Compliance Evidence Workspace · Free
Track readiness, store evidence in an encrypted vault, and export an auditor-ready pack. Do it yourself for free, or have intSignal run the whole program for you. Your evidence is isolated, encrypted, and yours — even our admins can't see it.
3
frameworks: SOC 2, ISO 27001, HIPAA
$0
free, no purchase required
100%
your evidence, isolated & encrypted
Most teams run their SOC 2 or HIPAA prep in a shared spreadsheet and a folder of screenshots — until an auditor asks for the one file nobody can find. The Compliance Workspace replaces that with a structured, fillable program: every control in one place, evidence attached where it belongs, readiness scored live, and an export that's ready for the audit. It's part of the intSignal portal — one account, one login — and it's free to use.
Pick the standard you need. The way you work an item — status, notes, evidence — is identical across all three.
The report your customers and prospects ask for. Work the Trust Services Criteria — security, availability, confidentiality, processing integrity, and privacy — with evidence attached to each.
The international standard for an information security management system. Track the Annex A controls and the ISMS requirements auditors certify against.
For anyone handling protected health information. Cover the administrative, physical, and technical safeguards of the Security Rule plus Privacy Rule requirements.
Structured controls for your framework. Set each to not started, in progress, implemented, or N/A with justification; add notes and structured fields. Progress is saved to your account — no spreadsheet to lose.
A live percentage complete per control domain and overall, plus a prioritized list of exactly what's still missing — so you always know how audit-ready you are and what to do next.
Upload and attach evidence to each control. Files are encrypted at rest in isolated storage, versioned, and stamped with who uploaded them and when. Reachable only through short-lived signed links.
Assign controls to owners, set due dates, and let the workspace send email reminders for what's upcoming or overdue — so evidence collection actually happens instead of stalling.
Generate a branded PDF/ZIP of your current state — controls, statuses, notes, gaps, and the attached evidence — to hand your auditor. Export is one click, on your schedule.
Your evidence lives in a separately isolated system with its own database, storage, keys, and tamper-evident audit log. Tenant isolation is enforced deny-by-default; even our admins can't see your files.
intSignal is targeted by attackers globally, so the workspace was built to a hostile threat model. It is a separately isolated system inside the portal: its own service and API boundary, its own database with least-privilege credentials, its own private encrypted storage, its own encryption keys, and its own append-only, tamper-evident audit log. Tenant isolation is enforced deny-by-default in the service layer — and a portal or global admin has no implicit access to your evidence. See the full security & isolation model.
From signup to a pack your auditor can read, in five steps.
Sign up with email, Google, or Microsoft. No purchase, no sales call. Turn on MFA if you're storing evidence.
Choose SOC 2, ISO 27001, or HIPAA. The workspace loads the control set and your readiness starts at zero — and only goes up.
Set a status and add notes for each control, and upload the evidence that proves it. Assign owners and due dates so the team shares the load.
Scoring updates live and the gap list shrinks as you go. You always know the one thing to do next.
When you're ready, export the branded pack — statuses, notes, gaps, and evidence — and walk into the audit prepared.
Create an account and work the program at your own pace. The full workspace — controls, scoring, evidence vault, tasks, and the auditor export — is free, forever, with no purchase required. Follow the getting-started guide and you can be working your first controls in minutes.
Short on time or expertise? Our team can operate the whole program as a managed / virtual-CISO engagement — mapping controls to your environment, gathering evidence, closing gaps, and getting you audit-ready. You keep the same workspace and see everything as it happens.
Create an account and pick a framework, or talk to our team about running it for you.
Yes. You can create an account and run a full SOC 2, ISO 27001, or HIPAA program — fillable controls, readiness scoring, the evidence vault, tasks, and the exportable auditor pack — at no cost, with no purchase required. If you later buy intSignal services, they're added to the same account and your compliance data stays exactly where it is.
SOC 2 (Trust Services Criteria), ISO 27001 (Annex A / ISMS), and HIPAA (Security and Privacy Rule safeguards). One engine serves all three, so the way you work an item — status, notes, evidence — is the same across frameworks.
The workspace is a separately isolated system: its own service, its own database with least-privilege credentials, its own private encrypted storage bucket, its own encryption keys, and its own tamper-evident audit log. Tenant isolation is enforced deny-by-default in the service layer, and a portal or global admin has no implicit access to your evidence. Files are encrypted at rest and reachable only through short-lived signed URLs.
No. Signup is open and self-service — email and password, or Google / Microsoft sign-in. You don't need to be a customer to use the workspace for free.
Yes. If you'd rather not run it yourself, our team can operate the program for you — mapping controls, gathering evidence, and preparing you for the audit as a virtual CISO / managed compliance engagement. Talk to sales to scope it.
Yes. You can export your program and evidence at any time (that's what the auditor pack is), and you can delete your data and account entirely. Optional MFA/TOTP is available and strongly encouraged for accounts holding evidence.