Openlane DocumentationFrameworks, controls, and evidence in one platform. Automate the repetitive work, drop the spreadsheets, and run SOC 2 through ISO 27001 with the same set of objects.
Start here
Explore by area
GovernanceWho decides, and how is it enforced?POLICIES · APPROVALS
PERMISSIONSRisk ManagementWhat could hurt us, and what are we doing about it?RISK REGISTER
EXPOSUREComplianceAre we meeting our obligations, and can we prove it?CONTROLS · EVIDENCE
PROGRAMSGRC FundamentalsThe concepts behind the product: what GRC is, how laws, regulations, and frameworks differ, and how to prepare for an audit.Law vs. regulation vs. frameworkAnatomy of a controlHow to prepare for an audit
PERMISSIONSRisk ManagementWhat could hurt us, and what are we doing about it?RISK REGISTER
EXPOSUREComplianceAre we meeting our obligations, and can we prove it?CONTROLS · EVIDENCE
PROGRAMSGRC FundamentalsThe concepts behind the product: what GRC is, how laws, regulations, and frameworks differ, and how to prepare for an audit.Law vs. regulation vs. frameworkAnatomy of a controlHow to prepare for an audit
FRAMEWORK PROGRESS141 CONTROLSSOC 261/66ISO 2700159/93HIPAA21/54Compliance ManagementPolicies, controls, evidence, and programs in one place — mapped across every framework you pursue.Build your first programMap controls to frameworksCollect and review evidence
ASSETS312VENDORS61PERSONNEL148prod-us-east · RDS clusterIN SCOPEdesign-sandbox · FigmaOUT OF SCOPERegistryThe system of record for what you operate: platforms, assets, vendors, personnel, and contacts.Model your platformsVendor tiering and reviewsDefine compliance scope
OPEN EXPOSURE4 CRITICALVULNERABILITIES6FINDINGS161RISKS11ExposureScans, vulnerabilities, findings, and remediations feed your risk register, so security work and risk decisions stay connected.Connect a scannerTriage findingsScore and treat risks