Skip to content
A monumental concrete letter A at night, lit from within, with a mint light across its crossbar.
  • ISO/IEC 27001
  • ISO 9001
  • GDPR
  • Law 195/2024
  • Law 48/2023

Every clause, with its evidence.

Axia turns every clause of a standard into controls and tests. The tests check themselves wherever the platform holds the data, so a company that passes every test it was given is covered, clause by clause.

No card needed for the trial. Interface in Romanian, English and Russian.

tests in the library
536
check themselves every day
190
controls
216
policy and procedure templates
45

Library as of September 2026. Every new organization receives it at creation.

From clause to evidence

Four links, each one visible. An auditor can follow the chain from either end.

  1. Clause

    Access rights

    ISO/IEC 27001 A.5.18

    Each standard is loaded as its tree of clauses. Every clause in scope needs at least one control; the Statement of Applicability records the ones you exclude, and why.

  2. Control

    Periodic user access review

    CTL-ACCESS-REVIEW

    What your company does about the clause: an owner, a frequency, the policy it follows. One control can answer several standards at once.

  3. Test

    Every account in the latest access review has a decision

    TD-AUTO-ACCESS-REVIEW-DECIDED

    Passing

    How you prove it. Automated tests read the platform’s own records every day. The others recur on a schedule and ask for a document or a record.

  4. Evidence

    The completed review

    Access register

    The record the test read: each account, the decision taken on it, who took it and when. Kept with its date for the audit.

One test, several frameworks

TD-AUTO-MEMBERS-MFA, “Every member signs in with a second factor”, answers ISO/IEC 27001 A.8.5 and A.5.17, GDPR Art. 32 and Law 195/2024 Art. 32. You fix it once.

What is covered

Two management-system standards and three laws, each with its own codes, exactly as the source writes them.

Sheets of glass stacked in layers, their edges lit mint against violet.
  • ISO/IEC 270012022

    Clauses 4 to 10 and the 93 controls of Annex A, with the Statement of Applicability, its snapshots and export.

    6.1.3A.5.18A.8.13

  • ISO 90012015

    Clauses 4 to 10, with a full procedure pack: document control, internal audit, nonconformity, management review.

    7.5.3§9.28.4.1

  • GDPR(EU) 2016/679

    The 99 articles in full, from EUR-Lex under CC BY 4.0, with the processing records, data-subject requests, breaches, DPIAs, transfers and retention.

    Art. 28Art. 32Art. 33

  • Law 195/2024Republic of Moldova

    Personal data protection, in force since 23 August 2026. 90 articles by number and title; the authority is the CNPDCP.

    Art. 28Art. 32Art. 33

  • Law 48/2023Republic of Moldova

    Cybersecurity, in force since 1 January 2025. The articles that bind service providers: security measures, incident notification and handling.

    Art. 11Art. 12Art. 15

A law gets no percentage. An article cannot be excluded the way an Annex A control can, so the dashboard counts instead: how many articles have a healthy control linked to them.

Checks that run themselves

190 tests read data the platform already holds, every day. When one fails, it names what is missing and what to do.

  • Second factor. Every member and every directory account has MFA; the workspace requires it.

  • Dormant accounts. No enabled account unused past your limit, 90 days unless you change it.

  • Leavers. People who have left no longer hold access.

  • Access reviews. Every account in the latest review has a decision.

  • Training. No member’s required training has expired.

  • Backups. Critical systems are backed up on schedule and restores are tested.

  • Suppliers. Vendors are reviewed on schedule; those processing personal data have a DPA.

  • Breaches. Notifiable breaches reached the authority within 72 hours (GDPR Art. 33).

  • Internal audit. The audit programme is approved on time and covers every clause (§9.2).

  • Risks. Every open risk is fully assessed; residual risk above appetite is escalated.

Connectors

  • Microsoft Entra ID

    Accounts, groups, MFA registration, last sign-in.

  • Google Workspace

    Accounts, groups, 2-step verification, last sign-in.

  • SharePoint

    Documents and evidence, kept in your own library.

The other tests recur on the interval you set, remind their owner, and wait for a record or a file.

A server corridor at night, lines of mint and violet light running along the floor.
Screenshot of Axia: the automated test “No enabled account has gone unused past the dormancy limit”, failing with the explanation “3 of 8 do not meet the requirement”, checked automatically every day. Below it, the Evidence tab lists the eight Microsoft 365 accounts it checked: three unused for a long time, five with a recent sign-in.
An automated test in the app: the Evidence tab shows every account it checked, not only the ones that fail. Screenshot of Axia, with an example company and accounts.

The registers an audit asks for

Each register feeds the tests. Filling one in is what makes a test pass.

Shelves of violet and white binders, one of them mint.
  • Risks

    Your own methodology and appetite, treatment plans, owner sign-off.

  • Statement of Applicability

    Exclusions only with a justification, snapshots, export.

  • Security incidents

    Timelines, notifications, lessons and actions.

  • Legal register

    Pre-filled with Moldovan acts, each with its obligation.

  • Customers

    Complaints and satisfaction, for ISO 9001 §9.1.2.

  • Change requests

    Approval, backup before risky changes, review.

  • Business continuity

    BIA, RTO and RPO, call tree, exercises.

  • Suppliers

    Weighted evaluation, re-evaluation after incidents.

  • Access

    Reviews, and access to customer environments for service providers.

  • Assets

    Owners and classification.

  • Internal audit

    Programme, plans, checklists, findings.

  • Management review

    Inputs and decisions, as §9.3 lists them.

  • Nonconformities

    Cause, correction, effectiveness.

  • Training and competence

    Plans, records, expiry, effectiveness.

  • Documents

    Approval, versions, read-and-acknowledge.

  • Trust Center

    A public page with what you choose to show customers.

Built in Moldova, for companies here and in the EU

The local law is not an add-on. It sits beside ISO and the GDPR, mapped the same way.

Vineyard hills in Moldova at dawn, mist in the valleys and a line of light on the horizon.
  • Law 195/2024 and the CNPDCP

    Moldova’s personal data law, in force since 23 August 2026, is loaded as its own framework. Breach tests check the 72 hours under Art. 33 of both the GDPR and Law 195/2024.

  • Law 48/2023 on cybersecurity

    Decide whether you are a covered service provider, and record why. Significant incidents are tracked against the notification duty in Art. 12.

  • A legal register already filled in

    16 acts to start from: the Labour Code, accounting, archives, occupational safety, electronic identification, cybercrime and more.

  • Three languages, one meaning

    Romanian, English and Russian carry the same sentence. Clause and article codes stay as the standard writes them.

  • Invoices in EUR

    By bank transfer or card. VAT is applied by country; invoices are also available as UBL and CSV.

A closed steel vault door with a mint light along its edge.

Your records stay yours

A compliance tool holds the evidence of how you protect data. It is built to the same standard.

  • Each organization is separated in the database itself, by Postgres row-level security.

  • A separate encryption key per organization for secrets and connector credentials.

  • Two-factor sign-in that an organization can make mandatory; single sign-on over OIDC.

  • An audit log of every change, and a full export or deletion when you ask.

How security works

See your own gaps in the first hour

Create the organization, pick the standards, connect your directory. The tests arrive with it.