Making Compliance Continuously Provable

Touchque builds AI-powered evidence collection, findings, and risk tracking — so your team proves compliance instead of scrambling for it every audit season.

touchque.com/dashboard
GENERAL
Dashboard
AI Assistant
SECURITY
Integrations
Findings
Risks
Remediation
AUDIT
Trust Center
Policies

Dashboard

Trust Score
82/100
Correlated Findings
14
3 Critical/High
Automation Coverage
76%

Open Findings — last 7 days

Trust Score breakdown

Base Score100
Severity Penalty−12
Correlation Penalty−6

Open Findings by severity

Critical
High
Medium
Low

AI Assistant

✦

How can I help you today?

Ask about your Trust Score, open findings, or automation coverage.

How many critical findings do I have?What's my Trust Score?What's my automation rate?Which integrations are connected?Collect evidence for my ISO 42001 audit
How many critical findings do I have?
✦
✦
You have 1 critical finding — an exposed API key in a GitHub repo, blocking SOC 2 CC6.1.

OPEN FINDINGS

Critical
Ask a question about your findings or compliance status…➤

Remediation

Open tasks
9
Overdue
2
Completed
14

Remediation tasks

Rotate exposed GitHub keyHIGHIN_PROGRESS
Encrypt S3 bucketMEDIUMTODO
Review Slack export policyLOWCOMPLETED

Trust Center

Trust Center is active

Preview — what visitors see

82/100 · Trust Score
SOC 2
ISO 27001

Findings

GitHubSecret scanning — exposed API key
CriticalOpen

Control CC6.1 · Detected 2 hours ago · GitHub secret scanning

Rotate the exposed key and update the secret in Vault. This closes the CC6.1 access-control gap and restores evidence for your next audit window.

AWSS3 bucket without encryption
MediumOpen
SlackWorkspace export policy
LowResolved

Integrations

All Integrations 16Connected 12Not connected 4Search integrations…
Connected

GitHub

Secret scanning & repo evidence

Connected

Slack

Alerts & workspace evidence

DisconnectedConnected

Okta

SSO & access evidence

Connected

AWS

Cloud config & IAM evidence

Connected

Jira

Remediation ticket tracking

Connected

Google Workspace

Access & device evidence

10xfaster evidence prep
24/7continuous monitoring
1place for every control
HOW IT WORKS

Everything your audit needs, in one workspace

Real-time evidence, the integrations your team already uses, and AI that drafts the fix — Touchque is more than a checklist.

AWS evidence collected — CC6.12 min ago
New finding: High severityGitHub secret scanning
Slack integration connectedJust now

See every change as it happens

A live feed of every piece of evidence, every finding, and every control update your team ships.

GitHub
Slack
Okta

Plug into your stack

GitHub, Slack, Okta, AWS, and more — toggle the integrations your team already lives in.

Suggest a fix for this finding
Rotate the exposed key and update the secret in Vault.
↳ Suggested action: Attach remediation evidence

Let AI fix the finding

Ask Touchque to draft a remediation plan grounded in the actual finding.

One score. Always current.

Your Trust Score updates the moment new evidence comes in — no waiting for the next audit to find out where you stand.

Trust Score

82/100
Base Score100
Severity Penalty−12
Correlation Penalty−6

Open Findings — last 7 days

Compliance pricing

Custom pricing, tailored to your organization.

Compliance

Everything a growing team needs to stay audit-ready, tailored to your organization.

Custom

tailored to your organization

Contact sales
  • Continuous evidence collection
  • Findings & risk register
  • Auditor-facing trust center
  • Dedicated support & SLA
  • Custom integrations & SSO

Talk to our team

Pick a time and we'll walk you through Touchque Compliance.

Or, if you'd prefer, you can email us at hello@touchque.com.

FAQ

Questions, answered clearly

Everything teams usually ask before getting started with Touchque Compliance.

SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, and KVKK today — each with its own evidence mapping. See our Frameworks pages for details on each.

Most teams connect their first integrations and see evidence flowing within a day. Full audit-readiness timelines depend on your framework and current state — typically weeks, not months.

No — Touchque automates evidence collection and continuous monitoring so your audit goes faster, but your auditor still performs the official assessment.

GitHub, GitLab, Bitbucket, Azure DevOps, Slack, Microsoft Teams, Okta, AWS, Azure Key Vault, GCP Secret Manager, HashiCorp Vault, Snyk, Google Workspace, Notion, Confluence, and more.

Yes — evidence is encrypted at rest and in transit, and role-based access controls (including a read-only Auditor mode) govern who can see what.

Talk to our team and we'll walk you through a live demo tailored to your framework and stack.

It drafts remediation steps for findings, summarizes evidence gaps, and can answer questions about your compliance posture — always reviewed by your team before anything is applied.