One compliance platform.
Five frameworks. Every artifact your auditor asks for.
Complyanz runs ISO 27001, ISO 27701, ISO 42001, SOC 2 and HIPAA in a single workspace — risk registers, controls, evidence and the audit-ready document set — so one team can carry certifications, attestations and regulatory programs at the same time.
Certifications, attestations and regulations — in one place
Enable the programs you need. Each one arrives with its own controls, risk library, document set and dashboard.
Add a standard. Don't start a second program.
Most tools sell one framework per subscription, so a second certification means a second set of policies, a second risk register and the same work done twice. In Complyanz the ISO standards compose: ISO 27001 is the foundation, and privacy and AI extend it into one integrated management system with a single, consistent document set.
Adding privacy to an existing ISMS moves you from 36 documents to 38 — not to 36 plus a separate privacy library. The overlapping clauses stay in one place, which is exactly what an integrated management system is supposed to deliver.
The same path your assessor expects
Each framework carries its own roadmap in the product. The shape is consistent, so a team that has run one program can run the next.
Scope
Define the organization, the boundary and the standards in play. Locations, entities and interested parties are captured once and reused across every program.
Assets and risk
Register the assets in scope with their confidentiality, integrity and availability values, then build the risk register from a library of 266 pre-written ISO scenarios.
Controls and applicability
Work through the controls for each active standard, record justifications and produce the Statement of Applicability, Controls Applicability Matrix or Safeguard Applicability the assessor wants.
Evidence and audit
Attach evidence to controls, run internal audits and management reviews, log incidents and corrective actions, and walk into the audit with the trail already assembled.
Nine modules, one system of record
Everything a compliance program generates — risks, controls, documents, evidence, incidents, people and suppliers — lives in one place and stays linked.
Risk register and treatment plans
Build the register from 266 pre-written ISO scenarios or your own. Map each risk to the controls that treat it, set owners and track residual risk to closure.
Statement of Applicability
The document an ISO auditor asks for first. Walk all 93 Annex A controls, record inclusion or exclusion with justification, and export the SoA. SOC 2 and HIPAA get their equivalent applicability views.
Document library
90 ISO documents, tagged by management-system variant, plus dedicated SOC 2 and HIPAA sets. Pre-filled with your organization's details and exported as formatted Word and PDF files.
Evidence vault
Attach evidence directly to the control or criterion it proves, with the audit period it covers. When the assessor asks, the answer is one click away instead of one email thread.
Incidents and corrective actions
Log security and privacy incidents, classify severity, and drive corrective actions to closure. Breach records and notification readiness are built in for HIPAA.
Suppliers and business associates
Track third parties, the data they touch and the assurance you hold over them — including business associate agreements for organizations handling protected health information.
Training and awareness
Assign awareness training, record completion and keep the evidence every framework asks for when it wants proof that your people know the policies.
AI systems and impact assessments
Inventory the AI systems you build or buy, classify their impact across affected domains, and produce the assessments ISO 42001 expects.
Management review and internal audit
Run the governance cycle the standards mandate — internal audits, management reviews, metrics and continual improvement — with the minutes and records generated as you go.
Spreadsheets and consultants, or one system of record
Most compliance programs start in a shared drive. They work until the first audit, the first standard added, or the first person who owned the spreadsheet leaves.
| Spreadsheets and consultants | Complyanz | |
|---|---|---|
| Getting started | A blank workbook, or a consultant's template pack that has to be adapted to your organization before it means anything. | Controls, risk scenarios and documents are pre-loaded for every standard you enable, already tied to your organization's details. |
| Writing the documents | Authored by hand or bought as a static pack, then edited in a shared drive where version history is whoever remembered to rename the file. | Generated from a maintained library, filled with your data, versioned in the platform and exported as Word or PDF. |
| Evidence at audit time | Screenshots gathered in the fortnight before the audit, chased over email, stored wherever the person who collected them put them. | Attached to the control it proves as part of normal work, with the period it covers recorded alongside it. |
| Adding a second framework | A second workbook and a second document set, with overlapping requirements maintained twice and drifting apart. | Enable the standard. ISO extensions integrate into one management system; SOC 2 and HIPAA reuse the assets, risks and evidence you already hold. |
| Keeping it alive between audits | Nothing happens until the surveillance audit is scheduled, and then the scramble repeats. | Internal audits, management reviews, corrective actions and training run on a schedule, with the records produced as a by-product. |
| Where the knowledge lives | With the consultant, or with one person and their spreadsheet. | In the platform, with roles per family so the right people see the right program. |
AI that drafts the work, not the decisions
Complyanz uses AI where it removes typing and leaves judgement with your team: drafting risk scenarios for the assets you register, filling policy content from your organization's details, suggesting control justifications, and scoring how ready a program looks.
Deterministic where it matters
Document selection, template filling and exports are deterministic. If AI is unavailable, those flows keep working exactly as before — the artifacts you hand an auditor never depend on a model being up.
Your data is not training data
Content sent to the configured model provider is used to answer your request and nothing else. It is not used to train models. Full detail is in the privacy policy.
Frequently asked
Does Complyanz certify us?
No, and no software can. Certification is issued by an accredited certification body, and a SOC 2 report is issued by a CPA firm. Complyanz gets you audit-ready and gives you the artifacts and evidence trail those assessors ask for.
How long does it take to get certified?
It depends on your scope, how much of the groundwork already exists and your assessor's availability — so anyone quoting a fixed number is guessing. What Complyanz changes is the preparation: the controls, risk library and documents are already there, so the time goes into decisions rather than authoring.
Can we run ISO 27001 and SOC 2 at the same time?
Yes. They are separate programs with separate applicability views, but they share the same assets, risks, evidence and people, so the underlying work is done once.
What is an integrated management system?
When you certify to several ISO standards, their requirements overlap heavily. An integrated management system maintains one set of policies and procedures covering all of them instead of parallel copies. Complyanz ships pre-built document sets for each combination: ISO 27001 alone, plus privacy, plus AI, or all three.
Are the documents actually accepted by auditors?
They are authored against the clause structure of each standard, tagged to the standards and management-system variant they apply to, and exported as formatted Word and PDF files. Your auditor still assesses whether the content reflects what your organization genuinely does — no document pack can substitute for that.
Can one person work across several organizations?
Yes. One identity can belong to many organizations and switch between them, which is how consultancies and groups with multiple legal entities use the platform. Roles are held per organization, and per framework family within it.
What happens to our data?
Your data belongs to you, is scoped to your organization, and can be exported. Content sent to the AI provider is not used to train models. The privacy policy has the detail.
Do we still need a consultant?
Many teams do not, and those that do use one for less time. Complyanz covers the structure and the artifacts; a consultant is most valuable on scope decisions and readiness review, which is a much smaller engagement than authoring a management system from scratch.
Is there a free tier?
You can create an organization and start building without a credit card. Get in touch if you want a walkthrough before committing time to it.
Start with one framework. Add the rest when you are ready.
Create an organization, pick the standards you are working towards, and the controls, risks and documents are waiting for you.