COMPLI-ONCE.

byXmodo· one and done.

YOU'RE DONE. WE'RE NOT.

The compliance operating system for enterprises a regulator writes to. Implement a control once; it stays satisfied across every framework, from SEBI CSCRF to ISO 27001, with AI that cites its source and a human on every approval.

Continuous · Autonomous · Always audit-ready

Posture, live

Recomputed 4 min ago

412

controls in scope

5

frameworks adopted

3

evidence expiring

ISO 27001:202288%
SOC 2 (Security)81%
NIST CSF 2.064%
PCI DSS57%

Illustrative. Every figure drills to its control, evidence, owner and date.

39
frameworks modelled, and any standard you author, on one control model
1
data model behind every dashboard and report
0
AI suggestions applied without a human approver

ISO 27001:2022ISO 27701ISO 42001ISO 22301SOC 2NIST SP 800-53NIST CSF 2.0CIS Controls v8HITRUST CSFPCI DSSHIPAA21 CFR Part 11EU GMP Annex 11SEBI CSCRFRBI CSFRBI IT Governance MDRBI Digital Payment SecurityDPDP ActIRDAI Cyber GuidelinesCERT-In DirectionsUAE IAUAE PDPLSAMA CSFNCA ECCQatar NIAUK GDPRNCSC CAFUK Operational ResilienceCyber EssentialsEU GDPREU DORAEU NIS2EU AI ActTISAXMAS TRMAPRA CPS 234Singapore PDPASOX ITGCCCPA / CPRACustom frameworksISO 27001:2022ISO 27701ISO 42001ISO 22301SOC 2NIST SP 800-53NIST CSF 2.0CIS Controls v8HITRUST CSFPCI DSSHIPAA21 CFR Part 11EU GMP Annex 11SEBI CSCRFRBI CSFRBI IT Governance MDRBI Digital Payment SecurityDPDP ActIRDAI Cyber GuidelinesCERT-In DirectionsUAE IAUAE PDPLSAMA CSFNCA ECCQatar NIAUK GDPRNCSC CAFUK Operational ResilienceCyber EssentialsEU GDPREU DORAEU NIS2EU AI ActTISAXMAS TRMAPRA CPS 234Singapore PDPASOX ITGCCCPA / CPRACustom frameworks

The problem

Why compliance programmes drown in their own tooling

None of these are tooling gaps you can patch with another tab. They are what happens when the programme has no single place to be true.

01

Framework sprawl

ISO was just the start. SOC 2 for customers, DPDP for the DPO, CSCRF from the regulator. Five frameworks × three artefacts each = fifteen parallel spreadsheets, for one security programme.

02

Evidence rot

Attestations expire, access reviews lapse, certificates age out. A folder of documents does not tell you which of them stopped being true. The auditor finds out first.

03

Audit fire drills

"Are we compliant right now?" "We were, eight months ago." Weeks of panic twice a year, for questions a live programme answers in seconds.

04

Questionnaire overload

You assess vendors. Customers assess you. Every answer is retyped from the same policies, and nothing connects the questions to the evidence.

A day inside the system

What changes when the programme is always on

Not a feature list. One ordinary Tuesday, seen from inside a live compliance operating system.

  1. 08:40

    Posture is already current

    Overnight, control state changed in three systems. Compli-Once recomputed the affected frameworks before anyone opened a laptop. Nobody assembled a status pack to find out.

  2. 11:05

    An expiry raises work, not a finding

    The DR drill report ages past its validity window. A renewal task lands with the named owner, the linked controls are flagged as at-risk, and the dashboard reflects it the same minute.

  3. 14:20

    An incident starts its clocks

    A classified incident opens the applicable jurisdictional reporting deadlines inside the workflow, links the control gap it exposed, and carries the CAPA that will close it.

  4. 17:30

    A board question answers itself

    "Which mandates would we fail today, and why?" One view, drilled to the control, the evidence, the owner and the date, with no request queued for the compliance team.

The platform

Eight modules. One data model.

A control implemented once updates every framework, dashboard and report that depends on it. Chains, not silos.

What you actually look at

Screens where every number drills to its source

Illustrative views of the working product. Each figure is computed from control state and traceable to its evidence, owner and date.

Controls implemented

73%

412 controls in scope

5 frameworks adopted

3 evidence items expiring

Illustrative, computed live per tenant in the platform.

Compliance trend, recomputed from live control state

Illustrative, computed live per tenant in the platform.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Evidence vault, validity tracked, not discovered

Access review Q2Valid
VAPT report 2026Valid
ISMS attestationExpires in 12 days
DR drill reportExpired

Renewal task raised on the DR drill report, before it lapsed into a finding.

Illustrative, computed live per tenant in the platform.

The name is the architecture

Comply once. Stay compliant always.

Three readings. One operating model built to keep compliance true after the project ends.

01

Compliance, said fast.

The category is built into the name.

02

Comply once.

One control satisfies every framework it maps to.

03

Once is your job. Always is ours.

You finish the work. Compli-Once keeps its state current.

Regulatory depth

Every mandate modelled, not approximated

India, the Middle East, Asia-Pacific, the UK, Europe, the Americas and the global standards. Each mandate modelled control by control and crosswalked to what you already run, with the same rigour as ISO 27001. Groups operating in several jurisdictions implement once and report separately.


India

SEBI CSCRF, the RBI cyber, IT governance and digital payment security directions, the DPDP Act, IRDAI obligations and the CERT-In reporting directions, each modelled control by control, with the six-hour and prescribed reporting windows running inside the incident workflow.

SEBI CSCRFRBI CSFRBI IT Governance MDRBI Digital Payment SecurityDPDP ActIRDAI Cyber GuidelinesCERT-In Directions

Middle East

The UAE Information Assurance regulation and federal data protection law beside Saudi Arabia's central-bank framework and essential cybersecurity controls, and Qatar's information assurance standard, with maturity levels reported, not just percentages.

UAE IAUAE PDPLSAMA CSFNCA ECCQatar NIA

Asia-Pacific

Singapore's technology risk expectations and personal data protection duties beside Australia's prudential information security standard, with notification clocks and third-party obligations modelled where the regulator places them.

MAS TRMSingapore PDPAAPRA CPS 234

United Kingdom

UK GDPR and the Data Protection Act with the 72-hour clock in the workflow, the outcome-based cyber assessment framework, the operational resilience regime with impact tolerances and mapping, and the Cyber Essentials baseline under expiry tracking.

UK GDPR & DPANCSC CAFUK Operational ResilienceCyber Essentials

Europe

Digital operational resilience obligations including the register of information, the NIS2 risk-management and staged reporting duties, the AI Act by risk class, GDPR accountability, and the automotive assessment catalogue.

EU DORAEU NIS2EU GDPREU AI ActTISAX

Americas

Sarbanes-Oxley IT general controls with test plans and deficiency tracking, and California privacy duties with statutory response windows, sharing the same evidence as your global standards work.

SOX ITGCCCPA / CPRA

Global standards

ISO 27001, ISO 27701, ISO 42001 and ISO 22301, SOC 2, NIST SP 800-53 and CSF 2.0, CIS Controls, HITRUST, PCI DSS and HIPAA, the standards your customers and auditors already expect.

ISO 27001ISO 27701ISO 42001ISO 22301SOC 2NIST SP 800-53NIST CSF 2.0CIS Controls v8HITRUST CSFPCI DSSHIPAA

Sector & GxP

21 CFR Part 11 and EU GMP Annex 11 for validated systems, with audit trail, validation and supplier governance evidence held under the same expiry rules as everything else.

21 CFR Part 11EU GMP Annex 11

Honest AI

Autonomous upkeep. Accountable decisions.

The category is racing to hand the programme to an agent. We built the opposite kind of autonomy: the tedious upkeep runs continuously on its own, and nothing changes your programme without a named human on the record. That is automation you can defend to an auditor.

Autonomy that acts

An agent changes the programme on its own

Fast, until the examiner asks who approved it. What you are left holding is a log of what a machine decided, with no person accountable for the decision.

Autonomy that maintains

The machine keeps state current. A human owns every change.

Monitoring, drafting and crosswalking run continuously. Every proposed change carries a source and a confidence score, and waits for a named approver. The record shows who decided, on what evidence.

Questionnaire assist, cited, scored, reviewable

Q: How is access to production systems reviewed?

Access to production systems is reviewed quarterly by the platform owner, with results recorded and exceptions remediated within 30 days.

Source: Access Control Policy v4.2, §3.1Confidence: 0.91Awaiting human approval

The audit trail records what was proposed, what was accepted, and by whom.

Illustrative, computed live per tenant in the platform.

Every AI output starts from your tenant's data and ends at a human decision. Nothing enters the programme silently. The audit trail records what was proposed, what was accepted, and by whom.

The standard we hold

What a compliance operating system should be able to answer

Any Tuesday

Posture answers on the day you ask, not eight weeks after the request.

One click

From a board-level figure to the control, the evidence, the owner and the date.

Zero silent AI

No AI-proposed change enters the programme without a recorded human approval.

The auditor's question is never "what did the system do." It is "who decided this, on what evidence, and where is that written down."

How we compare

Compare the approach, not the logo

We publish the criteria, mark ourselves honestly against them, and say where each other approach fits better.

  • SOC 2 Type II operating posture
  • Encryption at rest and in transit
  • Every action in the audit log

Proof of concept

Don't take the website's word for it

A proof of concept takes days, not months, and ends with a dashboard you own, not a slide about one. Adopt your frameworks. Load your evidence. Assess a slice of your vendors. Interrogate a live dashboard where every number drills to its source.

01

Adopt your frameworks and watch the crosswalk compute existing coverage on day one.

02

Load a slice of real evidence and see expiry tracking raise renewal tasks before a lapse.

03

Interrogate the dashboard with your hardest question, and drill it to source in front of us.

Get done once Your evidence stays yours, on the way in and on the way out.

Frequently asked questions

What is a compliance operating system?

A compliance operating system connects frameworks, controls, evidence, risks, audits, policies and vendor assessments on a single data model, so posture computes continuously instead of being reassembled before each audit.

Which frameworks does Compli-Once support?

Global standards including ISO 27001:2022, SOC 2, NIST SP 800-53, PCI DSS, HIPAA and ISO 22301; Indian mandates including SEBI CSCRF, RBI CSF, RBI IT Governance MD, DPDP Act, the IRDAI Cyber Guidelines and the CERT-In directions; Middle East frameworks including UAE IA, UAE PDPL, SAMA CSF, NCA ECC and Qatar NIA; UK and European regimes including UK GDPR, the Cyber Assessment Framework, operational resilience, Cyber Essentials and DORA; GxP frameworks including 21 CFR Part 11; plus custom frameworks you author.

How is Compli-Once different from a certification automation platform?

Certification automation is strongest for cloud-native companies proving SOC 2 and ISO 27001 to customers. Compli-Once is built for enterprises answerable to sector regulators: mandates modelled control by control, jurisdictional reporting clocks inside the incident workflow, and AI whose every suggestion carries a source, a confidence score and a human approver.

Does the AI act autonomously?

No. Compli-Once's AI proposes mappings and answers with a source and a confidence score. A human approves every change, and the audit trail records the decision.

How long does it take to see Compli-Once on our own data?

A proof of concept runs in days. You adopt your frameworks, load a slice of real evidence, assess a handful of vendors, and end with a live dashboard you can interrogate, not a slide about one.

Can Compli-Once run frameworks you do not ship?

Yes. Anything not in the library you author yourself, with the same crosswalks, dashboards, evidence tooling and reporting as a shipped framework. There is no second-class framework in Compli-Once.

Who owns the data inside Compli-Once?

You do. Evidence, controls, mappings and the full audit trail are exportable at any time in open formats, including after a proof of concept that does not convert.

How does Compli-Once handle a regulator's reporting clock?

Reporting deadlines are modelled inside the incident workflow rather than kept in a runbook. When an incident is classified, the applicable clocks start, the owner is notified, and the submission is filed against the incident record as evidence.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.