Coverage
A framework-agnostic audit platform: work the five lead frameworks out of the box, or bring your own — the agentic decoder maps it to a control set you can audit against.
Lead frameworks
Information security management. Assess Annex A controls, link evidence and review the client's Statement of Applicability against them.
Trust service criteria, with control operation and evidence tracked across the whole review period — not a point in time.
AI management. Maintain the AI system inventory, support impact assessments and assess Annex A controls.
Quality management. Model processes as controls and nonconformities as findings.
Privacy information management. Share one evidence base with your ISO 27001 audit.
Certification is issued by an accredited body, not by Kimova — we help you get audit-ready against any of these.
Bring your own
The agentic framework decoder turns a standard's requirements into a control set — assistive, cited, and confirmed by you.
Upload the standard's requirements — including one you wrote yourself.
Kimova drafts a row-by-row mapping to controls, with the source passage for each.
Approve the mapping and audit against it like any other framework.
Running several at once
Run ISO 27001 and SOC 2 in parallel and you collect the same access review twice, reconcile trackers that disagree, and assess one shared control two slightly different ways. The overlap between standards is real — most tooling never captures it.
An assessment you make for one standard is recognised everywhere that control applies — not repeated in a second tracker.
A document collected for one framework satisfies the equivalent control in every framework it maps to.
Each framework gets its own audit report and its own view of readiness, generated from the one set of work.
Questions
Yes — that's the point. The framework decoder turns any standard's requirements into a control set you approve, so you're never limited to a fixed list.
No. Certification against a standard is issued only by an accredited certification body, following an independent audit. Kimova helps you get audit-ready; it does not issue certificates.
No. Every framework, including bring-your-own via the decoder, is available on every plan — coverage is never metered by tier.