One control evaluation, reported against every framework you are held to — with evidence an auditor can verify rather than take on trust.
TraceLock is continuous control monitoring and evidence management. Connectors test your live environment, findings map through one unified control library, and every artifact lands in an append-only record with its own hash.
Audit readiness decays the moment the screenshot is taken
Point-in-time evidence describes a system that no longer exists, and every new framework means re-testing controls you already tested. The work is duplicated, the evidence is stale, and nobody can prove when it was collected.
Evidence goes staleA folder of screenshots proves what was true on the day someone had time to collect them, not what is true now.
Every framework re-tests the same controlAccess review, logging and change management get evaluated once per framework instead of once, mapped many.
Nobody can verify the chainIf evidence can be edited after the fact, the auditor is trusting your word rather than checking a record.
Evaluate once, report many
Unified Control Library with a cross-framework crosswalk
Internal control codes map to SOC 2, ISO 27001, NIST CSF 2.0, NIST AI RMF, ISO/IEC 42001, the EU AI Act, HIPAA, SEC rules and CIS Controls v8, with fifteen regulated framework packs available on top. One evaluation populates every report it defensibly maps to.
Live connectors instead of questionnaires
AWS, GCP, GitHub, Cloudflare and custody connectors test the real environment on a schedule and raise findings against the controls they cover.
Append-only evidence with hashes
Every artifact is recorded write-once with a SHA-256 digest, so an auditor can confirm nothing changed after collection.
A read-only room for your auditor
Scoped, revocable access to exactly the evidence in scope — no shared drives, no mailbox attachments, no standing accounts.
AI inventory and governance
Discover the models and AI services in use, attach them to obligations, and keep the EU AI Act and ISO 42001 mappings current as the estate changes.
A Privacy Wall in front of connector data
Connectors return posture and findings, not payloads. What TraceLock stores is deliberately narrower than what it can see.
What is actually covered
Numbers you can check against the product rather than a maturity claim.
9frameworks in the core crosswalkSOC 2 · ISO 27001 · NIST CSF 2.0 · NIST AI RMF 1.0 · ISO/IEC 42001:2023 · EU AI Act (2024/1689) · HIPAA Security Rule · SEC rules · CIS Controls v8.15regulated framework packsAttestation packs for financial-services, AML, sanctions and digital-asset regimes, sold per framework. Listed below.Write-onceevidence recordsAppend-only with per-artifact SHA-256 digests and recorded custody.Livecontrol testingCloud, code, custody and log-feed connectors run against the real environment on a schedule.
Core frameworks — every plan
SOC 2 (TSC 2017)
ISO/IEC 27001
NIST Cybersecurity Framework 2.0
HIPAA Security Rule
SEC Investment Adviser Rules
CIS Controls v8
Tested continuously by connectors against the live environment.
AI governance — Growth and Enterprise
NIST AI Risk Management Framework 1.0
ISO/IEC 42001:2023
EU AI Act (2024/1689)
Mapped at article, clause and function level; see the methodology note.
Regulated framework packs — financial services
NYDFS Part 500 Cybersecurity Requirements
SEC and FINRA books-and-records retention (17a-4)
Bank Secrecy Act record retention
UK FCA financial promotions regime
UCC Articles 8 and 12 — securities and controllable electronic records
Regulated framework packs — AML and sanctions
OFAC sanctions compliance
FinCEN money services business obligations
FATF Travel Rule and third-party reliance (R.16/17)
EU Anti-Money Laundering Regulation record-keeping
EU Transfer of Funds Regulation
UK Money Laundering Regulations 2017
Regulated framework packs — digital assets
FATF virtual asset service provider guidance
EU Markets in Crypto-Assets Regulation (MiCA)
NYDFS Part 200 virtual currency business activity (BitLicense)
US payment stablecoin requirements (GENIUS Act)
Each pack is one purchasable framework; Enterprise includes an allowance of two.
Methodology. EU AI Act, ISO 42001 and NIST AI RMF references are curated at article, clause and function level rather than sub-control, and are intended for a compliance reviewer to confirm before they are relied on as an audit deliverable. Where no defensible mapping exists the field is left empty rather than filled in. EU AI Act citations use the final adopted 2024 numbering. Regulated framework pack controls are attested — an owner records the review, the evidence and the date, and TraceLock tracks staleness against a 90-, 180- or 365-day interval. TraceLock does not screen transactions, exchange Travel Rule messages, determine regulatory status or verify reserves.
Plans
Priced per organization and billed by TraceLock. Every plan includes the core crosswalk, append-only evidence and the Privacy Wall.
Assurance Attach
$499/month or $5,988/year
SOC 2 and ISO 27001 monitoring for teams whose other regulatory program runs elsewhere.
Added to any plan from TraceLock's billing settings.
Regulated framework pack$9,000/year per framework
One of the fifteen regulated frameworks above: its control set, attestation workflow, evidence and staleness tracking. The framework is chosen at checkout.
Extra connector pack$99/month
Three more connectors on top of your plan's allowance.
Extra auditor room$299/month
One more scoped, expiring read-only room for an external auditor.
Monitored-user overage$3/user/month
Each monitored identity beyond the plan's limit.
Premium support$500/month
Priority response from the TraceLock team through your audit window.
White-glove onboarding$2,500 one-time
Guided setup: connectors, control owners and your first evidence cycle, run with you.
Warden · By Odingard
Run it as a managed program
Warden builds the crosswalk out to your control set, operates evidence collection, and manages the auditor room through the examination.