Expert review
AI proposes, a credentialed expert commits. Co-signing high-judgment controls is what makes Attestloop compliance, not a black-box guess.
3
In queue
JR
Jonas Reinhardt
CISSP, IAAP · acting reviewer for Northwind AI
3
Awaiting your co-sign
7
Co-signed
4h
Avg turnaround
Awaiting your co-sign
VR-1Vendor risk assessmentsOrgIn review
AI flagged this for human judgment before it can be attested. Vendor risk assessments maps to 2 requirements.
Requires ISO 27001 Lead AuditorSC-1Dependencies free of known CVEsCodePassing
AI verified this control and is ready to attest. Co-sign to make it compliance-grade. Dependencies free of known CVEs maps to 1 requirement.
Requires CISSPSC-2Static analysis on every PRCodeIn review
AI flagged this for human judgment before it can be attested. Static analysis on every PR maps to 1 requirement.
Requires CISSPRecently co-signed
| Control | Reviewer | Status | Co-signed |
|---|---|---|---|
| AC-2 MFA enforced on all accounts | JOJonas Reinhardt, ISO 27001 Lead Auditor | Passing | 2 min ago |
| GV-1 Information security policy | JOJonas Reinhardt, ISO 27001 Lead Auditor | Passing | 3 hr ago |
| DP-3 Data encrypted at rest and in transit | JOJonas Reinhardt, CIPP/E | Passing | 2 min ago |
| BC-2 Backups tested and recoverable | JOJonas Reinhardt, ISO 27001 Lead Auditor | Passing | yesterday |
| AI-1 No indirect prompt-injection paths | JOJonas Reinhardt, CISSP | Passing | 4 min ago |
| AI-2 Agent tool access allowlisted | JOJonas Reinhardt, CISSP | Passing | 14 min ago |
| LM-1 Audit logging on critical systems | JOJonas Reinhardt, ISO 27001 Lead Auditor | Passing | 1 hr ago |