
- ISO/IEC 27001
- ISO 9001
- GDPR
- Law 195/2024
- Law 48/2023
Every clause, with its evidence.
Axia turns every clause of a standard into controls and tests. The tests check themselves wherever the platform holds the data, so a company that passes every test it was given is covered, clause by clause.
No card needed for the trial. Interface in Romanian, English and Russian.
- tests in the library
- 536
- check themselves every day
- 190
- controls
- 216
- policy and procedure templates
- 45
Library as of September 2026. Every new organization receives it at creation.
From clause to evidence
Four links, each one visible. An auditor can follow the chain from either end.
Clause
Access rights
ISO/IEC 27001 A.5.18Each standard is loaded as its tree of clauses. Every clause in scope needs at least one control; the Statement of Applicability records the ones you exclude, and why.
Control
Periodic user access review
CTL-ACCESS-REVIEWWhat your company does about the clause: an owner, a frequency, the policy it follows. One control can answer several standards at once.
Test
Every account in the latest access review has a decision
TD-AUTO-ACCESS-REVIEW-DECIDEDPassing
How you prove it. Automated tests read the platform’s own records every day. The others recur on a schedule and ask for a document or a record.
Evidence
The completed review
Access register
The record the test read: each account, the decision taken on it, who took it and when. Kept with its date for the audit.
One test, several frameworks
TD-AUTO-MEMBERS-MFA, “Every member signs in with a second factor”, answers ISO/IEC 27001 A.8.5 and A.5.17, GDPR Art. 32 and Law 195/2024 Art. 32. You fix it once.
What is covered
Two management-system standards and three laws, each with its own codes, exactly as the source writes them.

ISO/IEC 270012022
Clauses 4 to 10 and the 93 controls of Annex A, with the Statement of Applicability, its snapshots and export.
6.1.3A.5.18A.8.13ISO 90012015
Clauses 4 to 10, with a full procedure pack: document control, internal audit, nonconformity, management review.
7.5.3§9.28.4.1GDPR(EU) 2016/679
The 99 articles in full, from EUR-Lex under CC BY 4.0, with the processing records, data-subject requests, breaches, DPIAs, transfers and retention.
Art. 28Art. 32Art. 33Law 195/2024Republic of Moldova
Personal data protection, in force since 23 August 2026. 90 articles by number and title; the authority is the CNPDCP.
Art. 28Art. 32Art. 33Law 48/2023Republic of Moldova
Cybersecurity, in force since 1 January 2025. The articles that bind service providers: security measures, incident notification and handling.
Art. 11Art. 12Art. 15
A law gets no percentage. An article cannot be excluded the way an Annex A control can, so the dashboard counts instead: how many articles have a healthy control linked to them.
Checks that run themselves
190 tests read data the platform already holds, every day. When one fails, it names what is missing and what to do.
Second factor. Every member and every directory account has MFA; the workspace requires it.
Dormant accounts. No enabled account unused past your limit, 90 days unless you change it.
Leavers. People who have left no longer hold access.
Access reviews. Every account in the latest review has a decision.
Training. No member’s required training has expired.
Backups. Critical systems are backed up on schedule and restores are tested.
Suppliers. Vendors are reviewed on schedule; those processing personal data have a DPA.
Breaches. Notifiable breaches reached the authority within 72 hours (GDPR Art. 33).
Internal audit. The audit programme is approved on time and covers every clause (§9.2).
Risks. Every open risk is fully assessed; residual risk above appetite is escalated.
Connectors
Microsoft Entra ID
Accounts, groups, MFA registration, last sign-in.
Google Workspace
Accounts, groups, 2-step verification, last sign-in.
SharePoint
Documents and evidence, kept in your own library.
The other tests recur on the interval you set, remind their owner, and wait for a record or a file.



The registers an audit asks for
Each register feeds the tests. Filling one in is what makes a test pass.

Risks
Your own methodology and appetite, treatment plans, owner sign-off.
Statement of Applicability
Exclusions only with a justification, snapshots, export.
Security incidents
Timelines, notifications, lessons and actions.
Legal register
Pre-filled with Moldovan acts, each with its obligation.
Customers
Complaints and satisfaction, for ISO 9001 §9.1.2.
Change requests
Approval, backup before risky changes, review.
Business continuity
BIA, RTO and RPO, call tree, exercises.
Suppliers
Weighted evaluation, re-evaluation after incidents.
Access
Reviews, and access to customer environments for service providers.
Assets
Owners and classification.
Internal audit
Programme, plans, checklists, findings.
Management review
Inputs and decisions, as §9.3 lists them.
Nonconformities
Cause, correction, effectiveness.
Training and competence
Plans, records, expiry, effectiveness.
Documents
Approval, versions, read-and-acknowledge.
Trust Center
A public page with what you choose to show customers.
Built in Moldova, for companies here and in the EU
The local law is not an add-on. It sits beside ISO and the GDPR, mapped the same way.

Law 195/2024 and the CNPDCP
Moldova’s personal data law, in force since 23 August 2026, is loaded as its own framework. Breach tests check the 72 hours under Art. 33 of both the GDPR and Law 195/2024.
Law 48/2023 on cybersecurity
Decide whether you are a covered service provider, and record why. Significant incidents are tracked against the notification duty in Art. 12.
A legal register already filled in
16 acts to start from: the Labour Code, accounting, archives, occupational safety, electronic identification, cybercrime and more.
Three languages, one meaning
Romanian, English and Russian carry the same sentence. Clause and article codes stay as the standard writes them.
Invoices in EUR
By bank transfer or card. VAT is applied by country; invoices are also available as UBL and CSV.

Your records stay yours
A compliance tool holds the evidence of how you protect data. It is built to the same standard.
Each organization is separated in the database itself, by Postgres row-level security.
A separate encryption key per organization for secrets and connector credentials.
Two-factor sign-in that an organization can make mandatory; single sign-on over OIDC.
An audit log of every change, and a full export or deletion when you ask.
See your own gaps in the first hour
Create the organization, pick the standards, connect your directory. The tests arrive with it.