Autopliance. Start free

How it works

Three steps,
one command each.

And then the part that matters: somebody who is not you, and not us, checks it.

01

Connect

Point Autopliance at your environment. Authentication and data-handling events anchor into an audit chain as they happen — not on an hourly poll, and not as a state blob computed after the fact.

The distinction matters more than it sounds. A record written at the moment of the event can be bound to that moment. A state pushed on a schedule cannot be, no matter how often the schedule runs.

02

Render

Pick a framework. Get PDF, HTML, Markdown, JSON or OSCAL — the same chain answers all 34 of them.

The machine-readable formats carry no narrative and no invented rows, because tools cannot see a watermark. A synthetic sample is marked on every page of every human-readable format, and the structured formats simply do not contain rows that did not happen.

03

Hand it over

Your auditor, your customer's security team or your supervisory authority runs the verifier against the bundle. They need no account with us, and no permission from us.

That is the whole design. If verification required our cooperation, it would not be verification — it would be another claim.

What the verdict means

Every report carries one of these on its face. They are produced by walking the chain, not by a status field somebody typed.

Anchored · Verified

The chain was walked to genesis and every link held. This is the only state that claims verification.

Verification incomplete

Part of the chain could be walked and part could not, so the report does not claim verification. That is deliberate: a partial archive cannot borrow a verified report's authority. The report names what could and could not be reached.

The second badge is not a failure message. It is a finding, rendered with the same weight as the first — because a verdict you would rather not show is exactly the verdict worth trusting.

What this is not

Autopliance produces technical-control evidence. It is not a certificate.

It does not replace your policies, your contracts or your governance, and it does not cover non-technical requirements. It will not make you compliant — it will let you prove the parts that are.

We have far fewer integrations than the established platforms. We do not do policy management or security questionnaires. We do not have auditor relationships, and we do not have our own SOC 2 yet. Those are their strengths and we are not pretending otherwise.

Autopliance is a hosted EU service. We are not going to give you a date for anything else.

Produce one against a real chain.

The free tier is a real fleet with real anchors. No card, no call.