Platform

The audit evidence operating system

ControlFrame turns framework obligations into executable evidence plans, private-runner jobs, validated artifacts, reviewer decisions, and auditor-ready package gates.

Beta

Agentic evidence command

Agent roles remain governed evidence work
24 role prompts · 11 evidence review roles
Inspect agent workspace

Framework-shaped agents plan collection, inspect sufficiency, map artifacts, flag redaction risk, and draft reviewer next actions without bypassing human approval.

  • Agents show control references, evidence references, confidence, and risk flags.
  • Skeptical auditor and security gatekeeper roles keep weak evidence visible.
  • Agent output is positioned as recommendation, not approval.

Operator value: Makes AI useful for audit work because every recommendation stays tied to source evidence and reviewer gates.

Beta

Private runner custody

Credential and raw-evidence boundary
Signed runner job packages · Hash artifact custody metadata
Review private runner model

Private runners and approved connectors collect browser, API, cloud, identity, code, ticket, document, and storage evidence while target access stays inside the customer or operator boundary.

  • Runner jobs can be claimed, leased, heartbeated, completed, failed, or retried.
  • Signed upload/download and object storage scaffolds keep artifact access controlled.
  • Demo mode is clearly separated from production evidence collection.

Operator value: Gives regulated teams a defensible path from source system to artifact vault without turning credentials into a SaaS-side shared secret.

Beta

Audit package release gates

Package-grade release discipline
Review human acceptance state · Manifest export control surface
Inspect package readiness

Evidence does not become package-ready because it exists. It moves through source mapping, validation, sensitive-data review, human decisions, manifest checks, and package readiness gates.

  • Package readiness calls out missing, stale, rejected, and sensitive artifacts.
  • Reviewer notes, client-visible notes, and internal notes stay separated.
  • Transfer ZIPs and sandbox data are labeled honestly before export.

Operator value: Turns evidence folders into a controlled release process auditors, clients, and internal reviewers can trust.

Evidence execution chain

Every artifact has a route from obligation to release.

01

Source-native requirement

Obligation

CMS EDE source rows and broader framework controls stay visible before collection starts.

source-bound
02

Framework-native evidence contract

Plan

ControlFrame defines expected artifacts, file formats, owners, due dates, and review gates by control.

configured
03

Private runner or approved connector

Collect

Collection executes through private runner custody, source-system integrations, or controlled client upload.

guarded
04

Artifact metadata and hash

Vault

Artifacts carry storage references, source, file type, version, hash, sensitivity flags, and chain-of-custody events.

tracked
05

Agent scoring plus human decision

Review

Agents flag sufficiency and risk. Reviewers accept, reject, request revisions, or hold for redaction.

human-gated
06

Package readiness and auditor room

Release

Only accepted, current, package-eligible evidence moves into manifests, reports, and controlled exports.

release-gated
Market signal
AI
is now table stakes

Competitors market AI assistants, agents, mapping, validation, and remediation. ControlFrame differentiates on governed evidence execution.

300+
integration claims are common

Connector breadth matters, but the premium wedge is whether evidence is mapped, scored, reviewed, packaged, and defensible.

Audit
needs source-grade proof

Auditors still need artifacts, provenance, scope, timestamps, reviewer decisions, and package traceability.

Why it holds

Beyond generic GRC

Evidence execution layer

ControlFrame can feed GRC systems while owning the hard work of collecting and defending audit proof.

Private runner custody

Regulated-system boundary

Customer-side collection is the right posture for CMS EDE, healthcare, financial services, federal, and sensitive SaaS audits.

Auditor defensibility

Package-grade artifacts

Evidence scoring, source mapping, redaction, hash checks, and human gates turn artifacts into a reviewable package.

Framework intelligence fabric

Third-party frameworks share one evidence spine without pretending every module is equally deep.

CMS EDE stays the active showcase. Other frameworks are presented as maturity-labeled intelligence, planning, and evidence reuse lanes.
Active showcase

CMS EDE active wedge

Deep source-native CMS EDE evidence collection, private-runner workflow, evidence package gates, and sandbox agent demo.

source rows · browser flows · API artifacts · redaction gates · package readiness
Next seed

Enterprise framework expansion

SOC 2, HIPAA, HITRUST, PCI, ISO, NIST, FedRAMP, CMMC, and AI governance move through the same evidence execution chain.

access reviews · change evidence · risk analysis · vulnerability evidence · control reuse
Planned intelligence

Integration and export fabric

Jira, GitHub, ServiceNow, S3-compatible storage, SharePoint, Google Drive, Slack, Teams, Confluence, and report exports are modeled as governed evidence channels.

ticketing · source control · object storage · collaboration · auditor exports