SOC 2 · HIPAA · NIST 800-171 · CMMC · PCI DSS

Be audit-ready before your auditor arrives.

AuditSquire maps five frameworks onto a single normalized control set — so a quarterly access review satisfies all of them at once, and you find the gap before an assessor does.

No credit card to start a trial. Your auditor can be invited free.

584

requirements catalogued

Across all five frameworks, kept current.

81

unified controls

The whole program, deduplicated.

967

crosswalk mappings

Every requirement traced to the control that satisfies it.

Most teams do the same work three times.

SOC 2 wants an access review. So does HIPAA. So does CMMC. Tracked separately, that is three spreadsheets, three evidence folders, and three chances for one of them to go stale without anyone noticing.

AuditSquire normalizes all five frameworks onto one control set. You implement the control once. Every requirement mapped to it moves at the same time — and you can see exactly which ones.

How it works

From nothing to a measured program in an afternoon.

01

Choose your frameworks

Enable the standards you are working toward. AuditSquire builds the control set behind them and maps every requirement automatically.

02

Assign owners and attach evidence

Give each control a person and a proof. Connect Microsoft 365, Azure, Okta, CrowdStrike, Jira, AWS or GitHub and the evidence behind your identity, endpoint, cloud and change-management controls collects itself every week, or whenever you ask.

03

Work the gap list

The dashboard ranks controls by how many requirements each one unblocks. Close the top item, watch every framework percentage move at once.

What you get

Everything an assessor will ask for, in one place.

One control set, every framework

A quarterly access review is one control — and it satisfies requirements in SOC 2, HIPAA, NIST, CMMC and PCI at the same time. Add a second framework and you usually start well above zero.

Evidence that never quietly expires

Every artifact has a shelf life. Readiness refuses to credit a control you cannot prove today, and tells you what lapses in the next 30 days — before an assessor finds it first.

Policies that pass their own test

Start from a template, then let validation check each document for the clauses its frameworks expect — and for lifecycle. A policy past its review date is treated as no policy at all.

Scan reports in plain English

Upload a PCI ASV or vulnerability scan. Each finding is explained in language a non-engineer can act on, prioritized by what actually blocks your report, and turned into tasks in one click.

Everyone sees only their part

Admins run the program. Managers get company status plus the controls they own. Employees get a personal to-do list. Auditors get read-only access. Enforced in the database, not just the interface.

Readiness you can actually show

A single weighted number, recorded every night, with the gap list that moves it fastest. Export the readiness report your auditor asks for before fieldwork begins.

Frameworks

Five standards. One set of work.

Enable what you need today; add the next one when a customer asks for it. The overlap is already mapped, so the second framework is never a second implementation.

SOC 2

Trust Services Criteria

HIPAA

Security & Privacy Rules

NIST 800-171

Controlled Unclassified Information

CMMC

Levels 1 and 2

PCI DSS

v4.0

Customer story

What happens when the auditor asks for something you don't have.

That is the question that decides this purchase, and the only honest answer is to show one company going through it. Northwind Health Analytics went from 26% to 77% readiness in 120 days, lost three pieces of evidence to expiry along the way, and ran fieldwork with the assessor holding a login rather than a folder.

Northwind Health Analytics is the company inside our demo environment, not a named customer. The gaps it shows are real gaps the product surfaces. The company is not. When a customer agrees to be named, this section will tell their story instead, and say so.

Read the story

Northwind Health Analytics · Healthcare SaaS · Demo environment

Frameworks
SOC 2 and HIPAA together
Controls in scope
77 of 81
Evidence on file
27 artifacts
Audit
SOC 2 Type 2, FY26 window

Surfaced before fieldwork

  • A policy went past its review date
  • Two vendors had no current SOC 2 report
  • The penetration test was not re-run in time

Pricing

Priced for the program you are actually running.

You pay for frameworks, not headcount. Every plan includes the full control catalog, policy validation, and the readiness report — and your employees and your auditor are free on all of them.

Merchant

PCI DSS for a business that never asked to be a security expert.

$99/ month

or $83/mo billed annually — two months free

  • PCI DSS v4.0
  • Unlimited employees and auditors, free
  • 10 seats for admins and control owners
  • Evidence library and policy templates
  • Readiness report export
  • 4 scan reports explained each quarter
Talk to us

Starter

One framework, start to audit.

$299/ month

or $249/mo billed annually — two months free

  • 1 framework
  • Unlimited employees and auditors, free
  • 25 seats for admins and control owners
  • Automated evidence collection
  • Audit workspace, findings, and readiness report
  • 4 scan reports explained each quarter
Talk to us
Most chosen

Growth

Three frameworks, where the crosswalk pays for itself.

$749/ month

or $624/mo billed annually — two months free

  • 3 frameworks
  • Unlimited employees and auditors, free
  • 100 seats for admins and control owners
  • Automated evidence collection
  • Audit workspace, findings, and readiness report
  • 12 scan reports explained each quarter
Talk to us

Enterprise

Every framework, with priority support.

$1,499/ month

or $1,249/mo billed annually — two months free

  • 5 frameworks
  • Unlimited employees and auditors, free
  • 500 seats for admins and control owners
  • Automated evidence collection
  • Audit workspace, findings, and readiness report
  • 40 scan reports explained each quarter
Talk to us

Need one more framework than your plan includes? From Starter up, add one for $150/mo rather than moving up a tier. Managed service providers running AuditSquire for multiple clients get flat per-client pricing — ask us.

Security & trust

You are handing us the evidence your auditor will judge you on.

So the security page is written the way you would want to read it: where the data lives, who can see it, how it leaves, and what we have not done yet.

Isolation is enforced in the database

Every table has a row-level policy keyed on your organization, and the app queries as the signed-in user. A bug in a page cannot cross a tenant boundary.

Your credentials never sit in plain text

Cloud credentials for evidence collection are encrypted with a key the database never sees. Collectors ask for read-only access, so we cannot change your environment.

You can see who did what

Every approval, status change and upload is logged with the person and the time. Your auditor gets read-only access to the same log, free.

Sign in under your own policy

Two-factor authentication with an authenticator app is on every account, and an owner can require it for everyone. SAML single sign-on connects Entra ID, Okta, Google Workspace and others.

Read the full security and trust page, including what is not done yet

Who is behind this

Chris Foster · Founder

Chris builds and runs AuditSquire from Mitchell, South Dakota, and uses it to run compliance programs for the businesses his own IT practice serves. Every question sent to the contact address reaches him.

hello@auditsquire.com

Questions worth asking.

We already track this in spreadsheets. Why change?
A spreadsheet cannot tell you that the access review you logged in March stopped counting in June, or that one control you are about to implement satisfies fourteen requirements across three frameworks. That arithmetic is the entire product.
How long before we see anything useful?
Enable a framework and the full control set with its requirement mapping exists immediately — 584 requirements and 967 crosswalk mappings are already catalogued. Your first readiness number is minutes away, not weeks.
What happens to our records if we stop paying?
Your workspace becomes read-only and nothing is deleted. Compliance records outlive subscriptions — a company that churns in March and gets audited in June still needs its evidence.
Who can see our evidence?
The people you give a role, your auditor if you invite one, and a small number of named AuditSquire operator accounts used for onboarding and support. Isolation between customers is enforced by row-level policy in the database, every write is logged with the actor, and the full answer, including what we have not done yet, is on the security and trust page.
Can our auditor have access?
Yes. The auditor role is read-only everywhere and does not consume a billable seat, so you can hand over access instead of assembling a folder of screenshots. The same is true of employees: everyone who only needs their own tasks and policy acknowledgments is free, however many of them you have.

See your own readiness number.

Thirty minutes, your frameworks, your questions. We will show you exactly what your first week in AuditSquire looks like.