Policy and compliance knowledge base · AI with MCP

Your policy and compliance documents, linked like a knowledge base.

Keep policies, standards, registers and evidence connected in one governed place. Search across them, ask questions with cited answers, control every change and prepare only the evidence a reviewer needs.

Monday, 09:00 · Seventy questions, one deadline
Monday, 09:00 · Seventy questions, one deadline

One connected place for the work behind compliance

Find every relevant word

Search across policies, registers, headings and tables.

Ask with company context

Get answers from your governed documents, with sources.

Follow every connection

See which policies, controls and registers depend on each other.

Build clean evidence packs

Share selected PDF or Markdown packs without internal notes.

Give the right access

Keep editors, viewers and external reviewers within their scope.

Trace every change

Keep versions, owners, review dates and change reasons visible.

Monday, 09:00 · Supplier review

Friday’s customer call starts on Monday morning.

Seventy questions, due Friday, and the customer will not sign until the answers come back. Two colleagues have already answered parts of it from memory. A third pasted the question into a chatbot and sent Lea a confident paragraph about a rule the company does not have. Every helpful answer now needs checking, and the checking is her week.

  • Which version is the real one?
  • What may leave the company?
  • Where did this answer come from?

The shortcut everyone takes

A general AI will answer anything. It just does not know your company.

Asked in a general chatbot

The reply reads well and sounds certain. It describes how a company like yours usually handles access reviews. It does not know your rule, your version, your owner or what you already told this customer last year. Someone still has to verify every line before it can be sent.

Asked inside your own documents

The same question is answered from the policies your company actually maintains, and the answer names the documents it used. Lea opens the wording, sees who owns it and when it was last reviewed, and forwards it. The verification is the answer, not a second job.

Tuesday, 10:15 · She stops rebuilding
Tuesday, 10:15 · She stops rebuilding

The same question, asked once, kept once.

Lea works from one governed set of documents instead of a folder of near-identical copies. Each policy carries an owner, a version, a status and a review date, and links to the standards and registers it depends on. When one rule changes, everything connected to it changes with it.

  • Owners, versions and review dates stay visible
  • Linked policies, standards and registers
  • One maintained answer instead of five copies

This is what Lea used on Tuesday and Wednesday

Open a linked policy, ask a question and see its source, then build a shareable pack. Sample data.

vault.iqu-erion.com

POL-01

Information security policy

Owner:
Head of Security
Version:
3.2
Status:
Published
#iso27001#governance
3.2Version
2Open comments
Safe to share

This policy sets how information is classified, handled and protected. It applies to all staff, contractors and systems.

Roles and approval authority are held in the role register and referenced here, not repeated. See .

Access is granted on least privilege and reviewed quarterly. The review procedure is defined in .

Retention periods are defined per data category in and are binding for all systems.

Linked sources:

Wednesday, 14:40 · The answer shows its source
Wednesday, 14:40 · The answer shows its source

She can see where the answer came from.

The assistant answers from the company’s own documents and names them. Lea opens the exact wording, confirms it is current and moves on. Her colleagues can do the same without routing every question back through her, which is the part that used to eat the afternoons.

  • Answers cite the documents behind them
  • Read-only: no silent changes to a policy
  • Colleagues stop queueing at Lea’s desk
Thursday, 16:00 · The pack leaves clean
Thursday, 16:00 · The pack leaves clean

What goes out is exactly what should go out.

Lea selects the evidence the reviewer asked for and builds the pack as PDF or Markdown. Internal notes, names and revision history stay inside. Nothing needs to be recalled on Friday morning because something slipped into the export.

  • Select documents, build a PDF or Markdown pack
  • Restricted notes excluded from exports
  • One hand-off instead of a clean-up round
Lea and an IT colleague working through hosting boundaries on a marked-up whiteboard

Thursday, 11:00 · IT joins the thread

Then IT asks where all of this actually runs.

It is a fair question and it usually stalls a project for a fortnight. Here it takes one meeting: Lea and IT record where the instance runs, who operates it and which location governs the data. Three answers, all defensible, none of them assumptions.

Your infrastructure

Your environment, your location.

Self-hosted

Switzerland

A dedicated instance managed by us.

Managed

Required region

A dedicated instance in the agreed location.

Managed

Friday, 15:00 · The customer call

Lea at her desk on Friday, looking up with a small knowing smile
Friday, 15:00 · Nothing left to reconstruct

The call is about the customer’s decision, not about Lea’s week.

The answers are traceable, the pack went out on Thursday and the next review is already in the system. Lea explains the evidence, the customer asks two follow-ups, and both are answered from the source while they are still on the call. Nobody is waiting on her tonight.

Which request is holding up your next decision?

Bring the assessment, the audit request or the IT question. We will map the evidence and the next hand-off with you.