Skip to content
An Treoraí

Compliance built on how you already work

You were handed ISO 27001 on top of your actual job. An Treoraí starts from your business processes, not a list of 93 controls.

Describe how you hire, deploy or respond once. Requirements from every framework attach to the steps that satisfy them.

Public pages only · No account, no card · You approve every suggestion
ISO 27001:2022SOC 2GDPRNIST CSF 2.0DORANIS2ISO 27701ISO 9001Cyber EssentialsPCI DSSHIPAATISAXEU AI ActISO 22301

An Treoraí reads your public pages and drafts context, scope, interested parties and a first action. You correct, keep or discard each one.

Starting analysis · yourcompany.comExample · enter your address above
Business context

B2B software for logistics operators, 34 people, hosted on AWS in eu-west-1.

From /about, /security
Interested parties

Enterprise customers, hosting provider, data protection authority, insurers.

From /customers, /privacy
Relevant frameworks

ISO 27001:2022 first, SOC 2 likely within a year, GDPR already applies.

Inference · confidence medium
Initial scope

The platform, the people who build it, and the AWS environment it runs in.

Editable before anything is signed
Likely priorities

Access control, supplier assurance, and change management on the platform.

Inference · confidence high
Your first actionMap how someone joins the organisation.Six steps. Covers 14 requirements across four frameworks.
Every line names the page it came from, and uncertain inferences say so. Nothing enters your programme until you keep it.
Process · Joining the organisationOwner: People team
These six steps also produce your Statement of Applicability entries, training records and access-review trail.
What this step proves4 requirements

Screening before the offer is confirmed is the evidence four different frameworks are asking for.

A.6.1ISO 27001:2022
ScreeningEvidence: Completed check record, dated before the start date
CC1.4SOC 2
Competent individuals are recruited and retainedEvidence: Screening standard plus a sample of completed checks
Art. 32(4)GDPR
Persons with access act only on instructionEvidence: Role definition and screening record
PR.AA-01NIST CSF 2.0
Identities are established for authorised personnelEvidence: Verified identity held against the personnel record
One step. One piece of evidence. Every framework that asks for it.
Today in An TreoraíRoadmap · 38% complete

Check who can reach your production systems

Confirm that the people with access still need it, and that leavers were removed. An Treoraí has pre-filled the list from your last review.

4 questionsAbout 6 minutesGuidance included
Start the review No dashboard of 93 amber squares. One next action, and the trail keeps itself current.
Updates when you finish
Control recordIAM-04, updated on completion
Evidence fileSaved and dated
Framework coverageRecalculated across five frameworks
Next reviewScheduled and reminded

A policy nobody follows still fails the audit

Every other toolImplement 93 controls, then hope the business follows them.
An TreoraíDescribe the process once. The frameworks attach to the steps that satisfy them.

Attach a quarterly access review to one control and it answers every requirement that asks for it, including the security questionnaires your customers send you.

Quarterly access reviewControl · IAM-04Evidence added once
Review of access rightsISO 27001 · A.5.18Covered
Logical access is reviewedSOC 2 · CC6.3Covered
Identities are managedNIST CSF · PR.AACovered
ICT access managementDORA · Art. 9Covered
Security of processingGDPR · Art. 32Covered
Five requirements, one piece of evidence, maintained in one place.

Five steps, in the order you will actually take them

01Set your starting pointAn Treoraí drafts your context and scope; you correct it.
02Map how you workHiring, access, deployment, suppliers and incidents, step by step.
03See what's missingGaps appear as missing steps in a process, not failed checkboxes.
04Close gaps with guidanceEach task explains why it exists and what it updates when you finish.
05Stay ready between auditsRunning the process produces the evidence. Reviews keep it current.

Who it’s for

Your first framework

No prior compliance experience

Start from a drafted context, learn each concept at the moment you need it, and work a sequence that ends in an audit you can pass.

Already running a programme

Several frameworks, one set of evidence

Bring existing controls, policies and evidence across, map them to the processes that produce them, and stop maintaining the same proof in four places.

Will an auditor accept this?Auditors ask for the same records either way: policies, evidence, review dates and a Statement of Applicability. An Treoraí produces those from your processes, with the source of each entry visible.
What can we use today?The process library, control catalogue, risk register, policy and management reviews, evidence, audits and reporting are built and in use.
How much of my time will this take?Tasks are sized in minutes and you get one next action at a time. Most teams work through a process in a couple of sittings.
All questions answered →

Start with the work you already do

Enter your website and we will prepare your starting point, context, interested parties, likely priorities and a first process to map, then walk you through it.

Public information only · You approve every suggestion · No card required