ControlQuayBook a walkthrough

CONTROLQUAY / SECURITY & COMPLIANCE

Keep your security
work in order.

Controls, evidence, policies and reviews.
One place to manage the work behind every answer.

Private walkthroughs · Customer deployment subject to validation

THE WORK BEHIND THE REVIEW

Who owns it?
What supports it?
When was it reviewed?

A record your team can follow.
ControlQuay / Acme SoftwareEXAMPLE WORKSPACE

EVIDENCE OVERVIEW

Evidence register

3 controls in scope
01Missing evidence
01Needs review
01Reviewed
Illustrative evidence records
ControlOwnerEvidence status
01 Source-code access reviewEngineeringReviewed
02 Incident response policyOperationsNeeds review
03 Backup verificationEngineeringMissing
Keep the decision with the evidence.

New evidence starts a new review. Earlier decisions stay with the record they describe.

Illustrative product presentation using fictional records.Illustrative data
THE PLATFORM

Compliance operations

Security reviews

Evidence management

01 / THE PROBLEM

The policy is in a folder.
The approval is in a chat.
The review is tomorrow.

A customer asks how access is reviewed. You have a policy, a spreadsheet and an approval somewhere in a chat. The hard part is connecting them.

ControlQuay connects requirements to their owners, supporting evidence and review history. Your team can see the outstanding work and follow the decisions already made.

01The requirementWhat should happen?
02The ownerWho is responsible?
03The evidenceWhat supports it?
04The decisionWho reviewed which version?

02 / HOW IT WORKS

Own the task.
Keep the supporting record.

Explore a fictional example of the workflows implemented in our development version.

CONTROL OWNERSHIP

Give the work
a name and an owner.

Define the requirement, assign a team member and set a due date. Record why a control applies—or why it doesn’t.

Changes to the control create a new revision and call for fresh supporting evidence.

EXAMPLE · CONTROL 003

Backup verification

Owner
Engineering
Evidence requested
Restore-test results and the date tested
Applicability
In scope · Production data
Requirement recorded. Evidence still needed.

Policies follow the same principle.

Draft, compare and approve versions. Record acknowledgments against the exact policy each member read.

VERSION → APPROVAL → ACKNOWLEDGMENT

03 / PLATFORM COVERAGE

Connected across
your security program.

Workflows implemented in the development platform. We will demonstrate the relevant capabilities and confirm deployment requirements with you.

01

Controls & evidence

Assign ownership, retain evidence versions and record review decisions with their supporting context.

02

Policies & people

Manage policy approvals, employee acknowledgments, training records and access reviews.

03

Risks & vendors

Track assessments, risk acceptance and remediation work alongside your compliance program.

04

Customer assurance

Prepare questionnaire responses, organise audit evidence and manage approved trust documents.

05

AI assistance

Draft questionnaire answers with source references for a person to review. Live provider validation is still pending.

06

Collection & access

Import records and evaluate the GitHub connector, provisioning and enterprise sign-in workflows. Live integration validation is still pending.

Currently in development and evaluation.Production readiness is not yet established. ControlQuay does not issue certifications.

04 / QUESTIONS

Before you book.

Who is ControlQuay for?+

Small B2B software teams that need to organise security requirements, evidence and policy decisions—particularly when customer security reviews expose gaps in ownership or documentation.

Can we use the product today?+

ControlQuay is in development. You can discuss your requirements and request a walkthrough. Customer access depends on the supported scope, deployment and validation; we are not offering instant production access.

Does it connect to our systems automatically?+

The development platform includes imports, a GitHub connector and scheduled jobs. Live provider validation is still pending. We will confirm the exact systems and permissions supported for your evaluation; we do not claim universal integration coverage.

How will AI be used?+

AI-assisted questionnaire drafting has been implemented with source references and human review. Live API validation is still pending. AI output is a draft, not an audit opinion or a compliance approval.

What does it cost?+

Pricing has not been finalised. We will define the supported scope, hosting needs and price before any paid evaluation. Requesting a conversation creates no purchase commitment.

What happens when I request a walkthrough?+

The link opens an email to our team. Tell us which systems you use and what evidence work is difficult. We will discuss fit, demonstrate the available workflows and identify any gaps before proposing next steps.

START A CONVERSATION

Bring us your
next security review.

Tell us what your customers are asking for and which systems you use. We’ll walk through the relevant workflows and discuss fit.

Book a walkthrough An initial conversation. No purchase commitment.