A ready-made SOC 2 program
One click creates a dedicated compliance space with 24 policy templates and 15 recurring activities, mapped to the Trust Services Criteria. Already have policies? Import them.
Compliance in a Box turns one Confluence space into your compliance system of record: policies, approvals, employee acknowledgements and recurring evidence, all bound to exact page versions and ready for your auditor.
Free for up to 10 users, every feature included. Runs on Atlassian.
Spreadsheets and screenshots don't survive an audit well. Compliance in a Box keeps the work in Confluence and records who approved and acknowledged exactly what, and when.
One click creates a dedicated compliance space with 24 policy templates and 15 recurring activities, mapped to the Trust Services Criteria. Already have policies? Import them.
Approvals and acknowledgements are bound to the exact page version and a hash of its content, so any later edit is detected. An append-only audit log backs every action.
Built on Atlassian Forge with no external services. Reminders are Confluence tasks, and people are stored only as Atlassian account IDs. Your evidence stays in your own space.
Policy text is written with the normal Confluence editor. The app handles the workflow, the state and the evidence.
Choose your employee and admin groups, your fiscal year and the Trust Services categories in scope. The app creates the compliance space and its page tree.
Each policy and activity gets an owner and approvers. Managed pages are locked so only the owner and Compliance Admins can edit them.
Owners submit a version, approvers approve that exact version, and employees acknowledge with one click. Material changes ask for acknowledgement again.
Access reviews, scans and tabletop exercises open their own dated evidence pages on schedule, with due dates, reminders and approvals.
Every approver signs off on a specific page version. Edit the page before it's approved and the submission is cancelled automatically.
Employees acknowledge from the policy page. Target all employees or specific groups, with due dates and completion tracking per policy.
Monthly, quarterly, semi-annual or annual controls, aligned to your fiscal year, each opening an evidence page for its period. Skips need a written reason.
Admins see overdue items, upcoming reviews and acknowledgement completion. Everyone else sees exactly what's waiting on them.
A byline on every policy and evidence page shows its approval status and lets people acknowledge, submit or approve without leaving Confluence.
Reminders arrive as Confluence task notifications, plus a weekly summary for admins. No email integrations to configure.
A policy approval log, acknowledgement report, activity completion report, audit log and controls matrix, generated as Confluence pages and kept up to date daily.
Import existing Confluence pages into the program, add custom policies, and retire the ones you no longer need, with history intact.
Give an optional Auditors group view-only access to the evidence and report pages, and nothing else.
Work approved without an independent approver is highlighted on the dashboard, so separation of duties is visible before your auditor asks.
Choose the Trust Services categories you're audited on: Security, plus Availability, Confidentiality, Processing Integrity and Privacy as needed.
The policy templates and control mappings are a starting point, not legal or audit advice. Have them reviewed by your auditor. SOC 2 is first; more frameworks are planned.
Compliance in a Box runs entirely on Atlassian's Forge platform. There is no Auralite backend, and we have no access to your data.
No external domains, no remote servers and no third-party subprocessors. Data lives in Forge hosted storage for your site, with data residency supported.
People are stored only as Atlassian account IDs, never names or emails. When an Atlassian account is closed, the app erases it from its records.
Policies, evidence and generated reports are ordinary Confluence pages in your space. They stay there even if you uninstall the app.
Billing is handled by Atlassian on the Marketplace, alongside your Confluence subscription.
For small teams preparing for their first audit.
The same app, for growing teams. Pricing follows your Confluence user tier and is shown on the Atlassian Marketplace listing.
Confluence Cloud. Page locking and restricted report pages need Confluence Standard or above. On Confluence Free the app still works, but it warns you during setup that pages can't be restricted.
The app creates one dedicated compliance space for your site, and every framework lives in it. If your organization prefers, an admin can create an empty space and hand it to the app instead. You can import policies from other spaces into it.
No. The app runs on Atlassian Forge and calls no external services. Its records are kept in Forge hosted storage for your site, and your policies and evidence are ordinary Confluence pages.
Your policies, evidence pages and generated reports stay in your Confluence space. The app keeps the Evidence & Reports pages refreshed daily and tries a final refresh when it is uninstalled. Its internal records are deleted by Atlassian after a retention period.
The app becomes read-only: everyone can still see their records and admins can still refresh the report pages, but approving, acknowledging and creating new content stop until the license is active again. Your Confluence pages are unaffected.
No. The policy templates and control mappings are a well-structured starting point. Tailor them to your company and have them reviewed by your auditor.
SOC 2 comes first. The app is designed so that more frameworks can be added as content, and they are on our roadmap. Tell us which one matters to you at support@auralitesolutions.com.
Install free for up to 10 users, or ask us anything first.