CEDX Compliance · IT & Security

Readiness you can
defend, dated.

CEDX Compliance keeps a library of 320 controls mapped to eight frameworks, scores each one, ages the evidence behind it, and puts the gaps in a queue with owners — so an audit is a query, not a project.

The framework cards are honest about the shape of the work: SOC 2 at 84% with 11 gaps, PCI DSS at 68% with 12. Zero frameworks are near-ready, and the card says zero.

compliance.cedxsystems.com — live build
CEDX Compliance overview: controls ready, program readiness, open gaps, stale evidence, failing tests and framework readiness bars.

Runs on demo data — Northline is the software's sample tenant, not a customer, and its readiness scores are the demo's own.

320 controls in the library173 passing · 35 failing · 43 not yet tested
77% program readinessweighted across 8 framework packs
65 stale evidence itemsaged 90 days or more, dated on the row

What it is

An evidence machine, not a checklist.

320 controls, each with a status and an owner

The library lists code, control, domain, status, the frameworks it maps to, owner and evidence age: a break-glass procedure passing with 95-day-old evidence, a code-review control failing, an encryption-in-transit control never tested.

  • Pass, partial, fail and not-tested as chips
  • Evidence age in days on every row
  • Multi-framework mapping printed per control
compliance — screen-4
320 controls, each with a status and an owner

Eight frameworks, weighted and dated

Each program shows readiness, control count, gaps and the next audit date: SOC 2 Type II at 84% with its audit on 2026-11-01, PCI DSS v4.0 at 68% due 2026-10-20, ISO 27701 not started at 62%.

  • 8 active packs, 0 near-ready at ≥85%
  • Next-audit dates on the rows that have them
  • 70 open gaps across all packs, totalled
compliance — screen-3
Eight frameworks, weighted and dated

An agent that drafts — never decides

The compliance agent chased a fresh MFA coverage export (evidence age 112 days, down to 2), nudged an owner on a 34-day-overdue review, and drafted dual-approval enforcement for the change pipeline. Four actions sit pending a human's approval.

  • Evidence chased, owner nudged, mapping proposed
  • Approve or dismiss on every proposed action
  • Projected gap impact shown before you apply
compliance — screen-2
An agent that drafts — never decides

Product tour

Four screens, captured from the running build.

Not a mockup and not a concept deck. This is what opens at /app/compliance.

compliance.cedxsystems.com
CEDX Compliance Overview screen.CEDX Compliance Gaps screen.CEDX Compliance Frameworks screen.CEDX Compliance Controls screen.

01 — Overview

The program, weighted

173 of 320 controls ready, 18 high-gap controls, 70 failing continuous monitors, 104 fail-or-partial with 43 never tested. The readiness bars per framework carry their gap counts — 84% SOC 2 means 11 gaps, not a grade.

  • Ready versus gaps, daily, with event markers
  • Failing-test gaps named: configuration management at 74
  • Agent actions this week: 6 done, 4 pending

02 — Gaps

The queue the audit will ask about

151 scored gap rows: clock sync failing with evidence 136 days old, logical access controls at 112 days, red-team findings at 167. Each row offers the agent's draft — and the draft waits for you.

  • High gap ≥55 · 18 to close first
  • Evidence staleness as its own tab: 125
  • Domain and top signal on every row

03 — Frameworks

One library, eight lenses

The same 320 controls roll up differently per program: 98 controls into SOC 2 Type II, 93 into ISO/IEC 27001:2022, 54 into PCI DSS v4.0, 42 into the HIPAA Security Rule. Status and owner per program, on the row.

  • Readiness weighted, not averaged — 77% overall
  • In progress versus not started, stated
  • CSV export of the framework table

04 — Controls

The library underneath

Search by code, title or owner and read the library directly: board reporting passing on 1-day-old evidence, subprocessor inventory untested, privileged-session recording partial. The library is the product; everything else is a view of it.

  • 320 rows, sortable by code
  • Owner on every control
  • Frameworks mapped per row, several at once

Who runs it

Three roles keep the evidence honest.

Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.

Compliance lead

Owns the framework packs and the audit dates — the 77% weighted readiness and the zero near-ready card are theirs to move.

frameworks · 8

Control owner

Keeps their controls' evidence fresh — a 34-day-overdue review is a nudge from the agent, not an audit finding.

stale evidence · 65

Engineering reviewer

Reads the failing tests on the change pipeline and approves — or dismisses — the agent's drafted remediation.

pending approvals · 4

The shape of it

What the demo program actually looks like.

Every figure below is legible in the captures above. Nothing here is a claim about any real organisation — it is the state of the demo data.

320controls in the librarymapped across 8 frameworks
18high-gap controlsscore ≥55, queued close-first
70failing testscontinuous monitors, today
65stale evidence items90 days old or more
Framework readiness, with gap countsweighted per program, from the Frameworks screen
  • SOC 2 Type II — 98 controls, audit 2026-11-0184% · 11 gaps
  • GDPR — 36 controls81% · 5 gaps
  • NIST CSF 2.0 — 48 controls78% · 7 gaps
  • ISO/IEC 27001:2022 — 93 controls76% · 14 gaps
  • HIPAA Security Rule — 42 controls71% · 9 gaps
  • PCI DSS v4.0 — 54 controls, audit 2026-10-2068% · 12 gaps
  • ISO 27701 — 28 controls, not started62% · 8 gaps
Controls by status173 passing of 320 in the library
  • Pass · 173
  • Partial · 69
  • Fail 35 · not tested 43
Program readiness77% weighted across the 8 packs
77%
  • Weighted readiness · 77%
  • 0 frameworks near-ready at ≥85% — the card says so

How it runs

A control's life, in the order it actually happens.

01

Map

A control enters the library and maps to the frameworks that cite it — one row, up to four programs.

02

Test

Continuous monitors test the control and the status lands: pass, partial, fail — 70 monitors are failing today, and each failure is a gap with an owner.

03

Evidence

Evidence attaches with a date; at 90 days it is stale and the count moves — the agent chases fresh exports and nudges owners before the audit does.

04

Approve

Remediation is drafted with its projected gap impact — dual-approval on the change pipeline projects roughly 18 points — and a human applies it or dismisses it.

One record

The evidence is the work
the estate already does.

A control is only testable if the thing it governs exists as a record — the grant, the rotation job, the restore test. Those records are the estate.

All 132 applications

Limits

What Compliance does not do yet.

Finding this out on the third call is worse for you than reading it here, and worse for us.

Start

Open it before you talk to anyone.

Pilot

Your controls, your frameworks

  • Everything in Try
  • Control-library mapping
  • Evidence-workflow workshop
  • Estate map
Talk to sales

Estate

Compliance with the rest of it

  • Compliance with Access, Vault, Backup and Endpoint
  • One identity, one bill
  • CEDX delivery
Book an estate map

Questions

Before you pilot Compliance.

Is the software on this page real?

Yes. Every screenshot is a capture of the running build and you can open the same build at /app/compliance. It runs on demo data — Northline is the sample tenant.

Does using this make us compliant?

No, and this page does not claim otherwise. The product tracks controls, gaps, evidence age and readiness against framework requirements — the attestation is an auditor's, and the work is yours. The demo's own cards show 0 of 8 frameworks near-ready, which is the honest shape of most programs.

What does the agent actually do?

It chases evidence (a fresh MFA coverage export arrived, ageing 112 days of staleness down to 2), nudges control owners on overdue reviews, proposes control-to-framework mappings, and drafts remediation with a projected gap impact. Every proposal waits for a human to approve or dismiss.

How does one library serve eight frameworks?

Each control maps to the frameworks that cite it — the same logical-access control feeds SOC 2, ISO 27001 and others from one row, with its evidence age shared. Readiness is then weighted per program, not averaged.

Is CEDX Systems itself certified?

No certification claim is made here or on this page. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.

The gaps are dated. Go and look at them.

Live build, demo data, no card. Then ask how old your oldest piece of evidence is.