Your policy still says 8-character passwordsPCI v4.0.1 raised the floor to 12 eighteen months ago

Generates compliance-aligned security policies with the mandated parameters locked in, and reviews the ones you already have against 473 control points, handing back the exact paragraph to insert for every gap.

Try it

Interactive demo, generate policies and run a gap analysis, no signup

How It Works

Pick frameworks, lock parameters, write, review.

01

Pick frameworks

Choose from PCI-DSS v4.0.1, ISO 27001/27002:2022, SOC 2 (TSC 2017) and the HIPAA Security Rule. The choice drives which of 473 control points apply and which parameters are mandated.

02

Lock parameters

Each framework locks the values it mandates, PCI fixes minimum password length to 12 and idle timeout to 15 minutes; HIPAA sets a 72-month retention floor. Locked fields cannot be weakened, even by accident.

03

Write

Any of 38 policies is generated as consultant-voice prose against those locked values, branded with your logo’s colours, and cited to all four frameworks in a single reference line.

04

Review

Upload an existing policy and every mapped control point is graded Covered, Partially Covered or Missing, producing a coverage score and, for each gap, the paragraph to paste in.

What You Can Do

Everything the engine does.

Two modes, one control matrix

Create a policy from scratch or review one you already have. Both run off the same 473-control-point matrix, so a generated policy and a gap analysis grade against identical criteria.

See it in the demo

Four frameworks, 473 control points

PCI-DSS v4.0.1 (203 sub-requirements), ISO 27001/27002:2022 (93 controls), SOC 2 TSC 2017 (90 criteria) and the HIPAA Security Rule (49 specifications), mapped once, applied everywhere.

See it in the demo

38 distinct policies

From Information Security and Access Control to Third-Party Risk, Data Loss Prevention and a Code of Conduct, 38 policies, each generated as its own branded, effective-dated PDF.

See it in the demo

Framework-locked parameters

The parameters a framework mandates are locked and cannot be undercut. PCI fixes password length to 12 and session timeout to 15 minutes; HIPAA’s 72-month retention overrides PCI’s 12. A generated policy physically cannot ship a non-compliant value.

See it in the demo

Consultant-voice prose, not templates

Each policy is written against the locked parameters as real prose, with a unified reference line citing all four frameworks at once, [PCI 8.3.6 | ISO 5.17 | SOC CC6.1 | HIPAA §164.308(a)(5)(ii)(D)].

See it in the demo

Auto-detected policy review

Upload one or many DOCX or PDF policies and each is auto-detected from its filename and mapped to the right control points, with an overridable dropdown if the guess is wrong.

See it in the demo

A coverage score with the working shown

Every control point is graded Covered, Partially Covered or Missing, producing a weighted coverage percentage on a colour-banded gauge, with the count of each behind it.

See it in the demo

Gaps come with the fix

Every Missing or Partial control point carries a ready-to-insert policy paragraph and a suggested section, so closing a gap is a paste, not a drafting exercise. The 8-character password rule is flagged and the 12-character replacement is written.

See it in the demo

XLSX and PDF deliverables

Review produces a two-sheet gap-analysis workbook (sortable, filterable) and a branded PDF report; create produces a branded PDF per policy, the artifacts an auditor and a board actually read.

See it in the demo

Business Outcomes

What it changes.

Locked

A generated policy cannot undercut a mandate, because the mandated parameters are disabled and cited at the point of authoring.

Current

A three-year-old policy is graded against today’s requirements, so v4.0.1 drift like the 8-character password rule surfaces before an assessor finds it.

Actionable

Each gap arrives with the paragraph to insert and the section it belongs in, turning remediation into a paste rather than a rewrite.

Policies that cannot undercut a mandate.

Generate a compliant policy set or grade the one you have in minutes, with every gap carrying its fix.