Compliance infrastructure
engineered for accountability
25 features across compliance, workflow, identity, collaboration, and AI, built for regulated teams that need provable control over every obligation.
The platform at a glance
Every number here is generated from the shipping code, so it stays true as the packs change.
25 features, one operating loop.
Not 25 disconnected tools. Each subsystem feeds the next: obligations become controlled work, gated by identity, surfaced to your team, and proven to auditors. Select a node to trace it.
The loop closes: AI & Certification feeds back into Compliance Core.
Compliance Core
5 features
The spine: frameworks, controls, evidence, and posture.
Framework coverage, control enforcement, evidence management, and posture scoring: the operational backbone of your compliance programme.
- 11 Pre-Built Framework Packs
- Compliance Gate Enforcement
- Compliance Scoring Engine
- Evidence Vault with SHA-256
- Framework Cross-Mapping
- Upload and hash
- SHA-256 checksum generated at upload. Every later access is verified against the original hash.
- Chain of custody
- Immutable record of who uploaded, reviewed, approved, and exported each evidence artifact.
- Audit export
- Framework-mapped evidence bundles export in auditor-ready format with verification metadata.
- Expiry tracking
- Alerts fire as evidence approaches its expiry date, and re-collection work is scheduled automatically.
Feature catalog · 25 features across 5 categories
Click a category to expandCompliance Core· 5 features
- 11 Pre-Built Framework Packs
- Compliance Gate Enforcement
- Compliance Scoring Engine
- Evidence Vault with SHA-256
- Framework Cross-Mapping
Workflow & Operations· 6 features
- Workflow Automation
- Bulk Operations
- Incident Management
- Care Plans & Participant Management
- Policy Lifecycle Management
- Integration Marketplace
Identity & Security· 4 features
- SAML 2.0 SSO & Identity Lifecycle Controls
- Data Residency Controls
- Immutable Audit Trail
- Risk Heatmap
Collaboration & UX· 7 features
- Inline Comments & Collaboration
- Notification Center
- Command Palette
- Global Search
- Contextual Help Assistant
- Real-Time Collaboration
- Custom Dashboard Builder
AI & Certification· 3 features
- Compliance Q&A assistant
- SOC 2 readiness + report generator
- REST API v1
Pre-built compliance framework libraries
11 framework packs covering 271 controls, of which 124 are checked automatically against your data and 162 are tracked as attestations. Each pack ships with mapped controls, evidence templates, and cross-framework overlap detection.
NIST CSF
Govern, identify, protect, detect, respond, and recover, mapped control by control.
CIS Controls
Prioritised security practices from the Center for Internet Security.
SOC 2
A shorter SOC 2 starting point for teams beginning readiness work.
SOC 2 (TSC)
Trust Services Criteria across security, availability, confidentiality, processing integrity, and privacy.
ISO 27001:2022
Information security management with the full Annex A control set.
GDPR
EU personal data obligations with article-level mapping.
HIPAA
Administrative, physical, and technical safeguards under the Security Rule.
PCI DSS
Cardholder data protection for organisations that take payments.
AU Financial Services
Australian financial services obligations, including ASIC and AUSTRAC duties.
NDIS Practice Standards
NDIS Practice Standards core module, for registered Australian providers.
National Mental Health Standards
National Standards for Mental Health Services, for Australian providers.
Five layers of defence in depth
Every request traverses five independent security and compliance verification layers. No single point of failure. No bypass path.
Frontend Gating
React compliance gates with real-time validation. Controls render-blocked UI when prerequisites are unmet.
API Guards
Server-side middleware enforcing permission checks, rate limiting, and compliance state validation on every request.
Business Logic
Workflow engine processing automation rules, scoring calculations, and cross-framework evidence mapping.
Database RLS
Row-Level Security policies ensure tenant isolation at the database layer. Every query is scoped by organization.
Environment Isolation
Infrastructure-level tenant isolation with dedicated encryption keys and configurable data residency.
Ready to operate compliance as infrastructure?
See how FormaOS replaces spreadsheet-based compliance with a structured operating system built for regulated teams.
Buying for a larger organisation? See the enterprise evaluation path.

