Frequently asked questions
Everything about pricing, security, AI privacy, standards, Trust Center and audits. Can't find it? hello@iso-standard.app.
Pricing
How much does ISO-STANDARD.app cost?
Current prices are on the pricing page — single-organisation plans (Starter, Growth, Business) and multi-tenant plans for consultants and MSPs, billed monthly or yearly. See iso-standard.app/pricing for live prices.
Do I need a credit card to sign up?
Yes. Subscriptions are activated at checkout via Stripe, so a payment method is required up front. There is no unpaid trial period — you subscribe on day one and can cancel any time.
Can I cancel any time?
Yes. Monthly and annual subscriptions auto-renew until cancelled. Cancel from Billing at any time; access continues until the end of the paid period and you can export your data before you leave.
What happens if I hit my plan's user or organisation limit?
You'll be prompted to upgrade to the next plan. Existing data stays intact — only additions above the limit are blocked until you upgrade.
Security
Where is my data hosted?
On managed cloud infrastructure with encryption at rest and TLS in transit. Backups are managed by our backend provider.
Do you support MFA?
Yes. MFA is available for every user and can be enforced org-wide on the Business plan.
AI privacy
Do you use my data to train AI models?
No. Your data is not shared with third-party model providers for training. AI features run through our AI gateway on a zero-retention basis and stay scoped to your workspace.
Can I turn AI off entirely?
AI features are opt-in per workspace. Turn them off and the app works fully without AI.
What AI features are included?
Guided policy drafting from prompts and drafting help inside the policy editor. Everything AI produces is editable by you before it is saved.
Standards
Which standards do you support?
ISO 27001, ISO 31000, ISO 9001, ISO 42001, Cyber Essentials and Cyber Essentials Plus. Controls, risks and evidence crosswalk across standards so you don't duplicate work.
Can one workspace hold multiple standards?
Yes — controls, risks, assets and evidence are shared across the standards you operate in a single organisation.
Buyer trust
What is a Trust Center?
A public page (unique slug per organisation) where you publish the security posture you choose to share — certifications, policies, evidence — with per-item visibility toggles. Included on all plans.
What should be public vs gated?
Public: your certifications, policy summaries, subprocessors, standards. Gated: full policies, pentest reports, SOC 2 report, insurance certificates.
Do I need an NDA click-through?
For pentest and SOC 2 reports, yes. For summarised policies, an email capture is usually enough.
Does the AI ever fabricate?
The generator only cites artifacts already in your workspace. Answers with no evidence source are flagged rather than hallucinated.
Does the buyer need an account?
No. They enter email (and accept NDA if you require it), then get access for as long as the pack is valid.
Audits
Can I run internal audits in the app?
Yes — plan an internal audit, assign auditors, capture findings, and raise corrective actions (CAPA). Available from the Growth plan upward.
Can I edit an internal audit after creating it?
Yes — open any audit from the Audits list to amend scope, reassign auditors, add findings, or update status.
Data
Can I export my data?
Yes — CSV and PDF exports are available across the main registers. No lock-in.
Agents & integrations
Can I connect ChatGPT, Claude or Cursor to my workspace?
Yes. ISO-STANDARD.app exposes an OAuth-protected MCP server at /mcp so AI clients can list organisations, risks, controls, policies, assets and tasks — and create risks — scoped to the signed-in user by your existing access rules. See /mcp-tools for the tool catalogue.
Support
How do I get help?
Email hello@iso-standard.app and we'll come back to you on the next business day.
Core workflows
Do I need one register per standard?
No. ISO-STANDARD.app maps each risk to every applicable standard (27001, 9001, 42001, SOC 2, GDPR) so one register serves them all.
What scoring scale should I use?
Use the built-in 1–5 likelihood × 1–5 impact scale. It matches ISO 31000 and the risk methodologies most enterprise buyers expect.
Can I bulk-import from a spreadsheet?
Yes — Import → CSV in the Risks page. Column headers match the export format so round-tripping is safe.
How do I show residual risk?
Set residual likelihood and impact after treatment. The register stores both inherent and residual scores and shows movement in the heatmap.
Who should own a risk?
A named individual with authority to act — not 'IT' or 'the CTO'. Buyers and auditors both flag generic ownership as a weakness.
Which control set should I start with?
ISO 27001:2022 Annex A is the widest. SOC 2 and NIST CSF crosswalk automatically, so you don't need to duplicate work.
How often should the SoA be reviewed?
At least annually and after any significant change (new product, new region, major incident).
Can I add custom controls?
Yes — add a bespoke control set with your own IDs and descriptions from Controls → Add framework.
Do I need to inventory every laptop?
For ISO 27001 you need to know which classes of device store what data. If MDM already covers device-level inventory, reference that system as the source of truth.
What about subprocessors?
Add subprocessors as asset type 'Third-party service'. The Trust Center automatically shows them under Subprocessors.
Can I bring my own policies?
Yes. Import Markdown or Word — the editor preserves structure. Set review dates and you're covered.
What about versioning?
Every save creates a version. You can diff and roll back at any time — auditors can see the full history.
Where is evidence stored?
In encrypted object storage inside your workspace. Only workspace members with the right role can read it.
What file types are supported?
PDF, DOCX, XLSX, PNG, JPG, CSV, TXT, and Markdown. Total per-file limit is 25 MB.
How do I go back into an existing audit?
Open Audits → click any audit card. From there you can edit scope, reassign auditors, add findings or reopen closed sections.
Can external auditors be given access?
Yes — invite them with a read-only role scoped to specific audits.
What is a good CAPA closure time?
Aim for 30 days for minor and 90 days for major, or per your management policy. What matters most to buyers is that you have a defensible cadence.
How often should we hold management reviews?
Annually is the minimum. Quarterly is the realistic cadence for a growing business.
Admin & org
Do consultant seats cost extra?
Each client workspace is one seat on the consultant plan; team members added inside a client workspace are additional seats.
Do you support SSO / SAML?
Yes on the Business plan (Google, Microsoft, Okta, generic SAML).
Can auditors access without a seat?
Yes — Auditor role is free and scoped to read-only for the audit period.
Can I use my own domain for evidence links?
Custom domain for Trust Center is available on the Business plan.
Standards playbooks
How long does certification take?
For a first-time SME, 12–20 weeks from start to Stage 2, plus the certifier's own scheduling.
What if I fail Stage 1?
Stage 1 finds gaps — that's its job. Findings become CAPAs; you close them before Stage 2.
Can 9001 and 27001 share the same management system?
Yes — that's an integrated management system (IMS). ISO-STANDARD.app is designed for exactly that.
Do we need ISO 42001 if we only use vendor AI?
Yes — you're still responsible for how you use it. Buyers ask the same questions regardless of build vs buy.
