Letting AI review the evidence, without breaking your audit
A document review engine maps each report to the control it evidences, checks currency and scope, and extracts real findings. Here is how it works, and the lines it will not cross.
Reading vendor evidence properly is slow, and slowness is why evidence often goes unread. A SOC 2 report gets a glance at the cover page and a tick; a penetration-test report is filed without anyone checking whether the critical findings were fixed. AI can read these documents properly and at scale. The question that matters is how to do that without introducing findings you cannot defend to an auditor.
Map first, then review
The engine never reviews a document in a vacuum. It first maps the file to the specific control it is meant to evidence, then reviews it only against that control's validation checks and red flags. A cloud-configuration procedure is judged on hardening baselines and patch SLAs; an access-control policy is judged on its access-control requirements. This is the single most important design choice, because it is what stops the review from inventing irrelevant observations. A review that is not anchored to a control will find generic 'gaps' in any document, which is noise, not assurance.
When evidence is provided against a control the vendor explicitly claimed, the mapping is not guessed at all: the review is pinned to that exact control's rubric. When a document is uploaded loosely, the engine ranks the most likely controls and reviews against the best match, flagging low-confidence cases for a human.
Go beyond 'does it exist'
Existence is a weak test. What matters is whether the evidence actually supports the control:
- For a penetration-test report, the engine extracts the open critical and high findings with their severity and remediation status, and bases the verdict on them. A recent report full of unremediated critical findings is not a pass just because it exists.
- For a certification or attestation (SOC 2, PCI AoC, ISO certificate), the verdict turns on currency and scope: is it within its validity window, and does it cover the service you actually use? A valid attestation for a different entity or an expired one is not evidence.
- For a policy or procedure, the engine checks whether the document specifies the control the checks demand, at the depth the control requires.
The lines the engine will not cross
Trust in an automated reviewer comes from its restraint as much as its capability. The rules are deliberately conservative:
- Every observation must be grounded in the actual document text. No generic, boilerplate findings that could apply to any document.
- When the text is silent, the verdict is 'insufficient evidence', not a guess. Absence of proof is reported as absence, not invented into a finding.
- Currency and effective dates are judged against the real current date, so a valid, in-date report is never mislabelled as expired, and a future-dated draft is caught.
- Genuine gaps are surfaced for a human. The engine flags what needs judgement; it does not sign off the assessment on your behalf.
Where the human stays in the loop
The engine's job is to do the slow reading and produce a defensible, control-anchored verdict with the evidence quoted. The reviewer's job is to make the risk decision: accept, request more, or flag for remediation. That division of labour is what keeps the audit intact. The AI makes the evidence legible and consistent; the accountable human makes the call.
Live review is the Enterprise step
Watching the engine read a report in real time, highlighting evidence as it maps to open questions and pre-filling answers with a quoted excerpt and a confidence score, is available on the Enterprise plan alongside the conversational copilot. The underlying review engine, though, backs every plan. It is how each claimed control earns a defensible verdict rather than a checkbox.
See it in your own portfolio
Full question bank, both portals, and transparent launch pricing by vendor volume.
See launch pricing