For accidental compliance owners

The questionnaire landed on you. threep helps you answer from evidence.

You already had a full-time job. Then a security questionnaire, vendor risk form, or SOC 2 / HIPAA / TX-RAMP control ask landed on your desk. threep helps small teams map policies, artifacts, and evidence to each control — so you reach a defensible answer instead of a guess.

Built for small teams, operators, IT owners, and founders who suddenly own compliance.
The shift

Small teams can spend weeks getting policies and documentation in place. Then the first questionnaire arrives — and the hard part is no longer “do we have documents?” It’s “which evidence actually satisfies this control?”

Evidence-backed by default

threep ties answers, gaps, and readiness claims back to the policies, procedures, and artifacts that support them.

Gaps are visible

Missing, stale, or weak documentation is called out clearly so teams know what to fix before a client or auditor asks.

Human approval before claims leave

threep helps draft and assess, but a human reviews what is official.

The problem

Someone with a full-time job just got handed a compliance emergency.

A client, an auditor, or a regulator asks for proof — and the person who already has a day job suddenly owns compliance, usually without a program, a team, or an obvious place to start.

01 · Scatter

Documentation starts scattered

Policies, handbooks, SOC artifacts, screenshots, spreadsheets, and prior answers live in different places.

02 · Mapping

Requirements are hard to map

Frameworks like TX-RAMP, SOC 2, HIPAA, and NIST ask for controls, but small teams think in documents and operations.

03 · Gaps

Gaps stay hidden

A policy may exist, but the supporting language may be stale, weak, or missing entirely.

04 · Drift

Readiness decays

Even if everything looked good once, documents and controls drift unless they are re-assessed.

The workflow

From scattered documents to review-ready evidence.

threep guides the work small teams usually handle manually: gather the evidence, benchmark it, fix the gaps, approve the result, and stay ready.

  1. Step 01

    Gather existing docs

    Policies, procedures, handbooks, SOC artifacts, screenshots, and prior answers.

  2. Step 02

    Create or strengthen what is missing

    Get guidance on the documents and language needed for the target framework.

  3. Step 03

    Benchmark against controls

    Compare the corpus against TX-RAMP, SOC 2, HIPAA, NIST, or customer requirements.

  4. Step 04

    Classify every answer clearly

    Use one consistent state model: STRONG, PARTIAL, GAP, or NONE.

  5. Step 05

    Fix gaps and reassess

    Update the documentation, rerun the assessment, and confirm the gap is closed.

  6. Step 06

    Approve and keep the record current

    Assign an owner, record reviewer decisions, export the result, and reassess when evidence changes.

When a questionnaire or assessment arrives, threep turns that readiness work into cited answers your team can review and export. Approval and submission stay with your team.
Inside the workspace

A readiness workspace — not a giant GRC suite.

threep benchmarks your policies and documentation against the controls you are held to, classifies each answer as STRONG, PARTIAL, GAP, or NONE, and keeps the supporting evidence visible.

Boundaries

What threep will not do.

threep is bounded on purpose. If a control needs human judgment, it stays with a human.

Invent documentation

If a policy, procedure, or artifact is missing, threep flags the gap instead of pretending it exists.

Claim implementation without evidence

A written policy is not the same thing as an implemented control. threep helps separate documented coverage from operational proof.

Replace compliance judgment

Scope, exceptions, risk acceptance, and official approvals stay with people.

Auto-submit on your behalf

Assessment answers and exports are reviewed and sent by a human.

Use cases

Built for the person who suddenly owns compliance.

For small teams handling important compliance work without a full GRC department.

Small business owner · Founder

You signed the contract; now you own the controls.

Get from scattered documents to a clear, evidence-backed readiness picture without hiring a compliance team or paying enterprise GRC prices.

Operations lead

Compliance landed on your desk.

See which controls are STRONG, PARTIAL, GAP, or NONE — and what to fix in the documents and operations you already understand.

IT · Microsoft 365 admin

You run the systems and the evidence.

Map your policies and artifacts to controls, then reassess them as configurations and evidence change.

Technical PM · support-security hybrid

You're the bridge between the work and the proof.

Track what each control needs, route gaps to the right owner, and keep the readiness record current.

vCISO · MSP supporting small clients

You carry compliance for several small clients.

Per-client workspaces keep each engagement's evidence, gaps, and assessments separate — so you can run the same readiness playbook repeatably without one client's posture bleeding into another's.

Packaging

Three ways to use it.

Choose the level of support that matches how your team works. Early-access terms are scoped with each team.

Starter

Readiness assessment

Early access · for teams that need to know where they stand.

  • Benchmark your docs against a framework
  • STRONG / PARTIAL / GAP / NONE breakdown
  • Prioritized gap list
  • Cited questionnaire answers as an output
Run a readiness assessment
Ongoing · recommended

Readiness workspace

Early access · for teams that want to keep the work moving over time.

  • Everything in the starter assessment
  • Re-run assessments as evidence changes
  • Gap tracking + reviewer follow-ups
  • Cited assessment and questionnaire answers
  • Reviewer decisions + audit trail
Get early access
Private deployment

Dedicated environment

Contact us · for teams that need private hosting or stricter data boundaries.

  • Dedicated tenant or private deployment
  • SSO and access-control configuration
  • Private evidence and model-routing options
  • Readiness and assessment workflows
Talk to us
threep is a hosted SaaS workspace at app.threep.ai. Private deployment is for teams that need isolation, SSO, custom retention, or private model routing.
Founder note

Built from a very specific kind of panic.

Dallas Weber, founder of threep

threep began when a compliance problem landed on my desk without a compliance team attached to it.

At a small, regulated SaaS company, I helped pull together policies, procedures, and evidence under real pressure — the kind of deadline where the work simply has to get done, and it lands on whoever is closest to it.

Getting the documentation in place felt like progress. Then the first questionnaire arrived, and the gap became obvious. I had the policies. What I did not have was a fast, reliable way to prove which policy, artifact, or evidence item actually satisfied the control in front of me.

I did not need another policy template. I needed to know whether the evidence we already had satisfied the control.

That is why threep exists.

Dallas Weber
Founder · threep
FAQ

Common questions.

Does threep answer the questionnaire automatically?

No. threep drafts answers that your evidence supports and flags everything else. A reviewer signs off on each answer before the response is exported. threep never submits on your behalf.

What happens when there's no evidence for a question?

The question is left unanswered, marked NONE, and routed to an owner. threep does not invent a plausible answer — that's the whole point.

Where does my evidence live?

threep is a hosted SaaS workspace, and your evidence stays inside your own tenant. If your team needs stricter data boundaries — dedicated infrastructure, custom retention, or private model routing — we can scope a private deployment.

Does this replace our GRC tool?

It's not trying to be a heavyweight GRC platform. threep is a readiness workspace for small teams: it benchmarks documentation against controls, classifies answers as STRONG, PARTIAL, GAP, or NONE, helps close gaps, and turns the evidence into review-ready assessments and questionnaire answers. It pairs with whatever else you use to track controls and policies.

Which frameworks does it support?

The workspace is framework-agnostic — it benchmarks your evidence against the control, not a single standard. It is designed for TX-RAMP, SOC 2, HIPAA, NIST, ISO 27001, and client security assessments.

Who reviews the answers?

Someone on your team. Usually the security owner, the founder, the IT lead, or a vCISO. The reviewer is logged per answer and shows up in the audit trail.

What does "early access" mean today?

Hands-on onboarding, a single point of contact, and a pricing arrangement that reflects you being early. We're working with a small number of teams at a time.

Early access

Know what your documentation supports before someone asks.

Run a readiness assessment, close the gaps, and turn your evidence into review-ready responses when clients, auditors, or regulators ask.

Hosted SaaS workspace · reviewer approval stays with your team · no autonomous submission