Agentic compliance for every framework

Map once. Comply many.
Run easy.

Teddy builds one model of your company, maps every framework onto one control set and runs the recurring work with agents. You approve what matters, and a compliance engineer takes you through the audit.

Read-only by defaultEvery agent action loggedNothing goes out without your approval
The problem

Every framework a new project.
Every answer a new spreadsheet.

Most companies run compliance one framework at a time. Each one starts from zero, and the picture is outdated by the next audit.

01A spreadsheet per framework. Nobody sees the whole program.

One tracker per framework, a consultant report that is outdated by the next audit, and an AI chat that has never seen your controls. You paste documents into ChatGPT or Claude and still get no answer you can show an auditor. With Teddy, a new framework starts from what you already have.

How it works

From regulation to work that is done

Teddy models your company once, maps every obligation onto one control set and runs the recurring work with agents. You approve what matters.

01 Map once

One model of your company. Every obligation that applies.

Teddy captures entities, products, systems, vendors and AI use in one model and works out which frameworks and laws apply to you, and why.

  • Connect Entra ID, AWS, Confluence and Slack, read-only by default
  • Products, vendors and AI systems in one place, kept current
  • Applicability explained for every framework and law

You get: every framework and law that applies, with the reason.

Company modelAcme Inc.
Microsoft Entra ID · 214 accountsConnected
AWS · 3 accountsConnected
Confluence · 128 pagesRead
NIS2 · important entityApplies
DORA · not a financial entityNot in scope
02 Comply many

One control set for every framework.

Every requirement maps onto shared controls. Policies are drafted from your real systems, and evidence collected once counts for every framework it supports.

  • Certification Agent plans your first ISO 27001 or SOC 2
  • Policy Agent drafts policies that match how you actually work
  • A new framework starts from the controls you already have

You get: one control set, and every new framework starts from what you have.

Frameworks134 shared controls
ISO 2700193%
NIS274%
CRA · 2 products58%
EU AI ActNew
Teddy: Adding SOC 2? 81% of the criteria are already covered by your existing controls.
03 Run easy

The routine runs itself. You decide.

Agents audit the program on a schedule, renew evidence, answer questionnaires and check contracts. Every action is logged, and nothing goes out without a named approval.

  • Gap Audit Agent checks the whole program every week
  • Evidence Agent renews stale evidence from connected systems
  • Questionnaire and Contract Agent answer from your live program

You get: a full check every week, and only decisions land on your desk.

This weekWeekly gap audit
Evidence renewed automatically46
New gaps · owners assigned2
Waiting for your approval2
Teddy: 6 gaps from last week are closed. The access control policy needs an update after Monday’s Entra ID change.
Why teams switch

The same work, done differently

Spreadsheets and consultantsGRC toolAI chatTeddy
A new frameworkA new projectA new module to fill inGeneral answersStarts from your controls
EvidenceCollected by handPartly automatedNot possibleCollected once, counts everywhere
Where you standAt the next auditWhen someone updates itUnknownEvery week
Who does the workYour teamYour teamYou, by copy and pasteAgents draft, you approve
Audit supportConsultant, extra costRarely includedNoneCompliance engineer included
AI Agents

Agents do the work.
People decide.

Each agent takes on one kind of recurring work. They draft, check and collect. Policies, answers and contract edits go out only after a person approves.

Getting started

From first session to audit-ready, within weeks

1First session

We build the model of your company together and show which frameworks and laws apply.

2First days

You connect your systems read-only. The first gap audit shows where you stand.

3Within weeks

Agents draft, collect and check, you approve. You are ready for your auditor, and a compliance engineer joins the audit.

Why Teddy

Teddy was built by former CISOs and GRC managers who ran one spreadsheet per framework for years. Map once, comply many is the program they wished they had.

Meet the founders →How we protect your data →
Never stuck

Ask what applies to you. Teddy answers from your own program.

Ask in plain language. Teddy answers from your live program and starts the work. For audits and complex programs, our compliance engineers are one message away.

1

Ask TeddyWhat applies to us? How far are we? Teddy knows your model, controls and evidence.

2

Agents do the workPlans, drafts, evidence and checks arrive ready for your approval, each with its source.

3

Our team backs you upCompliance engineers support audits and help you choose a certification body.

TeddyAcme Inc. · all frameworks
A new customer needs SOC 2. How far are we?
Your ISO 27001 controls already cover 81% of the SOC 2 criteria. Three areas need work:
  • CC7.2 Alert reviewGap
  • CC9.2 Vendor managementPartial
  • CC6.1 Logical accessCovered
Shall I start the SOC 2 plan with the Certification Agent?
Start planAsk our team
CEYour compliance engineer joins audits and complex decisions.
FAQ

Questions about how Teddy works

What does “map once, comply many” mean?

Teddy builds one model of your company and one set of controls. Every framework maps onto those controls, so work and evidence you already have count for each new framework.

How long until we are audit-ready?

Without help, a first ISO 27001 certificate typically takes 6 to 12 months. With Teddy you are audit-ready within weeks. The dates of the certification body stay fixed, and SOC 2 Type II needs an observation period, which can start as soon as you are ready.

Do our documents have to move?

No. Teddy reads policies and evidence where they live, for example in Confluence, SharePoint or your cloud, and writes approved changes back.

What happens to our data?

Teddy connects read-only by default, keeps each customer’s data separate and encrypted, and does not train on customer data. Every agent action is logged. Details are on our security page.

Who decides whether we are compliant?

Teddy measures your controls and evidence and shows what is missing. You approve the work, and the certification body or audit firm issues the certificate or report.

How do we get started?

In a first working session we build the model of your company together. A compliance engineer from our team stays with you through your first audit.

Map once. Comply many. Run easy.

Start with a working session on your own company.