Group security policy
Enterprise-wide controls codified once, mapped to every framework.
Build internal policies, sector regulations, customer questionnaires, or hybrid frameworks. Use the same evidence engine, the same workflows, the same auditor exports as our catalog frameworks.
What custom is for
Enterprise-wide controls codified once, mapped to every framework.
Bank- or insurer-grade questionnaires answered from live evidence.
Sector regulations not yet in our catalog — author once, reuse.
Country-specific privacy regimes alongside GDPR / DPDP.
Government baselines mapped to your control library.
When a single customer's security review becomes a recurring program.
Import or author
OSCAL-native ingestion, plus structured editors and bulk import for everything else.
Many-to-many mapping
Custom controls map cleanly to catalog frameworks. Evidence collected once feeds every audit.
Bring your control library and let it inherit every workflow, evidence integration, and auditor export the catalog frameworks already use.