AI-native GRC · 25 frameworks · one evidence set

Compliance that proves itself.

Compliance One runs ISO 9001, ISO 27001, SOC 2, ISO 42001, ISO 22301, ISO 20000, ISO 27701, ISO 27017, ISO 27018, HIPAA, PCI DSS, NIS2, NIST CSF 2.0, NIST AI RMF, the EU AI Act, GDPR, Singapore’s Cyber Essentials, Cyber Trust and DPTM, the Philippines DPA, New Zealand’s Privacy Act and India’s DPDP Act from one platform with a shared evidence layer — collecting evidence automatically, cross-mapping it across the frameworks it satisfies, and keeping you audit-ready every day, not just the week before.

  • No credit card to start
  • Built-in LMS — training included
  • Data residency: EU · US · APAC
  • Bring your own storage
  • MCP-enabled by default
  • Zero implementation charges
  • 180+ connectors, all included
Compliance overview
Live
84%

Controls satisfied

142 of 169 mapped

+9 this week

ISO 27001SOC 2HIPAANIS2
AWS CloudTrail evidence collected
Access review — Q3 signed off
Encryption policy v3 published

AI drafted this policy

you approve every word

Compliance, minus the busywork

Built-in threat intelligence — no other platform at this level

25

Frameworks, cross-mapped

1

Evidence set, mapped everywhere

3

Data regions: EU · US · APAC

24/7

Continuous monitoring

180+

Connectors to popular apps

Why Compliance One

Not another checklist tool

Most platforms digitise the busywork. We remove it — so proving trust stops being a fire drill.

Do it once, prove it everywhere

Cross-framework crosswalk

Security frameworks overlap heavily, so one control you implement — and the evidence behind it — can count toward ISO 27001, SOC 2, HIPAA and more at once. We map it across them automatically, so shared work isn't repeated and each framework's specific requirements are still tracked on their own.

No one else does this at this level

Threat intelligence, built in

Compliance tools stop at checklists. We ship a full threat-intelligence command centre inside the platform — actively-exploited vulnerabilities prioritised by CISA KEV × CVSS × EPSS, live ransomware activity, threat-actor and malware dossiers mapped to MITRE ATT&CK, network indicator feeds and curated security news. Your programme is driven by real-world risk, not just a control list — one click from your dashboard, with nothing extra to buy.

Training included — don't pay twice

Native security-awareness LMS, built in

Most GRC tools make you buy a separate training platform — another vendor, another bill, another login. We build the LMS right into Compliance One at no extra cost. Assign framework-specific courses to your staff, deliver them through a secure no-skip player, test understanding with AI-drafted (human-approved) quizzes, and auto-issue branded completion certificates that write straight back to each person's training record. Reminders, overdue chasing, per-department analytics and recurring re-training are all included — so awareness training is finally part of your compliance programme, not a line item next to it.

Built for the AI era

AI-native, not AI-bolted-on

Draft policies, summarise evidence and triage gaps with an assistant that understands your control set. Bring your own model key or use ours — your call, your data boundary.

Bring your compliance to your AI

MCP-enabled by default

Every account ships with a built-in Model Context Protocol server, so you can connect Claude — or any MCP client — straight to your live compliance data. Ask about risks, controls, your SoA, evidence and audits in plain language, and make audited changes, all org-scoped with secrets never exposed. Sign in with per-user OAuth (one click) or a scoped API key. No add-on, no extra cost.

Your data, your region

Data residency & bring-your-own-storage

Choose where your evidence lives — EU, US or APAC — at signup. Or point us at your own S3 bucket and keep full custody. Isolation is physical, not just a row in a shared table.

Honest by design

Continuous monitoring, real evidence

Live connectors watch your cloud and identity stack and collect timestamped evidence automatically. We show you what's actually covered — never a green dashboard hiding a red reality.

Plug into the tools you already run

Connectors for the apps your company lives in

Compliance One ships more than 180 connectors across cloud, identity, HRIS, device management, ticketing and chat, with the catalogue growing all the time. Link the widely used apps your team already runs, from AWS, Microsoft Entra ID and Okta to GitHub, Jira, Slack and BambooHR, and evidence starts collecting itself on the schedule you set. No screenshots, no manual uploads, and every connector is included at no extra cost.

The platform

Everything you need, in one place

From your first control to your fifth audit — without stitching five tools together.

Statement of Applicability

Every control, its justification and status — generated and export-ready.

Evidence automation

Connectors pull from AWS, identity and ticketing on a schedule you set.

Policy library

Framework-mapped templates you can adopt, edit and version in minutes.

Audit calendar

Schedule assessments and surveillance audits; nothing slips through.

Risk register

Score, treat and track risks with links straight to the controls that mitigate them.

Role-based access

Org admins configure every integration; least-privilege throughout.

MCP server, built in

Connect Claude — or any MCP client — to your live compliance data. Query and make audited changes in natural language, via OAuth or an API key.

Built-in training LMS

Assign framework courses to staff, quiz them, and auto-issue certificates — a full security-awareness LMS included, so there's no separate training tool to buy.

Coverage

Twenty-five frameworks. One source of truth.

Subscribe to what you need today; add more without starting over. Evidence maps across all of them.

ADG

ADGM DPR

Personal Data (ADGM)

ADGM Regulations 2021 · consolidated Feb 2024 + SPI Rules 2025 · Office of Data Protection

Learn more
Cyb

Cyber Essentials

CSA baseline mark

Certification · baseline

Learn more
Cyb

Cyber Trust

CSA mark of distinction

Certification · risk-based

Learn more
DIF

DIFC DPL

Personal Data (DIFC)

DIFC Law 5/2020 · in force 1 Jul 2020 · regulated by the DIFC Commissioner of Data Protection

Learn more
DPT

DPTM

Data Protection Trustmark

Certification · data protection

Learn more
EU

EU AI Act

AI Regulation

Regulation · risk-based

Learn more
GDP

GDPR

Data Protection (EU)

Regulation (EU) 2016/679 · in force 25 May 2018

Learn more
HIP

HIPAA

Health Data

Privacy & Security

Learn more
Ind

India DPDP

Data Protection (India)

Act 22 of 2023 · Rules 2025

Learn more
ISO

ISO 20000

IT Service Management

Certification · ITSM

Learn more
ISO

ISO 22301

Business Continuity

Certification · resilience

Learn more
ISO

ISO 27001

Information Security

Annex A · ISMS

Learn more
ISO

ISO 27017

Cloud Controls

Certification · cloud

Learn more
ISO

ISO 27018

Cloud PII (Processor)

Certification · cloud privacy

Learn more
ISO

ISO 27701

Privacy (PIMS)

Certification · privacy

Learn more
ISO

ISO 42001

AI Management

Responsible AI

Learn more
ISO

ISO 9001

Quality Management

Certification · 6th edition

Learn more
NIS

NIS2

EU Cyber Resilience

Directive 2022/2555

Learn more
NIS

NIST AI RMF

AI Risk Management

AI 100-1 · 2023

Learn more
NIS

NIST CSF

Cybersecurity Framework

CSWP 29 · 2024

Learn more
NZ

NZ Privacy Act

Data Protection (New Zealand)

Act 2020 · IPP 3A from 1 May 2026

Learn more
PCI

PCI DSS

Payment Security

v4.0.1

Learn more
Phi

Philippines DPA

Data Privacy Act

Regulation · data protection

Learn more
SOC

SOC 2

Trust Services

Type I & II

Learn more
UAE

UAE PDPL

Personal Data (UAE)

Federal Decree-Law 45/2021 · in force 2 Jan 2022 · Executive Regulations pending

Learn more

How it works

Live in a day, ready for audit

No six-week onboarding. Pick frameworks, connect your stack, and watch coverage climb.

01

Pick your frameworks

Choose the frameworks you need. Controls, policies and an SoA are provisioned instantly.

02

Connect your stack

Link cloud, identity and email so evidence starts flowing automatically.

03

Close the gaps

Work a clear, prioritised list — assign owners, attach evidence, track progress.

04

Prove & stay ready

Export auditor-ready packages and stay continuously compliant, not just at audit time.

Pricing

One platform. One price. Everything included.

No tiers, no per-seat math, no per-framework add-ons. Every framework, every feature, your whole team — one number.

No tiers. No add-ons.

Everything, in one plan

No tiers to decode. No line items to negotiate. One price covers the whole platform.

One flat price

no per-seat fees · no per-framework add-ons

  • All 25 frameworks — the ADGM DPR, Cyber Essentials, Cyber Trust, the DIFC DPL, DPTM, the EU AI Act, GDPR, HIPAA, India's DPDP Act, ISO 9001, ISO/IEC 20000, ISO 22301, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, NIS2, NIST AI RMF, NIST CSF 2.0, the New Zealand Privacy Act, PCI DSS, the Philippines DPA, SOC 2, and the UAE PDPL — automatically cross-mapped so shared evidence counts for all of them
  • Cross-framework crosswalk: capture a piece of evidence once and it counts for every framework it maps to
  • Dedicated threat-intelligence module, built in at no extra cost
  • Built-in security-awareness LMS — assign courses, quizzes & auto-issued certificates; no separate training tool to buy
  • Unlimited users — your whole team, no per-seat charges ever
  • Evidence automation & continuous monitoring across your cloud and identity stack
  • Statement of Applicability, policy library & audit calendar
  • Risk, asset, supplier, incident & document registers
LOYALTY

The longer you stay, the less you pay. Every renewal earns a loyalty discount — staying compliant should cost you less each year, not more.

30 minutes · no obligation · you leave knowing your number

Stop paper-shuffling.
Start proving trust.

See Compliance One mapped to your frameworks in a 30-minute walkthrough. Bring your hardest audit question.