AI-native GRC · 16 frameworks · one evidence set

Compliance that proves itself.

Compliance One runs ISO 27001, SOC 2, ISO 42001, ISO 22301, ISO 27701, ISO 27017, ISO 27018, HIPAA, PCI DSS, NIS2, the EU AI Act, Singapore’s Cyber Essentials, Cyber Trust and DPTM, the Philippines DPA and India’s DPDP Act from one platform with a shared evidence layer — collecting evidence automatically, cross-mapping it across the frameworks it satisfies, and keeping you audit-ready every day, not just the week before.

  • No credit card to start
  • Built-in LMS — training included
  • Data residency: EU · US · APAC
  • Bring your own storage
  • MCP-enabled by default
  • Zero implementation charges
Compliance overview
Live
84%

Controls satisfied

142 of 169 mapped

+9 this week

ISO 27001SOC 2HIPAANIS2
AWS CloudTrail evidence collected
Access review — Q3 signed off
Encryption policy v3 published

AI drafted this policy

you approve every word

Compliance, minus the busywork

Built-in threat intelligence — no other platform at this level

16

Frameworks, cross-mapped

1

Evidence set, mapped everywhere

3

Data regions: EU · US · APAC

24/7

Continuous monitoring

Why Compliance One

Not another checklist tool

Most platforms digitise the busywork. We remove it — so proving trust stops being a fire drill.

Do it once, prove it everywhere

Cross-framework crosswalk

Security frameworks overlap heavily, so one control you implement — and the evidence behind it — can count toward ISO 27001, SOC 2, HIPAA and more at once. We map it across them automatically, so shared work isn't repeated and each framework's specific requirements are still tracked on their own.

No one else does this at this level

Threat intelligence, built in

Compliance tools stop at checklists. We ship a full threat-intelligence command centre inside the platform — actively-exploited vulnerabilities prioritised by CISA KEV × CVSS × EPSS, live ransomware activity, threat-actor and malware dossiers mapped to MITRE ATT&CK, network indicator feeds and curated security news. Your programme is driven by real-world risk, not just a control list — one click from your dashboard, with nothing extra to buy.

Training included — don't pay twice

Native security-awareness LMS, built in

Most GRC tools make you buy a separate training platform — another vendor, another bill, another login. We build the LMS right into Compliance One at no extra cost. Assign framework-specific courses to your staff, deliver them through a secure no-skip player, test understanding with AI-drafted (human-approved) quizzes, and auto-issue branded completion certificates that write straight back to each person's training record. Reminders, overdue chasing, per-department analytics and recurring re-training are all included — so awareness training is finally part of your compliance programme, not a line item next to it.

Built for the AI era

AI-native, not AI-bolted-on

Draft policies, summarise evidence and triage gaps with an assistant that understands your control set. Bring your own model key or use ours — your call, your data boundary.

Bring your compliance to your AI

MCP-enabled by default

Every account ships with a built-in Model Context Protocol server, so you can connect Claude — or any MCP client — straight to your live compliance data. Ask about risks, controls, your SoA, evidence and audits in plain language, and make audited changes, all org-scoped with secrets never exposed. Sign in with per-user OAuth (one click) or a scoped API key. No add-on, no extra cost.

Your data, your region

Data residency & bring-your-own-storage

Choose where your evidence lives — EU, US or APAC — at signup. Or point us at your own S3 bucket and keep full custody. Isolation is physical, not just a row in a shared table.

Honest by design

Continuous monitoring, real evidence

Live connectors watch your cloud and identity stack and collect timestamped evidence automatically. We show you what's actually covered — never a green dashboard hiding a red reality.

The platform

Everything you need, in one place

From your first control to your fifth audit — without stitching five tools together.

Statement of Applicability

Every control, its justification and status — generated and export-ready.

Evidence automation

Connectors pull from AWS, identity and ticketing on a schedule you set.

Policy library

Framework-mapped templates you can adopt, edit and version in minutes.

Audit calendar

Schedule assessments and surveillance audits; nothing slips through.

Risk register

Score, treat and track risks with links straight to the controls that mitigate them.

Role-based access

Org admins configure every integration; least-privilege throughout.

MCP server, built in

Connect Claude — or any MCP client — to your live compliance data. Query and make audited changes in natural language, via OAuth or an API key.

Built-in training LMS

Assign framework courses to staff, quiz them, and auto-issue certificates — a full security-awareness LMS included, so there's no separate training tool to buy.

How it works

Live in a day, ready for audit

No six-week onboarding. Pick frameworks, connect your stack, and watch coverage climb.

01

Pick your frameworks

Choose the frameworks you need. Controls, policies and an SoA are provisioned instantly.

02

Connect your stack

Link cloud, identity and email so evidence starts flowing automatically.

03

Close the gaps

Work a clear, prioritised list — assign owners, attach evidence, track progress.

04

Prove & stay ready

Export auditor-ready packages and stay continuously compliant, not just at audit time.

Pricing

One platform. One price. Everything included.

No tiers, no per-seat math, no per-framework add-ons. Every framework, every feature, your whole team — one number.

No tiers. No add-ons.

Everything, in one plan

No tiers to decode. No line items to negotiate. One price covers the whole platform.

One flat price

no per-seat fees · no per-framework add-ons

  • All 16 frameworks — Cyber Essentials, Cyber Trust, DPTM, the EU AI Act, HIPAA, India's DPDP Act, ISO 22301, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, NIS2, PCI DSS, the Philippines DPA, and SOC 2 — automatically cross-mapped so shared evidence counts for all of them
  • Cross-framework crosswalk: capture a piece of evidence once and it counts for every framework it maps to
  • Dedicated threat-intelligence module, built in at no extra cost
  • Built-in security-awareness LMS — assign courses, quizzes & auto-issued certificates; no separate training tool to buy
  • Unlimited users — your whole team, no per-seat charges ever
  • Evidence automation & continuous monitoring across your cloud and identity stack
  • Statement of Applicability, policy library & audit calendar
  • Risk, asset, supplier, incident & document registers
LOYALTY

The longer you stay, the less you pay. Every renewal earns a loyalty discount — staying compliant should cost you less each year, not more.

30 minutes · no obligation · you leave knowing your number

Stop paper-shuffling.
Start proving trust.

See Compliance One mapped to your frameworks in a 30-minute walkthrough. Bring your hardest audit question.