Continuous compliance, reviewed by humans

Hold the line on every framework, without holding the line on your calendar.

Oathwright scans your contracts, policies, access logs and vendor agreements every day, maps each artifact to HIPAA, SOC 2, PCI DSS, GDPR and the US state privacy stack, and pre-builds the evidence package auditors expect. Reviewed by former Big-Four auditors before anything reaches your inbox.

$2K – $20K / month· HIPAA · SOC 2 · PCI DSS · GDPR · all 50 state privacy laws · 7-day stand-up

Mapped and maintained continuously

  • HIPAA
  • SOC 2
  • PCI DSS
  • GDPR
  • HITRUST
  • ISO 27001
  • CCPA / CPRA
  • VCDPA
  • CPA
  • CTDPA
  • UCPA
  • Texas DPA

Why Oathwright

Continuous evidence, written to the standard auditors actually apply.

Mid-market healthcare and financial-services teams are juggling four or more frameworks at once — and an audit failure rarely comes from a missing policy. It comes from a stale control, an unflagged rule change, or an evidence package that doesn’t survive scrutiny. Oathwright is built around what auditors test, not what compliance software historically has covered.

01

Continuous scan across every artifact.

Contracts, HR policies, vendor agreements, access logs and data-handling practices are pulled in daily, mapped against the frameworks you actually face, and scored against current control expectations. Gaps surface weeks — not during fieldwork.

02

Evidence packages, pre-assembled.

For every gap the platform flags, Oathwright produces the artifact, the control mapping, and the citation an auditor expects to see. Your team reviews and approves; you stop writing evidence the week before the engagement starts.

03

Rule changes in plain English.

The regulatory radar lands every covered rule the day it publishes — what changed, which controls it touches, and what action it implies, written for the compliance lead, not the privacy lawyer who already reads the Federal Register.

The regulatory radar

Every covered rule, the day it lands — in plain English.

Fed Register entries, state AG pronouncements, EU guidance — surfaced the same day with an assessed impact on your existing controls and a draft remediation plan. Compliance leads stop being the last people in the company to find out.

  • Plain-English summary first. Technical citations and the affected framework references follow, so you can route to legal or take action yourself.
  • Affected controls highlighted, by framework. The radar shows which of your mapped controls shift — and which evidence gaps change priority.
  • Drafted remediation, pre-reviewed. Every radar alert arrives with a proposed remediation plan that has already cleared an in-house reviewer.
HHS OCREDPBSTATE AGsPCI SSC
Sweep · live · 9s cycle
9 active alerts ·17 monitored

The evidence engine

Pre-built evidence packages, not week-of-audit scrambles.

Every flagged gap arrives with the artifact, the control mapping, the underlying rule citation, and the reviewer who signed off. Pull a package at any time — your team reviews and approves, and your auditor sees the same artifact set in their read-only workspace.

  1. CITED

    A cited rule, by section, by jurisdiction — never paraphrased.

  2. MAPPED

    A control mapping that traces cleanly back to the cited rule.

  3. EVIDENCED

    An artifact — log line, policy version, vendor contract clause — that proves the control is operating.

  4. REVIEWED

    A reviewer name from the in-house auditing team, recorded on the output.

package · soc2-type2 · q3-engagement

ready

/evidence · CC6.1

├ access-policy-v7.pdf

├ quarterly-access-review.csv

├ mfa-enforcement-config.json

├ privileged-role-roster.csv

├ reviewer-signoff.md

└ citation.md ✦ review-ready

Cited rule · Common Criteria 6.1

“The entity implements logical access security software, infrastructure, and architectures over protected information assets.”

Source

AICPA TSC 2017 (rev. 2022)

Reviewer

J. Patel · former EY

Why this matters

The quarterly-access-review CSV and privileged-role-roster together prove the control is operating — not just that a policy exists. Both surfaced automatically from your existing tools.

Trust & review

Reviewed by humans who know what auditors look for.

Every recommendation that reaches you has been read by an in-house former Big-Four auditor or healthcare privacy specialist. That is the trust bar the rest of the segment does not clear — and the reason cards stay closed once Oathwright is the system of record for evidence.

J. Patel

Former EY

SOC 2 · ISO 27001

A. Reyes

Former Deloitte

PCI DSS · HITRUST

M. Chen

Former HHS OCR

HIPAA · state privacy

S. Okafor

Former EDPB

GDPR · DPA

R. Kurtz

Former PwC

SOC 2 · vendor risk

Pricing

A fraction of a fractional consultant.

$2K – $20K / month, sized to your framework count, employee range, and audit calendar — versus the $50K – $200K / year a fractional compliance consultant typically bills out.

Below the cost of a single fractional consultant.

A continuous platform replaces the work of three to five fractional roles — and the TCO falls further each audit cycle you don’t start from zero.

Foundation

$2K – $5K / mo

Single framework, single entity

  • Up to 250 employees
  • One framework (HIPAA or SOC 2)
  • Continuous evidence collection
  • Quarterly rule-change briefings

Multi-framework

$6K – $14K / mo

Stacked frameworks, one entity

  • 250 – 1,500 employees
  • Up to 4 frameworks
  • Pre-built evidence packages
  • Monthly Big-Four-led review

Enterprise

$15K – $20K / mo

Multi-entity, multi-framework

  • 1,500+ employees or multi-entity
  • Unlimited frameworks, all 50 states
  • Inline auditor workspace
  • Same-day reviewer escalation

Procurement FAQ

The questions your CFO and General Counsel will ask first.

Speak to us — we’ll send a procurement packet with the security questionnaire, BAA/DPA templates, and a sample evidence package reviewed by in-house counsel.

Email oathwright-3@polsia.app

Get started

See your first audit-ready evidence package in 30 days.

We start with a 25-minute walk-through of your framework stack and audit calendar. On a mutual fit, the first scan lands within 7 business days — and a signed evidence review is queued the same week.

Email oathwright-3@polsia.app · BAA + DPA signed within one business day · procurement packet on request.