Skip to main content
NOVACompliance

The Eredox suite

Build Trust. Prove Compliance. Move Forward.

Eredox brings compliance, customer relationships, and business operations together in one connected suite of intelligent applications.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

Illustrative demo data. Readiness percentages are examples, not customer results.

4

Frameworks available now

10

Feature areas

4

Organisation solutions

6

Plans to scale with

Why NOVA

Compliance work that compounds instead of repeating

Most compliance programmes slow down because evidence is scattered, ownership is unclear and every assessment starts from scratch. NOVA keeps the programme record in one governed workspace.

Understand what is ready and what needs work across every activated framework

Stop duplicating evidence for every separate assessment or questionnaire

Trace every readiness claim back to reviewed evidence and accountable owners

Publish approved assurance content without exposing confidential artefacts

Keep risk, policies, assets and controls in one coherent programme record

Track reviewer sign-off, exceptions and scope changes in one audit trail

Platform

One workspace for frameworks, evidence and decisions

NOVA connects the parts of a compliance programme so the readiness report is a consequence of the records, not a separate exercise.

Frameworks

  • SOC 2
  • ISO 27001
  • Essential Eight
  • ISO 42001

Controls

  • Mapped expectations
  • Owners
  • Test cadence

Evidence

  • Uploads
  • Connectors
  • Reviewer validation

Assurance

  • Readiness reporting
  • Trust Centre
  • Auditor Portal

Frameworks

Available frameworks, with more on the roadmap

Activate the frameworks that apply to your organisation. Available frameworks map onto a shared control set so evidence can be reused rather than collected again for every assessment.

SOC 2

Available now

Service organisation reporting against the Trust Services Criteria, used widely in enterprise procurement.

View

ISO/IEC 27001

Available now

The international standard for an information security management system, certified by an accredited body.

View

Essential Eight

Available now

Eight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.

View

ISO/IEC 42001

Available now

The management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.

View

NIST Cybersecurity Framework

Planned

A voluntary framework organising cybersecurity outcomes into functions, categories and subcategories.

View

HIPAA

Planned

United States requirements for safeguarding protected health information held by covered entities and business associates.

View

Australian Government Information Security Manual

Planned

A cybersecurity framework of controls published by the Australian Signals Directorate for government systems and their suppliers.

View

Illustrative readiness snapshot

Illustrative interface concept. Values shown are examples, not customer data.

SOC 295%

Readiness

ISO/IEC 2700185%

Readiness

Essential Eight90%

Maturity coverage

ISO/IEC 4200182%

Readiness

How it works

From scope to readiness decision

A simple operating rhythm: define scope, build the structure, collect evidence, then use live reporting to support a human decision.

  1. 01

    Scope

    Choose frameworks and define what is genuinely in scope for your organisation.

  2. 02

    Structure

    Map requirements to controls, assign owners and set review cadence.

  3. 03

    Collect

    Upload or connect evidence, map it to controls, and have a reviewer validate it.

  4. 04

    Decide

    Use live readiness reporting to decide when to engage an assessor or share assurance.

Capabilities

The capabilities that make the programme coherent

Each feature is built around the same idea: keep the record together, keep people accountable, and never claim an outcome the evidence does not support.

Framework management

Available now

Activate the frameworks your organisation works towards, record scope, and map requirements once instead of maintaining parallel programmes.

Learn more

Controls and control testing

Available now

Define what each control is expected to do, who owns it, how often it is tested, and whether the last test passed.

Learn more

Evidence management

Available now

Collect evidence into governed storage, map it to the controls it supports, and have a person validate it before it counts.

Learn more

Policy management

Available now

Govern policy intent with versioning, approval routing and scheduled review, so the published policy is the approved one.

Learn more

Risk management

Available now

Record risks with owners, assess them consistently, assign treatment, and capture acceptance as an explicit decision.

Learn more

Asset governance

Partly available

Maintain the register of systems, services and data stores your controls depend on, and relate them to risks and evidence.

Learn more

Reporting

Available now

Readiness and coverage reporting derived from live control and evidence records, not from a separately maintained status sheet.

Learn more

Trust Centre

Available now

Publish approved assurance information to customers and prospects without exposing the underlying confidential evidence.

Learn more

Auditor Portal

Available now

Give auditors and assessors scoped access to the evidence for an engagement, with requests and findings tracked in one workflow.

Learn more

NOVA AI Assistant

Available now

Assistance grounded in your governed workspace content: interpretation, drafting and gap identification, always for human approval.

Learn more

NOVA AI Assistant

Assistance grounded in your workspace, always for human approval

The assistant works from your governed controls, policies and evidence to explain requirements, draft descriptions, summarise artefacts and identify likely gaps. It does not approve anything.

  • Interprets and summarises uploaded evidence
  • Prepares policy and control description drafts
  • Identifies likely gaps against activated requirements
  • Explains what a requirement is asking for in plain language
“NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.”

The assistant speeds preparation. It does not carry accountability for policies, risk acceptance or any statement made to an auditor, regulator or customer.

Evidence and automation

Automation that preserves accountability

Connectors and AI reduce repetitive work, but evidence only counts once a person has reviewed it. Every automation boundary is explicit.

Manual upload

Upload artefacts with structured metadata and map them to controls.

GitHub connector

Bring engineering evidence into the workspace automatically, then review it.

Reviewer validation

A person confirms the artefact actually demonstrates the control before it counts.

Connectors are listed on the integrations page. Planned connectors are clearly labelled as not available today.

Security and trust

Built to hold sensitive assurance material

NOVA keeps each organisation's evidence inside its own tenant boundary, with role-based access and scoped auditor engagement.

  • Tenant-isolated workspaces
  • Role-based access inside each tenant
  • Scoped Auditor Portal access per engagement
  • Published security practices, not unverified claims

Pricing

Plans that scale with the size of the programme

From a free evaluation workspace through to enterprise deployments with bespoke scope.

Free

Evaluate the workflow with a single framework and a small control set.

Free

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

  • One activated framework
  • Core control library
  • Manual evidence upload
  • Single administrator
Start free

Launch

A first certification or attestation programme run properly from the start.

$99/month

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

  • One activated framework
  • Control ownership and review cadence
  • Evidence mapping and reviewer validation
  • Policy versioning and approval
Start free
Popular

Growth

Multiple frameworks on one shared control set, with reuse across requirements.

$249/month

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

  • Multiple activated frameworks
  • Cross-framework control and evidence reuse
  • Risk register with treatment and acceptance
  • GitHub evidence connector
Book a demo

Roadmap

What is available today and what is planned

NOVA ships capabilities as they are ready. Planned work is labelled everywhere so nobody expects a feature that is not live.

AreaAvailable nowPlanned
FrameworksSOC 2, ISO/IEC 27001, Essential Eight, ISO/IEC 42001NIST CSF, HIPAA, ISM
Evidence collectionManual upload, GitHub connector, reviewer validationAdditional cloud connectors
AI assistanceEvidence interpretation, requirement explanation, gap identificationMulti-connector evidence suggestions
AssuranceReadiness reporting, Trust Centre, Auditor PortalExecutive board views for lower tiers

FAQ

Common questions

Browse by topic to find answers about NOVA, frameworks, evidence, AI, security and pricing.

About NOVA

Frameworks

Evidence and workflow

AI and human approval

Security and access

Commercial and support

What does NOVA Compliance do?

NOVA brings frameworks, controls, evidence, policies, risks, assets, reporting and external assurance into one governed workspace. It helps an organisation understand what is ready, what needs attention and what should happen next.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.