Agentic compliance for CISOs

Every framework. One live view. Run by agents.

ISO 27001, SOC 2, NIS2 and the EU AI Act on one control set. Teddy reads your program where it lives, audits it continuously and prepares the board update. You make the calls.

One control setFor every framework and law
Every weekA full check across all frameworks
Board updateStatus per framework and subsidiary
The CISO’s problem

Constant fire.
No single source of truth.

Every framework has its own spreadsheet, every stakeholder has a question, and the board wants one clear answer. Since NIS2, management is personally accountable for it.

01Many frameworks at once

ISO 27001, SOC 2, NIS2 and the EU AI Act run on the same controls.

02Management is liable

Under NIS2, management signs off. Teddy gives them a clear status and keeps the records.

03A small team

Agents handle evidence, policy updates and questionnaires. Your team reviews and decides.

04Your program lives everywhere. Answers live nowhere.

Policies in Confluence, evidence in SharePoint, tasks in a SaaS tool, questions in Slack. You paste documents into ChatGPT or Claude, spend tokens and hours, and still don’t know what current best practice is. Teddy works in your system of record: it reads Confluence and SharePoint, finds the gaps and rolls the fixes back out once you approve.

How it works

From constant fire to one calm, current program

Teddy connects to where your program already lives, audits it continuously and keeps everyone working in their own tools.

01 Evidence Agent

Start from your system of record

Teddy reads your program where it already lives: Confluence, SharePoint, your cloud and identity tools. Nothing has to move first.

Connected sourcesRead-only
Confluence · 128 pagesRead
SharePoint · 86 filesRead
Microsoft Entra IDConnected
AWSConnected
02 Gap Audit Agent

One control set for every framework

ISO 27001, SOC 2, NIS2 and the EU AI Act map onto shared controls. Evidence collected once counts everywhere it applies.

Frameworks134 shared controls
ISO 2700193%
SOC 2 Type II88%
NIS274%
EU AI Act12%
03 Gap Audit Agent

Gap audits every week, not once a year

Teddy audits the whole program on a schedule and turns every finding into an owned task. You see what changed, not a new spreadsheet.

Gap audit · this week4 findings
A.5.17 MFA for admin accounts · MaxGap
CC7.2 Alert review · LenaGap
Teddy: 6 gaps from last week are closed. 2 are new since the Entra ID change on Monday.
04 Gap Audit Agent

New regulation in, gaps out

When the AI Act or another rule arrives, Teddy checks what applies to you and how much your existing controls already cover.

EU AI Act · applicabilityAdded today
Support chatbot · transparency dutiesApplies
Inventory of AI systemsMissing
Covered by existing ISO 27001 controls38%
05 Policy Agent

Fixes rolled out where your team works

Approved changes go back into Confluence and SharePoint, so everyone keeps working in the tools they know.

RolloutAfter your approval
MFA policyUpdated v4
Risk registerSynced
Teddy: The MFA policy in SharePoint was outdated. I archived it and linked the current version in Confluence.
06 Teddy

A board update in minutes

Risk exposure, estimated risks, changes, recommendations and what was achieved, prepared from live data and ready for your review.

Board update · Q4Draft
Risk exposure · 2 high, 5 mediumDown 18%
Changes since the last board meeting3
Recommendations and decisions needed3
Achieved this quarter6 gaps closed
Never alone

Ask Teddy. Agents do it. People back you up.

Ask in plain language. Teddy answers from your live program and does the work. For audits, migrations and complex programs, our compliance engineers are one message away.

1

Ask TeddyWhat changed? What does the board need? Teddy knows your frameworks, controls and evidence.

2

Agents do the workAudits, drafts, evidence and supplier checks arrive ready for your approval, each with its source.

3

Our team backs you upCompliance engineers help with audits, certification bodies and moving off your current tool.

TeddyAcme Inc. · all frameworks
Which controls changed since our last ISO audit?
Since the audit in May, 9 controls changed. 7 have current evidence, 2 need you:
  • A.5.17 MFA for admin accountsGap
  • A.8.16 Monitoring after the SIEM switchEvidence missing
  • A.5.23 Cloud servicesUpdated
Shall I draft the update for the surveillance audit?
Draft updateAsk our team
CEYour compliance engineer joins audits and complex decisions.
Switching

Coming from a SaaS GRC tool or spreadsheets?

Our compliance engineers import your controls, policies, risks and evidence and lead the cutover. Your documents can stay in Confluence and SharePoint.

MigrationLed by our engineers
Controls imported134
Policies linked from Confluence42
Risks imported with history61
Evidence history keptComplete
“As a CISO I had a SaaS GRC tool. It tracked tasks, but before every board meeting I still spent days working out our risk exposure and what had changed. Teddy prepares that from the systems where our program actually lives.”
Sven MoritzCo-founder, Teddy · former CISO
FAQ

Questions CISOs ask

Does Teddy replace our GRC tool?

It can. Many teams move their program into Teddy with help from our compliance engineers. Teddy also works alongside your existing documentation in Confluence and SharePoint.

Do our documents have to leave Confluence or SharePoint?

No. Teddy reads them where they are and writes approved changes back, so your teams keep working in their own tools.

What is in the board update?

Risk exposure and estimated risks, changes since the last meeting, recommendations and the decisions needed, and what was achieved. Every figure links to its source.

How does Teddy handle new rules like the EU AI Act?

Teddy checks which obligations apply to your company, maps them onto your existing controls and shows exactly what is missing.

One view for every framework. Ready for the next board meeting.

Start with a live gap audit on your own program.

What changes with Teddy

From a yearly fire drill to a program that runs every week

TypicalOnce a year

A full gap audit once a year, and days of manual work before every board meeting.

With TeddyEvery week

Gap audits across every framework every week, and the board update prepared in minutes from live data.

Why Teddy

Teddy was built by former CISOs and GRC managers. Even with a GRC tool, days went into working out risk exposure and what had changed before every board meeting. Teddy prepares that from the systems where your program actually lives.

Meet the founders →