Compliance Assessment
Prove Compliance Across 13 Frameworks
1000+questions mapped to NIST, CIS, HIPAA, SOC 2, ISO 27001, PCI DSS, EU AI Act, and more. Scored results, gap analysis, and AI-powered remediation playbooks — not just a checklist, but a roadmap to compliance.

13 FRAMEWORKS
Comprehensive Coverage
Traditional security frameworks extended with AI-specific controls.
NIST 800-53
360 questions
Federal security controls
CIS Controls v8
179 questions
Prioritized security actions
NIST CSF 2.0
119 questions
Cybersecurity risk management
SOC 2
84 questions
Trust services criteria
HIPAA
80 questions
Healthcare data protection
AI Security
97 questions
AI security governance (free)
AI Agent Security
26 questions
Agent governance & MITRE ATLAS agentic techniques (free)
NIST AI RMF
80 questions
AI risk governance (Govern, Map, Measure, Manage)
NIST IR 8401
82 questions
Satellite ground segment cybersecurity — space vertical
ISO/IEC 42001
69 questions
AI management system — clauses 4-10 + all 38 Annex A controls
OWASP LLM Top 10 (2025)
77 questions
LLM application security — full OWASP coverage across all 10 categories
NIST AI 600-1 (GAI Profile)
44 questions
Generative AI Profile of NIST AI RMF — 12 GAI risks × GOVERN/MAP/MEASURE/MANAGE actions
ISO 27001
Coming Soon110 questions
Information security management
PCI DSS
Coming Soon124 questions
Payment card security
CAPABILITIES
More Than a Checklist
Assessments that tell you what's wrong, why it matters, and exactly how to fix it.
Structured Questionnaires
Framework-specific questions mapped directly to compliance controls. Answer once, map to multiple frameworks where controls overlap.
Scored Results & Grades
Weighted category averages on a 0-100 scale with letter grades A-F. See exactly where you stand across each framework domain.
AI-Powered Remediation
Get actionable remediation playbooks generated from your specific gaps. Prioritized by risk severity and implementation effort.
Trend Tracking
Compare scores across assessments over time. Track your compliance trajectory and demonstrate improvement to stakeholders.
Continuous Monitoring
Connect GitHub and your compliance scores refresh automatically every morning. When new evidence causes a control to regress, the org owner gets an email with severity-tiered alerts — triage critical drops (failing grades) separately from minor regressions. Configurable per-organization — talk to sales.
Gap Analysis
Identify exactly which controls are failing across which frameworks. Cross-framework gap analysis shows systemic weaknesses.
Compliance Evidence
Every answer becomes audit evidence. Export compliance-mapped reports that auditors can trace directly to framework requirements.
Compliance Scores Feed Your Governance
Assessment results integrate with your AI system registry, Trust Gap scoring, and executive reports. One assessment improves visibility across your entire security posture.
Start Your First Assessment Free
97-question AI Security assessment with scored results and recommendations. No credit card required.
