CEDX Compliance keeps a library of 320 controls mapped to eight frameworks, scores each one, ages the evidence behind it, and puts the gaps in a queue with owners — so an audit is a query, not a project.
The framework cards are honest about the shape of the work: SOC 2 at 84% with 11 gaps, PCI DSS at 68% with 12. Zero frameworks are near-ready, and the card says zero.
compliance.cedxsystems.com — live build
Runs on demo data — Northline is the software's sample tenant, not a customer, and its readiness scores are the demo's own.
320 controls in the library173 passing · 35 failing · 43 not yet tested
77% program readinessweighted across 8 framework packs
65 stale evidence itemsaged 90 days or more, dated on the row
What it is
An evidence machine, not a checklist.
320 controls, each with a status and an owner
The library lists code, control, domain, status, the frameworks it maps to, owner and evidence age: a break-glass procedure passing with 95-day-old evidence, a code-review control failing, an encryption-in-transit control never tested.
Pass, partial, fail and not-tested as chips
Evidence age in days on every row
Multi-framework mapping printed per control
compliance — screen-4
Eight frameworks, weighted and dated
Each program shows readiness, control count, gaps and the next audit date: SOC 2 Type II at 84% with its audit on 2026-11-01, PCI DSS v4.0 at 68% due 2026-10-20, ISO 27701 not started at 62%.
8 active packs, 0 near-ready at ≥85%
Next-audit dates on the rows that have them
70 open gaps across all packs, totalled
compliance — screen-3
An agent that drafts — never decides
The compliance agent chased a fresh MFA coverage export (evidence age 112 days, down to 2), nudged an owner on a 34-day-overdue review, and drafted dual-approval enforcement for the change pipeline. Four actions sit pending a human's approval.
Evidence chased, owner nudged, mapping proposed
Approve or dismiss on every proposed action
Projected gap impact shown before you apply
compliance — screen-2
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/compliance.
compliance.cedxsystems.com
01 — Overview
The program, weighted
173 of 320 controls ready, 18 high-gap controls, 70 failing continuous monitors, 104 fail-or-partial with 43 never tested. The readiness bars per framework carry their gap counts — 84% SOC 2 means 11 gaps, not a grade.
Ready versus gaps, daily, with event markers
Failing-test gaps named: configuration management at 74
Agent actions this week: 6 done, 4 pending
02 — Gaps
The queue the audit will ask about
151 scored gap rows: clock sync failing with evidence 136 days old, logical access controls at 112 days, red-team findings at 167. Each row offers the agent's draft — and the draft waits for you.
High gap ≥55 · 18 to close first
Evidence staleness as its own tab: 125
Domain and top signal on every row
03 — Frameworks
One library, eight lenses
The same 320 controls roll up differently per program: 98 controls into SOC 2 Type II, 93 into ISO/IEC 27001:2022, 54 into PCI DSS v4.0, 42 into the HIPAA Security Rule. Status and owner per program, on the row.
Readiness weighted, not averaged — 77% overall
In progress versus not started, stated
CSV export of the framework table
04 — Controls
The library underneath
Search by code, title or owner and read the library directly: board reporting passing on 1-day-old evidence, subprocessor inventory untested, privileged-session recording partial. The library is the product; everything else is a view of it.
320 rows, sortable by code
Owner on every control
Frameworks mapped per row, several at once
Who runs it
Three roles keep the evidence honest.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
Compliance lead
Owns the framework packs and the audit dates — the 77% weighted readiness and the zero near-ready card are theirs to move.
frameworks · 8
Control owner
Keeps their controls' evidence fresh — a 34-day-overdue review is a nudge from the agent, not an audit finding.
stale evidence · 65
Engineering reviewer
Reads the failing tests on the change pipeline and approves — or dismisses — the agent's drafted remediation.
pending approvals · 4
The shape of it
What the demo program actually looks like.
Every figure below is legible in the captures above. Nothing here is a claim about any real organisation — it is the state of the demo data.
320controls in the librarymapped across 8 frameworks
18high-gap controlsscore ≥55, queued close-first
70failing testscontinuous monitors, today
65stale evidence items90 days old or more
Framework readiness, with gap countsweighted per program, from the Frameworks screen
SOC 2 Type II — 98 controls, audit 2026-11-0184% · 11 gaps
Controls by status173 passing of 320 in the library
Pass · 173
Partial · 69
Fail 35 · not tested 43
Program readiness77% weighted across the 8 packs
77%
Weighted readiness · 77%
0 frameworks near-ready at ≥85% — the card says so
How it runs
A control's life, in the order it actually happens.
01
Map
A control enters the library and maps to the frameworks that cite it — one row, up to four programs.
02
Test
Continuous monitors test the control and the status lands: pass, partial, fail — 70 monitors are failing today, and each failure is a gap with an owner.
03
Evidence
Evidence attaches with a date; at 90 days it is stale and the count moves — the agent chases fresh exports and nudges owners before the audit does.
04
Approve
Remediation is drafted with its projected gap impact — dual-approval on the change pipeline projects roughly 18 points — and a human applies it or dismisses it.
One record
The evidence is the work the estate already does.
A control is only testable if the thing it governs exists as a record — the grant, the rotation job, the restore test. Those records are the estate.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Compliance is not generally available. What opens today is the live build on demo data — Northline is the software's sample tenant, and its readiness scores describe the demo only.
This page makes no certification claim about CEDX Systems. The framework screens show how the product tracks a tenant's readiness against framework requirements; they are not attestations, ours or anyone's.
The 77% readiness figure is the demo tenant's weighted score, printed on its own cards. It is not a prediction of your audit outcome.
The agent drafts and chases; it does not approve. Four of its actions sit pending a human in the demo, and that boundary is the design, not a limitation we plan to quietly remove.
We have no named customers to show you, so this page shows none.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/compliance. It runs on demo data — Northline is the sample tenant.
Does using this make us compliant?
No, and this page does not claim otherwise. The product tracks controls, gaps, evidence age and readiness against framework requirements — the attestation is an auditor's, and the work is yours. The demo's own cards show 0 of 8 frameworks near-ready, which is the honest shape of most programs.
What does the agent actually do?
It chases evidence (a fresh MFA coverage export arrived, ageing 112 days of staleness down to 2), nudges control owners on overdue reviews, proposes control-to-framework mappings, and drafts remediation with a projected gap impact. Every proposal waits for a human to approve or dismiss.
How does one library serve eight frameworks?
Each control maps to the frameworks that cite it — the same logical-access control feeds SOC 2, ISO 27001 and others from one row, with its evidence age shared. Readiness is then weighted per program, not averaged.
Is CEDX Systems itself certified?
No certification claim is made here or on this page. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.
The gaps are dated. Go and look at them.
Live build, demo data, no card. Then ask how old your oldest piece of evidence is.