Enterprise Quality & Compliance Management System
Built toward SOC 2 Type II and ISO 27001 programs. Not certified yet.
Local invite enrollment, password policy, TOTP MFA, session idle/absolute limits, and server-side RBAC. Document registers and WORM evidence storage are not live yet.
What is live today
Target frameworks (not a certification claim)
Core Compliance Architecture
Roadmap capabilities. Only authentication and RBAC are implemented in this build.
Controlled Document Governance Planned
Planned document lifecycle (Draft → Review → Approved → Effective → Superseded), versioning, and PDF snapshots. Not available in this build.
SOC 2 Controls Library & Mapping Planned
Planned control-to-policy mapping and evidence gap views. The 104-control library is not seeded in this build.
Authentication audit log
Login success and failure, MFA failure, lockout, and TOTP re-enrollment are written to auth_audit_events. This is not WORM object-lock storage and has no hash chain.
Workforce Sign-offs & Training Planned
Planned acknowledgement campaigns and role-based training. Not available in this build.
Restricted Enterprise Compliance Gateway
Access uses local invite enrollment, password, and TOTP MFA. SSO (SAML/OIDC) is not implemented. Failed and successful sign-in events are stored in the authentication audit log.