Compliance evidence review that shows what is ready — and exactly why.
Compass brings controls, process evidence, infrastructure facts, and reviewer decisions into one connected view. AI helps reconcile what belongs together; every claim stays visible, source-backed, and under human review.
- SOC 2 II 47/56
- ISO 27001 81/114
- HIPAA 38/45
- NIST 800-53 —
- PCI DSS —
- GDPR 29/34
- Common Criteria (CC)
- Availability
- Processing Integrity
- Confidentiality
- Privacy
The entity implements logical access security measures to protect against threats from sources outside its system boundaries.
Your tools already hold pieces of the answer. Compass connects them.
Policies explain intent. Processes show how the work should happen. Infrastructure and identity systems show what is actually running. Compass keeps those pieces connected so your team — and its AI — can reason from the same context.
Start with the systems you have. Build the connected view you need.
Turn scattered evidence into an answer you can see and question.
Compass resolves the same system, owner, control, and activity across sources. The graph is the mechanism, not the pitch: it gives people and agents one inspectable context instead of a pile of disconnected files.
ProcessWhat you say · 42 flows
BlueprintInfrastructure and dependencies
AtlasIdentity · Entra + Okta
CC6.1Access reviewed on a cadence
SOP: every 90 days
IAM: last review 134d agoBlueprint · cloud
△ Gap
CC6.2MFA enforced for all users
Policy: MFA required
Entra / Okta: 3 admins exemptAtlas · identity
△ Gap
CC6.6Data encrypted at rest
Policy: encryption required
S3 / RDS: KMS enabledBlueprint · cloud
✓ Aligned
CC7.2Audit logging enabled
SOP: multi-region logging
CloudTrail: multi-region onBlueprint · cloud
✓ Aligned
Readiness, scored liveEvery clause, against every source — recomputed on change
Audit pack — gated ↗Sealed until blockers clear
“Warehouse” and “Warehouse Team” collapse to one canonical node.
Each join cites a verbatim process step, identity record, or cloud resource.
Vanta or Drata evidence joins the graph — no rip-and-replace.
Know what is ready, what is blocked, and what needs a person.
Compass can summarize readiness because every result stays connected to its sources. Open the number, inspect the blocker, challenge the connection, and decide what happens next.
Audit runSOC 2 Type II · FY2026
RUNNING · 2 SOURCESReadiness23%1 blocker · 6 findings
BLOCKER · CC6.1Access review cadence is not supported by live evidence.Policy says 90 days · IAM shows 134 days since review
AI can trace the connection. Your team can inspect and correct it.
Creately’s visual surfaces make the agent’s reasoning tangible. Review the process step, cloud dependency, control, or finding in context — then accept, edit, or reject the proposed change.
Every AI-assisted step stays visible and reviewable.
AI can read, structure, match, and suggest. Provenance, confidence, and human sign-off decide what becomes accepted evidence.
- 01SourceDid we read the document?
- 02OutlineRight processes and parents?
- 03EvidenceSupported by the source?
- 04DiagramsFaithful to the records?
- 05PublishReady for the repository?
95%Security review follows every material release.Verbatim source: Release Management SOP · §4.2Accepted
87%Emergency changes receive retrospective approval.Suggested match · human sign-off requiredReview
Every claim is traceableA real process step or control with a verbatim quote and source link.
A confidence score on eachReviewers spend their time only where the model is unsure.
AI waits for human sign-offNothing counts as evidence until a person accepts it.
Addressed, and provably soThe clause clears only when its evidence clears.
Bring the context together without handing over control.
Connect the evidence you already run, retain ownership of the underlying data, and make every agent-assisted conclusion inspectable.
Processes, infrastructure, identity, and review decisions keep their origin.
Source connections use scoped access designed around the system being inspected.
Open the finding and inspect the facts and relationships behind it.
Processes and evidence are RDM — export, round-trip, and own them.
Bring existing GRC evidence into the same review context.
Agents can suggest; reviewers decide what counts and what changes.
What teams ask before connecting their evidence.
- What is Creately Compass?
- Creately Compass connects controls, process evidence, infrastructure facts, and reviewer decisions in one assurance model. Compliance and security teams use it to assess coverage, investigate gaps, and prepare evidence for audit review.
- What is the difference between Creately Compass and compliance management software?
- Compass focuses on the relationships between controls, documented work, and infrastructure evidence. It complements compliance management systems by bringing Creately Process and Creately Blueprint into the same review context. Reviewers still decide whether the evidence is sufficient.
- Can Compass connect process evidence, controls, and infrastructure facts for audit review?
- Creately Compass connects process records and source citations with controls and AWS infrastructure facts. An audit run captures a review snapshot, including decisions and source-health warnings, so reviewers can see what supports a conclusion and what still needs attention.
- What evidence sources can Compass use?
- Compass can read authorized Process and Blueprint folders, control catalogs, manual evidence uploads, and scanner reports. Vanta and Drata connectors are available in beta. Source permissions determine which records are available for a review.
- How is Creately Compass priced?
- Compass pricing depends on your Creately subscription and the review, evidence, and audit export capabilities required. Check Creately plans and request a Compass quote for your frameworks, connected sources, and review scope.
- What security and compliance controls does Compass provide for audit evidence?
- Compass uses explicit grants to read source folders and retains reviewer decisions alongside the evidence. Creately’s platform security controls protect hosted data, while Compass helps your team assess its own compliance readiness. See the security overview for Creately’s assurance documentation.
- How does Compass keep evidence source-backed, reviewable, and exportable?
- Compass retains links between evidence, its source records, and review decisions. Source-health warnings expose missing or stale inputs, and audit runs preserve the review context. Audit-pack exports support handoff; underlying diagram data can also use the RDM format.
Give your team — and your AI — the context behind every review.
Bring the relevant facts together, let AI help trace the connections, and keep the final judgment visible and in human hands.