Now accepting Q2 engagements ·Reserve a slot →

Deterministic GRC pipeline. Zero knowledge.

Audit-ready compliance outcomes, engineered like software. Bring your framework—we return verifiable evidence, mapped controls, and a signed report. Your data never persists on our side.

Zero data retention Framework-agnosticEU-HOSTED · GDPR-NATIVE
cplt / pipeline / run-#4829
01 / INGESTLIVE

Isolated sandbox

Infra snapshot ingested into an air-gapped, single-tenant workspace.

02 / MAP

Deterministic mapping

Controls pinned to your framework. Same inputs → same output, every run.

03 / DISCARD

Zero retention

Evidence returned as a signed report. Workspace is shredded on completion.

framework

SOC 2 · TYPE II

controls

127 / 127 mapped

evidence

48 artifacts signed

retention

0.0 MB · purged

Built for every serious framework · BYOF supported

SOC 2 Type II
ISO/IEC 27001:2022
ISO/IEC 27701
HIPAA
GDPR
PCI DSS v4.0
NIST CSF 2.0
NIS 2
CIS Controls v8
HITRUST CSF
Custom Control Set
Internal Policy
SOC 2 Type II
ISO/IEC 27001:2022
ISO/IEC 27701
HIPAA
GDPR
PCI DSS v4.0
NIST CSF 2.0
NIS 2
CIS Controls v8
HITRUST CSF
Custom Control Set
Internal Policy
01The Problem

Compliance audits were designed before infrastructure moved this fast.

Three structural flaws keep modern teams stuck in a 1990s audit cycle — manual, subjective, and dangerously over-permissioned.

THE PRIVACY GAP

Your auditors need your secrets.

Traditional audits require long-term access to production data, credentials, and infrastructure. That access itself becomes a compliance liability.

THE CONSISTENCY PROBLEM

Two auditors. Two verdicts.

Subjective audit methods produce non-reproducible results. Same infrastructure, different findings — because every auditor interprets controls differently.

THE AMNESIA TAX

Every year starts from zero.

Annual re-audits discard prior context. You pay, again, for someone to learn your environment from scratch — instead of diffing what changed.

02The Pipeline

Three stages. Zero interpretation. Verifiably reproducible.

CPLT runs every engagement through the same deterministic pipeline. Your infrastructure is never exposed. Your evidence is never stored. Your report is signed and reproducible.

01 / STRICT ISOLATION

Your evidence lands in a single-tenant, ephemeral workspace.

No shared infrastructure, no lingering sessions. Each engagement spins up an isolated environment — cryptographically sealed, scoped to a single run, destroyed on completion.

  • Per-engagement single-tenant sandbox
  • Hardware-isolated compute (EU region)
  • Scoped least-privilege access tokens
02 / DETERMINISTIC MAPPING

Same inputs in. Same findings out. Every run, every auditor.

Your raw evidence is mapped to framework controls through a rule-based, reproducible pipeline. No junior-auditor interpretation. No subjective grading. Just verifiable, diff-able output.

  • Rule-based control mapping (framework-agnostic)
  • Signed artifact hashes for every finding
  • Reproducibility guarantee — re-run yields identical mapping
03 / ZERO RETENTION

Your data is purged before the report is delivered.

The signed Architect Report contains everything your auditor or board needs. The raw evidence, credentials, and workspace are cryptographically shredded before hand-off. Nothing persists on our side.

  • Verifiable workspace destruction log
  • No long-term data processor relationship
  • GDPR-native: no residual processing scope
03The Product

The Architect Report.
Audit-ready, out of the box.

Every engagement produces a single, signed deliverable: the CPLT Architect Report. It is the finished artifact your board, regulator, or customer needs — not a dashboard you have to operate.

The Objective Grade

Framework-aligned control mapping, severity-weighted risk scoring, and audit-ready narrative sections — ready to submit.

Deterministic Remediation

Prioritized roadmap with implementation specs. Every finding ships with the exact fix, verifiable post-remediation.

Signed & Verifiable

Every artifact is cryptographically signed. Regulators and counter-parties can verify authenticity without contacting CPLT.

architect-report_soc2_ACME.pdf

SIGNED ✓

FINDING · CTRL-IAM-04

Privileged session timeout not enforced

HIGH

framework

SOC 2 CC6.3

iso map

A.5.15 / A.8.2

evidence

3 artifacts

status

open · priority 1

REMEDIATION · DETERMINISTIC

  • Enforce 15-min idle timeout on privileged IAM roles.
  • Rotate root-equivalent service accounts on 90-day cycle.
  • Ship session-termination log to immutable store.
sha256 · a7f9…91c4…3e08CPLT-ARCHITECT · v3.2
04What You Get

Six primitives that make “pass the audit” feel mechanical.

ZERO RETENTION

Zero-retention by construction

Your evidence is destroyed before the report ships. Not a policy — an architectural guarantee with a verifiable shred log.

REPRODUCIBLE

Deterministic mapping

Rule-based control mapping means two runs produce byte-identical output. Findings are reproducible by design.

BYOF

Bring your own framework

SOC 2, ISO 27001, HIPAA, PCI — or your internal control set. CPLT maps your evidence to your chosen framework, not ours.

EU / GDPR

EU-hosted · sovereign

Infrastructure operated from the EU with GDPR-native processing boundaries. Data residency is a design choice, not a checkbox.

SIGNED

Signed, verifiable evidence

Every artifact in the Architect Report carries a cryptographic signature. Third parties verify authenticity without a single CPLT call.

ARCHITECT

Architect-validated, not outsourced

Every engagement is reviewed by a senior practitioner. No junior auditor interpretation, no outsourced review queues.

05Bring Your Own Framework

Your framework.
Your language.
Our pipeline.

Most compliance products force you to adopt their control taxonomy. CPLT inverts that. Supply any framework — public, private, contractual, or bespoke — and the pipeline maps to it deterministically.

DROP-IN FRAMEWORK

Upload your control set as JSON, XLSX, or PDF. CPLT parses and pins every control to your raw evidence.

CROSS-MAPPING

One engagement can produce multiple mapped reports — SOC 2 and ISO 27001 simultaneously, from the same evidence.

SECURITY & PRIVACY

  • SOC 2 Type II
  • ISO/IEC 27001:2022
  • ISO/IEC 27701
  • NIST CSF 2.0

REGULATED INDUSTRIES

  • HIPAA
  • PCI DSS v4.0
  • HITRUST CSF
  • NIS 2

DATA PROTECTION

  • GDPR
  • EU AI Act
  • CCPA / CPRA
  • DORA

YOUR OWN RULES

  • Custom control set
  • Internal policy
  • Contractual (DPA / MSA)
  • Regulatory letter response

DON’T SEE YOURS?

If you can express your controls in text, CPLT can map them. Send your framework — we’ll confirm fit within 48 hours.

Supported frameworks include SOC 2 Type II, ISO/IEC 27001:2022, ISO/IEC 27701, HIPAA, GDPR, PCI DSS v4.0, NIST CSF 2.0, NIS 2, CIS Controls v8, HITRUST CSF, Custom Control Set, Internal Policy.

06Compared

Not compliance software.Not a billable-hour consultancy.

CPLT is a third category: a productized, deterministic audit engagement. Priced per outcome, not per seat, not per hour.

DIMENSION

CPLT

Productized engagement

Compliance SaaS

Vanta / Drata / etc.

Traditional audit

Big-4 / boutique

Pricing model
Fixed per-engagement. Outcome-based.
Per-seat + per-integration, annual.
Hourly or daily rate, variable.
Data retention
Zero. Evidence shredded on completion.
Indefinite — your data lives in their cloud.
Stored on auditor laptops, loosely.
Reproducibility
Deterministic — same inputs, same findings.
Subjective — driven by auto-scans.
Subjective — auditor-dependent.
Framework flexibility
Any framework. BYOF-native.
Fixed, pre-baked frameworks only.
Flexible, but re-scoped hourly.
What you own at the end
Signed, verifiable Architect Report.
A dashboard you keep paying to access.
A slide deck and a PDF.
07Project Anchor

Amnesia-free compliance.
Diff, don’t restart.

Every engagement ships with a signed Project Anchor — a cryptographic fingerprint of your environment’s control state. The next assessment runs a delta, not a full re-audit. You pay for what changed, not for what already passed.

First engagement: full scope

0.2–0.4×

Follow-ups: delta only

−60%

Typical reassessment time

DELTA ANALYSIS · PROJECT ANCHOR

CTRL-NET-02 · Network segmentation
UNCHANGED
CTRL-ACC-11 · Key rotation cadence
UNCHANGED
CTRL-IAM-04 · Privileged session timeout
IMPROVED
CTRL-LOG-09 · Immutable audit log introduced
NEW
CTRL-BCP-02 · RTO widened to 8h (was 4h)
REGRESSION

checked

127

unchanged

118

changes

9

Only 9 controls need reassessment. Your next engagement is priced accordingly.

08Why CPLT

The Architect Advantage.

Three non-negotiables that define how every CPLT engagement runs.

ARCHITECT-VALIDATED

Senior practitioner, every engagement.

Every finding is reviewed and signed by an engagement architect — not a junior analyst running a checklist tool. If it’s in your report, a senior practitioner staked their name on it.

SOVEREIGN INFRASTRUCTURE

EU-hosted. GDPR-native.

CPLT operates on EU-resident compute with cryptographically enforced data boundaries. No transatlantic transfers, no standard-contractual-clause gymnastics, no legal hedge.

TRANSPARENT ENGAGEMENT

Fixed-scope, fixed-fee, no surprise renewals.

One engagement, one price, one signed deliverable. No per-seat licensing, no SKU stacking, no auto-renewed subscription paying for access to your own compliance history.

09Questions

Straight answers.
No marketing-speak.

Still unsure? Scope a 30-minute technical call with the engagement architect. No sales layer.

— READY WHEN YOU ARE

Scope your next audit in one 30-minute call.

No sales engineers. No decks. Just the architect who will run your engagement, scoping the framework and environment directly with you.

EU-HOSTEDZERO RETENTIONDETERMINISTIC