Start free trial
Product Updates

Introducing the Urengi continuous compliance engine for NIST and ISO

Instantly map evidence artifacts to major global standards. Create audit-ready workspaces dynamically without replicating review actions.


Marcus Vance

Product Lead, Urengi

Published

1 min read

A dark monitor in a dim office showing a compliance dashboard

1. One review, every framework

Until today, a team running both SOC 2 and ISO 27001 collected the same evidence twice, because the two frameworks name the same control differently. The continuous compliance engine maps an artifact once and answers both.

2. How the mapping works

Every artifact that lands in the evidence vault is parsed for the controls it demonstrates, then attached to each framework that recognises them. NIST 800-53, ISO 27001 and GDPR Article 28 all read the same underlying record, so a gap closes everywhere at once.

  • Upload or auto-fetch happens once, per vendor.
  • Control coverage is computed per framework, not per upload.
  • A lapsed artifact re-opens every gap it was covering.

3. Audit-ready workspaces

When an auditor asks for the evidence behind a control, the workspace is generated from the same records rather than assembled by hand. Nothing is copied, so nothing can be copied wrong.

4. Availability

The engine is on for every workspace today. Existing evidence is mapped in the background; expect coverage numbers to move as the backfill completes.


About Marcus Vance

Marcus runs product at Urengi. He is responsible for the intake, approval and renewal surfaces, and spends most of his time watching security teams use them so the next release removes a step rather than adding one.

Related perspective pieces

A light desktop interface showing an approval thread with a pending vendor request
Product Updates

1 min read

Slack-native vendor requests: command, approve, and review in one window

Bring the operational intake directly to your corporate Slack channels. Introduce rapid approvals on low-risk standard vendors.


Marcus Vance

A glowing padlock inside a shield, rendered over a dark server corridor

Why traditional questionnaires fail to capture real vendor risk

Traditional point-in-time spreadsheets are outdated the minute they are sent. Discover how real-time evidence vault monitoring captures actual security posture.


Sarah Jenkins

Glowing orange data pathways threading through a dark circuit landscape
Engineering

2 min read

Scaling automated evidence extraction pipelines with zero-trust SLAs

How our security infrastructure team engineered a resilient parsing algorithm to handle gigabytes of SOC 2 and ISO PDFs daily.


David Kross