FinCompliance sits between the systems that hold your evidence and the frameworks you report against. Collection is scheduled, mapping is declarative, and the resulting trail is immutable.
A lightweight client polls for the current control manifest on the interval your policy defines, gathers the evidence each control requires, and files it. Nothing is collected that a control does not ask for.
Controls are declared once and mapped to the frameworks that reference them. A single access-review record can satisfy a SOC 2 CC6 control and an ISO 27001 A.9 control without being collected twice.
| Artefact | Default retention |
|---|---|
| Raw evidence | 7 years |
| Control results | 7 years |
| Client telemetry | 90 days |
Named support is included on reporting plans. Response targets are one business day, or four hours during a declared audit window.