AI Compliance Engineer · SOC 2 · ISO 27001 · ISO 42001

Your compliance platform finds the gaps. We close them.

For startups on Vanta, Drata, TrustCloud, or Secureframe without a security team to spare. Every failing control becomes a ready-to-approve pull request or ticket — with auditor-ready before-and-after evidence.

Read-only access to your environment, working continuously between audits. Every change ships as a pull request or ticket that your team approves.

Integrates with
  • VVanta
  • DDrata
  • SSecureframe
  • TTrustCloud
  • SSprinto
  • SScytale
  • TThoropass
  • HHyperproof
  • OOneTrust
  • AAuditBoard
  • AAnecdotes
  • CComp AI

The problem

Compliance platforms are excellent at telling you what’s broken. Someone still has to fix it.

Every red test in your dashboard becomes an engineering task nobody planned for — pulled from your roadmap, or billed by the hour by a consultant.

Finding

Your platform flags it

“MFA not enforced.” “Branch protection disabled.” “Access review overdue.” The dashboard turns red and stays red.

Reality

Your engineers park it

Compliance fixes compete with the product roadmap and lose. The alternative is paying consultants by the hour to chase your team with checklists.

Deadline

Your audit doesn’t move

The observation window closes whether the gaps are fixed or not. What’s left is a scramble — and evidence assembled at the last minute.

Your compliance platform flags the gap and stops there. Even its AI agent won’t open the Terraform PR in your AWS, the ticket in your Jira, or the fix in your GitHub. IOthreat does — and keeps doing it continuously between audits, so you stay ready instead of scrambling.

How it works

From red finding to merged fix, with your approval in the middle

It runs continuously, not just at audit time — new findings become fix PRs as they appear, so your posture stays green between audits.

Connect

We read the failing tests from your compliance platform and connect to your stack — AWS, GitHub, GitLab, Jira, Linear — with read-only credentials.

Plan

Each gap is mapped across every framework you run. One fix often closes the same control in SOC 2, ISO 27001, and ISO 42001 at once.

Fix, as a PR

The engineer opens pull requests and tickets with the exact change, the reason, and the control it closes. Nothing touches production until your team approves.

Prove

Before-and-after evidence is captured for every change and written back to your platform, mapped to the control — ready for your auditor.

What it fixes

The gaps that show up in almost every audit

Built from six years of preparing startups for SOC 2 and ISO audits — starting with the findings that appear on nearly every gap report.

Public storage buckets

Block public access on S3 buckets holding customer data, via a Terraform or console-config PR.

CC6.1A.8.3

Branch protection

Enforce reviews, status checks, and force-push protection on production repositories.

CC8.1A.8.32

MFA enforcement

Require MFA across your identity provider, cloud console, and code hosting — and prove it.

CC6.1A.5.17

Stale access & offboarding

Find accounts that should have been closed, open the removal tickets, and document the review.

CC6.2A.5.18

Key rotation & logging

Rotate long-lived IAM keys, switch on CloudTrail and retention, and encrypt what isn’t encrypted.

CC6.8A.8.15

Policies & AI governance

Draft the missing policies from your real configuration — including ISO 42001 AI-management controls.

ISO 42001A.5.1

Control references are representative examples (SOC 2 Trust Services Criteria and ISO 27001:2022 Annex A). Every remediation is mapped to your actual framework scope during onboarding.

Integrations

Reads from your compliance platform. Acts across your stack.

Reads findings from

Your compliance platform

VantaDrataSecureframeTrustCloudSprintoScytaleThoropassHyperproofOneTrustAuditBoardAnecdotesComp AI

Opens PRs & tickets in — via MCP or API

Your engineering stack

Cloud & infrastructure

AWSGoogle CloudAzureCloudflareTerraform

Code & CI

GitHubGitLabBitbucket

Work tracking

JiraLinearAsanaClickUp

Identity & access

OktaGoogle WorkspaceMicrosoft Entra ID1Password

Security & operations

DatadogSentrySnykPagerDutySlackJamf

IOthreat is an independent solution and is not affiliated with or endorsed by the platforms listed. All product names are trademarks of their respective owners.

Guardrails

Built for a market that has learned to distrust “AI compliance”

Automation you can put in front of an auditor — because every action is real, reviewed, and documented.

Read-only by default

We never hold write access to your production environment. Changes are proposed, not pushed.

A human approves every change

Your team reviews and merges each PR and ticket. The approval itself becomes part of the evidence trail.

No fabricated evidence, ever

If a control isn’t actually implemented, it stays red. We fix the control — we don’t decorate the dashboard.

Auditor-grade trail

Every change is logged with its before state, after state, approver, and the exact control it closes.

Let’s close your gaps — starting with your live report.

A 30-minute walkthrough: we look at your current findings together and show you which we’d close first.

Book a gap-closing walkthrough

Premium tier

Compliance-as-Code: your environment, imported to Terraform

For teams running click-ops infrastructure, we import your AWS environment into version-controlled Terraform. From then on, every remediation is a reviewable plan — you see exactly what changes before anything does, and your infrastructure history becomes part of your evidence.

Uri Fleyder-Kotler

Uri Fleyder-Kotler

Founder & CISO, IOthreat

CISSP16+ yrs security9 patents

Who’s behind it

Built by the person your auditor already knows

IOthreat isn’t a demo built by outsiders to security. It’s the work of a practitioner with 16+ years across both sides of cybersecurity — from adversarial research at RSA to leading security as a CISO — now taking startups through SOC 2, ISO 27001, and ISO 42001. The product does the engineering; an experienced CISO stands behind the judgment.

More about Uri →

FAQ

Questions teams ask before their first walkthrough

How is this different from Vanta or Drata’s own AI agent?

Those agents work inside their own platform — drafting policies, answering questionnaires, flagging failing controls. They won’t open the Terraform PR in your AWS, the ticket in your Jira, or the fix in your GitHub. IOthreat does that remediation work across your stack, and keeps doing it continuously.

What access do you need to my environment?

Read-only, on the basis you configure. We never hold write access to production. Every change is proposed as a pull request or ticket that your team reviews and approves before anything is applied.

Will an auditor accept the evidence?

Yes — that’s the point. Every change is logged with its before state, after state, approver, and the exact control it closes, and written back to your compliance platform. Nothing is fabricated: if a control isn’t actually implemented, it stays red until it’s fixed.

How fast do we see value?

We start from your live gap report and open the first fix PRs within days. A full gap backlog is typically 40–100 hours of remediation work per audit — handled for you.

How is this different from hiring a consultant?

A consultant chases your team with a checklist and bills by the hour. IOthreat does the engineering itself, continuously, for a flat subscription — with a CISO standing behind the judgment. It replaces the consulting and DevOps time, not adds to it.

Which frameworks and tools do you support?

SOC 2, ISO 27001, and ISO 42001 today, read from Vanta, Drata, TrustCloud, Secureframe and more. We act across AWS, GitHub, GitLab, Jira, Linear, and the rest of a typical startup stack via API or MCP.

Founding customer program

Be one of the first teams whose gaps close themselves

We’re onboarding just a handful of founding customers this quarter, ahead of general availability. You get founding pricing locked in for good, direct access to the founder — a CISO who’s taken startups through these audits — and a say in what we build next.

from $500/moFounding plan · locked in for life
10–20 hrs/moEngineering hours you get back

Typical estimates that scale with your environment — a full gap backlog is 40–100 hours of remediation work per audit, plus the recurring evidence that comes due between them, handled for you. Your free scan reports the exact figures for your own environment before you commit to anything.

We reply within one business day. A 30-minute call: we look at your live gap report together and show you which findings we’d close first.