A compliance analysis engine for regulatory frameworks.
Graphletter ingests evidence documents and evaluates them against the Secure Controls Framework (SCF), producing structured coverage assessments across 79+ regulatory standards including NIST, ISO 27001, SOC 2, GDPR, PCI DSS, and HIPAA.
SCF control catalog (1,200+ controls, 33 domains), regulatory framework mappings, and uploaded evidence documents (PDF, DOCX, images).
Content extraction and SCF control mapping via GPT-5.4, gap analysis and recommendations via Claude 3.7 Sonnet, cross-framework traceability.
Per-control confidence scores, evidence strength ratings, gap identification with remediation guidance, and exportable compliance reports.
Upload a document — a policy, a training record, a vendor assessment. Graphletter maps it to every relevant SCF control and returns structured findings per objective.
| Control | SCF-IAC-15Account Management |
| Result | Partial |
| Risk | Medium |
| Frameworks | NIST 800-53 AC-2ISO 27001 A.9.2.1SOC 2 CC6.1 |
| Deficiencies |
|
| Recommendations |
|
| Remediation | Effort: Low·Policy update, no tooling changes |