Adfirma reads your policies and records the way a certification auditor will — grades every clause and control in real audit vocabulary, and tells you what to fix, in order, every day of the year. Not a gap assessment. A workspace.
ISO/IEC 27001 · ISO 9001 · NSQDMH — manage the compliance you need.
The ISMS manager. The quality manager. The digital-health provider carrying NSQDMH. Usually one overworked person, holding the management system together with a spreadsheet, a SharePoint folder, and a calendar reminder. We know the week before the audit feels like this:
Somewhere in ninety-three controls and seven clauses, there's a finding waiting.
A gap assessment six months ago doesn't answer it. You need today's picture, graded the way the auditor will grade it.
Every copy you upload somewhere else is stale the moment someone edits the original. Review dates lapse quietly. The SoA says one thing; the procedure says another. Nobody notices until someone external does.
Show me how you meet A.8.12.
The answer exists — in a document, somewhere. And every evidence request becomes another email thread, another attachment, another sorry, which version is this?
— with no record of what was shared, or when.
Checkbox compliance tools were built for SOC 2 SaaS startups: connect an API, collect a tick. Your management system doesn't live in APIs — it lives in documents: policies, procedures, records, minutes. Adfirma reads them the way an auditor reads them, and grades every requirement in the vocabulary auditors actually use:
The dashboard is coverage across the standard. The backlog is whatever isn't green. The order is severity. No invented scores, no percentages that mean nothing at the closing meeting.
Not features for a comparison grid — each of these exists to make one of those bad weeks stop happening to you.
The auditor, the client questionnaire, your CEO — ask "how do we control access for leavers?" and your answer arrives with citations into your own procedures, section and paragraph. Nothing is asserted that you didn't confirm — so the answer holds up when it's read back to you at the closing meeting.
And when your evidence doesn't support an answer, you're told plainly — while it's still your private problem to fix, not a finding with your name on it.
Your documents stay where your organisation already keeps them — SharePoint / OneDrive, Google Drive, or Dropbox. No re-uploading, no stale copies to babysit. When a colleague edits the Risk Methodology, exactly the assessments resting on it flag themselves for you to re-check. Not the whole programme. Not nothing. Exactly those.
Every version is kept immutably — so when you're asked for the policy as it stood at the audit date, you have it, without having ever thought about it.
Audits run on evidence requests. Instead of email threads and drive links, you invite your auditor into a purpose-built room: the document register, current versions, originals downloadable — and a request line. They ask; you share the exact records they need in a click, each grant logged with date and scope. That log is the evidence-request record both sides keep for the closing meeting.
Sharing gets easier, and cleaner: the auditor gets precise, current evidence fast, instead of excavating a drive — and your working drafts and internal notes stay what they are, working papers. Structured requests in, exact evidence out, one shared record.
| Checkbox compliance platforms | Adfirma | |
|---|---|---|
| Built for | SOC 2 SaaS startups with API-connected stacks | Document-based management systems — ISO 27001 & 9001 |
| Reads | Integration checkboxes | Your actual policies, procedures and records |
| Verdicts | Pass / fail ticks | The real audit scale — Adfirmant → Major NC |
| AI answers | Generated, unattributed | Cited to your documents, human-confirmed — refuses when unsupported |
| Your documents | Re-uploaded copies going stale | Read in place — SharePoint, Drive, Dropbox — changes trigger re-assessment |
| The auditor | Email threads and drive links | A purpose-built audit room — requests and evidence, logged for both sides |
Manage the compliance you need — one standard is the normal case. And when you do carry more than one (27001 + 9001, or a sector scheme like NSQDMH on top), they ride the same document set on a shared skeleton, crosswalked — so the second standard is a plus, not a second job.
Bring your real documents — thirty minutes in, you'll be looking at your own graded worklist, not a demo dataset.
Log inIn-region hosting (Sydney) · your evidence stays yours · originals stored immutably.