Threat coverage reporting
Compare explicit policy mappings with Agent Threat Rules targets, distinguish direct, missing, ambiguous, and unmapped evidence, and export a CSV.
Draft or securely import policies, route decisions, assign and attest the right people, and export the evidence from one governed compliance workspace.
What shipped since the last site refresh
Built for compliance teams across regulated industries
How it works
One system carries every policy through its whole lifecycle — no spreadsheets, no email chains, no dropped threads.
Start from a curated template across seven compliance domains, or securely import a validated PDF or DOCX into an owned draft.
Per-policy, per-category, full workflow, or ad hoc — approval routing matches how your organization actually decides.
Publish with version history built in, then collect and track employee attestations automatically.
Every edit, approval, and signature lands in a tamper-evident audit trail, ready to export on demand.
Everything compliance needs
Curated starter templates, reusable template packs, and onboarding flows that prefill policy drafts from tenant data.
Rich text editing with structured sections, cross-references, and parent/child policy relationships.
Full change history with unified diffs and automatic change-impact scoring — review exactly what changed and roll back to any prior version.
Ordered approval steps, per-policy or per-category routing, reminders, escalation, and ad hoc review when exceptions happen.
Automated attestation requests and reminders — including optional quiz-based comprehension checks with a pass threshold — tracked down to the employee.
Native iOS and Android experiences combine MSAL and Microsoft Entra ID sign-in with assigned policies, approvals, notifications, and quiz-based attestations.
Mobile clients keep assignments, policy content, and notifications available with cache-aware sync and health-checked server configuration.
Microsoft Entra ID SSO, mobile MSAL authentication, security groups, and role-based access with organization-scoped data.
Export any policy, including any past version, to PDF or Word (.docx) — ready to print, sign, or share outside the platform.
In-app and email notifications, plus signed webhook delivery to your own systems — each endpoint gets its own secret, shown once at creation.
Manage tenant users, active accounts, department hierarchy and membership, role assignment, and custom-role permissions from one capability-aware console.
Compare explicit policy-control mappings with Agent Threat Rules targets, separate direct and missing evidence, and export a CSV for review.
Keep a policy tenant-wide or restrict it to selected departments; the same boundary applies across search, reading, exports, version history, and relationships.
Template library
Start from a vetted template and adapt it, or build your own from scratch.
Privacy, security, and breach-notification policy for healthcare organizations.
Workplace safety and hazard-communication policy for regulated worksites.
Financial controls, expense, and data-handling policy templates.
Employee conduct, leave, and workplace policy templates.
Acceptable use, data retention, and systems-access policy.
Incident response, access control, and data-protection policy.
Ethics, vendor management, and organization-wide policy templates.
See it in action
Status, approvals, reviews, and a compliance score — one screen, always current.
Mobile and offline
Native iOS and Android access now combines Microsoft Entra ID and MSAL authentication with health-checked server settings, cached policy content, offline-aware assignments, device-token lifecycle support, notifications, and attestation flows.
Employees can open assigned policies on iOS or Android, with cached content available after first load.
Approvers can see queues, review context, and act without waiting to get back to a desktop.
Read-and-acknowledge or quiz-based attestations support comprehension checks and due-date tracking.
Offline banners, cache-aware repositories, and background sync keep mobile work predictable.
Policy intelligence
Sync Agent Threat Rules intelligence, compare declared policy controls with relevant targets, and export a visibility-aware evidence file. The result is a clearer review queue, not an unearned compliance claim.
Compare explicit policy mappings with Agent Threat Rules targets, distinguish direct, missing, ambiguous, and unmapped evidence, and export a CSV.
Tenant administrators can search people, manage active accounts, assign roles, and maintain departments with lockout and hierarchy safeguards.
Custom roles receive only the capabilities granted to them, while tenant isolation, policy visibility, lifecycle, and lock checks stay in force.
Limit a policy to the departments that need it without creating a second repository or relying on a separate portal.
Security & compliance
Security isn’t a feature we bolted on. It’s the foundation everything else is built on.
TLS protects data in transit. Integration secrets are encrypted, and at-rest protection uses supported cloud services or encrypted storage configured for your deployment.
Application data is scoped by organization and protected with role-based access controls.
Hash-chained logging supports tamper detection, admin search, long-term retention, reporting, and evidence-package export.
Microsoft Entra ID integration, security-group roles, and explicit custom permissions control who can read, change, approve, publish, and administer.
Network guards reduce SSRF risk in directory and HRIS connectors, with TLS certificate checks for third-party integrations including ADP.
Upload validation and DOCX zip-bomb protections help keep imported policy files inside expected operating limits.
Agent Threat Rules metadata is bounded at import, and regex evaluation uses timeout-aware safeguards. Catalog, coverage, and runtime detection remain deliberately separate concerns.
A validated, operator-controlled onboarding path creates the first administrator with a hash-chained audit event instead of a first-user-wins rule.
Deploy self-hosted via Docker, or fully managed on Azure — your infrastructure, your choice.
Integrations
PolicyWizard doesn’t ask you to change how your organization is structured — it plugs into the systems you already use for identity, HR, and day-to-day work.
Sync users, groups, and access automatically from Microsoft Entra ID, on-prem Active Directory, or Google Workspace, so policy access always matches your org chart.
Push approved, published policies straight to SharePoint, Microsoft Teams, or Google Drive — no separate portal for employees to remember.
Configure BambooHR, Workday RaaS, or ADP for auditable workforce synchronization that keeps existing people and department data current for assignments and attestations.
Early access plans
Pricing goes live at general availability. Join the waitlist to lock in founding-member rates.
For a single department getting policy under control.
Most popular
For multi-department compliance programs.
For regulated, multi-entity organizations.
FAQ
PolicyWizard includes controls designed to support HIPAA requirements, including transport security, access controls, retention settings, and tamper-evident audit logging. Compliance also depends on deployment configuration, signed agreements, and your administrative and physical safeguards.
Yes. Bring your current policy documents in directly, or start from a curated template and adapt it to your organization.
Per-policy, per-category, full workflow-based routing, or ad hoc one-off approvals — whatever matches how your organization signs off today.
Every edit is tracked with full diffs. Review exactly what changed, who changed it, and roll back to any prior version.
Yes — deploy via Docker in your own environment, or run fully managed on Azure. Your infrastructure, your choice.
Microsoft Entra ID works across web and native mobile clients, with support for existing security groups and role-based access control.
Yes. A policy can stay visible across the tenant or be scoped to selected departments. Non-members do not receive it in list, search, reading, export, version, or relationship views.
PolicyWizard syncs Agent Threat Rules metadata, compares explicit policy-control mappings, separates direct, missing, ambiguous, and unmapped evidence, and exports a CSV. Runtime rule detection is kept behind a separate, timeout-aware safety boundary.
Yes. Mobile clients include a user-editable, health-checked server URL setting for approved self-hosted or managed deployments.
HIPAA, OSHA, finance, HR, IT, cybersecurity, and general organizational compliance — seven domains at launch.
We’re onboarding early access customers on a rolling basis. Join the waitlist and we’ll reach out as spots open.
Join the waitlist for early access to PolicyWizard — we’ll reach out as spots open.