Obilant A standard for real companies

SOC 2 · ISO 27001 · NIST 800-171 · CMMC

Whichever framework is blocking the deal.

Security questionnaires answered in whatever format they arrive, inside 48 hours, with every answer traced to something you can actually point at.

  • SOC 2
    Trust services criteria
  • ISO 27001
    Annex A · 93 controls
  • NIST 800-171
    110 requirements
  • CMMC
    Level 2

How it runs

Three steps, and a record at the end of them.

Compliance work goes wrong in the same place every time: answers get written to satisfy a form rather than to describe the company. This runs the other way round.

01 — INTAKE

No 75-minute discovery call.

Intake is a conversation with an agent instead of a meeting. You answer in your own words, at your own pace, and it asks a follow-up where an answer is thin. Your link arrives by email once we start.

02 — BUILD

Every answer starts on a blank sheet.

Policies are written against the cloud accounts, repositories and vendors you really run — never out of a library of stock responses. Where a control is not in place yet, it says so and gets a date.

03 — RECORD

What comes out is what you can defend.

Every claim traces back to a document or a screenshot. When an auditor asks where a line came from, there is somewhere to point.

Coverage

The controls overlap. The evidence is collected once.

Four frameworks ask many of the same questions in different words. The work is done against your systems, then mapped to whichever one the customer in front of you is asking for.

SOC 2 Trust services criteria — security, availability, confidentiality. Type I / Type II
ISO 27001 An information security management system, with the Annex A control set. 93 controls
NIST 800-171 Protecting controlled unclassified information on your own systems. 110 requirements
CMMC Defence supply chain maturity, built on the 800-171 requirement set. Level 2

AI

The AI questions arrived early. They are already in the set.

Buyers added AI sections to their security questionnaires faster than most programmes could answer them. Which models you use, what data reaches them, who approved the vendor, whether a person checks the output. Those questions are answered here the same way every other one is.

01

What your team already uses

The usual finding is not a policy gap, it is a tool nobody logged: adopted by one person, never reviewed, and holding customer data by the time anyone asks. That inventory is the first thing built.

02

Where the data actually goes

Model providers are vendors. They get the same review as any other one — retention, training on your inputs, subprocessors, region — and the answer is written down rather than assumed from a marketing page.

03

Who signed off, and who checks

Approval before adoption, a named owner, and a human review step on anything that reaches a customer. Mapped to ISO 42001 and to the AI clauses now turning up in contracts.

Obilant runs this with agents, not with a bigger team. The intake is a conversation with an agent instead of a spreadsheet sent back and forth, and the draft it produces is reviewed and submitted by a person before it reaches anyone. That is why two people’s worth of programme costs what it does — and it is also why the AI governance questions get a straight answer here.

About

Built so every answer can be traced.

Compliance documentation is usually written to satisfy a form. Obilant is built the other way round — every line traces back to a document, a screenshot, or a setting in a system you actually run.

Everything generates from one file.

The policy set and the questionnaire responses all come out of a single record of the systems you actually run — the cloud accounts, the repositories, the vendors. The documentation is generated, not billed by the hour, which is the whole reason the price sits where it does.

What that buys is not volume. It is that nothing gets claimed on your behalf that you could not defend in an assessment. Where a control is not in place, the document says so and gives it a date — and an answer that overstates what is there does not ship.

The short version

Focus
NIST 800-171 · CMMC
Also works in
SOC 2 · ISO 27001
Engagement
Flat monthly

Price

Two ways to work together.

Flat monthly, with no per-seat count and no charge per questionnaire. Move up a tier when the work moves up, not when the headcount does.

Questionnaire Response
$1,500
per month

Security questionnaires answered inside 48 hours, in whatever format they arrived, with every answer traced to something you can point at.

What is included
Security Program
$3,000
per month

The documented programme behind the answers: policy set, vendor reviews and a ranked gap list, kept current.

What is included

Both levels sit below the threshold where most companies convene a committee, which means one person can decide. Audit and assessment support is quoted separately — see why.