Skip to content

Results & maturity

Two separate things to be honest about: which use cases work today, and how good the compliance engine’s answers are on the latest audit.

Feature status

The production test checked features (FRs) across three areas. Headline status:

AreaAvailablePartialNot available
Framework Compliance & Gap AnalysisFR2, FR4FR5, FR7FR3, FR6, FR7-ITSCM
Local Health & SafetyFR11FR14
SAF Assessment & EvidenceFR15, FR16, FR18, FR19, FR20, FR21, FR22

“Available” means the capability exists and the tester reached the screen — not that a full end-to-end run was demonstrated. The test org had no adopted regulations and no answered controls, and the SAF workspace was not accessible for the test user, so several SAF items were confirmed present but not exercised live. See All use cases for the per-FR detail.

Answer-quality benchmark (2026-08-13)

The real audit (audit_compliance_service.mts all --compact) scored five compliance services on an 8-dimension review rubric, 0–16, against NYDFS/DORA and two internal policies (Access Control, Authentication).

ServiceScoreVerdict
evidence_check13/16Useful as a review draft — strongest
gap_analysis8/16Fail — treats missing selected evidence as a verified gap
draft_response8/16Fail — includes irrelevant/invented content
compare7/16Fail — misses the central MFA provision
requirement_analysis7/16Fail — omits Section 500.12 MFA analysis