Resources

Every risk program
must answer 12 questions.

They're not aspirational. They're asked by auditors, regulators, customers, and board members. AuditBull's feature set maps directly to all twelve — by design, not by accident.

1
What systems does our organization use?
System inventory. Capture every system with ownership and classification. Org structure (departments, teams) keeps it scoped.
2
What data do those systems hold?
Data classification. PII, ePHI, secrets, financial. Recertified through the assessment engine on cadence.
3
Who has access to those systems?
Seats. Personnel × systems matrix. Directory sync (Pro+) keeps it current. Ownership roles named per system.
4
Is that access still appropriate?
Access reviews. Standing + campaign reviews in Teams. Owners answer in chat. Generated questions from seat data.
5
What risks exist across systems and vendors?
Risk registers. Hierarchical, charter-bound, owner-named. Framework assessments and risk workshops feed them.
6
Who owns each risk and what's the treatment plan?
Risk ownership + state machine + CAPs. Active → Mitigated → Accepted → Transferred → Archived. Action items per risk.
7
Are our vendors meeting their obligations?
Vendor registry + risk ratings. Due diligence, recertification, contract renewal tracking on the assessment engine.
8
Are our people trained on their responsibilities?
Training surveys + acknowledgments. Policy versioning + acknowledgment tracking through the assessment engine.
9
What happened and when?
Audit log. Immutable, append-only, partitioned. Risk timeline + process instances. Auditor-readable by default.
10
Are we compliant with our commitments?
Framework assessments + control monitoring. Continuous review, not annual scramble. Compliance metrics on the dashboard.
11
What is our posture trending over time?
Risk posture snapshots + trend dashboard. Delta-aware campaigns. Framework scores tracked across cycles.
12
Can we prove it?
Audit log + assessment evidence. Document versioning, acknowledgments, review timestamps. Signed exports on Pro+.
Source-available licensing

Third-party risk, protected.

AuditBull is closed-source software — but source-available to customers through a flat license. Unrestricted use across your organization. One-time fee for source code access, plus an annual fee for updates. No per-seat charges. No module caps. No hidden fees.

01 · Unrestricted use

Flat license. The whole platform.

One license covers every team, every user, every system in your organization. No per-seat fees. No module unlocks. No tier upsells. Pay once for the source, pay yearly for updates — that's it.

02 · Cost ceiling

Pay once. Run forever.

If your usage scales past the point where SaaS pricing makes sense, the license is your escape hatch. Pay the one-time fee, host it yourself, and your costs are bounded by ownership instead of subscription.

03 · Beyond mid-market security

Self-host in your environment.

If you operate under regulated, sovereign, or air-gapped requirements that mainstream SaaS can't meet, we help you deploy AuditBull inside your own infrastructure. Your tenant. Your network. Your control plane.

04 · Verify, don't trust

Inspect everything.

Read the RLS policies. Read the tenant isolation. Read the audit trail. Inspect the migrations, the API surface, the bot pipeline. The CISO verifies; doesn't just trust the vendor's word.

Continuity bonus: if AuditBull ever stops existing as a company, you keep running. The code's yours, the data's yours, the program is yours. Worst-case becomes "spin up the Docker container and the migrations." That's it.

Inquire about licensing →
Coming soon

More resources, on the way.

We're building a content library alongside the product. If there's something specific you'd want to see, tell us.

Templates

Risk register starter packs.

Pre-built registers for SOC 2, HIPAA, ISO 27001 — drop into a fresh tenant and adapt.

Playbooks

Access review checklists.

Step-by-step playbooks for quarterly access reviews — privileged accounts, contractor offboarding, scope changes.

Blog

The 12 questions, deep-dive.

One post per question — what auditors actually look for, how to answer concretely, common pitfalls.

Want to be the first to read these?

We'll send one email when the resource library lands.
One email. No nurture sequence.

Get notified →