Skip to main content
ControlFrame
Platform

The evidence execution layer beneath enterprise GRC

ControlFrame defines required proof, dispatches governed collection, preserves artifact custody, routes human decisions, and assembles auditor-ready releases. Existing GRC systems can retain program context while ControlFrame owns the execution record underneath it.

Operating signals
Source
requirements and native identifiers remain visible
Custody
every promoted artifact keeps its operating history
Human
independent reviewers authorize package release
Demonstrated

Evidence contracts and private collection

Source-native execution plan
Browser workflow proof · API structured evidence · Docs controlled intake
Trace private collection

ControlFrame defines the expected proof, accepted source, collection method, file contract, sensitivity posture, freshness window, and reviewer gate before work is dispatched.

  • Signed runner jobs can be claimed, leased, heartbeated, retried, cancelled, and completed.
  • Browser, API, cloud, identity, code, ticket, storage, and manual evidence share one artifact contract.
  • Production, prepared-demo, and deterministic fixture states remain visibly distinct.

Operator value: Collection begins with a defensible evidence plan instead of an open-ended request for screenshots.

Demonstrated

Document and artifact repository

Governed evidence system of record
Hash integrity metadata · Version document history · Lineage source to package
Inspect the evidence repository

The repository stores evidence as governed objects rather than loose files. Each object carries source authority, version, checksum, owner, sensitivity, freshness, storage reference, review state, and every control mapping.

  • Document intake keeps accepted file types, requirement context, owner, due date, and common rejection reasons together.
  • Artifact preview, sidecars, validation results, and custody events remain attached to the same repository object.
  • Evidence can support multiple programs without duplicating or obscuring the source artifact.

Operator value: Compliance teams and auditors can answer where an artifact came from, what changed, who reviewed it, and where it was used.

Demonstrated

Control graph and GRC workflows

GRC context tied to operating proof
1 control spine · N framework projections
Review control mappings

Framework-native obligations project onto one canonical control spine while requirement context, risk, owner, finding, exception, remediation, and evidence-reuse decisions remain explicit.

  • Source-native requirement IDs remain first-class throughout mapping and review.
  • Cross-framework reuse is recorded as direct, supporting, or reviewer-required—not automatic satisfaction.
  • Findings and blocked controls route to an accountable owner with evidence and decision context.

Operator value: ControlFrame can complement an enterprise GRC system while owning the evidence execution truth underneath it.

Reference implementation

Agent review and human authority

Recommendations remain evidence-bound
Trace model and tool record · Gate reviewer decision
Inspect the human release gate

Framework-shaped agents can plan collection, inspect sufficiency, identify sensitive data, explain gaps, and draft reviewer next actions without approving their own output.

  • Recommendations include control references, artifact references, confidence, and risk flags.
  • Redaction and package eligibility stay fail-closed when required review is incomplete.
  • Reviewer notes, client-visible notes, and internal operating notes remain separated.

Operator value: AI reduces evidence handling work without taking judgment, signature, or accountability away from authorized people.

Demonstrated

Audit package release and verification

Package-grade release discipline
Manifest scoped package contents · Receipt offline verification
View package release gate

Approved artifacts, manifests, source mappings, checksums, custody events, reviewer decisions, and eligible governed receipts assemble into a controlled release.

  • Missing, stale, rejected, sensitive, and unreviewed evidence blocks release when policy requires it.
  • Release history retains package versions, eligibility state, and export references.
  • Eligible receipts use signed, hash-linked records that can be verified without a ControlFrame session.

Operator value: Auditors receive a defended package and review trail instead of a folder assembled at the end of the audit.

Evidence execution chain

Every artifact has a route from obligation to release.

01

Source-native requirement

Obligation

The original requirement, native identifier, applicability decision, and authoritative source stay visible before collection starts.

source-bound
02

Framework-native evidence contract

Plan

Expected artifacts, accepted sources, file formats, owners, freshness windows, and review gates are declared by control.

configured
03

Private runner or approved channel

Collect

Collection executes through customer-boundary runners, configured connectors, or control-specific document intake.

guarded
04

Governed artifact and document record

Repository

Objects carry storage references, source metadata, version, checksum, sensitivity, freshness, and chain-of-custody events.

tracked
05

Agent recommendation plus human decision

Review

Agents can flag sufficiency and risk. Authorized reviewers accept, reject, request revision, or hold for redaction.

human-gated
06

Package gate and auditor room

Release

Only current, accepted, package-eligible evidence moves into controlled manifests, exports, and verification records.

release-gated
Why it holds

Deeper than generic GRC

Evidence execution layer

ControlFrame can feed existing GRC systems while owning the difficult work of collecting, governing, and defending audit proof.

Private runner custody

Customer-controlled boundary

Target credentials and collection activity can stay inside a customer or operator runtime for regulated and sensitive systems.

Auditor defensibility

Package-grade artifacts

Source mapping, document history, validation, redaction, checksum verification, human decisions, and release history stay connected.

Framework intelligence fabric

Third-party frameworks share one evidence spine without pretending every module is equally deep.

CMS EDE stays the active showcase. Other frameworks are presented as maturity-labeled intelligence, planning, and evidence reuse lanes.
Active showcase

CMS EDE active wedge

Deep source-native CMS EDE evidence contracts, private-runner collection, document intake, review routing, and package gates.

source rows · browser flows · API artifacts · document repository · package readiness
Next seed

Enterprise framework expansion

SOC 2, HIPAA, HITRUST, PCI, ISO, NIST, FedRAMP, CMMC, and AI governance use the same evidence execution chain as mapped readiness lanes.

access reviews · change evidence · risk analysis · vulnerability evidence · approved evidence reuse
Planned intelligence

Integration and export fabric

Ticketing, source control, object storage, collaboration, document management, and auditor exports become governed evidence channels as configured.

ticketing · source control · object storage · documents · auditor exports
Platform | ControlFrame