Demo mode: mock AI responses
Manual review est. ~6.4 hrsAI triage ~45 sec
Based on document volume · estimate
Questionnaire
1,208 words
Policy
125 words
SOC 2 Summary
110 words
Policy
94 words
Drop PDF, Markdown or TXT here·10 MB per file · 4/5 documents

Sample assessment · Run triage to refresh from the documents

Overall risk score

High risk

Resolve material findings before approval.

0–100 · higher means more risk

Executive summary

Northwind's evidence identifies material gaps in privileged access, incident notification and subprocessor transparency. Optional administrator MFA and unresolved SOC 2 access review exceptions need attention before approval. Request current penetration testing and recovery exercise evidence, and confirm the offshore support arrangement against your intended data use.

Risk by domain
Access Control
75
Data Protection
—
Business Continuity
56
Incident Response
75
Vendor Sub-processors
75
Compliance & Certifications
50
Contractual
—

5/7 domains with findings · — unassessed

Risk findings6 findings

Evidence
NW-01Access ControlHighAlmost certain75 1 verified Needs follow-up
NW-02Incident ResponseHighAlmost certain75 1 verified Needs follow-up
NW-03Vendor Sub-processorsHighAlmost certain75 1 verified Needs follow-up
NW-04Access ControlHighAlmost certain75 1 verified Needs follow-up
NW-05Compliance & CertificationsGapMediumAlmost certain50 1 verified Needs follow-up
NW-06Business ContinuityGapHighLikely56 1 verified Needs follow-up
Evidence first. Decisions faster.Synthetic demo data · Analyst review required