Describe the company
A URL and a short profile. ARIMA scans the site and infers what you do, where you sell and whose data you touch.
ARIMA reads your company, works out which regulations actually apply to it, and shows you the gaps — in plain English, in about five minutes. Answer a requirement once and it counts everywhere it's asked.
Every standard ARIMA maps, cited to its issuing authority
Frameworks overlap far more than they differ. ARIMA holds one graph of controls, and every crosswalk row ties a requirement to the clause it satisfies in each standard — so a single honest answer moves all of them.
ARIMA first decides which of eleven categories apply to you, and why. You never answer for a regulation you aren't subject to.
Not a blog post or a model's guess: the regulation, the clause, the issuing body. Mappings a human hasn't verified are kept out of your score.
Where a verified crosswalk doesn't exist yet, ARIMA tells you the standard applies and points you at the source — and scores nothing.
Do you enforce multi-factor authentication for everyone with production access?Asked once, in plain English.
CC6.1A.5.17Art. 32164.312(d)No credentials to hand over, nothing to install. ARIMA works from what your company already looks like from the outside, plus what only you can tell it.
A URL and a short profile. ARIMA scans the site and infers what you do, where you sell and whose data you touch.
The questionnaire prunes itself to your surface. A pre-revenue dev-tools team never sees the AML questions a payments company must answer.
A readiness score per framework, gaps ranked by impact, remediation for your stack, and the policy drafts to close them.
Readiness is only useful if it tells you what to change next. Everything here points at an action.
One number per framework, built from your answers, your site scan and the documents you upload — with every control that fed it shown underneath.
Not an undifferentiated checklist. Gaps are ordered by severity and by how many frameworks each one unblocks at once.
Tailored fixes generated for the tools you actually run, instead of the generic 'implement access control' line every template gives you.
The documents an auditor asks for, pre-filled from what you've already told us — a starting draft, not a blank page.
Upload a policy and ARIMA reads it, then tells you which controls its contents actually satisfy — and which it only looks like it does.
Give an investor or consultant a read-only seat. They see readiness and progress; your raw answers stay yours, by construction.
25 standards across seven domains. 9 have a human-verified crosswalk and feed your readiness score — those are marked scored below. The rest ARIMA scopes and cites without pretending to grade them. Each one links to the authority that publishes it.
What buyers and auditors ask for first.
4 standardsTriggered the moment you hold a user record.
3 standardsMoney movement, cross-border sales, sanctions.
5 standardsThe diligence questions that stall a raise.
4 standardsNew obligations, arriving on a deadline.
3 standardsIf you ship an app, these gate the release.
3 standardsWhat enterprise procurement now asks for.
3 standardsNames are cited, not endorsed. The standards above belong to their issuing bodies, and the marks beside them are ARIMA's own drawings — no issuer has reviewed, certified or endorsed this product. ARIMA measures audit readiness; certification only ever comes from a qualified auditor or the relevant authority.
The same assessment, seen from whichever side of the table you sit on.
You're being asked for SOC 2 by a customer who won't sign without it, and you have no idea what it costs you.
You want portfolio-wide risk without chasing twelve founders for a spreadsheet each quarter.
You run readiness for a book of clients and re-do the same intake for every one of them.
Five minutes, no credentials, no sales call. You'll leave with a readiness score, a ranked list of gaps, and the drafts to start closing them.