Watch change. Prove the response.
A change and evidence workspace for regulated work: what changed in the rules, what it touches inside your estate, who reviewed it, and what proof answers it. Coverage is shown requirement by requirement, never as one unexplained number.
Regulatory change, read like an analyst.
Supported regulatory sources are versioned like any other document. Change analysis separates substantive updates from editorial noise and records the old and new obligations, dates, and review state.
Coverage counts only reviewed or policy-accepted requirement mappings. What is not mapped shows up as an explicit gap you can work, not a decimal hidden in a score.
Regulatory intelligence, documented45 CFR §164.312 amended
Publish a change. Watch the blast radius.
When a document version changes, EKOS aligns old and new passages, silently migrates citations to unchanged text, and marks dependent proof stale. Try it: publish v2 in the panel and see which records get flagged, and why each one was included.
The result is a focused worklist with reasons, severities, and suggested actions, routed to the owners who can resolve it.
Password Policy
All current citations point at unchanged text. Nothing to review.
- stale
Credential Management Procedure
- stale
Quarterly Access Review Evidence
- check
Vendor Access Standard
Unchanged citations migrated forward silently. Only records supported by the changed clause entered the report, each with its reason.
AI proposes. Your reviewers decide.
Proposed relationships arrive with excerpts from both documents, a confidence score, and the consequence of approval. Human review is the gate: decisions are recorded with notes, and conflict or supersession calls can never be auto-accepted.
Each tenant tunes its own thresholds for what is discarded, what queues for review, and what policy may accept.
Conflict and supersession proposals never auto-accept. The decision, the note, and the evidence stay on the record, and later automation cannot silently overwrite them.
One reviewed graph beneath every workflow.
Requirements, policies, procedures, controls, and evidence connect through typed relationships that keep their excerpts, confidence, and review state. Impact reports, coverage views, and evidence packages all read this same graph, so one relationship means one thing everywhere.
The knowledge graph, documentedEvery edge keeps its excerpts, confidence, extraction method, and review state. Trusted views show approved and policy-accepted relationships, not every raw suggestion.
The audit package, assembled from reviewed proof.
Scope a package to a framework or one control family. EKOS walks the reviewed relationships and assembles requirements, excerpts, provenance, and review context into a canonical manifest whose entries are linked by hashes, plus a readable PDF binder carrying the same root hash.
The result is tamper-evident: verification recomputes the chain and reports exactly where consistency breaks.
Evidence packages, documented- 001
Requirement AC-2 · Account Management
entry sha256: 9f31…c2a4 · prev ∅
- 002
Access Control Policy v3 · §3.1 excerpt
entry sha256: 5b0e…77f1 · prev 9f31…c2a4
- 003
Q2 Access Review Export · reviewed evidence
entry sha256: d84a…10be · prev 5b0e…77f1
root sha256: 77aa…09bd
Chain intactEdit, remove, or reorder any entry and verification reports exactly where the chain breaks.
The Compliance workspace, capability by capability.
Regulatory Compliance Intelligence
Turn regulatory change into a trail of proof.
Read the documentationVerifiable Evidence Packages
Build the audit package from reviewed proof.
Read the documentationChange Impact Analysis
Know what a changed clause affects before risk spreads.
Read the documentationHuman Review Queue
Put consequential AI judgments where people can govern them.
Read the documentationLiving Knowledge Graph
See how regulation, policy, procedure, control, and evidence connect.
Read the documentationActionable Notifications
Route change to the people who can resolve it.
Read the documentationEKOS shows documented coverage, reviewed mappings, and verifiable evidence. It supports deployment-specific compliance programs; it does not determine legal applicability, certify an organization or control, or guarantee a compliance outcome.
Walk one requirement from rule to proof.
Pick a framework you answer to. We will trace a change through mapping, review, impact, and a verifiable evidence package.
