Live demo

Look inside a working ISMS before you sign up.

This is the real GapLedger app, filled in for a fictional SaaS company a few months into ISO 27001. Open any control, follow a risk to the controls that treat it, and export the Statement of Applicability or the audit pack. No account, no email, no card.

Start your own free trial

Read-only · fictional company, invented data · nothing you do is saved

What you'll find inside

  • All 111 ISO 27001:2022 requirements. 93 Annex A controls and the 18 clause 4-10 requirements, each with a status and a written applicability justification.
  • A risk register linked to controls. 15 risks, each linked to the controls that treat it. Every control shows the risks it treats.
  • Ten justified exclusions. The physical and outsourcing controls a cloud-hosted, remote-first company can defend excluding.
  • The management system. A completed internal audit with findings, nonconformities with corrective actions, a management review and recurring tasks.
  • Real exports. Download the Statement of Applicability and the one-click audit pack exactly as a customer would.

Two-minute tour

Prefer to watch first?

A narrated walk through the same workspace: readiness, controls and the risks they treat, the Statement of Applicability, audits, nonconformities, management review and the audit pack.