Release Notes

Product News: Controls, Frameworks, the Auditor Portal, and Cloud Posture Checks

Adopt controls, map them to frameworks, give auditors a scoped portal, manage vendors, and let cloud posture checks and AI evidence collection test your controls for you.

Concord Team · Published Wed Sep 23 2026

Product News: Controls, Frameworks, the Auditor Portal, and Cloud Posture Checks

When we introduced Concord Trust in July, security controls were on the list as coming soon. They're here, along with the rest of the compliance side of Concord: frameworks, an auditor portal, vendor management, and integrations that check your cloud accounts and collect evidence for you.

Controls

Open Data Hub > Controls & Audits to build your control set from Concord's library. Adopt the controls that fit how you operate, give each one an owner, track its status, and attach the evidence that shows it's working.

  • Tests that open tasks. When a required control test fails, Concord opens a task for the control's owner, and a passing run closes it. Automated checks have to fail twice before they open a task, so a one-off blip doesn't create noise.
  • Show your controls publicly. In each trust center's Controls settings, choose which controls to publish. By default only implemented controls with a passing check appear, and you can choose to show in-progress ones too. Each shows when it was last updated. Failing, unverified, and not-yet-started controls are never shown.

Frameworks

Choose Adopt Framework to map your controls to a standard and see which requirements are covered and where the gaps are. Available frameworks:

  • SOC 2
  • ISO/IEC 27001:2022
  • ISO/IEC 27701:2025
  • ISO/IEC 42001:2023
  • NIST AI Risk Management Framework
  • NIST Privacy Framework
  • GDPR
  • CCPA/CPRA
  • HIPAA Security Rule
  • PCI DSS v4.0.1
  • CMMC 2.0 Level 1
  • SOX

Frameworks are available as add-on packs, with published prices on the Concord Trust pricing page.

The Auditor Portal

Every framework pack includes the auditor portal. Choose Invite Auditor to give an outside auditor access to a single audit. You decide whether they can view documents and comment, and when their access expires (90 days by default).

Auditors work in their own portal, not your admin. For each control they see the mapped requirements and the evidence, can request more evidence from your team, and record their own review (Accepted, Needs More Info, or Exception) with a comment thread. Their review is kept separate from your control's status, so both sides stay on record.

Vendor Management

Open Data Hub > Vendors to keep an inventory of the companies you work with. Add a vendor from Concord's global catalog or create your own, record details like its privacy policy, DPA, country, and categories, and link it to the data systems it provides.

Your vendor inventory feeds the sub-processor list on your trust center, which shows each sub-processor's name, description, and the countries where it processes data, so the list reflects your Data Hub rather than a page someone has to remember to update.

Integrations, Cloud Posture Checks, and AI Evidence Collection

Under Integrations > Browse Catalog (with Recommended and All Integrations tabs), connect the systems your controls depend on. Credentials are stored encrypted.

  • Cloud posture checks. Connect AWS, Microsoft Azure, or Google Cloud, and Concord checks your accounts nightly, or on demand, across areas like identity and access, logging, storage, networking, and databases, mapped to CIS benchmark criteria. Results are recorded as evidence on the controls they map to.
  • Honest results. When a check can't reach a conclusion (for example, when there's nothing in scope or a credential stops working), the result is Not Checked rather than a pass. A control is never marked as passing on partial coverage.
  • AI Evidence Collection. Set up an AI Review on a control, and an AI agent chooses and runs read-only checks against the connected systems you pick, then records a pass, a fail, or an inconclusive result along with its reasoning and a summary of the evidence.

Check runs use Actions: 50 per check group for each connected account, and AI Evidence Collection uses 200 Actions plus up to 100 Data Credits.

Get Started

Controls and vendor management are included in Concord Trust Premium and Enterprise, and frameworks with the auditor portal are available as add-on packs. Integrations and cloud posture checks are available now; contact us to turn them on for your organization. See Controls and Evidence, Adopting Frameworks, Auditor Access, and Automated Control Checks to get set up, or book a demo and we'll walk through how they fit your audit timeline.