ISMS Copilot
US

ISMS Copilot for US Compliance Teams

SOC 2, HIPAA, NIST, and CMMC. Built for US compliance teams.

ISMS Copilot billboard in Austin: 'If it retains your data forever, shall you trust it for compliance? With us, you can choose privacy.'

What the US Copilot Can Do

SOC 2 Type I and Type II readiness with Trust Services Criteria mapping

HIPAA Security and Privacy Rule guidance (policy drafting only: no ePHI in chats, no BAA)

NIST CSF 2.0, NIST 800-53, and NIST 800-171 / CMMC Level 1 and Level 2 documentation

CCPA / CPRA workflows, with a cross-map to GDPR when you also sell into the EU

Cross-framework mapping ISO 27001, SOC 2, and NIST so you implement once and report many

The same workspace also covers GLBA, PCI DSS, HITRUST, FERPA, FISMA, and SOX ITGC

About ISMS Copilot for US Compliance Teams

ISMS Copilot for US Compliance Teams is the specialist assistant for the frameworks US organizations actually run: SOC 2 Type I and Type II, the HIPAA Security and Privacy Rules, NIST CSF 2.0, NIST 800-53, NIST 800-171 and CMMC, and CCPA / CPRA. Draft the policies, map the controls, and prepare the audit pack in one workspace.

Cross-framework mappings

Working across US and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

Which US frameworks does it support?

Specialist coverage for SOC 2, HIPAA, NIST CSF 2.0, NIST 800-53, NIST 800-171 / CMMC, CCPA / CPRA, and the rest of the NIST family (AI RMF, 800-207, 800-218, 800-66 R2, Privacy Framework, FedRAMP). General guidance for HITRUST CSF, FERPA, FISMA, GLBA, and SOX ITGC. Cross-mapping to ISO 27001 and GDPR when you run those programs too.

Where is my data hosted?

Database and document storage live in Frankfurt. AI processing is your choice: Mistral in the EU with zero retention, or Anthropic in the US under standard contractual clauses. That choice is independent of HIPAA: we do not sign a BAA and you must not paste PHI, whichever inference region you pick. See /coverage for the full split.

Is ISMS Copilot a HIPAA Business Associate?

No. ISMS Copilot is a guidance and policy-drafting tool, not a HIPAA Business Associate. We do not sign BAAs and you must not paste protected health information (PHI or ePHI) into chats. Use the Copilot to draft policies, prepare risk analyses, and understand HIPAA requirements. Keep ePHI in your dedicated HIPAA-compliant systems.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.