Compliance Evidence Workspace · Free

Run your SOC 2, ISO 27001, or HIPAA program in one place — free

Track readiness, store evidence in an encrypted vault, and export an auditor-ready pack. Do it yourself for free, or have intSignal run the whole program for you. Your evidence is isolated, encrypted, and yours — even our admins can't see it.

3

frameworks: SOC 2, ISO 27001, HIPAA

$0

free, no purchase required

100%

your evidence, isolated & encrypted

A real compliance program, not a checklist in a spreadsheet

Most teams run their SOC 2 or HIPAA prep in a shared spreadsheet and a folder of screenshots — until an auditor asks for the one file nobody can find. The Compliance Workspace replaces that with a structured, fillable program: every control in one place, evidence attached where it belongs, readiness scored live, and an export that's ready for the audit. It's part of the intSignal portal — one account, one login — and it's free to use.

Three frameworks, one engine

Pick the standard you need. The way you work an item — status, notes, evidence — is identical across all three.

SOC 2 (Trust Services Criteria)

The report your customers and prospects ask for. Work the Trust Services Criteria — security, availability, confidentiality, processing integrity, and privacy — with evidence attached to each.

ISO 27001 (Annex A / ISMS)

The international standard for an information security management system. Track the Annex A controls and the ISMS requirements auditors certify against.

HIPAA (Security & Privacy Rule)

For anyone handling protected health information. Cover the administrative, physical, and technical safeguards of the Security Rule plus Privacy Rule requirements.

Everything you need to reach the audit

A fillable program

Structured controls for your framework. Set each to not started, in progress, implemented, or N/A with justification; add notes and structured fields. Progress is saved to your account — no spreadsheet to lose.

Readiness scoring & gaps

A live percentage complete per control domain and overall, plus a prioritized list of exactly what's still missing — so you always know how audit-ready you are and what to do next.

Encrypted evidence vault

Upload and attach evidence to each control. Files are encrypted at rest in isolated storage, versioned, and stamped with who uploaded them and when. Reachable only through short-lived signed links.

Tasks & reminders

Assign controls to owners, set due dates, and let the workspace send email reminders for what's upcoming or overdue — so evidence collection actually happens instead of stalling.

Exportable auditor pack

Generate a branded PDF/ZIP of your current state — controls, statuses, notes, gaps, and the attached evidence — to hand your auditor. Export is one click, on your schedule.

Built-in isolation

Your evidence lives in a separately isolated system with its own database, storage, keys, and tamper-evident audit log. Tenant isolation is enforced deny-by-default; even our admins can't see your files.

Your evidence is isolated — by design, not by promise

intSignal is targeted by attackers globally, so the workspace was built to a hostile threat model. It is a separately isolated system inside the portal: its own service and API boundary, its own database with least-privilege credentials, its own private encrypted storage, its own encryption keys, and its own append-only, tamper-evident audit log. Tenant isolation is enforced deny-by-default in the service layer — and a portal or global admin has no implicit access to your evidence. See the full security & isolation model.

How it works

From signup to a pack your auditor can read, in five steps.

1

Create a free account

Sign up with email, Google, or Microsoft. No purchase, no sales call. Turn on MFA if you're storing evidence.

2

Pick a framework

Choose SOC 2, ISO 27001, or HIPAA. The workspace loads the control set and your readiness starts at zero — and only goes up.

3

Work the controls

Set a status and add notes for each control, and upload the evidence that proves it. Assign owners and due dates so the team shares the load.

4

Watch readiness climb

Scoring updates live and the gap list shrinks as you go. You always know the one thing to do next.

5

Export for your auditor

When you're ready, export the branded pack — statuses, notes, gaps, and evidence — and walk into the audit prepared.

Two ways to get compliant

Do it yourself — free

Create an account and work the program at your own pace. The full workspace — controls, scoring, evidence vault, tasks, and the auditor export — is free, forever, with no purchase required. Follow the getting-started guide and you can be working your first controls in minutes.

Start free ➔

Have us run it for you

Short on time or expertise? Our team can operate the whole program as a managed / virtual-CISO engagement — mapping controls to your environment, gathering evidence, closing gaps, and getting you audit-ready. You keep the same workspace and see everything as it happens.

Talk to sales

Start your compliance program today — free

Create an account and pick a framework, or talk to our team about running it for you.

Frequently asked questions

Is the Compliance Workspace really free?

Yes. You can create an account and run a full SOC 2, ISO 27001, or HIPAA program — fillable controls, readiness scoring, the evidence vault, tasks, and the exportable auditor pack — at no cost, with no purchase required. If you later buy intSignal services, they're added to the same account and your compliance data stays exactly where it is.

Which frameworks does it support?

SOC 2 (Trust Services Criteria), ISO 27001 (Annex A / ISMS), and HIPAA (Security and Privacy Rule safeguards). One engine serves all three, so the way you work an item — status, notes, evidence — is the same across frameworks.

How is my evidence protected?

The workspace is a separately isolated system: its own service, its own database with least-privilege credentials, its own private encrypted storage bucket, its own encryption keys, and its own tamper-evident audit log. Tenant isolation is enforced deny-by-default in the service layer, and a portal or global admin has no implicit access to your evidence. Files are encrypted at rest and reachable only through short-lived signed URLs.

Do I have to be an intSignal customer to use it?

No. Signup is open and self-service — email and password, or Google / Microsoft sign-in. You don't need to be a customer to use the workspace for free.

Can intSignal just do our compliance for us?

Yes. If you'd rather not run it yourself, our team can operate the program for you — mapping controls, gathering evidence, and preparing you for the audit as a virtual CISO / managed compliance engagement. Talk to sales to scope it.

Can I export or delete my data?

Yes. You can export your program and evidence at any time (that's what the auditor pack is), and you can delete your data and account entirely. Optional MFA/TOTP is available and strongly encouraged for accounts holding evidence.