Who it's for
Today
You are the founder or ops lead. There is no compliance hire, and a consultant quoted weeks.
With Quick Policy
You answer a short profile (sector, size, jurisdiction) and get four drafts that read like your firm.
Four core drafts written from a six-to-eight-minute profile of your sector, size and regions. Each is scored against the frameworks you selected — ISO 27001, SOC 2, UK GDPR — with every gap listed and how to close it.
Built for UK operators, not a GRC department
Who it's for
Today
You are the founder or ops lead. There is no compliance hire, and a consultant quoted weeks.
With Quick Policy
You answer a short profile (sector, size, jurisdiction) and get four drafts that read like your firm.
The pack that doesn't fit
Today
A 40-page template pack that still says "[Company Name]", or a portal built for a bank.
With Quick Policy
The drafts are yours to edit. ISO 27001, SOC 2 and UK GDPR sit on the scorecard, not in a 400-standard catalogue you have to browse.
Standing behind it
Today
A customer or auditor asks for policies and you would rather not attach last year's Word doc.
With Quick Policy
You have reviewed the four cores and the PASS / WARN / FAIL notes. Publishing and PDFs wait until you choose a plan.
Training, audit rooms and EU AI Act workflows are in the product and come later. First-run is preview, four drafts, review.
What the preview produces
The profile you complete decides what goes in them. A payroll bureau and a software firm answer the same questions and get different obligations, different owners, and different evidence expectations.
IT security
Information Security Policy
Access, acceptable use and the controls an ISO 27001 or SOC 2 reviewer asks to see first.
Data protection
Data Protection Policy
Lawful basis, retention and subject rights, written against UK GDPR rather than the EU original.
Operations
Business Continuity Policy
What happens when something breaks, who decides, and how long you have said it takes.
Compliance
Anti-Bribery & Corruption Policy
The conduct obligations a customer due-diligence questionnaire asks about by name.
Fifteen more policy families are in the library, and the generator can draft any of them once you are set up. Browse the policy library.
Your organisation profile and documents are processed to produce your drafts and for nothing else. We do not use your content to train AI models, and the providers we use are engaged under commercial terms that bar them from doing so. Every sub-processor, what it receives and where, is listed publicly.
No. The drafts are generated from a structured profile of your organisation, then scored against the frameworks you selected — ISO 27001, SOC 2, UK GDPR — with a pass mark per standard and a list of what is missing. A chat window will write you a policy; it will not tell you where that policy falls short of a named control, and it will not keep the two in step when the standard changes.
Your content is processed to produce your drafts and for nothing else. We do not use it to train AI models, and the AI providers we use are engaged under commercial terms that bar them from training on submitted content. The current sub-processor list, what each one receives and why, is published at quickpolicy.co.uk/subprocessors.
The guided preview is free and takes no card: you complete onboarding and generate four core drafts from your own organisation, and you can read and review them in full. Publishing, PDF export and team sign-off need a plan, which starts at £99 per month excluding VAT. Annual billing is eight times the monthly price, so four months are free.
That is your decision to make, not ours to promise. What the product gives you is the working: every draft is mapped to the controls it is answering, scored against the standards you selected, and carries a record of who reviewed and approved it. Policies are drafts for your review — a person in your organisation still has to read, amend and adopt them.