joiner-mover-leaver procedure
Actions
None open · last CAPA closed 2026-05-12
History
14 changes · every one in the audit log

Modules

Sixteen modules. One spine.

Annex SL gives ISO 27001, 9001, 45001 and 14001 the same ten-clause skeleton, so document control, corrective action, internal audit and management review run once and serve every standard you adopt.

Know where you stand

Frameworks & requirements

Every clause and control as a row with an owner and a status.

Assessments

Guided questionnaires per standard; maturity and readiness roll up from answers.

Dashboard

Per-standard posture, what is overdue, what is due next.

Reports

Statements of Applicability, gap reports, dossiers, frozen and hashed.

Prove it

Evidence

Upload, link or generate. Collection cadence, expiry, reuse across standards.

Documents

Policies and procedures with versions, approval, acknowledgement and review dates.

Registers

Assets, risks, legal obligations, interested parties, exceptions, as data, not tabs in a spreadsheet.

Trust centre

A public page that answers questionnaires once.

Run the system

Actions & CAPA

Nonconformities, corrective actions, root cause, verification.

Internal audits

Programme, checklists, findings, follow-up.

Management reviews

Agenda from the standard; minutes as records.

Incidents, hazards & inspections

Safety and security events captured from the field.

People & suppliers

People & training

Competency matrix, acknowledgements, onboarding.

Access reviews

Periodic review of who can reach what.

Vendors

Third-party register with risk and evidence.

MSP & multi-client

One screen across clients; hard isolation between them.

Template library

More than 400 templates, included on every plan.

The toolkits ISO Assist is known for are now a module. Every policy, procedure, register and job safety analysis opens in the editor, adapts to your organisation profile, and lands in document control with a version and an approver.

ISO 27001
Policies, procedures, registers, risk and asset templates, SoA
ISO 45001
WHS policies, procedures, job safety analyses, inspection and incident forms
ISO 9001
Quality manual set, process procedures, nonconformity and CAPA forms
ISO 14001:2026
Environmental policy set, aspects and impacts, compliance obligations
SOC2
Trust Services Criteria narratives mapped from your 27001 documents

Essential Eight requirements are technical and verified in the Assessments module rather than described in documents. Import your existing .docx policies and keep working in place.

Evidence

Evidence that stays current, from the tools you already use.

Upload it, link it live from Google Workspace or Microsoft 365, or generate it from a register. Set a collection cadence and the platform tells you what is expiring before an auditor does.

Google Workspace and Microsoft 365

Documents linked, not copied. Staleness detected when the source changes or the review date passes.

Reuse across standards

One access-review export satisfies 27001 A.5.18, an Essential Eight ML2 requirement and SOC2 CC6.2, mapped once.

Deterministic upload safety

Magic-byte checks, archive inspection, PDF action scanning. Never executed, always served through signed URLs.

Auditor access

Time-boxed, read-only, scoped to the pack. Every view logged.

AI

Six ways AI does the heavy lifting. Six ways you stay in control.

Compliance state is arithmetic over your records. AI works at these labelled boundaries, every output is validated before it becomes a record, and every call is logged with its cost so you always know what it did and what it spent.

01

Interpret a written answer

Turns a free-text response into a proposed status with its reasoning. You confirm it.

02

Draft a policy or remediation plan

A first draft from your organisation profile and the template, versioned as a draft. A person approves it.

03

Summarise the gaps

A plain-English account of what is missing and what to do first.

04

Map documents to requirements

Suggests which controls a document evidences. You accept or dismiss each suggestion.

05

Review evidence against the standard

An opinion on whether a piece of evidence is sufficient, with the reasoning. Advisory, never a status.

06

Assistant across the workspace

Answers questions from your records and proposes draft changes you confirm.

Your content is treated as data, never as instructions. Uncertain output becomes needs review, never a pass.

Reports

Every report is a frozen, hashed snapshot.

Statement of Applicability, gap report, certification dossier, evidence index, maturity report. Generated from your records, stamped with a SHA-256, reproducible. Archived, never deleted.

SOA-2026-Q3Statement of Applicability2026-08-209F3A…C21E
GAP-2026-08Gap report · 27001 + E82026-08-1471D0…8B4F
DOSS-27001-S1Stage 1 dossier2026-08-210C5E…AA19
E8-ML2-Q3Essential Eight maturity report2026-08-21E4B7…3D02

A public trust page answers questionnaires once; secure links share a specific report with a specific person for a specific time.

MSPs and consultants

Every client on one screen. Hard walls between them.

Tenant isolation is enforced by the database itself, not by convention in application code. An MSP manager role spans clients; nothing else does.

Switch client and the tenant chip changes. It never hides, so you always know whose data you are looking at. Reports, evidence and registers belong to the client tenant. Your own certification runs in the parent.

Certification consultants get the same model: bring your clients, run their programmes, hand them a system that keeps working after you leave.

The MSP worked example

See the platform run your standard.

14 days free, no card. Or book a demo and we will walk it with you.