Security & Compliance
Lynx Compliance
Framework/control registry, assessment workflow, evidence linking, auditor export for NIST CSF 2.0 / ISO 27001 / SOC 2 / Law 25 / Bill C-26
lynx_compliance
· v19.0.1.4.1
· Premium
What this solves
Lynx Compliance — NIST CSF 2.0 System of Record
The system of record that lets a CISO honestly claim and prove alignment with NIST CSF 2.0, ISO 27001, SOC 2, Quebec Law 25, and Canadian Bill C-26 out of one Odoo instance — without spreadsheets, without GRC tooling, and without inventing controls.
Compliance frameworks all overlap. Stock GRC suites duplicate work by asking you to maintain CSF, ISO, and SOC 2 evidence separately; smaller teams give up and reach for Excel. Lynx Compliance treats the framework catalog as data: compliance.framework → compliance.function → compliance.category → compliance.control, all cross-linked. Each compliance.profile defines a scope (Lynx SaaS, Patrii Cloud, Corporate IT) and gets a row per control with status, owner, maturity tier 1-5, policy reference, and polymorphic evidence links pointing at any Odoo record, NetBox object, or attachment — so the auditor sees live data instead of screenshots.
Key Features
Framework registry — compliance.framework / compliance.function / compliance.category / compliance.control models hold CSF 2.0, ISO 27001:2022, SOC 2 TSC, Law 25, and Bill C-26 with cross-references in iso_27001_refs, soc2_tsc_refs, law25_refs, and billc26_refs so one piece of evidence proves multiple frameworks at once.
Per-scope profiles — compliance.profile is a scope (period, owner, framework); action_populate_assessments materialises one compliance.control.assessment per framework control with maturity, status, owner, policy reference, and evidence list.
Polymorphic evidence — compliance.evidence.link points at any Odoo record, a NetBox object, an external URL, or an attachment; action_open_target jumps the auditor right there from the row.
Cross-framework export — action_export_coverage_xlsx builds an XLSX matrix (CSF / ISO / SOC 2 / Law 25 / Bill C-26); action_generate_signed_export renders the profile PDF for CISO signature via lynx_sign.
Findings + remediation — compliance.finding aggregates gaps, overdue reviews, and incident-driven CAPAs with severity, owner, due date, and escalation workflow.
Weekly CISO digest — extends digest.digest with KPIs for overdue reviews, stale evidence, open incidents, overdue training, overdue DSAR, and DR exercises so issues surface before the auditor.
Integrates With
lynx_sign — signed evidence, profile sign-off, CISO attestations.
lynx_compliance_govern / _data / _training / _audit_log / _incident / _privacy / _resilience — companion modules that cover policies, BIA, training, tamper-evident logs, incidents, privacy (Law 25 / GDPR), and disaster recovery on top of this base.
Try Lynx Compliance on your team.
Free trial, no credit card. Talk to sales when you're ready.