Evidence-backed claims for regulated SaaS

Know what your company can prove.

The client questionnaire is due Friday. threep turns scattered policies, procedures, and artifacts into a reviewed record of what your company can prove, what it must qualify, and what happens next.

Built for 25–500-person B2B SaaS companies facing enterprise, government, or regulated-market requirements before they have a mature compliance organization.

A person on your team approves every answer before it leaves.
threep Meridian assessment 41 questions · CompleteReview 26 flagged
● STRONG ● PARTIAL ● GAP ● NONE
Reviewed answer

After an incident is resolved, is a post-mortem review conducted? Are procedures updated accordingly?

The policy requires a Post-Incident Report within five business days, including root cause analysis and corrective actions with owners and due dates.

Not substantiated by the answer’s evidence: Procedure Update Evidence
Source: Incident Response Plan › 5.6 Post-Incident Review PARTIAL
Illustrative product view using fictional assessment data.
Claim states

Every claim has a state.

Not a confidence score. A reviewed boundary between what the evidence supports, what it narrows, and what still requires a human decision.

● STRONGSUPPORTED

Is there a formal process for notifying customers when a breach occurs?

Customers affected by a data breach must be notified within 72 hours of confirmed breach determination. The cited evidence supports a short answer ready for review.

Source: Incident Response Plan › 6.2 Customer Notification
● PARTIALNARROWER ANSWER

After an incident, is a post-mortem conducted—and are procedures updated?

The Post-Incident Report requirement is supported. Evidence that procedures are updated from its findings is not.

Not substantiated: Procedure Update Evidence
Source: Incident Response Plan › 5.6 Post-Incident Review
● GAPNOT ESTABLISHED

Can product event logs be exported or forwarded to a customer-managed SIEM?

Available evidence does not establish whether Meridian Software can export or forward product event logs to a customer-managed SIEM such as Splunk.

Next: Product-owner confirmation is required before this can be answered externally.
● NONEMANUAL REVIEW

Do engineering practices incorporate the OWASP Developer’s Guide and Cheat Sheet Series?

The available policy evidence does not address this requirement; it requires manual review before it can be answered.

Evidence: No usable support found in the reviewed corpus.
Entry workflow

Security questionnaires are where it starts. The reviewed record of what you can prove is what you keep.

When a questionnaire lands, threep turns the reviewed record into cited answers your team can approve without inventing what the evidence cannot support.

Product proof

When evidence runs out, record what is actually true.

GAP and NONE are not the same operating problem. The verifier records the distinction instead of inventing certainty.

Verifier decision

One missing answer. Five honest paths.

The reviewer decides whether evidence exists elsewhere, must still be created, or requires a safe revision or manual judgment.

The verifier did not find supporting evidence in your corpus. What is the actual situation?

Evidence exists outside the knowledge base
Evidence or policy does not exist yet
Accept “no usable evidence” as the answer
Apply the verifier’s safe revision
Other / needs manual review
Record decision✓ Verified — re-run

Illustrative product view using fictional assessment data.

The workflow

Evidence, gap, owner, next action.

One pass turns a live requirement into answers your team can defend — and a record that stays useful afterwards.

  1. Step 01

    A requirement arrives

    A questionnaire, RFP, or control ask lands with a real deadline.

  2. Step 02

    threep retrieves reviewed evidence

    Policies, procedures, and artifacts already in your workspace.

  3. Step 03

    Each answer is classified

    Supported, qualified, or unsupported — STRONG, PARTIAL, GAP, or NONE.

  4. Step 04

    A person approves what leaves

    Reviewer decisions are recorded against each answer.

  5. Step 05

    Gaps name what is missing

    The missing or stale evidence, the owner, and the next defensible action.

  6. Step 06

    The record stays useful

    Reassess as evidence changes, and reuse the record on the next request.

Boundaries

What threep will not do.

threep is bounded on purpose. If a control needs human judgment, it stays with a human.

Invent documentation

If a policy, procedure, or artifact is missing, threep flags the gap instead of pretending it exists.

Claim implementation without evidence

A written policy is not the same thing as an implemented control. threep helps separate documented coverage from operational proof.

Replace compliance judgment

Scope, exceptions, risk acceptance, and official approvals stay with people.

Auto-submit on your behalf

Assessment answers and exports are reviewed and sent by a human.

Certify, scan, or advise

threep does not certify compliance, audit your program, scan live infrastructure, or provide legal interpretation.

Who it is for

The people who own the answer.

Inside that profile, four roles usually carry the work.

Founder · COO

You signed the contract; now you own the proof.

Get from scattered documents to a defensible readiness picture without standing up a compliance department.

Security · compliance lead

You have to say what is true.

See which controls are STRONG, PARTIAL, GAP, or NONE, and exactly what each answer rests on.

Technical PM · operations lead

You are the bridge between the work and the proof.

Track what each control needs, route gaps to the right owner, and keep the record current.

vCISO · fractional compliance practitioner

You carry readiness for several clients.

Per-client workspaces keep each engagement's evidence, gaps, and assessments separate, so one client's posture never bleeds into another's.

Packaging

Three ways to use it.

Early-access terms are scoped with each team.

Starter

Readiness assessment

Early access · for teams that need to know where they stand.

  • Benchmark your documents against a framework
  • STRONG / PARTIAL / GAP / NONE breakdown
  • Prioritized gap list
  • Cited questionnaire answers as an output
Run a readiness assessment
Ongoing · recommended

Readiness workspace

Early access · for teams keeping the record current.

  • Everything in the starter assessment
  • Re-run assessments as evidence changes
  • Gap tracking and reviewer follow-ups
  • Reviewer decisions and audit trail
Get early access
Private deployment

Dedicated environment

Contact us · for teams that need private hosting or stricter data boundaries.

  • Dedicated tenant or private deployment
  • SSO and access-control configuration
  • Private evidence and model-routing options
Talk to us
threep is a hosted SaaS workspace at app.threep.ai.
Founder note

Built from a very specific kind of panic.

Dallas Weber, founder of threep

threep began when a compliance problem landed on my desk without a compliance team attached to it.

At a small, regulated SaaS company, I helped pull together policies, procedures, and evidence under real pressure — the kind of deadline where the work simply has to get done, and it lands on whoever is closest to it.

Getting the documentation in place felt like progress. Then the first questionnaire arrived, and the gap became obvious. I had the policies. What I did not have was a fast, reliable way to prove which policy, artifact, or evidence item actually satisfied the control in front of me.

I did not need another policy template. I needed to know whether the evidence we already had satisfied the control.

That is why threep exists.

Dallas Weber
Founder · threep
FAQ

Common questions.

Does threep answer the questionnaire automatically?

No. threep drafts what your evidence supports and flags everything else. A reviewer signs off on each answer before it is exported, and threep never submits on your behalf.

Why not just use ChatGPT?

ChatGPT can draft an answer from what you paste into a conversation. threep keeps the proposed claim, supporting evidence, claim state, source, human decision, gap, owner, and next action together—so the answer can be defended, reviewed, and reused.

What happens when there is no evidence for a question?

The question is left unanswered, marked NONE, and routed to an owner. threep does not invent a plausible answer — that is the whole point.

Where does my evidence live?

Inside your own tenant in the hosted workspace. Teams that need dedicated infrastructure, custom retention, or private model routing can scope a private deployment.

Does this replace our GRC tool?

No. threep is the record of what you can prove and what you cannot yet claim. It pairs with whatever you use to track controls and policies.

Which frameworks does it support?

It benchmarks your evidence against the control, not a single standard. Teams bring TX-RAMP, SOC 2, HIPAA, NIST, ISO 27001, and client security assessments.

Who reviews the answers?

Someone on your team — usually the security owner, the founder, or a vCISO. The reviewer is logged per answer and shows up in the audit trail.

What does “early access” mean today?

Hands-on onboarding, a single point of contact, and pricing that reflects you being early.

Early access

Start with what you can prove today.

Run a readiness assessment, see the gaps and who owns them, and keep the reviewed record for the next request.

Hosted SaaS workspace · reviewer approval stays with your team · no autonomous submission