Skip to main content
First-run platform

Guided preview, four core drafts, then review

Complete onboarding, generate four core policy drafts from your organisation, and review them against ISO 27001, SOC 2, and UK GDPR. Publishing and PDFs unlock after you choose a plan.

Guided preview, no card
Four core policy drafts
ISO / SOC 2 / UK GDPR review
Upgrade before publish or PDFs

Standards assurance

Guided preview
Four core policies
ISO / SOC 2 PASS scorecard
No card required

What first-run includes

Capture your organisation profile, generate four core drafts, and review them. Extra modules stay in the product for later — they are not sold as live today.

Guided preview and onboarding

No card required. Core onboarding captures sector, size, and jurisdiction so the first drafts are grounded in your organisation, not a generic template pack.

Outcome: A verified organisation profile that unlocks generation of the four core policy drafts.

Four core policy drafts

AI drafts the first four policies from that profile. Other policy families can be generated later; first-run is not a 15-template library.

Outcome: Review-ready drafts you can edit before anything is published.

ISO 27001, SOC 2, and UK GDPR review

Score the drafts against the frameworks you selected. A PASS scorecard on ISO 27001 and SOC 2 is the first-run review, not a finished audit programme.

Outcome: See gaps in plain English, then choose a plan before publishing or exporting PDFs.

Coming later

These modules exist in the codebase and will appear for organisation admins as they land. They are hidden from first-run, not deleted.

Staff training modules

Training content and campaign tracking exist in the codebase. They are not sold as part of first-run today. Team sign-off is separate, and is included on every paid plan.

Audit rooms and evidence packs

Auditor access and exportable evidence packs will surface for organisation admins as they land.

EU AI Act and full GRC

AI governance, incident operations, and the wider GRC modules stay in the product — hidden from first-run, not sold as shipping today.

First-run path from profile to review

Complete onboarding, generate four core drafts, and review them. Publishing and PDFs unlock after you choose a plan.

1

Capture Core Profile

6-8 minutes
Unlocks drafting with a verified organisational baseline.

Admins complete adaptive onboarding to establish operating model, risk posture, and compliance objectives.

2

Determine Applicable Standards

1-2 minutes
Prevents generic policies by grounding outputs in real obligations.

Standards applicability ranks obligations by industry, geography, services, and data profile.

3

Generate and Harmonise Policy

3-8 minutes
Creates review-ready drafts with quality diagnostics and provenance.

Three-pass generation drafts, repairs contradictions, and validates coverage before reviewer handoff.

4

Review, Approve, and Sign Off

Team dependent
Maintains accountability, publication controls, and an exportable sign-off record.

Approvers validate policy language, mappings, and obligations, then publish through a sign-off chain that tracks every person against every policy on one exportable compliance matrix.

See the workflow in product

Review the main user states for onboarding, generation, and draft review.

Core onboarding question cards with guided inputs

Core Onboarding

Guided question cards for the core organisation profile — the start of a first-run preview, not a finished library.

Need the adjacent buying context?

Use pricing, trust, and support pages for commercial details, diligence review, and rollout questions.

Start a guided preview, then publish when you are ready

Complete onboarding and generate four core drafts from your organisation. Publishing and PDFs unlock after you choose a plan.

Platform FAQs

How does the three-pass generation process improve policy quality?

Pass 1 drafts the policy, pass 2 checks and repairs consistency against existing obligations, and pass 3 validates compliance coverage and operational practicality.

Can teams start generating policies before every onboarding field is complete?

Yes. Policy generation unlocks once the core onboarding profile is complete, while deep profile details continue to improve precision.

What happens when a generated draft fails quality gates?

The draft is quarantined with remediation guidance and review actions so teams can fix issues without losing generation history.