Agentic compliance for every audit

Agents do the work.
You decide.

Teddy’s agents take on the recurring compliance work: certification, gap audits, policies, evidence, questionnaires and contracts. Every action is logged, and nothing goes out without your approval.

The agents

One agent for each kind
of recurring work.

Pick an agent to see what it does, what it works with and what stays with you.

First ISO 27001 or SOC 2 Type II

From zero to your first certificate or report.

The Certification Agent turns a standard written for auditors into an ordered plan in plain language and stays with you until the auditor has finished.

What it does

  • Proposes a scope that fits what your customers expect
  • Turns every requirement into a task with an owner and a due date
  • Runs a readiness check before stage 1 and stage 2

What it works with

  • Your company profile, systems and suppliers
  • Connected tools and existing documents

What you approve

  • Scope and statement of applicability
  • Risk treatment and readiness sign-off
Your first certificate as a startup →
ISO 27001 · certification planAcme Inc.
Scope · product and supporting infrastructureProposed
Tasks across 6 owners64
Statement of applicabilityDraft
Readiness for stage 158%
Teddy: Stage 1 within weeks is realistic. Three policies are on the critical path.
Weekly instead of once a year

A complete gap audit in minutes.

The Gap Audit Agent checks your whole program across every framework and entity, as often as you need. New gaps show up when they appear, not at the next annual review.

What it does

  • Rates every requirement as met, partly met or missing, with the reason
  • Checks controls in connected systems, not just in documents
  • Scores each gap and turns it into a task

What it works with

  • Controls, policies, evidence and the risk register
  • Previous findings and connected systems

What you approve

  • Priorities and owners for remediation
  • Risk acceptance where a gap stays open
How CISOs run it every week →
Gap audit · NIS2Run this morning
Requirements met61 of 82
Partly met9
Missing12
Tasks created with owners21
Teddy: Incident reporting within 24 hours is the most severe gap. I put it first.
Policies that match reality

Policies written for how you actually work.

The Policy Agent drafts policies from your real systems, roles and terminology, in the languages your teams need, and flags policies that drift from reality.

What it does

  • Drafts the policy set your frameworks require
  • Maps every section to the controls it supports
  • Proposes an update when a system or process changes

What it works with

  • Your systems, roles and owners
  • Existing policies and procedures

What you approve

  • Every draft before it applies to employees
  • Updates and exceptions
One policy set for several frameworks →
Access control policy · v5 draft

User accounts are managed in Google Workspace Microsoft Entra ID.

Multi-factor authentication is required for administrator all accounts.

Access is reviewed every 12 6 months by the system owner.

Waiting for approval · Marie, CISO

Collected once, counted everywhere

Evidence that stays current on its own.

The Evidence Agent collects evidence from the systems you already run, on a schedule, and maps each item to every requirement it supports.

What it does

  • Collects daily, weekly or monthly and timestamps at the source
  • Checks each item against its control
  • Maps one item to every framework it supports

What it works with

  • Identity, cloud, HR and code tools
  • Dedicated read-only service accounts

What you approve

  • The permission list before a system is connected
  • Failing evidence and exceptions
Evidence for every framework at once →
Evidence · this week46 items
MFA report · Entra IDCurrent
Backup logs · AWSCurrent
Branch protection · GitHubRenewed
Offboarding · Personio2 accounts active
Teddy: The MFA report counts for ISO 27001, SOC 2 and NIS2 at once.
Drafted immediately from evidence

Questionnaires answered from your live program.

The Questionnaire Agent drafts every answer from your controls, policies and evidence, links the source and marks what it cannot answer instead of guessing.

What it does

  • Reads Excel, Word and PDF questionnaires
  • Drafts each answer with a link to its source
  • Learns from answers you approved before

What it works with

  • Your control set, policies and evidence
  • Your library of approved answers

What you approve

  • Every answer before it is sent
  • Flagged answers and commercial commitments
Questionnaires for SaaS teams →
Granite Mutual Insurance214 questions
Drafted with a source205
Flagged for your review9
4.12 Are backups encrypted? · Policy and evidenceLinked
7.3 Contractual liability capsNeeds Legal
Teddy: Ready for review. Security can approve the drafts in one pass.
Clause by clause

Contracts checked against your obligations.

The Contract Agent reads vendor contracts and DPAs against GDPR Art. 28, DORA Art. 30 and NIS2 supply chain clauses, and against your own standard positions.

What it does

  • Rates each required clause as present, weak or missing
  • Shows deviations from your standard positions
  • Suggests wording for every gap

What it works with

  • Vendor contracts, DPAs and customer agreements
  • Your clause library and fallback positions

What you approve

  • Which clauses are acceptable
  • Every edit before it goes to the other party
Contract checks for legal teams →
DPA · Bluefin Systems LtdGDPR Art. 28
Audit rightsPresent
Subprocessor approvalWeak
Breach notification deadlineMissing
Return and deletion at exitMissing
Teddy: Suggested wording for three clauses is ready. Nothing goes to Bluefin without your approval.
Control

Agents work.
People approve.

You decide what agents may do and who signs off. Every action is recorded, so you can show an auditor exactly what happened and why.

  • Approval workflow. You define owners and approvers per policy, framework and entity.
  • Activity log. What an agent read, drafted and changed, with source, version and time.
  • Read-only by default. Agents connect with their own service accounts and the permissions you approve.
  • Agents work together. The Certification Agent plans, the Policy Agent drafts, the Evidence Agent collects and the Gap Audit Agent checks.
Activity logToday
09:02 · Evidence Agent collected MFA report · Entra IDLogged
10:40 · Questionnaire Agent drafted 214 answersDraft
11:15 · Policy Agent drafted access control policy v5Waiting
11:42 · Marie approved policy v5Approved
11:43 · Policy v5 published to ConfluenceLogged
Why Teddy

Teddy was built by former CISOs and GRC managers who spent years on exactly this recurring work: evidence, policies, questionnaires and contracts. The agents take it on, so people can focus on the decisions only they can make.

Meet the founders →
Never stuck

You don’t have to pick an agent. Just ask Teddy.

Ask in plain language and the right agents start the work. Our compliance engineers are one message away.

1

Ask TeddyWhat changed? What is waiting for me? Teddy answers from your live program.

2

Agents do the workPlans, drafts, evidence and checks arrive ready for your approval, each with its source.

3

Our team backs you upCompliance engineers support audits and complex decisions.

TeddyAcme Inc. · all agents
Granite Mutual sent a security questionnaire and a DPA. Due Friday.
Both are in progress. Here is where they stand:
  • Questionnaire · 205 of 214 draftedDraft
  • 9 answers need your reviewReview
  • DPA · breach notification clause missingGap
Shall I send both to Security and Legal for approval?
Send for approvalAsk our team
CEYour compliance engineer joins audits and complex decisions.
FAQ

Questions about the agents

Do the agents act on their own?

Agents collect, check and draft on their own. Anything that goes out or applies to people, such as policies, answers or contract edits, needs a named approval first.

Can agents change our systems?

Connections are read-only by default, and you approve every permission before a system is connected. Approved documents can be written back, for example to Confluence.

What does the activity log contain?

Every agent action with its source, the version it produced, the time and who approved it. You can export it for auditors.

Do the agents replace our compliance team?

No. They take on the recurring work, so your team can focus on decisions. Our compliance engineers support you through audits.

Let the agents take the routine.

See them work on your own program in a first session.