Se rendre au contenu

Security & Compliance

Lynx Compliance

Framework/control registry, assessment workflow, evidence linking, auditor export for NIST CSF 2.0 / ISO 27001 / SOC 2 / Law 25 / Bill C-26

lynx_compliance · v19.0.1.4.1 · Premium

What this solves

Lynx Compliance — NIST CSF 2.0 System of Record

The system of record that lets a CISO honestly claim and prove alignment with NIST CSF 2.0, ISO 27001, SOC 2, Quebec Law 25, and Canadian Bill C-26 out of one Odoo instance — without spreadsheets, without GRC tooling, and without inventing controls.

Compliance frameworks all overlap. Stock GRC suites duplicate work by asking you to maintain CSF, ISO, and SOC 2 evidence separately; smaller teams give up and reach for Excel. Lynx Compliance treats the framework catalog as data: compliance.frameworkcompliance.functioncompliance.categorycompliance.control, all cross-linked. Each compliance.profile defines a scope (Lynx SaaS, Patrii Cloud, Corporate IT) and gets a row per control with status, owner, maturity tier 1-5, policy reference, and polymorphic evidence links pointing at any Odoo record, NetBox object, or attachment — so the auditor sees live data instead of screenshots.

Key Features

  • Framework registrycompliance.framework / compliance.function / compliance.category / compliance.control models hold CSF 2.0, ISO 27001:2022, SOC 2 TSC, Law 25, and Bill C-26 with cross-references in iso_27001_refs, soc2_tsc_refs, law25_refs, and billc26_refs so one piece of evidence proves multiple frameworks at once.

  • Per-scope profilescompliance.profile is a scope (period, owner, framework); action_populate_assessments materialises one compliance.control.assessment per framework control with maturity, status, owner, policy reference, and evidence list.

  • Polymorphic evidencecompliance.evidence.link points at any Odoo record, a NetBox object, an external URL, or an attachment; action_open_target jumps the auditor right there from the row.

  • Cross-framework exportaction_export_coverage_xlsx builds an XLSX matrix (CSF / ISO / SOC 2 / Law 25 / Bill C-26); action_generate_signed_export renders the profile PDF for CISO signature via lynx_sign.

  • Findings + remediationcompliance.finding aggregates gaps, overdue reviews, and incident-driven CAPAs with severity, owner, due date, and escalation workflow.

  • Weekly CISO digest — extends digest.digest with KPIs for overdue reviews, stale evidence, open incidents, overdue training, overdue DSAR, and DR exercises so issues surface before the auditor.

Integrates With

  • lynx_sign — signed evidence, profile sign-off, CISO attestations.

  • lynx_compliance_govern / _data / _training / _audit_log / _incident / _privacy / _resilience — companion modules that cover policies, BIA, training, tamper-evident logs, incidents, privacy (Law 25 / GDPR), and disaster recovery on top of this base.

Try Lynx Compliance on your team.

Free trial, no credit card. Talk to sales when you're ready.