The Eredox suite
Build Trust. Prove Compliance. Move Forward.
Eredox brings compliance, customer relationships, and business operations together in one connected suite of intelligent applications.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
Illustrative demo data. Readiness percentages are examples, not customer results.
4
Frameworks available now
10
Feature areas
4
Organisation solutions
6
Plans to scale with
Why NOVA
Compliance work that compounds instead of repeating
Most compliance programmes slow down because evidence is scattered, ownership is unclear and every assessment starts from scratch. NOVA keeps the programme record in one governed workspace.
Understand what is ready and what needs work across every activated framework
Stop duplicating evidence for every separate assessment or questionnaire
Trace every readiness claim back to reviewed evidence and accountable owners
Publish approved assurance content without exposing confidential artefacts
Keep risk, policies, assets and controls in one coherent programme record
Track reviewer sign-off, exceptions and scope changes in one audit trail
Platform
One workspace for frameworks, evidence and decisions
NOVA connects the parts of a compliance programme so the readiness report is a consequence of the records, not a separate exercise.
Framework management
Activate the frameworks that apply, map requirements to shared controls, and record scope honestly.
ExploreEvidence and controls
Describe operating expectations, collect evidence with context, and review it before it counts.
ExploreRisk and governance
Record risks, treatment plans, policy approvals and asset ownership as connected records.
ExploreReporting and assurance
Produce readiness and gap reporting from live records, then share the right view with each audience.
ExploreFrameworks
- SOC 2
- ISO 27001
- Essential Eight
- ISO 42001
Controls
- Mapped expectations
- Owners
- Test cadence
Evidence
- Uploads
- Connectors
- Reviewer validation
Assurance
- Readiness reporting
- Trust Centre
- Auditor Portal
Frameworks
Available frameworks, with more on the roadmap
Activate the frameworks that apply to your organisation. Available frameworks map onto a shared control set so evidence can be reused rather than collected again for every assessment.
SOC 2
Available nowService organisation reporting against the Trust Services Criteria, used widely in enterprise procurement.
ISO/IEC 27001
Available nowThe international standard for an information security management system, certified by an accredited body.
Essential Eight
Available nowEight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.
ISO/IEC 42001
Available nowThe management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.
NIST Cybersecurity Framework
PlannedA voluntary framework organising cybersecurity outcomes into functions, categories and subcategories.
HIPAA
PlannedUnited States requirements for safeguarding protected health information held by covered entities and business associates.
Australian Government Information Security Manual
PlannedA cybersecurity framework of controls published by the Australian Signals Directorate for government systems and their suppliers.
Illustrative readiness snapshot
Illustrative interface concept. Values shown are examples, not customer data.
Readiness
Readiness
Maturity coverage
Readiness
How it works
From scope to readiness decision
A simple operating rhythm: define scope, build the structure, collect evidence, then use live reporting to support a human decision.
- 01
Scope
Choose frameworks and define what is genuinely in scope for your organisation.
- 02
Structure
Map requirements to controls, assign owners and set review cadence.
- 03
Collect
Upload or connect evidence, map it to controls, and have a reviewer validate it.
- 04
Decide
Use live readiness reporting to decide when to engage an assessor or share assurance.
Capabilities
The capabilities that make the programme coherent
Each feature is built around the same idea: keep the record together, keep people accountable, and never claim an outcome the evidence does not support.
Framework management
Available nowActivate the frameworks your organisation works towards, record scope, and map requirements once instead of maintaining parallel programmes.
Learn moreControls and control testing
Available nowDefine what each control is expected to do, who owns it, how often it is tested, and whether the last test passed.
Learn moreEvidence management
Available nowCollect evidence into governed storage, map it to the controls it supports, and have a person validate it before it counts.
Learn morePolicy management
Available nowGovern policy intent with versioning, approval routing and scheduled review, so the published policy is the approved one.
Learn moreRisk management
Available nowRecord risks with owners, assess them consistently, assign treatment, and capture acceptance as an explicit decision.
Learn moreAsset governance
Partly availableMaintain the register of systems, services and data stores your controls depend on, and relate them to risks and evidence.
Learn moreReporting
Available nowReadiness and coverage reporting derived from live control and evidence records, not from a separately maintained status sheet.
Learn moreTrust Centre
Available nowPublish approved assurance information to customers and prospects without exposing the underlying confidential evidence.
Learn moreAuditor Portal
Available nowGive auditors and assessors scoped access to the evidence for an engagement, with requests and findings tracked in one workflow.
Learn moreNOVA AI Assistant
Available nowAssistance grounded in your governed workspace content: interpretation, drafting and gap identification, always for human approval.
Learn moreNOVA AI Assistant
Assistance grounded in your workspace, always for human approval
The assistant works from your governed controls, policies and evidence to explain requirements, draft descriptions, summarise artefacts and identify likely gaps. It does not approve anything.
- Interprets and summarises uploaded evidence
- Prepares policy and control description drafts
- Identifies likely gaps against activated requirements
- Explains what a requirement is asking for in plain language
“NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.”
The assistant speeds preparation. It does not carry accountability for policies, risk acceptance or any statement made to an auditor, regulator or customer.
Evidence and automation
Automation that preserves accountability
Connectors and AI reduce repetitive work, but evidence only counts once a person has reviewed it. Every automation boundary is explicit.
Manual upload
Upload artefacts with structured metadata and map them to controls.
GitHub connector
Bring engineering evidence into the workspace automatically, then review it.
Reviewer validation
A person confirms the artefact actually demonstrates the control before it counts.
Connectors are listed on the integrations page. Planned connectors are clearly labelled as not available today.
Security and trust
Built to hold sensitive assurance material
NOVA keeps each organisation's evidence inside its own tenant boundary, with role-based access and scoped auditor engagement.
- Tenant-isolated workspaces
- Role-based access inside each tenant
- Scoped Auditor Portal access per engagement
- Published security practices, not unverified claims
Trust resources
Solutions
Built for the people who run compliance
By organisation or by role, NOVA is designed around the work that actually happens.
Startups and SaaS
Get through your first enterprise security review without pausing the roadmap.
Read moreTechnology SMEs
Consolidate overlapping obligations into one maintainable programme.
Read moreRegulated organisations
Build a defensible record where proof matters as much as practice.
Read moreCompliance teams
Spend less time chasing artefacts and more time on judgement.
Read morePricing
Plans that scale with the size of the programme
From a free evaluation workspace through to enterprise deployments with bespoke scope.
Free
Evaluate the workflow with a single framework and a small control set.
Free
Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.
- One activated framework
- Core control library
- Manual evidence upload
- Single administrator
Launch
A first certification or attestation programme run properly from the start.
$99/month
Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.
- One activated framework
- Control ownership and review cadence
- Evidence mapping and reviewer validation
- Policy versioning and approval
Growth
Multiple frameworks on one shared control set, with reuse across requirements.
$249/month
Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.
- Multiple activated frameworks
- Cross-framework control and evidence reuse
- Risk register with treatment and acceptance
- GitHub evidence connector
Roadmap
What is available today and what is planned
NOVA ships capabilities as they are ready. Planned work is labelled everywhere so nobody expects a feature that is not live.
| Area | Available now | Planned |
|---|---|---|
| Frameworks | SOC 2, ISO/IEC 27001, Essential Eight, ISO/IEC 42001 | NIST CSF, HIPAA, ISM |
| Evidence collection | Manual upload, GitHub connector, reviewer validation | Additional cloud connectors |
| AI assistance | Evidence interpretation, requirement explanation, gap identification | Multi-connector evidence suggestions |
| Assurance | Readiness reporting, Trust Centre, Auditor Portal | Executive board views for lower tiers |
FAQ
Common questions
Browse by topic to find answers about NOVA, frameworks, evidence, AI, security and pricing.
About NOVA
Frameworks
Evidence and workflow
AI and human approval
Security and access
Commercial and support
What does NOVA Compliance do?
NOVA brings frameworks, controls, evidence, policies, risks, assets, reporting and external assurance into one governed workspace. It helps an organisation understand what is ready, what needs attention and what should happen next.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.