ISMS Copilot for US Compliance Teams
SOC 2, HIPAA, NIST, and CMMC. Built for US compliance teams.

What the US Copilot Can Do
SOC 2 Type I and Type II readiness with Trust Services Criteria mapping
HIPAA Security and Privacy Rule guidance (policy drafting only: no ePHI in chats, no BAA)
NIST CSF 2.0, NIST 800-53, and NIST 800-171 / CMMC Level 1 and Level 2 documentation
CCPA / CPRA workflows, with a cross-map to GDPR when you also sell into the EU
Cross-framework mapping ISO 27001, SOC 2, and NIST so you implement once and report many
The same workspace also covers GLBA, PCI DSS, HITRUST, FERPA, FISMA, and SOX ITGC
About ISMS Copilot for US Compliance Teams
ISMS Copilot for US Compliance Teams is the specialist assistant for the frameworks US organizations actually run: SOC 2 Type I and Type II, the HIPAA Security and Privacy Rules, NIST CSF 2.0, NIST 800-53, NIST 800-171 and CMMC, and CCPA / CPRA. Draft the policies, map the controls, and prepare the audit pack in one workspace.
Who it's for
US SaaS startups
SOC 2 readiness and CCPA for Series A founders chasing enterprise deals.
US healthcare
HIPAA documentation and Security Rule mapping. Guidance only: no BAA, no PHI in chats.
US federal contractors
NIST 800-171 and CMMC Level 1 / Level 2 documentation. Not for storing CUI itself.
US CPAs and SOC 2 audit firms
SOC 2 readiness and attestation engagements. AICPA, SSAE 18, Trust Services Criteria.
US fintech
SOC 2 plus PCI DSS plus the GLBA Safeguards Rule, written once.
Cross-framework mappings
Working across US and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.
Browse free mappingsFrequently Asked Questions
Which US frameworks does it support?
Specialist coverage for SOC 2, HIPAA, NIST CSF 2.0, NIST 800-53, NIST 800-171 / CMMC, CCPA / CPRA, and the rest of the NIST family (AI RMF, 800-207, 800-218, 800-66 R2, Privacy Framework, FedRAMP). General guidance for HITRUST CSF, FERPA, FISMA, GLBA, and SOX ITGC. Cross-mapping to ISO 27001 and GDPR when you run those programs too.
Where is my data hosted?
Database and document storage live in Frankfurt. AI processing is your choice: Mistral in the EU with zero retention, or Anthropic in the US under standard contractual clauses. That choice is independent of HIPAA: we do not sign a BAA and you must not paste PHI, whichever inference region you pick. See /coverage for the full split.
Is ISMS Copilot a HIPAA Business Associate?
No. ISMS Copilot is a guidance and policy-drafting tool, not a HIPAA Business Associate. We do not sign BAAs and you must not paste protected health information (PHI or ePHI) into chats. Use the Copilot to draft policies, prepare risk analyses, and understand HIPAA requirements. Keep ePHI in your dedicated HIPAA-compliant systems.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
