The governed control library: every framework, every control, and the common controls between them, read through one API.
ControlRegistry is the shared substrate: a superset control library where each framework's controls project from common controls, with graded STRM credit between them. Approve evidence once and the equivalent control is credited across every framework it maps to.
It is served as a governed, versioned asset: the backbone every product inherits. The only way to read the data is the ControlRegistry API.
| Feature | Milestone | Scope |
|---|---|---|
| Dark library UI (framework + control wiki) | v1.0 | In MVP v1.0 |
| AC pilot cross-framework maps | v1.0 | In MVP v1.0 |
| Library asset + snapshot pipeline | v1.1 | Planned |
| Live pull-credit UX | v1.1 | Planned |
| The Vault + public API | v2.0 | Planned |
| Governance model (SoD / four-eyes) | v2.0 | Planned |
Milestones are roadmap targets, not shipped dates. Target for MVP v1.0: Live since Aug 2026. Provisioning is white-glove, never self-serve.
What this establishes. These products prepare you for certification and audit. They do not award either. Every figure is derived from what your organisation reports, and is a documented position rather than an independent verification.
The simulation stood in while this product was being built. It is now live, so there is no rehearsal to walk: you see the product itself.
Provisioned to your organisation and configured to your environment, with its own product website.
Provisioning is white-glove rather than self-serve, and scope follows the due diligence review. The stage above is the honest position today, not a target.