Your regulatory obligations, turned into action.
GDPR, ISO 27001, ISO 22301, NIS2, DORA, SOC 2. Specialized AI agents that map your obligations, analyze gaps and generate your compliance deliverables — deployed on-premise, under human control.
// aligned with GDPR · ISO 27001 · NIS2 · DORA · EU AI Act
Domains covered.
14 frameworks and domains of compliance and governance, indexed and kept up to date.
Example agents.
Specialized agents to structure and accelerate your compliance journey.
GDPR agent
Builds and maintains the records of processing, carries out data protection impact assessments (DPIAs), identifies missing legal bases and generates contractual clauses for processors.
ISO 27001 agent
Performs a full gap analysis against Annex A, generates the Statement of Applicability (SoA), proposes missing policies and tracks progress of the risk treatment plan.
NIS2 agent
Assesses your NIS2 eligibility, builds the compliance checklist by article, identifies critical gaps and generates the action plan to meet transposition deadlines.
Policy agent
Generates security policies tailored to your context: general policy, acceptable use policy, password policy, backup policy, incident management procedure.
Risk agent
Conducts a risk analysis using the EBIOS RM methodology: identification of business assets, risk sources, strategic and operational scenarios, then the treatment plan.
Advisory mode vs MCP mode.
The agent is already useful on its own. With an MCP connector, it becomes 10x more powerful.
Generates tailored security policies
Produces gap analyses and Statements of Applicability
Prepares compliance documents and registers
Analyzes gaps based on what you provide
Checks compliance directly inside your GRC tools
Updates the records of processing in real time
Syncs evidence with your audit platform
Automatically alerts on detected gaps
// bespoke deployment
Possible MCP connectors.
Connect to your governance tools via the MCP protocol. Each connector is configured and tailored to your environment. Integration on quote.
// bespoke deployment
Use cases.
Concrete scenarios where CompliForge delivers immediate value.
GDPR compliance for an SMB
The GDPR agent maps personal data processing, identifies 8 processing activities with no documented legal basis, generates the register records and drafts the missing privacy notices.
Preparing for ISO 27001 certification
The ISO 27001 agent performs a gap analysis across the 93 controls, identifies 34 gaps, generates 12 missing policies and proposes a 6-month roadmap to reach certification.
NIS2 assessment for a critical operator
The NIS2 agent determines the status (essential or important entity), assesses compliance article by article, and produces a prioritized action plan with the required technical and organizational measures.
EBIOS RM risk analysis
The Risk agent runs the 5 EBIOS RM workshops: scoping, risk sources, strategic scenarios, operational scenarios and risk treatment. Deliverable ready for management.
Structure your compliance with CompliForge.
Request a demonstration tailored to your regulatory obligations. Audit, on-premise installation, agent configuration for your context, training for your teams.