Compliance
In development - playable below
Most compliance tooling asks you what you do and files the answer. This reads the configuration of the workspace you are actually running — where the models are, who can see what, whether the retention job runs, whether the logs are tamper-evident — and grades it. Where a thing genuinely cannot be checked from a machine, the check says so and asks a person to attest instead, and the score reports the two separately. The module is still in development: everything below is running, but it is not finished and the details will change before it is.
Try it below
How sovereignty worksLive demo · in development
Van Dael Assurantiën exists only here. Switch between the privacy frameworks and ISO 27001 on the left, open a failing check to see what it read, work through the DSR inbox, look at the breach register, or open the Statement of Applicability and read a control exclusion.
This module is still in development: it is real and running, but it is not finished and the details will change. Sample organisation, sample findings. The checks are the real ones and the Annex A catalogue is the real one; the results are invented, nothing is saved, and the PDF exports are switched off because the demo has no server behind it.
Open the real thingHow it works
The scan queries your own installation: which providers are configured and in which region, whether encryption at rest is on, who holds administrative permissions, whether the retention job is scheduled, whether outbound calls are resolved to a country at log time. Nothing is uploaded anywhere to be assessed — the checks execute where the data already is, which is the only way the answer can be about you rather than about a form you filled in.
Some obligations cannot be verified by software. Whether your privacy notice is accurate, whether staff have had AI literacy training, whether a supplier agreement is signed — those are human statements, and the hub records them as attestations with a date and a person against them. The overview shows the split rather than blending the two, because a score that presents self-declarations as verified facts is worse than no score.
A score on its own is not evidence. Behind it sit the artefacts a regulator or an auditor asks for: the data-subject request inbox with its statutory clock, the breach register that starts a 72-hour authority deadline the moment an incident is recorded, the record of processing activities assembled from what is actually deployed, a DPIA per assistant, and for ISO the Statement of Applicability, the ISMS policy set, the risk register, the internal audit and the training attestations.
Every check run writes a hashed evidence record, every register exports as a PDF, and the whole evidence set packs into a bundle you hand over as one file. Ten evidence connectors extend the reach beyond the workspace itself, reading the systems an ISMS actually spans — Google Workspace, Microsoft Entra, Nextcloud, GitHub, your TLS endpoints, mail security, monitoring — so the trail covers the estate, not just this product. The point is not the export button: the document you hand an auditor was generated from the same configuration the systems are running on, on a date the trail can prove, rather than assembled by hand from memory the week before the audit.
It is not a certificate, and it does not make you compliant. No auditor has signed off on how we map a check to an article, no certification body is involved, and a high score is a statement about your configuration rather than about your organisation. What the tool removes is the part that is genuinely mechanical — finding out what the software is currently doing, and keeping the registers current — so the judgement work is left with the people qualified to do it. If you want the reverse of that arrangement, this is the wrong product.
GDPR, the EU AI Act and ISO 27001 ask overlapping questions about the same installation. Where your models run answers a transfer question under one, a residency question under another, and a supplier control under the third. Running them as three separate exercises means gathering the same evidence three times and getting three slightly different answers. Here the evidence is collected once and read by each framework in its own terms, with the Annex A controls cross-referenced to the automated checks that evidence them.
Scope
FAQ
In development, and the roadmap says the same in the same words. It is enterprise-plan and reachable today for an administrator with the compliance permission — real code you can use, not finished. Evaluate it on that basis.
No. The checks run inside your own deployment and read your own configuration; the score, the registers and the evidence records are stored in your database. There is no assessment service to send anything to, which is also why the result is specific to you rather than to a category you were sorted into.
The control references and our own descriptions of them are, and the Statement of Applicability is built around the Annex A structure. The standard’s text itself is copyright ISO and is not reproduced — you need your own copy, as you would for any ISO work.
Some of it. Where a finding maps to a setting the product owns, the check offers to change it and records that it did. Most findings do not work that way, and for those the check links to the screen where the decision is made rather than pretending it can make it for you.
An administrator holding the compliance permission. It is deliberately a separate permission from general organisation administration, because the person who runs your privacy programme is often not the person who runs your workspace, and neither should have to become the other to do their job.
The first scan usually finds two or three things nobody had got to yet. That is the useful outcome — a scan that finds nothing is a scan that was not really looking.
Open the app Talk to us