> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberopsource.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance OS Overview

> Understand the purpose, applications, and client experience of Compliance OS.

# Compliance OS Overview

Compliance OS is Cyber Op Source's coordinated client platform for cybersecurity and compliance work. It connects the client-facing parts of an engagement—access, interviews, published findings, remediation, evidence, documents, and executive governance—while preserving a clear boundary between internal assessment work and information intentionally released to the client.

## What Compliance OS is designed to solve

Security assessments often produce information across email, spreadsheets, meetings, file shares, ticketing tools, and standalone reports. That fragmentation makes it harder to know what requires attention, who owns an action, what evidence supports completion, and what leadership should review.

Compliance OS gives those workflows a shared operating environment.

The platform is designed around four principles:

* **Clear client boundaries** — client users should only see information authorized for their organization and engagements.
* **Purpose-based applications** — interviews, remediation, and executive governance have distinct workflows rather than being forced into one generic screen.
* **Published client-safe information** — internal working data is not automatically client-visible.
* **Human-governed decisions** — software and AI can assist, but Cyber Op Source professionals and authorized client decision-makers remain responsible for substantive decisions.

## Key applications

### Client Portal

The Client Portal is the starting point. It identifies your client context after sign-in and presents only the Compliance OS applications you are permitted to use. It can also surface real tasks, recent activity, and application-level metrics.

### Interview Application

The Interview Application supports structured stakeholder interviews. It can be used for text-based or voice-assisted interview workflows, depending on the engagement. Interview assignments are engagement-specific and intended to capture the participant's knowledge efficiently and consistently.

### Remediation Workspace

The Remediation Workspace is where client participants work with published findings and treatments. It supports treatment collaboration, assigned actions, evidence, activity history, evidence requests, documents, and related remediation workflows.

### Security Program Hub

The Security Program Hub is the leadership and governance experience. It is intended for authorized executives and client administrators who need published program-level information such as assessments, findings, risks, roadmaps, decisions, documents, and program health.

## Client-safe publication model

Cyber Op Source may perform extensive internal analysis before information is ready for client use. Compliance OS does not treat all internal records as client content.

Instead, client-facing applications operate on authorized client-safe information. This makes publication an intentional governance step rather than a side effect of internal data creation.

<Info>
  A finding can exist internally before it becomes visible to a client. Client visibility is created through the applicable publication and authorization process.
</Info>

## Role and engagement awareness

A user may belong to the same client organization as another user but have different responsibilities. Compliance OS therefore considers more than simple account membership.

Depending on the application, access may consider:

* client membership,
* active account status,
* engagement assignment,
* engagement-scoped role,
* application authorization,
* ownership or assignment,
* publication audience.

This is why two valid users may see different dashboards, findings, treatments, interviews, or governance information.

## Where to go next

<CardGroup cols={2}>
  <Card title="Signing in" icon="log-in" href="/getting-started/signing-in">
    Learn what to expect when entering your client environment.
  </Card>

  <Card title="Roles & Access" icon="users" href="/getting-started/roles-access">
    Understand why application access and actions differ by user.
  </Card>

  <Card title="Client Isolation" icon="building-2" href="/security-and-trust/client-isolation">
    Review the high-level controls used to separate client contexts.
  </Card>

  <Card title="Data Handling" icon="database" href="/security-and-trust/data-handling">
    Learn how client-facing information is governed across the platform.
  </Card>
</CardGroup>
