Roadmap · open beta

ComplyReady is built and growing in the open. Here's where things stand, organized by how certain we are rather than by dates. We'd rather show you what is real than promise a calendar.

Available

Live now and free during beta.

In progress

Being built or tested with early users.

Exploring

Directions under consideration, shaped by feedback.

Available now10

This is the bulk of ComplyReady, and it is all live right now, free during open beta. AWS, DigitalOcean, OpenStack and GitHub are scanned today: 240 checks live out of 370 written across every provider.

AWS cloud scanning

01

Connect AWS read-only and run 93 automated checks — encryption, IAM, logging, network, Lambda, KMS, EKS and more — each mapped to the SOC 2 criteria it covers, with remediation for anything that fails.

Available

DigitalOcean scanning

02

59 checks across droplets, managed databases, Cloud Firewalls, Kubernetes clusters, load balancers and backups — the same connect, scan, verify flow as AWS.

Available

OpenStack scanning

03

42 checks against a private or hosted OpenStack project: security groups, volume encryption, image exposure, Barbican key management, load balancer TLS and backup health.

Available

GitHub source-control scanning

04

Scan your GitHub organization across 46 checks: 2FA enforcement, branch protection, required reviews, Actions hardening, secret scanning and other change-management safeguards.

Available

Questionnaires answered from verified data

05

Upload any vendor security questionnaire — PDF, Excel, or Word. ComplyReady answers it directly from your verified cloud and source configuration, with the scan evidence cited.

Available

AI-assisted answers with human review

06

For questions a scan can't answer, AI drafts a response from your profile and prior answers. Nothing is auto-approved — you review and confirm before anything is used.

Available

Audit-ready policy generation

07

Generate security policies tailored to your actual stack — access control, incident response, encryption, and more — fully editable and version-tracked.

Available

SOC 2 readiness view

08

A live readiness checklist whose items are verified from your scans, so your status reflects what's actually configured instead of a manual self-assessment.

Available

Public trust center

09

Publish a clean, public trust page that shows prospects your security posture and policies — without emailing another PDF.

Available

Free during open beta

10

Everything above is free while ComplyReady is in open beta. No credit card, no payment, no trial countdown.

Available
In progress03

These are actively being built or tested. Each is labelled by its real maturity rather than called done: early access means it works but is still being proven with our first users.

Kubernetes scanning

01

A read-only, in-cluster agent running 39 checks mapped to SOC 2 CC6, CC7, CC8 and CC9. It runs inside your cluster and pushes results out — no kubeconfig or cluster credentials are ever stored. In early access and being tested with our first users.

Early access

Google Cloud (GCP) scanning

02

91 checks are written and running against IAM, Cloud Storage, Compute, Cloud SQL, GKE and org policy. The connect flow is being reworked so nothing is stored until a project verifies, which is what keeps this out of Available.

In progress

Re-checking answers after you fix and re-scan

03

Closing the verify → fix → re-verify loop: when a scan flags a gap, fix it, re-scan, and have the affected questionnaire answers re-checked against the fresh results — so “verified” always means verified right now.

In progress
Exploring03

These are not commitments and have no timeline. They are the directions we think matter most for a serious compliance posture. Which ones get built, and in what order, is shaped by what beta users tell us they need.

Continuous monitoring

01

Scheduled scans, drift detection, and alerts when your posture changes — the direction that keeps you continuously compliant instead of compliant only on the day you checked. This is where we most want to take verification next.

Exploring

More clouds & integrations

02

Additional cloud providers and tooling integrations, prioritized by what beta users actually connect and ask for.

Exploring

Deeper coverage & more frameworks

03

Broader check coverage and compliance frameworks beyond SOC 2 over time — shaped by demand rather than a fixed plan.

Exploring

ComplyReady is built by a solo founder, in open beta, in the open. What gets built next is not decided behind closed doors. It is decided by what early users actually run into and ask for.

Start free, put it against a real questionnaire, and tell us what is missing. The fastest way onto this page is to ask for it.

Free during open beta · No credit card · No payment required

Where things stand
10shipped and free during beta
03being built or in early access
03directions under consideration