9 scored25 mapped to their source

Know exactly how audit-ready you are.

ARIMA reads your company, works out which regulations actually apply to it, and shows you the gaps — in plain English, in about five minutes. Answer a requirement once and it counts everywhere it's asked.

  • No cloud credentials
  • No agent to install
  • Free to start

Every standard ARIMA maps, cited to its issuing authority

SOC 2
ISO 27001
HIPAA
PCI DSS
GDPR
CCPA / CPRA
FERPA
BSA / AML
EU VAT
Sales-tax nexus
OFAC
EAR
Corporate & Legal
Employment & HR
Trademarks
SPDX licences
EU AI Act
NIST AI RMF
ISO 42001
App Store
Google Play
Meta Platform
Modern Slavery
GHG Protocol
CSRD / ESRS
The control graph

Answer once. Satisfy many.

Frameworks overlap far more than they differ. ARIMA holds one graph of controls, and every crosswalk row ties a requirement to the clause it satisfies in each standard — so a single honest answer moves all of them.

  • Scope before questions

    ARIMA first decides which of eleven categories apply to you, and why. You never answer for a regulation you aren't subject to.

  • Every mapping cites a primary source

    Not a blog post or a model's guess: the regulation, the clause, the issuing body. Mappings a human hasn't verified are kept out of your score.

  • We won't invent a number

    Where a verified crosswalk doesn't exist yet, ARIMA tells you the standard applies and points you at the source — and scores nothing.

Do you enforce multi-factor authentication for everyone with production access?Asked once, in plain English.

SOC 2CC6.1
ISO 27001A.5.17
GDPRArt. 32
HIPAA164.312(d)
How it works

Three steps, about five minutes.

No credentials to hand over, nothing to install. ARIMA works from what your company already looks like from the outside, plus what only you can tell it.

Describe the company

A URL and a short profile. ARIMA scans the site and infers what you do, where you sell and whose data you touch.

Answer only what applies

The questionnaire prunes itself to your surface. A pre-revenue dev-tools team never sees the AML questions a payments company must answer.

Get gaps, fixes and drafts

A readiness score per framework, gaps ranked by impact, remediation for your stack, and the policy drafts to close them.

What you get

The work an auditor would make you do.

Readiness is only useful if it tells you what to change next. Everything here points at an action.

A readiness score you can defend

One number per framework, built from your answers, your site scan and the documents you upload — with every control that fed it shown underneath.

Gaps ranked by what bites first

Not an undifferentiated checklist. Gaps are ordered by severity and by how many frameworks each one unblocks at once.

Remediation written for your stack

Tailored fixes generated for the tools you actually run, instead of the generic 'implement access control' line every template gives you.

Policy drafts to start from

The documents an auditor asks for, pre-filled from what you've already told us — a starting draft, not a blank page.

Evidence read for you

Upload a policy and ARIMA reads it, then tells you which controls its contents actually satisfy — and which it only looks like it does.

A room for your investors

Give an investor or consultant a read-only seat. They see readiness and progress; your raw answers stay yours, by construction.

Coverage

Every framework, and exactly how far we take it.

25 standards across seven domains. 9 have a human-verified crosswalk and feed your readiness score — those are marked scored below. The rest ARIMA scopes and cites without pretending to grade them. Each one links to the authority that publishes it.

Corporate, people & IP

The diligence questions that stall a raise.

4 standards
Corporate & LegalScoredARIMA Corporate & Legal baseline (curated)ARIMA · internal baseline
Employment & HRScoredARIMA Employment & HR baseline (curated)ARIMA · internal baseline
TrademarksCitedU.S. trademark registration (Lanham Act)USPTO · 15 U.S.C. ch. 22SPDX licencesCitedSPDX License List (open-source licence identification)Linux Foundation / SPDX · SPDX License List

Names are cited, not endorsed. The standards above belong to their issuing bodies, and the marks beside them are ARIMA's own drawings — no issuer has reviewed, certified or endorsed this product. ARIMA measures audit readiness; certification only ever comes from a qualified auditor or the relevant authority.

Who it's for

One workspace, three seats.

The same assessment, seen from whichever side of the table you sit on.

Founders

You're being asked for SOC 2 by a customer who won't sign without it, and you have no idea what it costs you.

  • Find out where you stand before you pay an auditor
  • One questionnaire, every framework that applies
  • Drafts and fixes, not a 200-page PDF

Investors

You want portfolio-wide risk without chasing twelve founders for a spreadsheet each quarter.

  • Read-only seats across your portfolio
  • Benchmarks gated at five companies minimum
  • Progress over time, not a point-in-time claim

Consultants

You run readiness for a book of clients and re-do the same intake for every one of them.

  • Every client in one portfolio view
  • Shared workspaces with per-client access
  • The crosswalk does the mapping work

Find out where you stand.

Five minutes, no credentials, no sales call. You'll leave with a readiness score, a ranked list of gaps, and the drafts to start closing them.