Guides
Practical, evidence-based guides on compliance frameworks, engineering intelligence, and technical due diligence — written by the team building the platform. 64 guides and growing.
In-depth, vendor-neutral explainers on metrics and governance.
- Software development metrics: the full catalog, organized by lens
- AI development metrics: a catalog for AI-assisted SDLC and AI systems
- AI governing AI: how law and measurement are co-evolving
- California GovOps and its role in state AI governance
- Public-sector AI governance: how California's GovOps runs the model
- Public-sector GenAI procurement: how California buys AI safely
Solutions
11Platform and category overviews.
- Technical due diligence software: measure the asset, not the pitch
- Engineering intelligence: measure delivery without gaming it
- Technical debt management software: make the cost visible
- AI governance software: inventory, oversight, and evidence
- AI compliance and risk management software, explained
- AI readiness assessment software: measure, do not guess
- Application modernization assessment: deciding what to modernize, and in what order
- Continuous compliance and security readiness, explained
- Software portfolio management: a practical guide
- Software risk management: measuring and treating the risk that lives in software
- Technology investment intelligence: allocating engineering spend on evidence
What each compliance framework requires and how to run it.
- SOX compliance for ITGC and §302/§404 readiness
- SOC 2 compliance: what it requires and what auditors sample
- ISO 27001: the ISMS, Annex A, and the certification cycle
- The EU AI Act: risk tiers, obligations, and timeline
- ISO/IEC 42001: the AI management system standard
- NIST AI Risk Management Framework, explained
- The Colorado AI Act (SB 24-205), explained
Frameworks and approaches weighed side by side.
Criteria-first evaluation guides for switching platforms.
- Vanta alternatives: an evaluation guide for compliance buyers
- Drata alternatives: an honest guide to evaluating your options
- Secureframe alternatives: an evaluation guide for compliance buyers
- Hyperproof alternatives: an evaluation guide for GRC buyers
- LinearB alternatives: an engineering-metrics buyer's guide
- Jellyfish alternatives: an engineering-metrics buyer's guide
- Swarmia alternatives: an engineering-metrics buyer's guide
Category buying guides, criteria first.
The view from your seat — CTO, CISO, board, PE.
Glossary
23Plain-English definitions of the terms auditors use.
- IT general controls (ITGC), defined
- Segregation of duties (SoD), defined
- Section 302 certification, defined
- Information produced by the entity (IPE), defined
- DORA metrics, defined
- Technical debt, defined
- Continuous control monitoring, defined
- Technical due diligence, defined
- What are complementary user entity controls (CUECs)?
- What is the SPACE framework?
- What is MTTR (mean time to restore)?
- What is change failure rate?
- What is lead time for changes?
- Agent health
- Control register
- COSO (Committee of Sponsoring Organizations)
- Deficiency evaluation
- Deployment frequency, defined
- Evidence-based compliance, defined
- Risk appetite, defined
- SBOM (software bill of materials)
- Statement of Applicability (SoA), defined
- Trust center, defined