How does OptiTech help with SOX ITGC?
Access, change, and operations controls verified continuously on financially relevant systems, with auditor-ready populations.
Access, change, and operations controls verified continuously on financially relevant systems, with auditor-ready populations.
The IT general controls behind Sarbanes-Oxley: access, change, and operations controls that make financial reporting trustworthy.
Tier-scoped diagnostic statements, one control set feeding every regulator view, and examiner-ready evidence.
The Cyber Risk Institute's framework for financial services: regulatory expectations harmonized into one assessable profile with four tiers.
All eight strategies verified continuously with maturity-level tracking, and patch clocks that actually count hours.
Australia's ACSC-mandated mitigation strategies: eight controls that raise the technical cost of attacking you.
The QMS on the same management-system machinery as your ISMS: shared audits, documents, and improvement loops.
The global standard for quality management: proof that your organization delivers consistently and improves continuously.
The DPR mapped to your existing privacy and security controls, with the annual attestation cycle on rails.
Microsoft's Supplier Security and Privacy Assurance program: mandatory requirements for vendors handling Microsoft data.
The ISA catalog with maturity scoring, automotive-specific controls, and readiness tracking toward your target label.
The automotive industry's information security assessment, required by European OEMs before sensitive data flows to suppliers.
The named requirements as verified controls, the 72-hour NYDFS clock in the incident flow, and a defensible annual certification.
New York's cybersecurity regulation for financial institutions: risk assessments, a CISO, incident reporting, and an annual certification.
CJI-scoped controls, personnel clearance tracking, and audit-ready access logs for agency and FBI review cycles.
The FBI's security policy for criminal justice information, binding for public safety agencies and every vendor touching their data.
Board-ready oversight evidence, controls testing on a managed cadence, and the APRA notification clocks in the incident flow.
APRA's information security standard for Australia's banks, insurers, and super funds, and it reaches their service providers.
Pick your implementation group, verify the safeguards continuously, and reuse the evidence across every mapped framework.
The prioritized safeguards that block common attacks, mapped to major frameworks and sized by implementation group.
Cloud-first requirements verified against a cloud-first stack, with evidence your bank partners can consume.
The Open Finance Data Security Standard: cloud-first security requirements for fintech and open finance companies.
The checklist as your first verified control set, satisfied in days and reused for every framework after it.
The lightweight security checklist for B2B SaaS and outsourcing vendors: baseline expectations, fast to satisfy.
The FTR checklist as verified controls against your actual AWS accounts, with evidence ready for the review.
AWS's review of your architecture and security practices, the gate to partner benefits like ISV Accelerate.
BIA and continuity plans as living records, backup verification through integrations, and the exercise calendar that auditors check.
The standard for business continuity management: a structured, auditable system for surviving disruptions.
PII-in-cloud controls layered on your ISMS, GDPR, and 27701 work, with the processor commitments as verified artifacts.
Privacy controls for public cloud processors: PII protection commitments that extend ISO 27001.
Cloud controls verified against AWS and Azure directly, shared-responsibility documentation per service, and an incremental audit.
The cloud security extension to ISO 27001: controls for cloud service providers and customers alike.
The four functions mapped onto your AI inventory, risk register, and controls, shared with your AI Act and ISO 42001 work.
The voluntary US framework for trustworthy AI: govern, map, measure, and manage AI risks across the lifecycle.
Built from the Swedish Cybersecurity Act and MSB regulations, with the 24-hour incident flow no other platform has.
The EU directive imposing cybersecurity duties on essential and important entities across 18 sectors, with personal management liability.
System inventory, guided risk classification, and the high-risk obligation set as maintained controls and documentation.
The EU regulation with risk-based oversight of AI systems, from minimal risk to prohibited, with fines up to 7 percent of turnover.
CUI scoping in the asset inventory, the 110 requirements verified continuously, and the SSP and POA&M maintained as living documents.
The 110 requirements for protecting controlled unclassified information in nonfederal systems, the core of CMMC Level 2.
Baseline selection and tailoring in the platform, with the catalog cross-mapped to every other framework you run.
The catalog of security and privacy controls behind FedRAMP and most US federal information systems.
The five themes verified continuously, the 14-day patch clock tracked per device, and the annual renewal on rails.
The UK government-backed baseline: five technical control themes that block the most common attacks.
The PIMS as an extension of your existing ISMS and GDPR machinery, certifiable without a parallel program.
The privacy extension to your ISMS: certifiable privacy information management aligned with GDPR and global regulations.
The ICT contract register as a native artifact, incident reporting on DORA clocks, and resilience testing as a managed calendar.
The EU regulation making financial entities and their tech providers resilient to ICT disruptions, in force since January 2025.
CUI scoping, the 110 controls of NIST 800-171 as monitored controls, and assessment-ready evidence per practice.
The US Department of Defense certification for protecting federal contract information and CUI across the defense supply chain.
Machine-verifiable controls and queryable evidence are the platform default, which is exactly what 20x assesses.
The automated reimagining of FedRAMP: machine-readable evidence and faster paths to Low and Moderate authorization.
Baseline gap analysis against NIST 800-53, SSP-ready control documentation, and the continuous monitoring rhythm.
The authorization program proving your cloud service is secure enough for US federal agencies.
Level-aware requirement catalogs for e1, i1, and r2, evidence maturity tracking, and reuse of your HIPAA and ISO work.
The certifiable framework for safeguarding health data, with e1, i1, and r2 assessment levels aligned to HIPAA.
Current and target profiles, the six functions as a live dashboard, and cross-mapping into your certifiable frameworks.
The most widely used cybersecurity framework: six functions for governing and reducing cyber risk, with no auditor required.
Scope the cardholder data environment, automate the technical checks, and never miss a quarterly deadline.
The card industry security standard for anyone that stores, processes, or transmits cardholder data.
AI system inventory, impact assessments, and lifecycle controls in the same workspace as your security ISMS.
The management system standard for responsible AI: ethical use, transparency, and continuous improvement, certifiable like ISO 27001.
One privacy control set mapped to 19+ state laws, with applicability scoping and deltas when new laws pass.
California, Virginia, Colorado, and 16+ more states each have their own privacy law; the overlap is manageable if you centralize.
Security Rule safeguards as monitored controls, the risk analysis as a living document, and BAA tracking per vendor.
US rules for protecting health information, binding for healthcare providers and every vendor that touches PHI.
Living records of processing, DPA tracking in the supplier register, and the 72-hour breach flow to IMY built in.
The EU regulation protecting personal data, with obligations for any company that processes it and fines up to 4 percent of turnover.
The ISMS machinery built in: risk register, statement of applicability, document control, and continuous evidence.
The global standard for an auditable information security management system, and the default ask outside the US.
Automated evidence across the audit period, cross-mapped controls, and an auditor portal that shortens fieldwork.
SOC 2 is the industry standard for proving to customers that you manage and protect their data responsibly.
Generate it under Reports > Auditor access: scoped, read-only, expiring, and logged.
The dashboard shows your score per framework with trend; the board report packages it for management.
Trust Center settings show your public URL, like security.yourcompany.example.com, ready to send to prospects.
Each integration page shows connection status, granted permissions, last sync, and the checks it feeds.
Usually a stale session, a browser extension, or a network proxy; here is the diagnostic order.
Every register and report has an export button; PDF for humans, CSV for systems.
Turn it on under Settings > AI on Professional and Enterprise plans; EU-hosted models, no training on your data.
Toggle collection per integration or per check from the Integrations page; pauses are visible in the evidence timeline.
Settings > Export produces documents, structured CSV data, and the evidence log with its integrity chain.
Deactivate frameworks to stop monitoring while keeping history; workspace deletion is a two-step process with an export prompt.
Work inside the incident record: actions, notes, and artifacts are logged append-only while deadlines count down.
Yes. A sandbox workspace with sample data lets you explore the full workflow, then reset or convert when ready.
The evidence log keeps every check result with timestamps, so historical failures are queryable, not archaeological.
Deletions are soft and versioned: restore from the object history or the recycle area, with the audit trail intact.
Findings are isolated per control: investigate, remediate, and re-check one control while everything else keeps running.
A scoping wizard turns 20 questions into frameworks, controls, draft policies, and a prioritized plan.
Deduplication, ownership routing, and severity tiers keep the signal; auto-remediation removes the noise at the source.
New employees, repos, and cloud accounts enter monitoring automatically instead of by remembering to add them.
Draft mode shows exactly which controls, requirements, and sign-offs a policy change touches before anyone sees it.
Grant scoped, read-only access that expires automatically, with every action logged.
Suppliers answer once in their own free workspace and reuse it for every customer, so your questionnaires actually get answered.
A guided assessment per AI system determines its risk category and generates the matching obligation list.
Define the control, map it to framework requirements, and attach automated or manual evidence.
Sign up, answer the 20-question onboarding wizard, and get a scoped compliance program with a prioritized action list.
Activate it from the Frameworks page; cross-mapping shows immediately how much your existing controls already cover.
Add an integration from the catalog, authorize read-only access, and checks start running within minutes.
No. Collected evidence and history are retained; automation pauses, and export is always available.
Activate the framework in assessment mode: you get the delta analysis while your live program stays untouched.
The Frameworks page shows each active framework and its version, like ISO 27001:2022, with upgrade paths when versions change.
Workspace settings show the hosting region; the same information belongs in your records of processing.
A free scoping test plus the Start plan covers the legal baseline for less than a consultant day per year.
Request a managed relocation from support, update your records of processing, and verify the evidence log after the move.
Workspace data stays in the Swedish and EU data centers chosen at creation. Contact support to relocate it.
Assign control ownership per team, route findings to the right tracker, and keep one shared source of truth.
ISO 27001 or SOC 2 as the base, a public Trust Center, and AI questionnaire answers to unblock deals.
RAG grounds every AI answer in actual legal text and your own control data, with citations you can check.
Findings become tickets in your tracker, checks run in your repos, and nobody logs into a GRC suite.
Per-entity workspaces with group-level rollup fit corporate structures where units are audited separately.
A multi-tenant console with white label options turns NIS2 demand from your customers into a service line.
Continuous control monitoring catches drift the day it happens, not at the annual audit.
Owners, deadlines, evidence, and status live in one system instead of a fragile Excel file.
Read-only API connections to your systems replace the screenshot folder and keep controls verified continuously.
Agent platforms face the AI Act, GDPR, and customer security reviews at the same time. Automate all three.
Draft states, version history, and review workflows replace the "final_v3_REAL.docx" problem.
A CLI step in your workflow verifies controls pre-merge and logs the run as audit evidence.
Classify your AI systems by risk category now; high-risk obligations phase in through 2026 and 2027.
Cross-mapped controls mean ISO 27001 work counts toward NIS2, SOC 2, and DORA automatically.
Automate the repeatable 80 percent and save consultant hours for judgment calls.
Fail the build on a control violation instead of finding it in an audit six months later.
Export everything, run both tools in parallel through one audit cycle, and verify the evidence trail before cutting over.
Import what you have, map it to a framework, and let integrations take over the evidence work.
Compliance as code: a CLI, a REST API, a Terraform provider, and checks that run in your pipeline.
Transparent per-month pricing lets you start small and scale, instead of committing to a five-figure annual deal upfront.
A Trust Center plus AI questionnaire answers turns security reviews from a sales blocker into a checkbox.
Free scoping tests and a gap analysis tell you in minutes whether you are in scope and what to fix first.
Look for transparent monthly pricing, a small starter plan, and automation that replaces consultant hours.