About this story. Northwind Health Analytics is the company inside our demo environment, not a named customer. The steps, screens, roles and numbers on this page are exactly what you will see in a demo, and the gaps are real gaps the product surfaces. The company is not, and neither is its assessor, Brackenridge Assurance LLP, nor any person named here. When a customer agrees to be named, this page will tell their story instead, and say so.
The question that decided the purchase
"What happens when the auditor asks for something we don't have?" Not whether the tool tracks controls — every tool tracks controls. Whether it would tell them about the hole before the assessor found it, and whether handing the assessor a login would expose more than it proved.
What happened
Month 1
Northwind enabled SOC 2 and HIPAA on the same afternoon. AuditSquire built the control set behind both: 77 of the 81 unified controls map to those two frameworks. Two were marked not applicable, each with a written justification, because Northwind runs no on-premise infrastructure and the database trigger will not accept "N/A" without a reason.
The first readiness number was 26 percent. It was low because the product refused to credit anything without current evidence attached. A shared drive full of screenshots and a spreadsheet of "done" columns did not count. That was uncomfortable, and it was the point: it was the same number a Type 2 would have produced.
Months 2–4
The dashboard ranked every unsatisfied control by how many in-scope requirements it unblocked. Periodic access reviews sat at the top: one control, fourteen requirements across both frameworks. Dana Whitfield, who runs security and compliance, assigned owners to the top ten and turned them into tasks in one click.
Six people owned controls. Priya in platform engineering carried the technical ones; Tom in IT operations owned logging and endpoints; Sarah in people operations owned onboarding, offboarding and training. Each saw only their slice. Nina in customer success, with no compliance job at all, saw two tasks and three policies to acknowledge and nothing else. Nobody needed a training session to find their part.
The readiness line climbed 51 points in 120 days. Nightly snapshots recorded every step, which mattered later: the auditor asked how the program had progressed over the observation window, and the answer was a chart rather than a recollection.
Month 6
Three artifacts lapsed mid-window: the annual penetration test, the semi-annual firewall rule review, and the Q1 access review. None of them had been deleted or forgotten. They had simply aged past the shelf life Northwind set for evidence, and the product moved each control from satisfied to evidence expired the night it happened.
The "evidence expiring" card had been warning about all three for weeks. Two were re-collected before fieldwork. The penetration test was not, and the control was reported as a gap to the assessor rather than hidden behind a stale PDF. That was the outcome Northwind had bought the product for: it made the hole visible on their timeline, not the auditor's.
Month 9
Ray Coleman, the lead auditor at Brackenridge, was invited with the auditor role. Read-only across the whole workspace, no ability to change a status or edit a policy, and no billable seat. He raised evidence requests inside the audit record; the owning control's person answered by attaching evidence already on file, and the request closed with a note of who responded and when.
Before kickoff, Northwind exported the readiness report. It lists every framework percentage, every control's health, the top gaps and the policy validation summary, with each figure traceable to the screen it came from. The assessor started from the same document the company had been staring at for months, so there were no surprises in either direction.
Fieldwork
A login, not a folder. Here is what that login could and could not do.
The auditor role cannot write anything except an evidence request. That is a row-level policy in Postgres, not a hidden button, so an assessor cannot accidentally change what they are assessing.
Each request names the requirement, the person who raised it, the person who answered, the evidence attached and the date. The audit record becomes the index of what was asked and what was shown.
Every approval, status change and evidence upload over the observation window is timestamped with the person who did it. When the assessor asked who approved the access control policy and when, it was one row.
Printable, high contrast, no interactivity. Written to be read by an assessor rather than a dashboard user, and handed over at kickoff so both sides work from the same numbers.
How that access is enforced, and who else can see a workspace, is on the security and trust page.
The gaps
A story with no gaps is a brochure. These are the three that surfaced, and where each one stood when the assessor arrived.