A marketplace of audit-ready frameworks — SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST 800-171 — with every control and requirement structured and ready to map evidence against. Fork any pack to build your own. It's the rules engine your audits run on.
Each pack breaks a standard into its controls and atomic requirements, each with the evidence it expects — so a machine (and your auditor) can actually work with it.
Trust Services Criteria — security, availability, confidentiality, processing integrity, privacy.
Type I & IIAnnex A controls for an information security management system, mapped to requirements.
ISMSAdministrative, physical and technical safeguards for protected health information.
PHIThe twelve requirements for handling cardholder data, broken into testable checks.
Cardholder dataProtecting controlled unclassified information across fourteen control families.
CUIFork any pack or start blank — add controls, requirements and evidence asks. Your custom framework, tenant-local.
CustomizableCompAIQ is the standards layer of the AI-IQ platform. The frameworks you assemble here become exactly what AuditAIQ audits against — and DocAIQ supplies the evidence. One pipeline, privacy-native throughout.
Browse the marketplace, fork a pack, and make compliance something a machine can help you actually do.