SOC 2 · ISO 27001 · NIST 800-171 · CMMC
Whichever framework is blocking the deal.
Security questionnaires answered in whatever format they arrive, inside 48 hours, with every answer traced to something you can actually point at.
- SOC 2Trust services criteria
- ISO 27001Annex A · 93 controls
- NIST 800-171110 requirements
- CMMCLevel 2
How it runs
Three steps, and a record at the end of them.
Compliance work goes wrong in the same place every time: answers get written to satisfy a form rather than to describe the company. This runs the other way round.
No 75-minute discovery call.
Intake is a conversation with an agent instead of a meeting. You answer in your own words, at your own pace, and it asks a follow-up where an answer is thin. Your link arrives by email once we start.
Every answer starts on a blank sheet.
Policies are written against the cloud accounts, repositories and vendors you really run — never out of a library of stock responses. Where a control is not in place yet, it says so and gets a date.
What comes out is what you can defend.
Every claim traces back to a document or a screenshot. When an auditor asks where a line came from, there is somewhere to point.
Coverage
The controls overlap. The evidence is collected once.
Four frameworks ask many of the same questions in different words. The work is done against your systems, then mapped to whichever one the customer in front of you is asking for.
AI
The AI questions arrived early. They are already in the set.
Buyers added AI sections to their security questionnaires faster than most programmes could answer them. Which models you use, what data reaches them, who approved the vendor, whether a person checks the output. Those questions are answered here the same way every other one is.
What your team already uses
The usual finding is not a policy gap, it is a tool nobody logged: adopted by one person, never reviewed, and holding customer data by the time anyone asks. That inventory is the first thing built.
Where the data actually goes
Model providers are vendors. They get the same review as any other one — retention, training on your inputs, subprocessors, region — and the answer is written down rather than assumed from a marketing page.
Who signed off, and who checks
Approval before adoption, a named owner, and a human review step on anything that reaches a customer. Mapped to ISO 42001 and to the AI clauses now turning up in contracts.
Obilant runs this with agents, not with a bigger team. The intake is a conversation with an agent instead of a spreadsheet sent back and forth, and the draft it produces is reviewed and submitted by a person before it reaches anyone. That is why two people’s worth of programme costs what it does — and it is also why the AI governance questions get a straight answer here.
About
Built so every answer can be traced.
Compliance documentation is usually written to satisfy a form. Obilant is built the other way round — every line traces back to a document, a screenshot, or a setting in a system you actually run.
Everything generates from one file.
The policy set and the questionnaire responses all come out of a single record of the systems you actually run — the cloud accounts, the repositories, the vendors. The documentation is generated, not billed by the hour, which is the whole reason the price sits where it does.
What that buys is not volume. It is that nothing gets claimed on your behalf that you could not defend in an assessment. Where a control is not in place, the document says so and gives it a date — and an answer that overstates what is there does not ship.
The short version
- Focus
- NIST 800-171 · CMMC
- Also works in
- SOC 2 · ISO 27001
- Engagement
- Flat monthly
- Contact
- [email protected]
Price
Two ways to work together.
Flat monthly, with no per-seat count and no charge per questionnaire. Move up a tier when the work moves up, not when the headcount does.
Security questionnaires answered inside 48 hours, in whatever format they arrived, with every answer traced to something you can point at.
What is includedThe documented programme behind the answers: policy set, vendor reviews and a ranked gap list, kept current.
What is includedBoth levels sit below the threshold where most companies convene a committee, which means one person can decide. Audit and assessment support is quoted separately — see why.