What problem does it solve?
This Skill provides a comprehensive framework for implementing and managing regulatory compliance (SOC 2, ISO 27001, ISO 27701), ensuring auditable evidence, secure data retention with verifiable deletion, legal hold capabilities, and robust third-party risk management for B2B products.
Core Features & Use Cases
- Compliance Framework Implementation: Guides through setting up controls and policies for major certifications.
- Auditable Evidence Management: Automates the collection and organization of evidence for audits.
- Data Lifecycle Management: Implements secure data retention and verifiable deletion processes.
- Third-Party Risk Management (TPRM): Manages risks associated with vendors, including DPAs and security agreements.
- Use Case: A SaaS company needs to achieve SOC 2 compliance. This Skill helps them define their compliance profile, map controls to evidence, establish data retention policies, and vet their critical third-party vendors.
Quick Start
Use the cumplimiento-certificaciones skill to generate a compliance profile for a B2B SaaS product targeting SOC 2 Type II compliance.