Quickstart
Your first analysis in 5 minutes
Typical Workflow
Step-by-step from workspace to export
Playbook Guide
Create, customize, and share playbooks
Usage & EVUs
How Evidence Units meter your analyses
Compliance Checks
DORA, NIS2, GDPR gap analysis
Counterparties
Party registry, concentration & impact
Plans & trial
Free trial, plans, and billing
Team Administration
Manage users, orgs, and simplified UI
Quickstart β your first analysis in 5 minutes
The fastest path from an empty account to a verified, citation-backed result. Each step happens in the app section named in bold.
Use the workspace switcher in the sidebar. Your personal workspace already exists; team workspaces are shared with your organization.
In Document Collections, click New Collection, then drag in PDFs/DOCX/XLSX, paste a URL, or connect Google Drive. Text is extracted automatically.
Open the collection and pick a playbook β a built-in template, your own, or a regulatory one (DORA/NIS2/GDPR). A playbook is just the set of questions to ask.
Click Run. Each question is checked against your documents in parallel; watch progress in the Active Jobs panel and the Execution Queue.
Open the result: every answer carries the exact quote, page/section, and a confidence score. Export to PDF/DOCX/Excel/JSON, or share a read-only link.
Key concepts
A quick glossary of the building blocks you'll meet throughout ComplianceOS.
Workspace
An isolated container for your collections, playbooks, and analyses. Personal or shared with a team.
Collection
A group of documents you analyze together (a contract set, a data room, a policy suite).
Playbook
A reusable set of questions/requirements organized into groups β the "what to check". Written in a simple SKILL.md format.
Group
A themed bucket of questions inside a playbook. Groups can be conditional β they only run when a gate answer or document type matches.
Finding
One answered question or checked requirement, returned with the verbatim source quote, location, and a 0β1 confidence score.
Evidence Unit (EVU)
The billing unit: one sealed, verifiable finding equals one EVU, scaled by how it was produced (panel, adversarial, screenshots).
Persona
A reviewer viewpoint (e.g. CISO, DPO, Compliance Officer) the AI adopts. Multiple personas can review the same documents in a panel.
Verification
Optional layers that harden a finding: quote verification, adversarial review, and multi-model consensus.
Crosswalk
Curated control-to-control mappings between frameworks, so evidence collected once can satisfy several frameworks.
Register of Information (RoI)
The DORA register of ICT third-party arrangements, built from contracts via dual-model extraction with human review of disagreements.
Typical Workflow
From start to finish, here is the standard process for running a compliance or document analysis.
Select the workspace for your project from the sidebar dropdown. Each workspace isolates its collections, playbooks, and analyses.
Go to Document Collections and click New Collection. Give it a name describing the documents you will analyze.
Add files (PDF, DOCX, XLSX, PPTX, TXT) by uploading, pasting URLs, or connecting Google Drive. Text is extracted automatically.
Open the collection and choose a playbook. Use a built-in template, a custom playbook, or a regulatory playbook.
Click Run. The AI processes each question or requirement against your documents. Progress shows in the Active Jobs panel.
Once complete, review findings with evidence citations. You will receive an email notification. Export as PDF, DOCX, Excel, or JSON.
Usage & Billing β Evidence Units (EVU)
ComplianceOS meters work in Evidence Units (EVUs): one sealed, verifiable finding equals one EVU, scaled by how the finding was produced. Unlike opaque token billing, every EVU maps to a concrete deliverable β a question answered with citations, a compliance requirement checked, or a panel-consolidated finding β so you can audit exactly what you pay for.
What counts as an EVU
An EVU is recorded each time an analysis seals a finding. All analysis paths are metered: contract Q&A sessions, playbook analyses, regulatory compliance checks, and review-panel workflows. Sealed findings are immutable β once recorded with their timestamp, they can never be altered.
How EVU weights are computed
- Base weight β set by the response type: simple yes/no answers weigh 0.6, dates and numbers 0.7, narratives and summaries up to 1.2.
- Panel factor β review panels with 3, 5, or 6 personas multiply the weight by 3Γ, 5Γ, or 6Γ, reflecting the parallel expert reviews performed.
- Mode factor β adversarial review (a second AI pass that challenges every conclusion) multiplies by 1.6Γ.
- Evidence factor β findings backed by source screenshots multiply by 1.1Γ.
Where to see your usage
Open Settings β Usage for your personal or workspace dashboard: totals, daily consumption, breakdowns by model and response type, and a per-finding transaction history with the full weight breakdown.
Scopes & access
You always see your own usage. Workspace usage is visible to active workspace members; organization-wide usage is restricted to organization admins.
Plans, allowances & overage
Each plan includes a monthly EVU allowance (e.g. Professional 750, Business 2,500). When you approach it, ComplianceOS warns you at 80% and 95%. What happens at the limit depends on your billing mode: prepaid accounts top up with EVU packs or upgrade; credit accounts (typical for established organizations) continue seamlessly into metered overage at the published per-EVU rate, up to an agreed headroom. Your administrator can arrange credit terms with us.
Top-up packs
Prepaid EVU packs (50, 200 or 1,000 EVUs) are valid for 12 months and are consumed after your monthly allowance, before any overage. Unused monthly allowance does not roll over; unused top-ups do.
Plans, free trial & billing
How access, the free trial, and pricing work. Usage is metered in Evidence Units (see the section above); plans set your monthly allowance and support level.
Your 30-day free trial
Every new account starts on a 30-day free trial with access to the platform so you can analyze real documents end to end before committing.
What happens when the trial ends
When the trial ends your account becomes read-only: you can still sign in and view every past analysis, finding, and export β nothing is deleted β but starting a new analysis is paused until you choose a plan.
Paid plans
Professional
Entry enterprise agreement for a single compliance team β verified findings with full evidence trails.
Business
For multi-team compliance functions β a higher EVU allowance with metered overage.
Enterprise
Bank- and firm-scale deployment β the highest allowance, lowest effective rate, and priority support.
Monthly vs annual β save 20%
Pay monthly at the list price, or prepay for the year and save 20%. Example: Professional is β¬1,875/month billed monthly, or β¬1,500/month (β¬18,000/year) prepaid annually. Switch the billing cycle on the pricing page or in Settings β Billing.
How usage is metered
Work is metered in Evidence Units. Each plan includes a monthly EVU allowance; beyond it you either top up or run into metered overage, depending on your plan and organization's billing mode.
Workspaces
Workspaces organize your work. Each workspace has its own collections, playbooks, and analyses. The workspace switcher is in the sidebar.
Individual Workspace
Your personal workspace, created automatically. Only you can see its contents.
Team Workspace
Shared with your organization. Members can collaborate on collections and analyses.
Workspace Roles
- Owner -- Full control, can delete the workspace and manage all members
- Admin -- Can manage members, create/delete collections and analyses
- Member -- Can create collections, upload documents, run analyses
- Viewer -- Read-only access to collections and analysis results
Switching workspaces: Click the workspace name in the sidebar to open the dropdown. Your choice is saved and persists across sessions.
Inviting members: Open Settings β Workspace, paste one or more email addresses (one per line or comma-separated), choose a role, and send. Invitees receive an email link that auto-accepts on first login.
Manage workspace membersEmail Inbox
Send documents straight to ComplianceOS by email. Attachments are extracted, classified, and analysed without you opening the app.
Forward documents to [email protected]
Use a normal subject line for context. Add a shortcode (e.g. "DORA") to pick a specific playbook, or rely on your default.
Configure defaults
In Settings β Email Inbox, set the default workspace, default playbook, and default language used when no shortcode is provided.
Shortcodes
Map short keywords (e.g. NIS2, KYC) to playbooks. Mention the keyword in the subject line or body to route the email automatically.
Monitor: The Email Inbox dashboard shows received emails, the playbook that ran, and links straight to the resulting analysis or collection.
Document Collections & Sources
A collection is a group of documents you want to analyze together. You can add documents from multiple sources.
File Upload
Drag and drop or browse to upload files. Supported formats:
URLs
Paste any web URL. The page content is fetched, screenshots are captured, and text is extracted for analysis.
Google Drive
Connect your Google account to import documents directly from Drive.
Configure in SettingsPlaybooks
A playbook is a reusable set of questions or requirements that define what to check in your documents. Think of it as an analysis template.
Playbook Types
- Built-in Templates -- Pre-made playbooks for common use cases (contract review, due diligence, financial audit). Ready to use.
- Custom Playbooks -- Create your own question sets manually or with the AI Builder. Fully editable.
- Regulatory Playbooks -- Compliance checks against specific regulations (DORA, NIS2, GDPR). Linked to official legal sources.
Creating a Playbook
- Go to Playbooks in the sidebar
- Click New Playbook or use the AI Builder
- Add question groups -- each group covers a topic area
- Add questions within each group
- Optionally configure verification settings (adversarial review, multi-model consensus)
- Save -- your playbook is now available when running analyses
Groups and Conditional Groups
Questions are organized into groups (also called buckets). Each group has a name, purpose, and optional weight for scoring.
Conditional groups only run when a condition is met. For example, you can create a group that only runs if a previous question was answered "Yes".
- Always -- Group always runs (default)
- If Answer -- Runs if a gate question matches a specific value
- If Not Answer -- Runs if a gate question does NOT match
- If Document Type -- Runs only for specific file types
- If Score Above/Below -- Runs based on a numeric threshold
Tip: Set conditional group weight to 0 so skipped groups do not affect the overall score. Put gate questions in earlier groups so their answers are available for later conditions.
Import & Export
- Import: Upload .md, .json, .docx, .pdf, .xlsx, .pptx, or .txt files
- Export: Download playbooks as JSON or Markdown
- Copy: Copy a playbook to another workspace
Verification Options
- Quote Verification -- Confirms cited evidence exists in your documents
- Adversarial Review -- A second AI pass challenges findings
- Multi-Model Consensus -- Cross-checks with alternative AI models
- Screenshot Capture -- Captures legal source page screenshots
Clause Libraries
Workspace-scoped libraries of approved clauses. Link them to a playbook and the engine will propose compliant replacements whenever it flags a non-compliant finding.
Create a library
Give it a name, description, and default language. Add clauses individually or import them from a master template.
Link to a playbook
Open the playbook editor, scroll to Linked clause libraries, and pick one or more libraries. They activate during the next run.
Language variants
Each clause can hold EN/FR/DE variants. The matcher serves the variant that matches the analysed document's language.
Copy across workspaces
Copy a polished library from one workspace into another to share approved language across teams without losing the originals.
AI Playbook Builder
Describe what you want to analyze in plain language, and the AI generates a complete playbook with groups, questions, and conditional logic.
Type a natural language description of what you want to check
The AI creates question groups, individual questions, and suggests conditional logic
Preview the generated playbook. Click Edit to customize in the full editor
Save to your library. The playbook appears in your workspace immediately
Regulatory Compliance
Run documentation gap analyses against EU and national regulations. The system checks your documents against official legal requirements and cites specific evidence.
How It Works
- Go to Compliance in the sidebar to see your posture dashboard
- Choose a regulation or browse all compliance playbooks
- Select a document collection and start the analysis
- The engine checks each requirement against your documents in parallel
- Review findings with evidence quotes, confidence scores, and recommendations
- Click Track on findings to create remediation items
- Export the full report as PDF, DOCX, Excel, or JSON
Key Features
- Compliance Posture Dashboard -- Overall scores per regulation with trend indicators
- Remediation Tracking -- Track gaps as items to resolve
- Legislative Source Monitoring -- Legal text auto-refreshed from EUR-Lex, Legifrance, RIS
- Source Screenshots -- Screenshots of legal source pages captured and included in results
- Quote Verification -- Confirms evidence actually exists in your documents
- Adversarial Review -- Skeptical second-pass review that challenges findings
- Reviewer Personas -- CISO, DPO, or Compliance Officer perspectives
The compliance section
- Obligations β One catalogue of what you must comply with β regulatory articles and framework controls β with per-workspace status.
- Sources β Every law, framework, and binding policy you treat as authoritative, each with a version, fetch history, and cryptographic fingerprint. Upload your own internal policies as binding sources.
- Audits β Auditor engagements with a sealed evidence bundle; each piece of evidence is tagged with its strength (compliance engine, playbook, or manual).
Deal Analyzer
Automated data room analysis for M&A, investments, and vendor assessments. Upload a folder of documents and the AI classifies, organizes, and analyzes them.
Name your project
Upload the entire data room
Documents are automatically classified by type
Review and adjust the AI's document classifications
The system runs a comprehensive analysis using matched playbooks
Get a structured report with contract database, executive summary, and findings
Review Panels (multi-AI workflows)
Run several AI reviewers on the same documents in parallel and surface where they agree, disagree, or only partially overlap. Useful for high-stakes reviews where a single verdict isn't enough.
Consensus
All reviewers agree on the finding. Highest confidence β safe to action.
Conflict
Reviewers disagree. Open the panel to see each reviewer's reasoning and decide.
Partial
Some reviewers found the issue, others didn't. Often a phrasing or scope difference worth a human look.
Execution Queue
A live view of every analysis that's running, queued, paused, or failed for you (or your workspace, if you're an admin).
Statuses you'll see
- Running -- Currently processing. Progress bar shows percent complete.
- Queued -- Waiting for a worker to pick it up β typically seconds.
- Paused -- Manually paused; resume from the deal/analysis page.
- Failed -- Hit an error. Use Retry to resume from the last checkpoint without re-running completed steps.
Retry resumes from the most recent checkpoint, so you don't lose work already done.
Open Execution QueueMCP Connections (external data sources)
Connect external services like Google Workspace and Microsoft 365 so analyses can pull live data β calendars, mailboxes, drives β into their reasoning.
How it works
Pick a provider on the MCP page, authorise via OAuth, and the connection becomes available to playbooks that opt in to MCP context.
Providers
Google Workspace (Drive, Calendar, Gmail), Microsoft 365 (OneDrive, Outlook, Teams), plus any MCP server published in the registry.
Register of Information (DORA)
Turn ICT service contracts into a validated, submission-ready DORA Register of Information. Every extracted field is cross-validated by two independent AI models and sealed as tamper-evident evidence.
How it works
- 1. Create the financial entity and its contractual arrangements
- 2. Run extraction β two different models read the contract independently
- 3. Agreements are auto-accepted and sealed; disagreements go to your review queue
- 4. Generate the register β a validation report plus the official ESA CSV package and EBA XBRL-CSV report package, versioned
Human review queue
When the two models disagree on a field, nothing is resolved silently. You see both candidate answers side by side and accept, edit, or reject β your decision is recorded and sealed.
Independent verification
Every sealed Evidence Unit has a public verification link (/verify/evu/{id}). Auditors and counterparties can check the cryptographic hash chain and timestamp proofs without a ComplianceOS account.
Validation rules
Registers are checked against ESA taxonomy rules (required fields, LEI checksums, country codes, date consistency) before export. Rules are data, not code β they update as regulation changes.
Export formats
Download the register as the official ESA per-template CSV package (one file per template, official column codes) or the EBA XBRL-CSV report package β the taxonomy-bound ZIP (reportPackage.json, report.json, parameters, filing indicators) that competent authorities collect.
Frameworks & crosswalks
Map your evidence to controls once, and it automatically satisfies every framework you've cross-mapped β DORA, ISO 27001, ReCyF, NIS2. Collect once, comply many.
How coverage works
- Every sealed Evidence Unit is tagged with the control(s) it evidences
- A control is 'directly covered' when evidence is tagged straight to it
- It is also covered when evidence sits on a mapped control in another framework
- The coverage view shows direct vs mapped per control, with an overall %
The crosswalk
Admins curate control-to-control mappings (equivalent / strong / partial / related). Mappings are bidirectional for surfacing but keep a direction, strength, and reviewer for audit.
White-label
Partners can apply their own logo, accent colour, and name to the portal and exported PDFs from the branding settings.
Counterparties & Relationship Intelligence
One registry of every party across your documents β plus the views built on it: vendor concentration, legislative impact, and cross-framework evidence reuse. The golden rule: nothing merges silently β automatic matching only suggests; every link is an exact match or your decision.
How it works
- 1. Run sweep β collects party names from documents, collections, and subcontracting chains; exact LEI/name/alias matches auto-link
- 2. Work the Review Queue β link the suggestion, pick another party, create a new one, or reject; confirming a variant spelling teaches an alias that auto-links next time
- 3. AI suggest (2 models) β two different models pre-sort big queues; only where both agree does a suggestion update, and you still confirm
- 4. Click any party for its 360Β° view β every document, analysis, and sealed finding that touches it
Vendor concentration (DORA)
Provider groups ranked by how many critical functions transitively depend on them β through direct contracts and subcontracting chains. 'Transitive exposure' flags providers reached both ways.
Open ConcentrationImpact Analysis
Pick a changed article and see its blast radius: mapped controls, findings now in doubt, affected documents, and the counterparties to notify.
Open Impact AnalysisCross-framework reuse
Evidence collected once, credited many times: the controls in other frameworks each sealed finding pre-fills via the crosswalk, with weakest-link strength.
Open Cross-framework reuseOntology graph
See how your entities, ICT arrangements, providers and their evidence and cross-framework links connect β the whole ontology as one interactive graph, built live from your data.
How it works
- 1. Add entities, arrangements and providers in the Register of Information β the graph builds from them automatically
- 2. Hover any node to trace its links; click it for a detail panel
- 3. Pan, zoom and drag to explore; drag nodes to rearrange the layout
- 4. Use the story filters to spotlight provider concentration or cross-framework reuse
Provider concentration
Follow the subcontracting chains to see how many critical arrangements and entities transitively depend on a single provider group.
Cross-framework reuse
Trace how one sealed finding maps across frameworks through the crosswalk β evidence collected once, credited many times.
Export & Notifications
Export analysis results in multiple formats. Email notifications are sent automatically when analyses complete.
Export Formats
- PDF -- Professional compliance report with verification badges, adversarial review notes, and screenshot links
- DOCX -- Word document with verification info and source screenshot links
- XLSX -- Multi-sheet spreadsheet for data analysis
- JSON -- Structured data for integration with other tools
Notifications & Sharing
- Email notifications -- Sent to analysis owner on completion
- Share links -- Generate read-only links to share results with anyone
- Webhooks -- Send analysis results to external systems
- Active Jobs panel -- Track running analyses on the dashboard
Interface Modes
ComplianceOS supports two interface modes. Your organization admin chooses which one your team uses.
Complete Interface
Full access to all features. This is the default for all users and admins.
- All sidebar navigation items visible
- Full playbook editor with groups, conditions, verification settings
- Compliance dashboard, deal analyzer, settings
- Choose any playbook, persona, and model
- Custom analysis options (verification, screenshots, language)
Simplified Interface
Streamlined for team members who just need to run analyses. Configured by org admins.
- Only essential sidebar items (Dashboard, Collections, Playbooks)
- Pre-configured playbook presets with one-click run
- Hidden complexity: no persona selector, no verification toggles
- Admin-chosen defaults for model, verification, and screenshots
- Clean, focused experience for non-technical users