Skip to main content

Compliance OS

Compliance OS is the coordinated client experience used by Cyber Op Source to support cybersecurity and compliance engagements from information gathering through remediation and executive governance. It brings together the workflows clients need without exposing unrestricted internal assessment records. Access is controlled by client, engagement, role, and application authorization.

Client Portal

Your front door to authorized Compliance OS applications, current tasks, useful metrics, and recent activity.

Interview Application

Participate in guided stakeholder interviews that collect engagement-specific knowledge and supporting context.

Remediation Workspace

Review published findings, collaborate on treatments, provide evidence, and track remediation progress.

Security Program Hub

A leadership and governance experience for authorized executives and client administrators.

Start here

If this is your first time using Compliance OS, begin with Signing in, then review Roles & Access. Your available applications and actions may differ from another user at the same organization because access is intentionally scoped.

Getting Started

Sign in, understand your Client Portal, and learn how application access works.

User Guides

Step-by-step guidance for interviews, findings, treatments, evidence, plans, and governance.

Security & Trust

Learn how authentication, client isolation, data handling, AI use, and human oversight are approached.

How Compliance OS fits an engagement

A typical engagement moves through several coordinated stages:
  1. Access and onboarding — authorized users sign in through their client-specific entry point.
  2. Information gathering — participants may complete guided interviews and provide engagement context.
  3. Assessment and publication — Cyber Op Source performs assessment work internally and publishes client-safe information when it is ready for client use.
  4. Remediation collaboration — clients review findings, work with treatments, provide evidence, and complete assigned actions.
  5. Leadership governance — authorized leaders use the Security Program Hub for published program information, risk visibility, roadmap progress, and governance decisions.
Not every client or user receives every application. Compliance OS intentionally presents only the applications and information authorized for your organization, engagement, and role.

Documentation scope

These pages focus on the client experience. They explain what you can do in Compliance OS and the security principles that shape the platform. Internal Cyber Op Source administrative procedures, unrestricted assessment data, infrastructure secrets, and sensitive implementation details are not part of the public help center. For questions specific to your engagement, contact your Cyber Op Source engagement lead.