Control evidence

Prove the control was enforced, not that a policy says it should be

CompliancePortal maps the findings the other products already produce onto the frameworks you are working against, and keeps that evidence current. The pitch is narrow and worth stating precisely: an auditor does not want a document saying MFA is required, they want proof it was enforced across a period, with the exceptions named and time-boxed. The catalogue holds 24 frameworks across 7 families, and the licence is scoped to the ones you actually work against rather than to all of them.

Coming soon Built, but you cannot buy it yet

This one is built and running, and it is close. You still cannot buy it, and nothing on this page is an invitation to try. Its price is published so the number is settled before it ships rather than negotiated after.

Why it matters

The gap this closes is a proof gap, not a reporting one. Most compliance tooling stores the statement that a control exists; the evidence that it was enforced gets assembled by hand in the fortnight before an audit, out of screenshots taken on the day — which prove nothing about the eleven months before them. The findings that would have proved it were being generated the whole time and thrown away.

Two axes rather than one. Scope is how many frameworks you need. Depth is whether you want sign-off and automatic capture. Those used to share a number, which meant a company doing SOC 2 alone had to buy every regime in the catalogue to reach attestation — paying for twenty-three frameworks it would never open, to get one capability. They are priced apart now, and the bands show both.

Providers get pooled framework licences: a framework is licensed once across the whole book rather than sixty times, because sixty clients paying per tenant is not a price, it is a decline. The crosswalk is written once, so it is charged for once. That is arithmetic, not a concession.

What it does

  • Reuses evidence instead of re-collecting it — the control-tagged findings from SecurityPortal, ShareCare, WebScan and MailTrust are already structured and already dated. An assessment reads them. Nobody re-screenshots a setting a scan recorded three weeks ago.
  • Crosswalks one fact onto many controls — MFA enforcement is demanded by SOC 2, ISO 27001, NIST CSF, PCI DSS, HIPAA and a dozen others, in a dozen different vocabularies. The crosswalk answers all of them from the same evidence, which is the only reason a second framework is less work than the first.
  • Runs automated control probes — across the planes SeQontrol connects to: Entra ID, Exchange Online, SharePoint, Teams, Intune, Azure, Purview and Power Platform, plus Google Cloud and AWS through read-only connectors, and GitHub and Azure DevOps for the engineering controls.
  • Snapshots each assessment immutably — an audit asks what was true across a window, not what is true this morning. An assessment keeps the state it saw, so a control fixed in March still reads as failing in February. That is the answer an auditor is entitled to.
  • Asks for the evidence a probe cannot fetch — an evidence repository with provided-by-client requests, for the board minute, the signed procedure, the third-party letter. Those are named and requested rather than scored around.
  • Attests, with four eyes and an expiry — sign-off names a person and stops being valid on a date. Control ownership and remediation tasks come with it, so a failing control has somebody against it rather than a colour.
  • Lets the auditor read it in place — time-boxed access, so the evidence is examined where it lives instead of exported into a shared folder that outlives the engagement.

What it will not do

It covers the controls that map to a technical implementation on the platforms SeQontrol connects to. It is not a compliance programme: it will not run your policy management, your training records or your vendor reviews, and it does not replace the GRC platform that does. If a framework you care about is mostly people and process, most of it stays outside this product, and you should hear that now rather than in month two.

Assessments are on-demand. You raise one when you want one; there is no recurring cadence, and that row sits empty on the pricing page rather than quietly ticked. What is continuous is the evidence underneath — the other products scan on their own schedules, and their control-tagged findings are what an assessment reuses.

It produces readiness, not an opinion. Your auditor still signs, and nothing here shortens that conversation by pretending to have had it already.

One gap behind the provider pricing

Pooled framework licences have a published price, but the entitlement shape behind them is still being built. Entitlements in this platform resolve per tenant, and a licence saying "this provider may assess SOC 2 against any client in its book" has to be granted at the provider and enforced at the tenant. The figures are what you would be quoted; the gate behind them is work in progress, and it is listed here rather than discovered at onboarding.

Capability and what you get from it

CapabilityWhat you get from it
Multi-framework crosswalkOne piece of evidence answers the same control in every regime that asks for it
Automated control probesThe control is checked on the platform, not asserted in a spreadsheet
Evidence reuse from the other productsThe proof was already being collected, so the audit stops being a collection exercise
Immutable assessment snapshotsWhat was true on the date stays readable after the estate moved on
Evidence repository with client requestsThe documents no probe can fetch are asked for by name instead of scored around
Attestation with four eyes and expiryA sign-off that names a person and stops being valid on a date
Time-boxed auditor accessThe auditor reads the evidence in place, and the window closes behind them
Scope and depth priced apartSOC 2 alone costs a single-framework band rather than the whole catalogue
Pooled framework licencesOne crosswalk licensed once across a whole book, not once per client

Ask where it actually is

It is built and close, and it is not released — no order form, and no waiting list dressed up as one. What you can have today is a straight answer on the state it is in, the catalogue and the crosswalk checked against the frameworks you actually work against, and a look at what the shipped products are already recording as evidence for it.