Multi-tenant AI platform that automates SOC 2 / ISO 27001 compliance — policy generation, evidence evaluation, gap analysis, security-questionnaire answering, and vendor risk management.
Preparing for SOC 2 or ISO 27001 means rewriting policies, answering security questionnaires, evaluating evidence, and tracking vendor risk — slow, manual work spread across teams. Refine AI needed all of it automated inside a strictly isolated multi-tenant SaaS with subscription billing built in.
We built a Node.js + TypeScript backend that orchestrates a RAG-powered AI microservice: it ingests company policies, rewrites them into framework-aligned versions, maps questionnaire questions to the correct controls, and auto-drafts answers with confidence scores and human-review flags. Evidence is continuously scored against control areas to surface remediation gaps, and a full vendor risk module covers onboarding, automated scoring, certifications, incidents, and scheduled reviews.
frameworks automated: SOC 2 and ISO 27001
role-based access levels with strict tenant isolation
subscription billing and bank linking
AI policy ingestion with RAG vector embeddings and semantic control retrieval
AI policy rewriting into SOC 2 / ISO 27001-aligned versions, with versioning and review workflow
Security-questionnaire parsing, AI control-mapping, and auto-drafted answers with confidence scores
Evidence evaluation engine: compliance scoring, risk levels, and control-coverage analysis
Automated gap analysis and remediation tracking
Third-party vendor risk management: onboarding, risk scoring, certifications, incidents, and scheduled risk reviews
Compliance-readiness dashboards and reusable answer library
Multi-tenant architecture with strict tenant isolation and 7 role-based access levels
Stripe subscription billing with plans, webhooks, and Plaid bank-account linking
Real-time collaboration and progress updates via Socket.io / WebSocket
Secure document uploads to AWS S3 with presigned URLs and Excel/CSV import
JWT + Google OAuth authentication, hardened with Helmet, rate limiting, XSS and NoSQL-injection protection
Node.js 22 (ESM), Express.js, TypeScript, MongoDB (Mongoose), Vector Embeddings / RAG (via AI microservice), Socket.io + WebSocket (ws), AWS S3 (presigned URLs), Stripe, Plaid, Firebase Admin (FCM), Passport.js (Google OAuth + JWT), Joi, Winston, Swagger (OpenAPI), Helmet, express-rate-limit, xss-clean, express-mongo-sanitize, PM2, XLSX/CSV parsing
AI-Powered GRC / Compliance Automation SaaS
Node.js 22 + Express.js + TypeScript (ESM)
MongoDB (Mongoose)
RAG microservice + vector embeddings
SOC 2, ISO 27001
Socket.io + WebSocket
AWS S3 (presigned URLs)
JWT + Google OAuth (Passport)
Stripe + Plaid
Multi-tenant, 7 user roles