A maturity score per control against ISO/IEC 42001, SOC 2, GDPR or India's DPDP Act — measured where a machine can measure, attested where it cannot — with a clause-level gap report and a costed plan your board can act on.
India DPDP · GDPR · ISO 27001 · ISO 42001 · SOC 2 · HIPAA · DORA · EU AI Act · NIST AI RMF
Before an auditor tells you where you stand, GOVERNTIQ already has — scored, evidenced, and costed to close.
Readiness evidence and a remediation plan — not a certification. Certificates are issued by independent accredited auditors. We get you to their door prepared, and keep you there.
A maturity score from 1 to 5 per control, rolled up by objective — measured directly wherever a machine can read the evidence, attested where only documents and judgement can. A control not yet measured is marked not evaluated, never failed; one the evidence contradicts is scored down.
Register the systems in scope — or let the scanner discover them from an API spec and register them for you.
Give the scanner read-only access to where the data lives: APIs, databases, log platforms, consent stores, file shares. One command per source.
The scanner reads in place and scores every control a machine can verify: what is stored, how old it is, who can read it, what the logs keep, what the consents say.
Answers and measurements meet per sub-claim. Telemetry settles what a mechanism did; design, accountability and effectiveness stay with documents and judgement. Claims without corroboration are named.
A maturity score, a clause-level gap report, a critical path and an effort estimate — then a programme that closes the gaps in dated phases.
A consultant writes down your answer. GOVERNTIQ checks it. If you attest that human oversight is operating and measured evidence on a given system says otherwise, that control is scored down and named by system — months before an auditor would have found it in fieldwork. A system not yet scanned is not failed: the claim stands, labelled unverified. And because oversight is four claims, not one — the mechanism ran, it fits the risk, the right people operate it, the intervention means something — telemetry only ever speaks to the first. The other three are scored separately, from documents and judgement. No questionnaire can do this.
1–5 per control, rolled up by objective, with a Statement of Applicability and justified exclusions.
Every gap traced to its clause — ISO A.9.2, DPDP Sec. 8(6), SOC 2 CC7 — not generic advice.
Person-days by role, a critical path, and a calendar estimate: “audit-ready in ~22 weeks at 1.5 FTE.”
Most personal data is not behind a tidy endpoint. It sits in databases, log platforms, consent managers and file shares. GOVERNTIQ connects to each with a read-only credential you issue, reads in place, and brings back kinds and counts — never the content.
The applications that serve personal data: whether the notice, consent and rights paths behave as declared, and what the records they return actually contain.
Which tables hold personal data and roughly how many records; records kept past their retention period; whether the store is encrypted, who can read it, and whether access is logged.
How long logs are kept against the period the rules require, whether they can be altered, who can read them, and whether personal data is leaking into them.
Whether each consent is specific, timestamped and tied to a notice; whether withdrawals apply; whether consents for minors carry verified parental consent.
Exposure, encryption and logging of the store; stale exports and backups; files named like identity or payroll documents; personal data in a bounded sample.
Name the source and the framework pack; the scanner reads, scores and reports, and keeps doing so on the schedule you set. The common databases, log platforms, consent managers and storage services are supported — ask us for the current list. Anything a credential cannot see is reported as not evaluated — never guessed, never failed.
What leaves your network, per source →Every framework pack ships as a sequenced programme. A phase cannot close until its evidence exists — a completed scan on every system, an adequate document on every required control, a frozen assessment — and the page says exactly what is missing and who it is waiting on.
Systems registered, sources connected, baseline scan, vendor register
Questionnaire, evidence, Statement of Applicability, gap report, roadmap
Governance, policy & SOP pack, notice and consent templates — each reviewed
Runbooks executed, training recorded, re-scan proves the change
Final recompute, frozen assessment, attestation, handover
Inventory, gap assessment, register, roadmap and report are the platform's work — hours, not weeks. Design and Implement are your team's weeks; the programme shows when it is waiting on them.
SOC 2 Type 2's 90-day observation and ISO's internal audit before certification cannot be shortened by tooling, so they are enforced as gates — never a number an agency can trim.
The letter is issued in your assessor's name and discloses what was not evaluated, every exclusion and every waiver. Certificates come from accredited bodies; this gets you to their door with the evidence in hand.
Tell GOVERNTIQ the jurisdictions you serve and the sector you are in, and it recommends the packs that apply. Each pack scans only what its rulebook needs and scores readiness against exactly its controls, on the scale that regulator uses. Every citation is checked against the official text and dated, so nothing you are measured against is out of date.
The AI management system standard, Annex A in full, with the 2025 impact-assessment guidance.
The information-security baseline, as amended in 2024.
Trust Services Criteria with the 2022 points of focus, Type 1 and Type 2.
Govern, map, measure and manage, with the generative-AI profile.
Provider and deployer duties on the 2026 timeline, including transparency and incident reporting.
Lawful processing through to breach notification and automated decisions.
ICT resilience, incident reporting and third-party risk for financial entities.
Readiness against the Act and the notified Rules on their phased commencement, including Significant Data Fiduciary duties.
DPDP together with a certifiable AI management system, for banks and NBFCs.
The amended Law with its Implementing and Transfer Regulations: notice, security, the 72-hour SDAIA clock, transfers outside the Kingdom.
For SAMA-regulated banks, insurers and finance companies, read on SAMA's own 0-5 maturity scale.
The seven principles and their governance for any developer or deployer of AI.
Decree-Law 45/2021 for mainland and non-financial free-zone organisations.
Law No. 5 of 2020 as amended in 2025, with Regulation 10 on autonomous systems.
The 2021 Regulations as amended in 2024 and 2025.
The regulators' joint enabling-technologies guidelines and the central bank's responsible-AI expectations.
The twelve principles of the 2024 Charter for any developer or deployer of AI.
Safeguards for electronic health information and its handlers, on the rule in force.
Enterprise Governance Packs combine several rulebooks in one programme: India BFSI, EU high-risk AI, SaaS trust, Saudi financial and enterprise, and UAE mainland, DIFC and ADGM financial. SOC 2 ships as both Type 1 and Type 2.
A questionnaire records what you say. GOVERNTIQ reconciles it against what your systems show, control by control, and names the claims nothing corroborates.
APIs, databases, log platforms, consent stores, file shares and buckets — the places personal data actually sits — read directly, read-only, inside your network.
Measurement runs inside your perimeter. Documents are fingerprinted in your browser and never uploaded. Only findings flow upstream.
A sequenced remediation plan with a critical path and an effort estimate in person-days — a number your board can act on, not a colour on a heat map.
We agree the frameworks and the systems in scope — the APIs, databases, log platforms, consent stores and shares where personal data actually lives.
Run one binary inside your perimeter and hand it read-only credentials, one command per source. No Python, no Docker, no inbound ports.
Maturity per control, clause-level gaps, unverified claims and a costed plan — then a dated programme that closes them and ends in an attestation.
Your security team set the perimeter. GOVERNTIQ deploys inside it — under your firewall, your credentials, your control — and proves what it does without ever touching your raw data.
GOVERNTIQ reads in place. Rows, log messages, file contents, prompts and credentials never leave — only kinds, counts, masked samples and scores do.
A read-only database role, a log-platform token, a SAS token, a consent-API credential: each issued by you, scoped to one source, revocable at any time. The scanner never writes.
An HTTPS client that dials out to GOVERNTIQ — never a listener. It drops in behind your firewall with zero inbound rules and works air-gapped.
TLS in transit, mTLS available; every finding and every review sits on an append-only, hash-chained timeline, so evidence cannot be silently altered.
Dry-run prints the exact payload the scanner would transmit, so your security team can read it before reporting is switched on.
Every finding cites the clause of the rulebook in scope — DPDP, GDPR, Saudi PDPL, the DIFC law, SOC 2, ISO 27001 — so the evidence lands where your auditor looks.
Outbound-only · Read-only by default · Redacted findings · Air-gap capable · Revocable keys · Dry-run auditable · TLS/mTLS · Tamper-evident evidence
If assessments are your business, GOVERNTIQ is the measurement underneath them. Onboard each client, connect the scanner to their APIs, databases, logs, consent records and shares inside their perimeter, and hand over a maturity score their auditor can follow — with the claims already checked against what the systems show.
Illustrative view of the agency console. Each organisation is isolated — one client's evidence is never visible to another.
We’re a young company and we don’t have customer logos to show you yet. So here is the deliverable instead — judge it on its own terms, and ask us to run it on your systems.
Weighted 1–5 across every applicable control, broken down by objective, with the evidence behind each level visible — attested, measured, or both.
Every control in scope, with any exclusion recorded alongside a written justification — the artefact ISO/IEC 42001 Cl. 6.1.3 expects you to produce.
The controls you believe are in place that your systems don’t corroborate, named by AI system, ranked by severity.
Person-days split by role, a dependency-ordered critical path, and a calendar estimate with a stated ±25% range.
Issued when the programme closes: scope, method, every control reviewed, what was not evaluated, every exclusion and waiver — and the hash of the frozen scores it describes. An attestation, not a certificate.
The letter, the frozen scores, the Statement of Applicability, the evidence register and an append-only timeline of who closed what, when, against which artefact.
Straight answers for security, risk and compliance teams.
Need a deeper security review, a DPIA, or a pen-test summary? Get in touch.
A readiness programme runs about six weeks end to end — Discover to a signed attestation — against the rulebook you answer to, with the evidence measured in your databases, logs, consent records and shares rather than taken on trust.