Skip to content

Platform

Compliance Center

Fifteen frameworks mapped over one common control set, with evidence collected from the platform itself. US, Canada and India rules sit side by side, so one piece of evidence answers many questions.

Illustration. Sample data. Shared controls with owners and evidence state.

Frameworks

Fifteen frameworks, one control set.

Controls mapped, evidence collected. Mapping is designed to support your audits. It is not a certification.

Security and AI

  • SOC 2
  • ISO/IEC 27001
  • ISO/IEC 42001
  • NIST CSF 2.0
  • NIST AI RMF
  • PCI DSS

United States

  • FDCPA and Reg F
  • TCPA
  • GLBA Safeguards Rule
  • HIPAA Security Rule
  • CCPA and CPRA

Canada

  • PIPEDA

India

  • DPDP Act
  • CERT-In Directions

Europe and UK

  • GDPR and UK GDPR

How it works

From requirement to evidence pack.

The work your team does twice a year for each audit becomes a standing process.

  1. Map once

    Each framework requirement points at a control in one common control set.

  2. Collect evidence

    The platform gathers evidence from its own records: approvals, guardrail results, the ledger and configuration.

  3. Assign and attest

    Every control has an owner who attests on a schedule. Exceptions go through a waiver with an end date.

  4. Hand it over

    Export an evidence pack for your auditor, per framework, from the same source.

What you get

Evidence you can stand behind.

  • Evidence collection

    Evidence comes from the same records the agents write, so it matches what happened.

  • Owners and attestations

    Each control has a named owner and a review schedule. Missed reviews show up as gaps.

  • Waivers with an end date

    Accept a known gap on purpose with a reason and an expiry. The requester cannot approve their own waiver.

  • Guardian agent

    Guardian looks for gaps across the frameworks and explains each one in plain words with the fix.

  • Auditor evidence packs

    Export per framework with the evidence and its source, ready to hand to your auditor.

  • Three regions in one view

    US, Canada and India rules are mapped together, so a lender in two markets runs one programme.

What we do not claim

Spine maps controls and collects evidence. Certification is a decision for your auditor about your organisation.

See your frameworks on one screen.

Tell us which regulators you answer to. We will show the controls, evidence and gaps for that set.