One compliance platform. Five frameworks. Every artifact your auditor asks for.
Complyanz runs ISO 27001, ISO 27701, ISO 42001, SOC 2 and HIPAA in a single workspace — risk registers, controls, evidence and the audit-ready document set — so one team can carry certifications, attestations and regulatory programs at the same time.
- No credit card required
- ISO 27001:2022 aligned
- Your data is never used to train models
Coverage
Certifications, attestations and regulations — in one place
Enable the programs you need. Each arrives with its own controls, risk library, document set and dashboard.
ISO 27001
The information security management system. 93 Annex A controls and 23 main-body clauses, with the Statement of Applicability auditors open first.
CertificationISO 27701
Privacy information management, layered onto ISO 27001. 78 privacy controls and a document set that integrates rather than duplicates.
CertificationISO 42001
The AI management system. 38 controls plus an AI system inventory and impact assessments for the models you build or buy.
AttestationSOC 2
AICPA Trust Services Criteria. 62 criteria entries, evidence mapped to the audit period, and readiness tracking ahead of a Type I or Type II examination.
RegulationHIPAA
Security, Privacy and Breach Notification Rules. 68 safeguards, PHI inventory, business associate agreements and breach readiness.
Integrated management system
Add a standard. Don't start a second program.
Most tools sell one framework per subscription, so a second certification means the same work done twice. In Complyanz the ISO standards compose: ISO 27001 is the foundation, and privacy and AI extend it into one integrated management system.
The platform
Nine modules, one system of record
Everything a compliance program generates — risks, controls, documents, evidence, incidents, people and suppliers — lives in one place and stays linked.
Risk register and treatment plans
Build the register from 266 pre-written ISO scenarios or your own. Map each risk to the controls that treat it, set owners and track residual risk to closure.
Statement of Applicability
Walk all 93 Annex A controls, record inclusion or exclusion with justification, and export the SoA. SOC 2 and HIPAA get their equivalent applicability views.
Document library
90 ISO documents tagged by management-system variant, plus dedicated SOC 2 and HIPAA sets, pre-filled with your details and exported as Word and PDF.
Evidence vault
Attach evidence directly to the control or criterion it proves, with the audit period it covers. When the assessor asks, the answer is one click away.
Incidents and corrective actions
Log security and privacy incidents, classify severity, and drive corrective actions to closure. Breach records and notification readiness are built in for HIPAA.
Suppliers and business associates
Track third parties, the data they touch and the assurance you hold over them — including business associate agreements for organizations handling PHI.
Training and awareness
Assign awareness training, record completion and keep the evidence every framework asks for when it wants proof your people know the policies.
AI systems and impact assessments
Inventory the AI systems you build or buy, classify their impact across affected domains, and produce the assessments ISO 42001 expects.
Management review and internal audit
Run the governance cycle the standards mandate — internal audits, management reviews, metrics and continual improvement — with records generated as you go.
Questions