Preview of a future cluster · Knowledge & Compliance Infrastructure is on the long-term roadmap — designed on the shared substrate, not yet built. All figures synthetic and aggregated (Meridian Industrials).
AssetShopKnowledge & Compliance SuiteMeridian Industrials · FY26Roadmap · Planned
Reading synthetic sources read-only - never writes back

Compliance posture overview

The SCO read-only thesis, pointed at compliance: framework coverage, control status, evidence freshness, findings, and audit readiness — observed across your GRC and policy systems to surface drift, not to run your program.

What this is, and what it is not. A preview of a future cluster, not a live product. In production it would sit read-only on top of your GRC, policy, evidence, and identity systems — reading control status, evidence metadata, and policy records to surface coverage, freshness, and audit drift. It is not a system of record, does not file or attest on your behalf, does not remediate, and does not generate compliance claims. The knowledge index references what your operational modules already surface; it makes no autonomous decisions. Figures here are synthetic.

82
Posture score
+6 YoY
6
Frameworks tracked
88%
Control coverage
+4 pts
91%
Evidence current
37
Open findings
9
Findings overdue
94%
Policies current
3 / 6
Audit-ready frameworks

Compliance posture trend & plan synthetic

PosturePlanBand

Open findings by domain synthetic

Signals worth attention

9 findings overdue, 3 on SOC 2 CC6 — the clearest audit exposure; close before the next evidence pull.
11 evidence artifacts expire within 30 days — renew to hold control coverage above 88%.
Posture up 6 points YoY — control automation and faster evidence cycles are compounding toward 90.

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Frameworks

Coverage across the frameworks your customers and regulators ask about. Each framework maps to the same shared control set, so evidence collected once satisfies many.

6
Frameworks
389
Controls mapped
82%
Avg coverage
2
Frameworks <80%

Framework coverage synthetic

Control count and current coverage per framework. One control often maps to several frameworks.
FrameworkScopeControlsCoverageStatusNext milestone
SOC 2 Type IITrust services (CC, A, C)64
89%
on trackWindow opens Q3
ISO 27001ISMS, Annex A93
82%
in progressStage 1 Q4
GDPRData protection, DPA41
90%
on trackDPIA refresh Q3
HIPAASecurity & privacy rules54
76%
in progressRisk analysis Q3
NIST CSF 2.0Govern → Recover106
71%
baselineProfile Q4
PCI DSS 4.0Scoped (SAQ-A)31
84%
on trackAttestation Q4

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Control register

Every control, its frameworks, owner, and the freshness of the last test. Status buckets honestly: met, partial, or gap.

389
Controls
88%
Met
9%
Partial
3%
Gap

Control status synthetic

How to read this

Met controls have current, mapped evidence.
Partial controls have aging or incomplete evidence.
Gap controls have no current evidence — the audit priority.

Control detail (drill-down) synthetic

ControlFrameworksDescriptionStatusOwnerLast tested
CC6.1SOC 2 / ISO A.9Logical access — least privilegemetSecurity12 days ago
CC7.2SOC 2 / NIST DEContinuous monitoring & alertingmetSecOps8 days ago
A.12.3ISO 27001Backup & restore verificationpartialPlatform41 days ago
164.308HIPAAWorkforce risk & sanctionspartialPeopleaging
CC8.1SOC 2Change management approvalsmetEng5 days ago
A.18.1ISO 27001Records retention & disposalgapLegalnot tested

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Evidence library

Evidence mapped to controls, with freshness and expiry. Collected once, reused across frameworks. The library is read-only and references where each artifact lives.

1,240
Evidence artifacts
91%
Current
6%
Aging
3%
Expired

Evidence freshness synthetic

Evidence collected per quarter synthetic

Evidence detail synthetic

ArtifactControlsFreshnessCadenceSource
Access review exportCC6.1, A.9.2Currentauto, 90dIdP
Backup restore logA.12.3Agingmanual, 180dPlatform
Pen-test reportCC4.1ExpiredannualExternal
Change tickets sampleCC8.1Currentauto, 30dITSM
DPIA recordGDPR Art.35CurrentannualLegal
Training completion164.308AgingquarterlyLMS

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Findings & remediation

Open findings, severity, owner, and due date — with an honest bridge of what opened, what closed, and what remains.

37
Open findings
4
High
9
Overdue
21 days
Median age

Findings bridge (quarter) synthetic

How to read this

Overdue findings are the audit-exposure priority.
In-progress findings have an owner and a date.
Closures are validated against evidence before they leave the register.

Open findings synthetic

FindingFrameworkSeverityOwnerDueStatus
Backup restore not verified this periodA.12.3highPlatformoverdue 11dopen
Records retention schedule undefinedA.18.1highLegaldue in 9dopen
Access review evidence agingCC6.1mediumSecuritydue in 14din progress
Pen-test refresh requiredCC4.1highSecOpsscheduledplanned
HIPAA risk analysis incomplete164.308mediumPeopledue in 20din progress
Vendor DPA missing — 1 sub-processorGDPRmediumLegaldue in 7dopen

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Audit readiness

Readiness per framework, the gaps that remain, and when each window opens. Readiness is the share of in-scope controls with current, mapped evidence.

3 / 6
Audit-ready
82%
Avg readiness
17
Gaps to close
Q3
Next window

Readiness trend synthetic synthetic

Blended readiness across tracked frameworks, trailing 8 quarters with plan.

Readiness by framework synthetic

FrameworkReadinessGapsWindow
SOC 2 Type II
89%
4Window opens Q3
ISO 27001
82%
6Stage 1 Q4
GDPR
90%
2DPIA refresh Q3
HIPAA
76%
5Risk analysis Q3
PCI DSS
84%
3Attestation Q4

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Policy register

Policies, versions, owners, review cadence, and attestation. Each policy maps to the controls it supports, so a lapse surfaces as a control risk.

48
Policies
94%
Current
3
Due for review
96%
Attested

Policy detail synthetic

PolicyVersionOwnerLast reviewAttestation
Information Security Policyv3.2CISOreviewed 2mo ago98%
Access Control Policyv2.1Securityreviewed 4mo ago97%
Data Retention Policyv1.0Legaldue this quarter
Incident Response Planv2.4SecOpsreviewed 1mo ago99%
Acceptable Use Policyv3.0Peoplereviewed 3mo ago95%
Vendor Management Policyv1.3Procurementdue this quarter91%

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Knowledge index

A read-only, lineage-anchored index across every operational domain — so a control, a finding, or a policy resolves to the source record behind it. The audit-readiness surface that compounds with each module.

A federated index, not an oracle. The knowledge layer indexes what your operational modules already surface — policies, evidence, findings, and the signals from every domain — into one read-only, lineage-anchored reference. It links to source records; it does not generate answers, summaries, or claims on its own. Every reference traces to a system of record.

14
Domains indexed
3,820
Source records
92%
References current
100%
Lineage-anchored

Indexed references per quarter synthetic synthetic

Index coverage by domain synthetic

DomainSourcesRecordsFreshness
ProcurementERP, eProc412current
FinanceERP, AP, Treasury308current
RiskGRC221current
SecurityIdP, SIEM356aging
QualityQM, MES274current
LegalCLM189current
PeopleHRIS246current

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Access & data governance

How data is held, who can reach it, and how that is proven — residency, retention, least privilege, and encryption. The posture AssetShop applies to itself, surfaced honestly.

100%
Data in tenant region
Quarterly
Access reviews
Least-priv
Default posture
0
Standing prod access

Governance controls synthetic

AreaApproachStatusCadenceLast verified
Data residencyPer-tenant, region-pinnedmetcontinuousverified
Access reviewsRole recertificationmetquarterly2mo ago
Retention & disposalSchedule by data classpartialannualpolicy pending
Least privilegeJIT elevation, no standing accessmetcontinuousverified
EncryptionAt rest & in transit, KMSmetcontinuousverified
Audit loggingImmutable, anchoredmetcontinuousverified

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Sub-processors & vendor compliance

Every sub-processor, its purpose, DPA status, attestation, and data region — the list a security questionnaire asks for, kept current.

9
Sub-processors
8
DPA in place
1
DPA pending
100%
Region-disclosed

Sub-processor detail synthetic

Mirrors the published sub-processor list. One DPA is in review and flagged as a finding.
Sub-processorPurposeDPAAttestationRegion
Cloud hosting (primary)Compute & storagein placeSOC 2 / ISOUS / EU
Object storageEvidence & backupsin placeSOC 2US
Error monitoringTelemetryin placeSOC 2US
Email deliveryTransactional mailin placeSOC 2US
Analytics (privacy-first)Product usagependingin reviewEU
Identity providerSSO / SCIMin placeSOC 2 / ISOUS / EU

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Connectors & data

Where Knowledge & Compliance would read from, and the posture it would read with — read-only, conformance-certified, never writing back.

Read-only sources synthetic

Each connector declares exactly what it reads. Adapters ship with a conformance certificate; none are write-enabled.
SourceReadsModeAssurance
GRC / control platformControl status, mappingsread-onlyconformance cert
Policy store / CLMPolicies, versions, attestationread-onlyconformance cert
Identity providerAccess, reviews, MFA stateread-onlyconformance cert
Evidence storesArtifacts, freshness, expiryread-onlyconformance cert
Ticketing / ITSMFindings, change recordsread-onlyconformance cert
Operational modulesCross-domain signals & lineageread-onlyinternal

Posture

Read-only on top of your systems — control status and evidence metadata, never secrets or write paths.
Adapter conformance is reported honestly; scaffolds return 0/12 until validated on a live tenant.

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Signals & opportunities

Compliance signals — control gaps, expiring evidence, overdue findings, attestation lapses — ranked so the audit-exposure items rise first.

9
Open signals
17
Gaps
3
High
11
Addressable

Detected signals synthetic

Each signal is an observation with source lineage; confidence reflects how directly the data supports it.
SignalAreaSeverityMagnitudeConf.Source
Overdue findings — SOC 2 CC6Audithigh9 findingshighGRC
Evidence expiring < 30 daysEvidencehigh11 artifactshighevidence store
Control gaps — retentionControlsmedium3 controlshighGRC
Policy reviews duePolicymedium3 policieshighCLM
Sub-processor DPA pendingVendormedium1 vendorhighCLM
Attestation lapse — 1 policyPolicylow9% gapmedCLM
HIPAA risk analysis incompleteAuditlow1 itemmedGRC

Opportunities the signals point to

What the observation suggests. AssetShop quantifies; your team decides and acts in the source systems.
9 items
Close overdue findings on SOC 2 CC6 before the evidence pull.
11 art
Renew expiring evidence to hold control coverage above 88%.
3 ctrl
Define retention controls to clear the open gap.
1 DPA
Execute the pending sub-processor DPA ahead of the GDPR review.

How to read this

High signals are concentrated and well-evidenced — act on these first.
Confidence separates observed facts from modeled estimates.
Every figure traces to a read-only source. Nothing here is written back.

Synthetic preview of a future cluster. In production, derived read-only from GRC, policy, evidence, and identity systems with SHA-256-anchored lineage, as in SCO. AssetShop surfaces posture; it does not file, attest, or remediate on your behalf.

Theme