Your compliance program, in one workspace. Controls, automated tests, evidence, and policies across every framework and system you run — scoped by the ribbon up top, laid out so the whole program reads at a glance. This is an interactive preview with fictional data; click the rail and the ribbon to explore.
Acme
Compliance workspace
System Prod Web Enclave ▾

Overview

Prod Web Enclave · CMMC 2.0
Scoped to Prod Web Enclave under CMMC 2.0 — switch the system or framework up top to re-scope everything.
◎ Framework score
68%
75 of 110 requirements met
✔ Controls
35
need attention
13 partial 22 gap
◎ Tests
7
failing of 42 automated
35 passing 7 failing
▧ Documents
5
drafts of 23
18 published
◷ POA&M
6
open items · 2 overdue

Systems in scope

3 systems
🖥 Prod Web Enclave
Debian 13 · web+api
CMMC 68%SOC2 54%
🖥 CI Runner Pool
Rocky 9 · build
CMMC 51%
🖥 Corp Laptops
Windows 11 · endpoints
CMMC 33%

Controls

110 requirements · Prod Web Enclave · CMMC 2.0
The requirement is the row; the Tests column links the automated checks that evidence it, and Evidence is what an assessor opens first.
Status: All ▾
Family: All ▾
Owner: All ▾
ControlRequirementStatusTestsEvidenceOwner
3.1.1
Limit system access to authorized users
Access Control
● Met3 passing▧ IAM policy AV Alex Vega
3.1.5
Least privilege
Access Control
● Partial1 failingNone recorded JR Jordan Rowe
3.4.2
Enforce baseline configuration
Configuration Mgmt
● Met6 passing◎ Salt cmmc_report AV Alex Vega
3.5.3
Multi-factor authentication
Identification & Auth
● Gap2 failingNone recorded Unassigned
3.8.9
Protect backups of CUI
Media Protection
● N/A▧ Boundary note JR Jordan Rowe
3.13.11
FIPS-validated cryptography
System & Comms
● Partial2 passing▧ Cipher config AV Alex Vega
3.14.1
Flaw remediation
System & Info Integrity
● Gap1 failingNone recorded JR Jordan Rowe

Tests

42 automated checks · last run 14m ago
Automated checks reported by the Salt runner on Prod Web Enclave. Each maps to the control(s) it evidences — a passing test is evidence, not a control status by itself.
Result: All ▾
Host: Prod Web Enclave ▾
TestResultLast runCoversHost
SSH root login disabled
sshd_permitrootlogin
✓ Pass14m ago3.1.1 3.5.3Prod Web Enclave
Password quality (pwquality)
pam_pwquality_minlen
✓ Pass14m ago3.5.7Prod Web Enclave
MFA enrolled for privileged users
mfa_priv_enrolled
✕ Fail14m ago3.5.3Prod Web Enclave
Automatic security updates
unattended_upgrades
✕ Fail14m ago3.14.1Prod Web Enclave
Firewall default-deny inbound
nftables_default_deny
✓ Pass14m ago3.13.1 3.13.5Prod Web Enclave
Audit daemon running (auditd)
auditd_active
✓ Pass14m ago3.3.1Prod Web Enclave

Documents

23 documents
Policies, uploaded evidence, and the org's SSP / POA&M in one place — the paper an assessor asks for, with its status and owner.
Type: All ▾
Status: All ▾
TitleTypeStatusUpdatedOwner
Access Control PolicyPolicy● PublishedAug 9AV Alex Vega
System Security Plan (SSP)SSP● DraftAug 11JR Jordan Rowe
Plan of Action & MilestonesPOA&M● CurrentAug 11AV Alex Vega
Nessus scan — 2026-08-10.pdfEvidence● AcceptedAug 10JR Jordan Rowe
Incident Response PlanPolicy● MissingUnassigned

Policies

8 policies
Read your org's policies any time — check a scenario against them, refresh your memory before you act. Everyone can read; owners and admins can edit. Use the toggle to preview each view.
Preview as:
Access Control Policy
Access Control · v3 ● Acknowledged
Acceptable Use Policy
Governance · v2 ● Not read
Data Handling & Classification
Data Protection · v4 ● Acknowledged
Incident Response Policy
Security Ops · v1 ● Not read
Password & MFA Policy
Identity · v2 ● Acknowledged
Access Control Policy
Access Control · updated Aug 9, 2026 · version 3 · owner Alex Vega

This policy governs how access to Acme systems and Controlled Unclassified Information (CUI) is granted, reviewed, and revoked. It applies to all members, contractors, and automated identities.

Least privilege

Access is granted on a need-to-know basis. A person or service receives only the permissions required for their current role, and elevated access is time-bound and logged.

Multi-factor authentication

MFA is required for all privileged access and for any access to systems that store or process CUI. A scenario you're unsure about — "can I use a shared login for the CI runner?" — is answered here: no, individual accounts with MFA only.

Review & revocation

Access is reviewed quarterly and on any role change. Departures trigger same-day revocation across all systems in scope.

🕑 You acknowledged this policy on Aug 9, 2026. Re-read any time — your acknowledgment stands until the policy changes.
Editing is restricted to owners and admins. Members see this read-only, with an Acknowledge button and their acknowledgment history.

Registers

6 areas · 15 registers
Your existing register program (the editors you already have), grouped so the rail isn't a wall of fourteen items. This is the "program" content, kept but tidied.
Security ownership
RACI · responsibilities · authority
Data & flows
Data inventory · data flow · access-control matrix
Engineering
DevSecOps evidence · dependencies · logging design
Risk & decisions
Assumptions · decisions · corrective actions
Incidents
Incident register
Maturity & gov
Maturity assessment · FOCI · gov worksheet

Roadmap

POA&M · 6 open
Open items with a target date — the same data as the POA&M document, worked as a list.
ItemStatusTargetOwner
Enroll all privileged users in MFA (3.5.3)● OverdueAug 8AV Alex Vega
Enable unattended security updates (3.14.1)● In progressAug 20JR Jordan Rowe
Author Incident Response Plan● Not startedSep 1Unassigned

People

4 members
Who's acknowledged which policy and completed which training — the roster, for the human controls.
MemberRolePoliciesTraining
AV Alex VegaOwner● 6/6● 3/3
JR Jordan RoweAdmin● 4/6● 3/3
SO Sam OkaforEditor● 1/6● 0/3

Tell us what you think

Comments, bugs, or a feature you wish this had — it goes straight to the team.
✓ Thanks — we read every one of these.