An obligation you didn't know applied
A regulation, contract clause, or buyer commitment that has been quietly in scope for months. Surfaced with jurisdiction, source, and the assumption it depends on.
Frank is the tool you run on yourself before the audit, the board, or the regulator — not the dashboard you show afterwards. It stamps a scope and an expiry date on your posture, with the named owners and the evidence that earned it — so the person who signs can stand behind what they signed.
Conditional posture holds until 2026-12-16. Identity Service and Incident Management are the binding constraints.
Reading this: confidence is the probability the posture still holds at the decay date. Signals are the individual checks contributing to it.
Most GRC tools optimise for the moment a certificate issues. Frank optimises for the eleven months in between — when posture decays, ownership drifts, and evidence quietly goes stale. The problem is not your team. It is a category built to manufacture confidence.
The coverage assertion is the artefact Frank exists to produce — we stand behind this posture, for this scope, until this date, on this evidence. Every claim links to its obligations, commitments, control reality, and known limitations, so you hand a regulator a credential, not a slide deck.
A regulator, insurer, or buyer verifies provenance — not just trust the publisher. Aligned with verifiable credentials and assurance levels.
Obligation to verifiable claim, without inventing what you don't have. One shape across the platform — same four layers, same expiries, same ownership rules wherever assurance is asserted. Each layer adds explicit structure to the next. Confidence is time-bounded; exceptions are governed; evidence has lineage. Nothing renews itself silently.
Regulations, contracts, and commitments that bind you. Scope, jurisdiction, and the assumptions you're standing on — named.
Obligations translated into commitments your organisation actually made — to customers, regulators, your board — with named owners.
How each commitment is met in practice. Effectiveness, fragility, dependency risk. Exceptions are first-class, not hidden.
Machine-consumable trust signals linked to obligations, evidence lineage, scope, and known limitations. Renewable. Auditable.
Four things Frank looks for in your first week. None of them require an enterprise contract — and none of them are flattering.
A regulation, contract clause, or buyer commitment that has been quietly in scope for months. Surfaced with jurisdiction, source, and the assumption it depends on.
A backup system, an upstream feed, a vendor — load-bearing but un-owned. Frank treats unowned dependencies as first-class objects, not footnotes.
The thing a control implicitly trusts: a tenancy boundary, a key rotation, an SLA. Once named, it stops being silent and starts being defensible.
A treatment marked complete that stalled months ago. An acceptance whose review window lapsed. Frank surfaces the contradiction between what you recorded and what the evidence shows — before an auditor does.
Most registers record what you told them: scores you assigned, residuals you declared, a heat map that turns a guess into a coloured square. Frank reads risk as a read-only lens over the canonical model — every risk domain materialises from the obligations, decisions, debts, and assumptions already under assurance, and lights up where the register and the incidents beneath it diverge: a stalled treatment, an acceptance whose review window has lapsed, a residual reduction the incident record disproves. You do not curate it. It resolves to the same coverage assertion as everything else Frank publishes — with one named authority standing behind it.
No credit for self-reports. The register materialises from the model, or it does not exist. These refusals are the difference — not gaps we apologise for.
Commitments encoded into the product. None are subject to renegotiation by sales.
One canonical shape across the platform — obligation, commitment, control reality, claim. Each layer has named owners, scoped assumptions, and an expiry. Confidence is a window, not a stamp.
Surfacing gaps, fragility, and dependency risk is the point — not a failure mode. Frank exists to make things uncomfortable enough to act on.
No anonymous controls. A named accountable owner per commitment, with contributors and dependencies made explicit.
We reject "one-click compliance" and AI-powered maturity scores. Discomfort you can act on beats reassurance you cannot.
Frank is a tool you run on yourself. It is not an auditor, not a certifier, and not a shortcut to either — and the boundaries that keep it that way are structural, not policy. They are why a posture produced in Frank is one you can defend.
Frank grades no maturity and issues no pass. It is the dress rehearsal you run before the audit, the attestation, or the assessment — never a substitute for them.
Evidence stays in the systems that produce it. Frank references it with lineage and stores none of it — there is no second copy to secure, and no incentive for us to hoard your data.
If the evidence does not support the claim, Frank will not publish the claim. That is not a limitation. That is the product working.
No auditor, assessor, or consultant is paid, given quotas, or otherwise incentivised to recommend Frank. Nobody who certifies you can also sell you Frank.
The free tier won't certify you, score you, or reassure you. It will tell you what's actually true about your scope. That's where useful work begins.
We turn buyers away. It saves both of us a renewal.