Skip to main content
Skip to main content

Compliance infrastructure
engineered for accountability

25 features across compliance, workflow, identity, collaboration, and AI, built for regulated teams that need provable control over every obligation.

Compliance Core5
Workflow & Operations6
Identity & Security4
Collaboration & UX7
AI & Certification3

The platform at a glance

Every number here is generated from the shipping code, so it stays true as the packs change.

25
Platform features
11
Framework packs
271
Mapped controls
286
Control evaluators
124
Checked automatically
162
Tracked as attestations

25 features, one operating loop.

Not 25 disconnected tools. Each subsystem feeds the next: obligations become controlled work, gated by identity, surfaced to your team, and proven to auditors. Select a node to trace it.

The loop closes: AI & Certification feeds back into Compliance Core.

Compliance Core

5 features

The spine: frameworks, controls, evidence, and posture.

Framework coverage, control enforcement, evidence management, and posture scoring: the operational backbone of your compliance programme.

  • 11 Pre-Built Framework Packs
  • Compliance Gate Enforcement
  • Compliance Scoring Engine
  • Evidence Vault with SHA-256
  • Framework Cross-Mapping
Upload and hash
SHA-256 checksum generated at upload. Every later access is verified against the original hash.
Chain of custody
Immutable record of who uploaded, reviewed, approved, and exported each evidence artifact.
Audit export
Framework-mapped evidence bundles export in auditor-ready format with verification metadata.
Expiry tracking
Alerts fire as evidence approaches its expiry date, and re-collection work is scheduled automatically.

Feature catalog · 25 features across 5 categories

Click a category to expand
Compliance Core· 5 features
  • 11 Pre-Built Framework Packs
  • Compliance Gate Enforcement
  • Compliance Scoring Engine
  • Evidence Vault with SHA-256
  • Framework Cross-Mapping
Workflow & Operations· 6 features
  • Workflow Automation
  • Bulk Operations
  • Incident Management
  • Care Plans & Participant Management
  • Policy Lifecycle Management
  • Integration Marketplace
Identity & Security· 4 features
  • SAML 2.0 SSO & Identity Lifecycle Controls
  • Data Residency Controls
  • Immutable Audit Trail
  • Risk Heatmap
Collaboration & UX· 7 features
  • Inline Comments & Collaboration
  • Notification Center
  • Command Palette
  • Global Search
  • Contextual Help Assistant
  • Real-Time Collaboration
  • Custom Dashboard Builder
AI & Certification· 3 features
  • Compliance Q&A assistant
  • SOC 2 readiness + report generator
  • REST API v1

Pre-built compliance framework libraries

11 framework packs covering 271 controls, of which 124 are checked automatically against your data and 162 are tracked as attestations. Each pack ships with mapped controls, evidence templates, and cross-framework overlap detection.

NIST CSF

Govern, identify, protect, detect, respond, and recover, mapped control by control.

Controls15
Checked automatically6

CIS Controls

Prioritised security practices from the Center for Internet Security.

Controls18
Checked automatically7

SOC 2

A shorter SOC 2 starting point for teams beginning readiness work.

Controls11
Checked automatically9

SOC 2 (TSC)

Trust Services Criteria across security, availability, confidentiality, processing integrity, and privacy.

Controls61
Checked automatically29

ISO 27001:2022

Information security management with the full Annex A control set.

Controls93
Checked automatically30

GDPR

EU personal data obligations with article-level mapping.

Controls10
Checked automatically2

HIPAA

Administrative, physical, and technical safeguards under the Security Rule.

Controls10
Checked automatically3

PCI DSS

Cardholder data protection for organisations that take payments.

Controls11
Checked automatically5

AU Financial Services

Australian financial services obligations, including ASIC and AUSTRAC duties.

Controls20
Checked automatically7

NDIS Practice Standards

NDIS Practice Standards core module, for registered Australian providers.

Controls8
Checked automatically22

National Mental Health Standards

National Standards for Mental Health Services, for Australian providers.

Controls14
Checked automatically4

Five layers of defence in depth

Every request traverses five independent security and compliance verification layers. No single point of failure. No bypass path.

Frontend Gating

React compliance gates with real-time validation. Controls render-blocked UI when prerequisites are unmet.

API Guards

Server-side middleware enforcing permission checks, rate limiting, and compliance state validation on every request.

Business Logic

Workflow engine processing automation rules, scoring calculations, and cross-framework evidence mapping.

Database RLS

Row-Level Security policies ensure tenant isolation at the database layer. Every query is scoped by organization.

Environment Isolation

Infrastructure-level tenant isolation with dedicated encryption keys and configurable data residency.

Ready to operate compliance as infrastructure?

See how FormaOS replaces spreadsheet-based compliance with a structured operating system built for regulated teams.

Buying for a larger organisation? See the enterprise evaluation path.

SOC 2-aligned workflows
Privacy review support
Enterprise review support
Assessment-led onboarding