Compliance Primitives Explorer

58 controls,
built once. Reused everywhere.

A compliance primitive is a runnable control — not a paragraph in a policy. Assemble them into any of the 64 supported frameworks, or your own. Every primitive ships implemented, with continuous control checks.

AData Lifecycle8 primitives

A1

Data Retention

Keeps records for a mandated min/max period, then queues disposal.

Implemented · continuous control check

A2

Data Disposal / Destruction

Irreversibly destroys or de-identifies data, with proof.

Implemented · continuous control check

A3

Data Classification / Labeling

Assigns sensitivity labels that drive all downstream primitive parameters.

Implemented · continuous control check

A4

Data Minimization

Restricts collection to what is necessary for a stated purpose.

Implemented · continuous control check

A5

Data Residency / Localization

Constrains storage/processing location and cross-border transfer.

Implemented · continuous control check

A6

Data Portability / Export

Machine-readable export of a subject’s data.

Implemented · continuous control check

A7

Right to Erasure (DSAR)

Deletes on verified request, cascading to processors.

Implemented · continuous control check

A8

Backup & Recovery

Recoverable copies plus restorability validation.

Implemented · continuous control check

BAccess & Identity7 primitives

B1

Authentication

Verifies identity before any access.

Implemented · continuous control check

B2

Authorization (RBAC/ABAC)

Grants only permitted actions per role or attribute.

Implemented · continuous control check

B3

Least Privilege

Keeps every grant at the minimum needed.

Implemented · continuous control check

B4

Segregation of Duties

No single person controls an entire critical process.

Implemented · continuous control check

B5

Access Review / Recertification

Periodically re-approves every access grant.

Implemented · continuous control check

B6

Unique User Identification

No shared accounts — every action is attributable.

Implemented · continuous control check

B7

Session Management

Lifetime, timeout and re-authentication rules.

Implemented · continuous control check

CAudit & Accountability5 primitives

C1

Audit Trail

Immutable, attributable who/what/when/why without obscuring prior values.

Implemented · continuous control check

C2

Log Retention

Keeps audit logs for the mandated period.

Implemented · continuous control check

C3

Log Review

Scheduled human or automated review of logs.

Implemented · continuous control check

C4

Trusted Timestamp

Time synchronization every record can rely on.

Implemented · continuous control check

C5

Chain of Custody

Tracks possession and handling of evidence end-to-end.

Implemented · continuous control check

DRecords & Signatures5 primitives

D1

Electronic Record Integrity (ALCOA+)

Attributable, legible, contemporaneous, original, accurate records.

Implemented · continuous control check

D2

Electronic Signature

Binds an authenticated identity to a record with legal meaning.

Implemented · continuous control check

D3

Document Control

Draft → review → approve → effective → retire workflow.

Implemented · continuous control check

D4

Versioning

Every change creates a new, comparable version.

Implemented · continuous control check

D5

Attestation

Read-and-understood / certification capture.

Implemented · continuous control check

EConsent & Notice4 primitives

E1

Consent Capture / Management

Collect → store → withdraw → renew consent.

Implemented · continuous control check

E2

Privacy Notice / Disclosure

Serves the right notice at the right moment.

Implemented · continuous control check

E3

Purpose Limitation

Data is used only for its declared purpose.

Implemented · continuous control check

E4

Opt-Out / Preference Management

Honors channel and processing preferences.

Implemented · continuous control check

FNotification & Reporting3 primitives

F1

Breach / Incident Notification

Deadline clock plus required content per regulation.

Implemented · continuous control check

F2

Regulatory Filing / Submission

Produces and tracks mandated filings.

Implemented · continuous control check

F3

Whistleblower Channel

Protected internal reporting route.

Implemented · continuous control check

GRisk & Assessment4 primitives

G1

Risk Assessment

Identify → score → treat risks on a cadence.

Implemented · continuous control check

G2

DPIA / Impact Assessment

Assesses processing before it starts.

Implemented · continuous control check

G3

Vendor / Third-Party Risk

Extends the controls to processors and suppliers.

Implemented · continuous control check

G4

Periodic Review

Recurs any obligation on a schedule.

Implemented · continuous control check

HTraining & Competency3 primitives

H1

Training Assignment

Right course to the right role at the right time.

Implemented · continuous control check

H2

Training Records

Evidence of completion, retained.

Implemented · continuous control check

H3

Competency Attestation

Demonstrated capability, signed off.

Implemented · continuous control check

IEncryption & Protection4 primitives

I1

Encryption at Rest

Stored data is unreadable without keys.

Implemented · continuous control check

I2

Encryption in Transit

Data in motion is protected end-to-end.

Implemented · continuous control check

I3

Key Management

Generate → rotate → destroy keys, on policy.

Implemented · continuous control check

I4

De-identification / Tokenization

Pseudonymizes data for safe secondary use.

Implemented · continuous control check

JMonitoring & Control6 primitives

J1

Change Management

Every change is proposed, approved, and traceable.

Implemented · continuous control check

J2

Configuration Management

Known-good baselines, detected drift.

Implemented · continuous control check

J3

Vulnerability Management

Find, rank and remediate weaknesses.

Implemented · continuous control check

J4

Patch Management

Timely, verified patching.

Implemented · continuous control check

J5

Continuous Monitoring

Controls checked as they run, not annually.

Implemented · continuous control check

J6

Integrity Checks

Detects unauthorized modification.

Implemented · continuous control check

KPhysical & Operational4 primitives

K1

Asset Inventory

Every asset known, owned and tracked.

Implemented · continuous control check

K2

Environmental Monitoring

Temperature/humidity with excursion handling.

Implemented · continuous control check

K3

Calibration Records

Instruments proven accurate, on schedule.

Implemented · continuous control check

K4

Maintenance / Visitor Logs

Physical activity, recorded.

Implemented · continuous control check

LWorkflow & Process5 primitives

L1

Approval Workflow

With segregation of duties and e-signature built in.

Implemented · continuous control check

L2

CAPA

Investigation → root cause → action → effectiveness check.

Implemented · continuous control check

L3

Deviation / Exception Management

Captures, evaluates and closes deviations.

Implemented · continuous control check

L4

Escalation

Unanswered obligations climb the ladder automatically.

Implemented · continuous control check

L5

System Validation (CSV/CSA)

Documented evidence the system does what it claims.

Implemented · continuous control check

Six meta-primitives underneath it all.

The shared engines the 58 primitives are built on — so a fix or an improvement lands everywhere at once.

Retain-Until / Dispose

The shared clock behind every retention and disposal rule.

Classification-Driven Parameterization

One label change re-tunes every dependent control.

Time-Bound Obligation

Deadlines with escalation, reused by every notification rule.

Reviewed Approval with SoD

The approval engine every workflow primitive builds on.

Assess → Treat → Monitor

The risk loop shared by every assessment primitive.

Attributable Event Ledger

The immutable ledger behind every audit trail.