Boundary
OpenCompliance does not replace licensed CPA firms, ISO certification bodies, or internal human judgment. It improves the quality, structure, and inspectability of evidence that those parties review.
Physical controls, policy adequacy, board oversight, and other normative questions remain partly or wholly attestation-driven or judgment-driven.
MVP Corridor
The initial scope is deliberately narrow: the technical overlap corridor between SOC 2 Security and ISO 27001. Access-control invariants, MFA enforcement, repository protections, CI policy guarantees, cryptographic settings, and similar inspectable controls come first. The public fixture set now also includes dedicated synthetic cyber-baseline and AI-governance corridors, while the reviewed mapping pilot remains broader than the implemented proofs, covering public exact anchors across GDPR, IRAP, Cyber Essentials, NCSC CAF, NIST CSF 2.0, NIST SP 800-53, the EU AI Act, the EU GPAI Code of Practice, and NIST AI RMF, and keeping ISO AI standards at candidate status until licensed review exists.