Features
Everything you need to run a governed compliance programme
Each feature area is described with its workflow, capabilities, and what the human team remains responsible for.
Framework management
Available nowActivate the frameworks your organisation works towards, record scope, and map requirements once instead of maintaining parallel programmes.
Most organisations end up running each framework as a separate project, with its own spreadsheet, its own evidence folder and its own version of the truth. The same control is described three different ways, and nobody can say confidently which requirements are actually covered.
Explore framework managementControls and control testing
Available nowDefine what each control is expected to do, who owns it, how often it is tested, and whether the last test passed.
A control list without owners and testing is an inventory, not a programme. When an assessor asks how a control operates, the answer is usually reconstructed from memory by whoever happens to be available.
Explore controls and control testingEvidence management
Available nowCollect evidence into governed storage, map it to the controls it supports, and have a person validate it before it counts.
Evidence usually lives in shared drives, ticket attachments and email threads. During an assessment it is gathered again from scratch, and nobody can prove when a screenshot was taken or which control it was meant to support.
Explore evidence managementPolicy management
Available nowGovern policy intent with versioning, approval routing and scheduled review, so the published policy is the approved one.
Policies drift. A draft becomes the working version, the approved copy sits in a different folder, and the review date passes unnoticed until an assessor asks when the document was last approved.
Explore policy managementRisk management
Available nowRecord risks with owners, assess them consistently, assign treatment, and capture acceptance as an explicit decision.
Risk registers are often assembled for an audit and abandoned afterwards. Treatment plans have no owner, and acceptance is implied by silence rather than recorded as a decision someone made.
Explore risk managementAsset governance
Partly availableMaintain the register of systems, services and data stores your controls depend on, and relate them to risks and evidence.
Controls are described in the abstract while risk lives in specific systems. Without an asset register, scope arguments during an assessment cannot be settled with a record.
Explore asset governanceReporting
Available nowReadiness and coverage reporting derived from live control and evidence records, not from a separately maintained status sheet.
Board reporting is usually re-created by hand every quarter. By the time it is presented it is out of date, and it cannot be traced back to the records it summarises.
Explore reportingTrust Centre
Available nowPublish approved assurance information to customers and prospects without exposing the underlying confidential evidence.
Security questionnaires arrive constantly and are answered individually, often inconsistently. Meanwhile the material customers actually want is confidential and cannot simply be attached to an email.
Explore trust centreAuditor Portal
Available nowGive auditors and assessors scoped access to the evidence for an engagement, with requests and findings tracked in one workflow.
Audit fieldwork usually runs on email and shared folders. Requests are lost, the same artefact is sent three times, and nobody has a single view of what remains outstanding.
Explore auditor portalNOVA AI Assistant
Available nowAssistance grounded in your governed workspace content: interpretation, drafting and gap identification, always for human approval.
Compliance work contains a large amount of reading, summarising and drafting. Doing it by hand is slow; doing it with an ungoverned general-purpose tool creates content nobody can trace or defend.
Explore nova ai assistantNOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.