ComplianceOS Documentation

Help & Documentation

Everything you need to know about ComplianceOS

Quickstart β€” your first analysis in 5 minutes

The fastest path from an empty account to a verified, citation-backed result. Each step happens in the app section named in bold.

1
Pick a workspace

Use the workspace switcher in the sidebar. Your personal workspace already exists; team workspaces are shared with your organization.

2
Create a collection & add documents

In Document Collections, click New Collection, then drag in PDFs/DOCX/XLSX, paste a URL, or connect Google Drive. Text is extracted automatically.

3
Choose a playbook

Open the collection and pick a playbook β€” a built-in template, your own, or a regulatory one (DORA/NIS2/GDPR). A playbook is just the set of questions to ask.

4
Run it

Click Run. Each question is checked against your documents in parallel; watch progress in the Active Jobs panel and the Execution Queue.

5
Review & export

Open the result: every answer carries the exact quote, page/section, and a confidence score. Export to PDF/DOCX/Excel/JSON, or share a read-only link.

Worked example: upload a 40-page vendor contract, choose the "Vendor DPA review" playbook, hit Run. Two minutes later you get a finding for each clause β€” "72-hour breach notice: present (p.12, Β§9.3)", "Sub-processor list: missing" β€” each traceable to the source text.

Key concepts

A quick glossary of the building blocks you'll meet throughout ComplianceOS.

Workspace

An isolated container for your collections, playbooks, and analyses. Personal or shared with a team.

Collection

A group of documents you analyze together (a contract set, a data room, a policy suite).

Playbook

A reusable set of questions/requirements organized into groups β€” the "what to check". Written in a simple SKILL.md format.

Group

A themed bucket of questions inside a playbook. Groups can be conditional β€” they only run when a gate answer or document type matches.

Finding

One answered question or checked requirement, returned with the verbatim source quote, location, and a 0–1 confidence score.

Evidence Unit (EVU)

The billing unit: one sealed, verifiable finding equals one EVU, scaled by how it was produced (panel, adversarial, screenshots).

Persona

A reviewer viewpoint (e.g. CISO, DPO, Compliance Officer) the AI adopts. Multiple personas can review the same documents in a panel.

Verification

Optional layers that harden a finding: quote verification, adversarial review, and multi-model consensus.

Crosswalk

Curated control-to-control mappings between frameworks, so evidence collected once can satisfy several frameworks.

Register of Information (RoI)

The DORA register of ICT third-party arrangements, built from contracts via dual-model extraction with human review of disagreements.

Typical Workflow

From start to finish, here is the standard process for running a compliance or document analysis.

1
Choose a Workspace

Select the workspace for your project from the sidebar dropdown. Each workspace isolates its collections, playbooks, and analyses.

2
Create a Collection

Go to Document Collections and click New Collection. Give it a name describing the documents you will analyze.

3
Upload Documents

Add files (PDF, DOCX, XLSX, PPTX, TXT) by uploading, pasting URLs, or connecting Google Drive. Text is extracted automatically.

4
Select a Playbook

Open the collection and choose a playbook. Use a built-in template, a custom playbook, or a regulatory playbook.

5
Run the Analysis

Click Run. The AI processes each question or requirement against your documents. Progress shows in the Active Jobs panel.

6
Review & Export

Once complete, review findings with evidence citations. You will receive an email notification. Export as PDF, DOCX, Excel, or JSON.

Email: When an analysis completes, the owner receives an email with a direct link to the results. You can also share a read-only link with anyone using the Share button.

Usage & Billing β€” Evidence Units (EVU)

ComplianceOS meters work in Evidence Units (EVUs): one sealed, verifiable finding equals one EVU, scaled by how the finding was produced. Unlike opaque token billing, every EVU maps to a concrete deliverable β€” a question answered with citations, a compliance requirement checked, or a panel-consolidated finding β€” so you can audit exactly what you pay for.

What counts as an EVU

An EVU is recorded each time an analysis seals a finding. All analysis paths are metered: contract Q&A sessions, playbook analyses, regulatory compliance checks, and review-panel workflows. Sealed findings are immutable β€” once recorded with their timestamp, they can never be altered.

How EVU weights are computed

  • Base weight β€” set by the response type: simple yes/no answers weigh 0.6, dates and numbers 0.7, narratives and summaries up to 1.2.
  • Panel factor β€” review panels with 3, 5, or 6 personas multiply the weight by 3Γ—, 5Γ—, or 6Γ—, reflecting the parallel expert reviews performed.
  • Mode factor β€” adversarial review (a second AI pass that challenges every conclusion) multiplies by 1.6Γ—.
  • Evidence factor β€” findings backed by source screenshots multiply by 1.1Γ—.

Where to see your usage

Open Settings β†’ Usage for your personal or workspace dashboard: totals, daily consumption, breakdowns by model and response type, and a per-finding transaction history with the full weight breakdown.

Scopes & access

You always see your own usage. Workspace usage is visible to active workspace members; organization-wide usage is restricted to organization admins.

Plans, allowances & overage

Each plan includes a monthly EVU allowance (e.g. Professional 750, Business 2,500). When you approach it, ComplianceOS warns you at 80% and 95%. What happens at the limit depends on your billing mode: prepaid accounts top up with EVU packs or upgrade; credit accounts (typical for established organizations) continue seamlessly into metered overage at the published per-EVU rate, up to an agreed headroom. Your administrator can arrange credit terms with us.

Top-up packs

Prepaid EVU packs (50, 200 or 1,000 EVUs) are valid for 12 months and are consumed after your monthly allowance, before any overage. Unused monthly allowance does not roll over; unused top-ups do.

Re-runs and resumed analyses are never billed twice β€” the ledger is idempotent per analysis. Failed findings are never billed. A running analysis that crosses your limit always completes; limits only apply to starting new work.
EVU records are append-only and protected at the database level: sealed findings cannot be updated or deleted, giving you a tamper-evident billing trail.
Open your usage dashboard

Plans, free trial & billing

How access, the free trial, and pricing work. Usage is metered in Evidence Units (see the section above); plans set your monthly allowance and support level.

Your 30-day free trial

Every new account starts on a 30-day free trial with access to the platform so you can analyze real documents end to end before committing.

What happens when the trial ends

When the trial ends your account becomes read-only: you can still sign in and view every past analysis, finding, and export β€” nothing is deleted β€” but starting a new analysis is paused until you choose a plan.

Need more time? A system administrator can extend your trial at any point (Admin β†’ Organizations β†’ Set Trial/Plan). The moment a new end date is set, new runs are unblocked automatically.

Paid plans

Professional

Entry enterprise agreement for a single compliance team β€” verified findings with full evidence trails.

Business

For multi-team compliance functions β€” a higher EVU allowance with metered overage.

Enterprise

Bank- and firm-scale deployment β€” the highest allowance, lowest effective rate, and priority support.

Monthly vs annual β€” save 20%

Pay monthly at the list price, or prepay for the year and save 20%. Example: Professional is €1,875/month billed monthly, or €1,500/month (€18,000/year) prepaid annually. Switch the billing cycle on the pricing page or in Settings β†’ Billing.

How usage is metered

Work is metered in Evidence Units. Each plan includes a monthly EVU allowance; beyond it you either top up or run into metered overage, depending on your plan and organization's billing mode.

Hosting & data residency: Your choice of sovereign EU infrastructure or AWS. Your data stays in the EU, is encrypted in transit and at rest, and is never used to train models.
Open Billing settings

Workspaces

Workspaces organize your work. Each workspace has its own collections, playbooks, and analyses. The workspace switcher is in the sidebar.

Individual Workspace

Your personal workspace, created automatically. Only you can see its contents.

Team Workspace

Shared with your organization. Members can collaborate on collections and analyses.

Workspace Roles

  • Owner -- Full control, can delete the workspace and manage all members
  • Admin -- Can manage members, create/delete collections and analyses
  • Member -- Can create collections, upload documents, run analyses
  • Viewer -- Read-only access to collections and analysis results

Switching workspaces: Click the workspace name in the sidebar to open the dropdown. Your choice is saved and persists across sessions.

Inviting members: Open Settings β†’ Workspace, paste one or more email addresses (one per line or comma-separated), choose a role, and send. Invitees receive an email link that auto-accepts on first login.

Manage workspace members

Email Inbox

Send documents straight to ComplianceOS by email. Attachments are extracted, classified, and analysed without you opening the app.

Forward documents to [email protected]

Use a normal subject line for context. Add a shortcode (e.g. "DORA") to pick a specific playbook, or rely on your default.

Configure defaults

In Settings β†’ Email Inbox, set the default workspace, default playbook, and default language used when no shortcode is provided.

Shortcodes

Map short keywords (e.g. NIS2, KYC) to playbooks. Mention the keyword in the subject line or body to route the email automatically.

Monitor: The Email Inbox dashboard shows received emails, the playbook that ran, and links straight to the resulting analysis or collection.

Document Collections & Sources

A collection is a group of documents you want to analyze together. You can add documents from multiple sources.

File Upload

Drag and drop or browse to upload files. Supported formats:

PDF
DOCX
XLSX
PPTX
TXT
CSV
MD
HTML
JSON

URLs

Paste any web URL. The page content is fetched, screenshots are captured, and text is extracted for analysis.

Google Drive

Requires Setup

Connect your Google account to import documents directly from Drive.

Configure in Settings

Playbooks

A playbook is a reusable set of questions or requirements that define what to check in your documents. Think of it as an analysis template.

Playbook Types

  • Built-in Templates -- Pre-made playbooks for common use cases (contract review, due diligence, financial audit). Ready to use.
  • Custom Playbooks -- Create your own question sets manually or with the AI Builder. Fully editable.
  • Regulatory Playbooks -- Compliance checks against specific regulations (DORA, NIS2, GDPR). Linked to official legal sources.

Creating a Playbook

  1. Go to Playbooks in the sidebar
  2. Click New Playbook or use the AI Builder
  3. Add question groups -- each group covers a topic area
  4. Add questions within each group
  5. Optionally configure verification settings (adversarial review, multi-model consensus)
  6. Save -- your playbook is now available when running analyses

Groups and Conditional Groups

Questions are organized into groups (also called buckets). Each group has a name, purpose, and optional weight for scoring.

Conditional groups only run when a condition is met. For example, you can create a group that only runs if a previous question was answered "Yes".

  • Always -- Group always runs (default)
  • If Answer -- Runs if a gate question matches a specific value
  • If Not Answer -- Runs if a gate question does NOT match
  • If Document Type -- Runs only for specific file types
  • If Score Above/Below -- Runs based on a numeric threshold

Tip: Set conditional group weight to 0 so skipped groups do not affect the overall score. Put gate questions in earlier groups so their answers are available for later conditions.

Import & Export

  • Import: Upload .md, .json, .docx, .pdf, .xlsx, .pptx, or .txt files
  • Export: Download playbooks as JSON or Markdown
  • Copy: Copy a playbook to another workspace

Verification Options

  • Quote Verification -- Confirms cited evidence exists in your documents
  • Adversarial Review -- A second AI pass challenges findings
  • Multi-Model Consensus -- Cross-checks with alternative AI models
  • Screenshot Capture -- Captures legal source page screenshots
Example: a "Vendor DPA review" playbook could have a group "Data processing" with questions like "Does the contract name its sub-processors?" and "Is there a 72-hour breach-notification clause?" β€” each answer returns with the exact quote and page.

Clause Libraries

Workspace-scoped libraries of approved clauses. Link them to a playbook and the engine will propose compliant replacements whenever it flags a non-compliant finding.

Create a library

Give it a name, description, and default language. Add clauses individually or import them from a master template.

Link to a playbook

Open the playbook editor, scroll to Linked clause libraries, and pick one or more libraries. They activate during the next run.

Language variants

Each clause can hold EN/FR/DE variants. The matcher serves the variant that matches the analysed document's language.

Copy across workspaces

Copy a polished library from one workspace into another to share approved language across teams without losing the originals.

Tip: keep one library per document family (ISDA, NDA, SaaS MSAs…) so suggestions stay precise.
Open Clause Libraries

AI Playbook Builder

Describe what you want to analyze in plain language, and the AI generates a complete playbook with groups, questions, and conditional logic.

1
Describe Your Need

Type a natural language description of what you want to check

2
AI Generates Playbook

The AI creates question groups, individual questions, and suggests conditional logic

3
Review & Edit

Preview the generated playbook. Click Edit to customize in the full editor

4
Save & Use

Save to your library. The playbook appears in your workspace immediately

Tip: Be specific in your description. Instead of "check contracts", try "Review vendor contracts for data processing clauses, liability caps, termination rights, and SLA commitments".
Open AI Builder

Regulatory Compliance

Run documentation gap analyses against EU and national regulations. The system checks your documents against official legal requirements and cites specific evidence.

Documentation Gap Analysis: Compliance analysis checks whether your documentation addresses regulatory requirements. It does not verify that technical controls are actually implemented. Results should be reviewed by a qualified compliance professional.
DORA
NIS2
GDPR
Austrian DSG
French AML/KYC
Austrian Banking (BWG)
Custom Regulations

How It Works

  1. Go to Compliance in the sidebar to see your posture dashboard
  2. Choose a regulation or browse all compliance playbooks
  3. Select a document collection and start the analysis
  4. The engine checks each requirement against your documents in parallel
  5. Review findings with evidence quotes, confidence scores, and recommendations
  6. Click Track on findings to create remediation items
  7. Export the full report as PDF, DOCX, Excel, or JSON

Key Features

  • Compliance Posture Dashboard -- Overall scores per regulation with trend indicators
  • Remediation Tracking -- Track gaps as items to resolve
  • Legislative Source Monitoring -- Legal text auto-refreshed from EUR-Lex, Legifrance, RIS
  • Source Screenshots -- Screenshots of legal source pages captured and included in results
  • Quote Verification -- Confirms evidence actually exists in your documents
  • Adversarial Review -- Skeptical second-pass review that challenges findings
  • Reviewer Personas -- CISO, DPO, or Compliance Officer perspectives
Example: run the DORA playbook against an ICT outsourcing contract. The engine checks each Article 30 requirement (audit rights, exit plan, sub-outsourcing limits…) and returns present / partial / missing, each with its citation.

The compliance section

  • Obligations β€” One catalogue of what you must comply with β€” regulatory articles and framework controls β€” with per-workspace status.
  • Sources β€” Every law, framework, and binding policy you treat as authoritative, each with a version, fetch history, and cryptographic fingerprint. Upload your own internal policies as binding sources.
  • Audits β€” Auditor engagements with a sealed evidence bundle; each piece of evidence is tagged with its strength (compliance engine, playbook, or manual).

Deal Analyzer

Automated data room analysis for M&A, investments, and vendor assessments. Upload a folder of documents and the AI classifies, organizes, and analyzes them.

1
Create a Deal

Name your project

2
Upload Documents

Upload the entire data room

3
AI Classification

Documents are automatically classified by type

4
Confirm Mappings

Review and adjust the AI's document classifications

5
Run Analysis

The system runs a comprehensive analysis using matched playbooks

6
Review Results

Get a structured report with contract database, executive summary, and findings

Go to Deal Analyzer

Review Panels (multi-AI workflows)

Run several AI reviewers on the same documents in parallel and surface where they agree, disagree, or only partially overlap. Useful for high-stakes reviews where a single verdict isn't enough.

Consensus

All reviewers agree on the finding. Highest confidence β€” safe to action.

Conflict

Reviewers disagree. Open the panel to see each reviewer's reasoning and decide.

Partial

Some reviewers found the issue, others didn't. Often a phrasing or scope difference worth a human look.

Best for: M&A diligence, regulator-facing audits, and any review where you want a second (or third) opinion before signing off.
Open Review Panels

Execution Queue

A live view of every analysis that's running, queued, paused, or failed for you (or your workspace, if you're an admin).

Statuses you'll see

  • Running -- Currently processing. Progress bar shows percent complete.
  • Queued -- Waiting for a worker to pick it up β€” typically seconds.
  • Paused -- Manually paused; resume from the deal/analysis page.
  • Failed -- Hit an error. Use Retry to resume from the last checkpoint without re-running completed steps.

Retry resumes from the most recent checkpoint, so you don't lose work already done.

Open Execution Queue

MCP Connections (external data sources)

Connect external services like Google Workspace and Microsoft 365 so analyses can pull live data β€” calendars, mailboxes, drives β€” into their reasoning.

How it works

Pick a provider on the MCP page, authorise via OAuth, and the connection becomes available to playbooks that opt in to MCP context.

Providers

Google Workspace (Drive, Calendar, Gmail), Microsoft 365 (OneDrive, Outlook, Teams), plus any MCP server published in the registry.

OAuth scopes are read-only by default. You can revoke a connection any time from the MCP page or your provider's account settings.
Open MCP Connections

Register of Information (DORA)

Turn ICT service contracts into a validated, submission-ready DORA Register of Information. Every extracted field is cross-validated by two independent AI models and sealed as tamper-evident evidence.

How it works

  • 1. Create the financial entity and its contractual arrangements
  • 2. Run extraction β€” two different models read the contract independently
  • 3. Agreements are auto-accepted and sealed; disagreements go to your review queue
  • 4. Generate the register β€” a validation report plus the official ESA CSV package and EBA XBRL-CSV report package, versioned

Human review queue

When the two models disagree on a field, nothing is resolved silently. You see both candidate answers side by side and accept, edit, or reject β€” your decision is recorded and sealed.

Independent verification

Every sealed Evidence Unit has a public verification link (/verify/evu/{id}). Auditors and counterparties can check the cryptographic hash chain and timestamp proofs without a ComplianceOS account.

Validation rules

Registers are checked against ESA taxonomy rules (required fields, LEI checksums, country codes, date consistency) before export. Rules are data, not code β€” they update as regulation changes.

Export formats

Download the register as the official ESA per-template CSV package (one file per template, official column codes) or the EBA XBRL-CSV report package β€” the taxonomy-bound ZIP (reportPackage.json, report.json, parameters, filing indicators) that competent authorities collect.

The register is built against the official ESA templates (Commission Implementing Regulation (EU) 2024/2956). Full XBRL taxonomy validation in external tools may require your administrator to load the EBA DORA taxonomy package.
Open Register of Information

Frameworks & crosswalks

Map your evidence to controls once, and it automatically satisfies every framework you've cross-mapped β€” DORA, ISO 27001, ReCyF, NIS2. Collect once, comply many.

How coverage works

  • Every sealed Evidence Unit is tagged with the control(s) it evidences
  • A control is 'directly covered' when evidence is tagged straight to it
  • It is also covered when evidence sits on a mapped control in another framework
  • The coverage view shows direct vs mapped per control, with an overall %

The crosswalk

Admins curate control-to-control mappings (equivalent / strong / partial / related). Mappings are bidirectional for surfacing but keep a direction, strength, and reviewer for audit.

White-label

Partners can apply their own logo, accent colour, and name to the portal and exported PDFs from the branding settings.

Open Frameworks

Counterparties & Relationship Intelligence

One registry of every party across your documents β€” plus the views built on it: vendor concentration, legislative impact, and cross-framework evidence reuse. The golden rule: nothing merges silently β€” automatic matching only suggests; every link is an exact match or your decision.

How it works

  • 1. Run sweep β€” collects party names from documents, collections, and subcontracting chains; exact LEI/name/alias matches auto-link
  • 2. Work the Review Queue β€” link the suggestion, pick another party, create a new one, or reject; confirming a variant spelling teaches an alias that auto-links next time
  • 3. AI suggest (2 models) β€” two different models pre-sort big queues; only where both agree does a suggestion update, and you still confirm
  • 4. Click any party for its 360Β° view β€” every document, analysis, and sealed finding that touches it

Vendor concentration (DORA)

Provider groups ranked by how many critical functions transitively depend on them β€” through direct contracts and subcontracting chains. 'Transitive exposure' flags providers reached both ways.

Open Concentration

Impact Analysis

Pick a changed article and see its blast radius: mapped controls, findings now in doubt, affected documents, and the counterparties to notify.

Open Impact Analysis

Cross-framework reuse

Evidence collected once, credited many times: the controls in other frameworks each sealed finding pre-fills via the crosswalk, with weakest-link strength.

Open Cross-framework reuse
Sweeps re-run automatically when new documents are classified, and they never overwrite your decisions. Full walkthrough: docs/ONTOLOGY_USER_GUIDE.md in your documentation bundle.
Open Counterparties

Ontology graph

See how your entities, ICT arrangements, providers and their evidence and cross-framework links connect β€” the whole ontology as one interactive graph, built live from your data.

How it works

  • 1. Add entities, arrangements and providers in the Register of Information β€” the graph builds from them automatically
  • 2. Hover any node to trace its links; click it for a detail panel
  • 3. Pan, zoom and drag to explore; drag nodes to rearrange the layout
  • 4. Use the story filters to spotlight provider concentration or cross-framework reuse

Provider concentration

Follow the subcontracting chains to see how many critical arrangements and entities transitively depend on a single provider group.

Cross-framework reuse

Trace how one sealed finding maps across frameworks through the crosswalk β€” evidence collected once, credited many times.

Open Ontology graph

Export & Notifications

Export analysis results in multiple formats. Email notifications are sent automatically when analyses complete.

Export Formats

  • PDF -- Professional compliance report with verification badges, adversarial review notes, and screenshot links
  • DOCX -- Word document with verification info and source screenshot links
  • XLSX -- Multi-sheet spreadsheet for data analysis
  • JSON -- Structured data for integration with other tools

Notifications & Sharing

  • Email notifications -- Sent to analysis owner on completion
  • Share links -- Generate read-only links to share results with anyone
  • Webhooks -- Send analysis results to external systems
  • Active Jobs panel -- Track running analyses on the dashboard

Interface Modes

ComplianceOS supports two interface modes. Your organization admin chooses which one your team uses.

Complete Interface

Full access to all features. This is the default for all users and admins.

  • All sidebar navigation items visible
  • Full playbook editor with groups, conditions, verification settings
  • Compliance dashboard, deal analyzer, settings
  • Choose any playbook, persona, and model
  • Custom analysis options (verification, screenshots, language)

Simplified Interface

Streamlined for team members who just need to run analyses. Configured by org admins.

  • Only essential sidebar items (Dashboard, Collections, Playbooks)
  • Pre-configured playbook presets with one-click run
  • Hidden complexity: no persona selector, no verification toggles
  • Admin-chosen defaults for model, verification, and screenshots
  • Clean, focused experience for non-technical users
If your interface looks different from this guide, your organization may have the simplified mode enabled. Contact your org admin to switch modes or adjust visible features.

Keyboard Shortcuts

Quick SearchCtrl+K
New AnalysisCtrl+N
New ProjectCtrl+P
Close DialogEsc