[ system :: comply ]

Comply .

Compliance posture for your cloud tenant — read-only, evidence-ready, and prioritized so the work has a finish line.

[ master plan ]
cis soc2 cmmc hipaa iso
Enable MFA for admin users soc2 · cmmc · hipaa
Disable legacy auth protocols soc2 · cmmc
Configure conditional access soc2 · cmmc
Update PHI document labels hipaa
Wire posture-change webhook soc2

[ 00 / brief ]

Compliance tools tend to come in two shapes. One is a checkbox-factory that auto-clicks settings inside your tenant and hands you a green dashboard with no evidence of what just happened. The other is a spreadsheet exporter that hands you a 400-row gap list and walks away.

Comply is neither. It reads your Microsoft 365 or Google Workspace tenant against the frameworks you have to satisfy, surfaces the gaps in plain English, and gives you a single ordered list of work to do — ranked by how many frameworks each action advances, weighted by severity, scaled to effort. We don’t touch your tenant. The remediation is yours to run, on your timeline, with our guidance in your shell.

[ 01 / what’s covered ]

  1. Read-only by design — Comply connects to your tenant with the smallest set of read-only scopes that get the job done, and that’s the only kind of access it ever asks for. There is no auto-remediation mode today and there isn’t going to be one. Every change to your tenant is a deliberate action by your team, with a record of who did it and when.

  2. Frameworks that overlap, evaluated together — CIS Benchmarks as the always-on baseline. SOC 2, CMMC, HIPAA, ISO 27001, NIST CSF as opt-in overlays. Most controls satisfy multiple frameworks at once; Comply knows the cross-map and uses it.

  3. The Master Plan — One ordered list of remediation actions, ranked by how many of the frameworks you selected each one advances, then weighted by control severity and effort estimate. “Do these ten things and you’ll close 80% of your gaps across the three frameworks you care about.” That’s the deliverable. It updates live as you complete work.

  4. Continuous scans — Weekly tenant scans by default, with a refresh button for when you’ve just changed something and want the next scan now. Posture changes flow as notifications, optional webhooks, and — if you’re also a Grid customer — as cases inside Grid.

  5. Snapshot mode for one-time engagements — Need a single compliance check for SOC 2 prep, an annual audit, or a board meeting? There are two ways in. You can connect Comply directly to the tenant, let it scan, get the report, and revoke the scopes when you’re done. Or — if granting access isn’t on the table — you can export the configuration from the source SaaS tool yourself, upload that export to Comply, and we’ll evaluate it without ever touching your environment. Partners can run either path on behalf of their own clients end-to-end.

  6. Audit-ready output — A PDF report for the auditor, CSV exports for the analyst pulling the numbers, JSON for the GRC platform you already paid for, and the portal dashboard for the people doing the work day to day. Every format carries the evidence trail your auditor is going to ask for.

  7. The auditor guest seat — Invite your external auditor directly. They get read-only access to your compliance evidence, time-bounded to your engagement window. They don’t need a Censored Systems account. You revoke when you’re done.

  8. Remediation that respects your team’s time — Every gap comes with a plain-English explanation of why it matters, a step-by-step click-through, the exact PowerShell or gcloud command to run yourself, and links to the underlying control documentation. Accepted-risk is a first-class option, with the justification preserved in the audit log.

[ 02 / who this is for ]

  • Compliance and security leads at organizations already in M365 or Google Workspace, trying to satisfy more than one framework at the same time.
  • Public-sector and regulated industry organizations working toward CMMC, HIPAA, SOC 2, or a state-specific equivalent — particularly the ones whose audit prep has historically been “screenshots in a shared folder.”
  • Auditors and external consultants who want a real evidence surface from their client’s tenant, without the back-and-forth.
  • MSPs and integrators running compliance work for a portfolio of customers. Snapshot mode is built to be resold.

[ 03 / how it fits ]

  • Identity is centralized. Comply uses the same identity plane as the rest of our products. Your team and your invited auditors authenticate once.
  • Grid takes Comply’s findings as work. If you run both products, a new gap or a regression on an existing control can land in Grid as a case — investigated, tracked, and closed when the next Comply scan confirms the fix.
  • Cortex writes the explanations, not the assertions. The plain-English narrative on every gap is generated on our hardware from sanitized inputs. Cortex never sees your raw tenant configuration. The control findings themselves come from the same engines (including CISA’s own ScubaGear for M365) used by federal evaluators.
  • No vendor lock. PDF, CSV, and JSON outputs work in whatever GRC tooling you already have. The continuous-monitoring webhook lets you wire Comply into your own systems without leaving our portal.

[ 04 / where we are ]

Comply is live for Microsoft 365 today. Google Workspace assessment is shipping next, on the open-source engine we’re building for it. CIS Benchmarks are the live baseline; SOC 2, CMMC, HIPAA, ISO 27001, and NIST CSF overlays are rolling out in priority order, with the federal-adjacent frameworks first.

If you’ve got a multi-framework audit ahead of you and you want the Master Plan instead of the gap list, get in touch. We’ll scope it honestly.

[ master plan workflow ]

Five steps, end-to-end

The whole point of the Master Plan is that the work has a finish line. Frameworks in, ordered actions out, validated by the next scan.

01
Pick your frameworks
CIS Benchmarks always on. SOC 2, CMMC, HIPAA, ISO 27001, NIST CSF as opt-in overlays.
02
Read-only scan
Tenant configuration evaluated against every selected framework. No writes. Ever.
03
Master Plan ranking
Every gap weighted by frameworks-it-advances × severity × effort. One ordered list.
04
You remediate
Click-through guides, PowerShell / gcloud commands, accepted-risk option. Customer-controlled.
05
Re-scan, re-rank
Next weekly scan validates closures. The plan re-ranks live as gaps close.
[ ready :: contact ]

Talk to us.

Tell us which frameworks you're working toward, what tenants you're on, and where you are in your audit cycle. We'll tell you whether Comply is the right fit, and what a first scan would actually surface.