Getting Started
What frameworks does Matproof support?
Matproof currently supports: DORA, ISO 27001, SOC 2, NIS2, GDPR, CSRD, and BaFin BAIT/ZAIT. Controls are cross-mapped — evidence you collect for one framework automatically counts toward overlapping controls in others.How long does setup take?
The setup wizard takes 15–30 minutes. Reaching meaningful compliance coverage (policies approved, vendors added, first integrations connected) takes 2–4 hours of focused work. See the Onboarding guide for the recommended order of operations.Can I activate multiple frameworks at once?
Yes. Most customers activate 2–3 frameworks from the start. Matproof’s cross-framework control mapping means you won’t collect the same evidence twice for overlapping controls (e.g., ISO 27001 and NIS2 share many security controls).Do I need to be a compliance expert to use Matproof?
No. Matproof is designed for teams without a dedicated compliance officer. The AI policy generator, pre-built control libraries, and step-by-step framework guides are intended to make compliance accessible for engineers, operations leads, and founders managing compliance themselves.Controls and Evidence
Why is a control showing as “Not Started” even though I’ve done the work?
Controls only advance status when evidence is attached. Go to the control, click Add Evidence, and upload documentation, screenshots, or link an integration. Once evidence is reviewed and marked compliant, the control status updates.How long is evidence valid?
Evidence validity depends on the control. Common expiry windows:
Matproof sends expiry reminders 30 days before evidence expires. Configure notification preferences under Settings → User → Notifications.
Can I bulk upload evidence?
Yes. Go to Evidence → Bulk Upload to upload multiple files at once and assign them to controls in batch.Why is my compliance score lower than expected?
The compliance score reflects the percentage of controls in Compliant status. Controls with no evidence, expired evidence, or evidence marked as insufficient reduce the score. Go to Dashboard → Controls by status and filter by “Gap” or “Not Started” to see what’s pulling the score down.Policies
How does AI policy generation work?
Matproof generates policies using your organization context (from Settings → Context Hub) combined with framework-specific templates. The more detail you provide in the Context Hub, the more relevant the output. Generated policies are drafts — you must review, customize, and publish them.Can I import existing policies instead of generating new ones?
Yes. Go to Policies → Import to upload existing policy documents (PDF, Word, or Markdown). Matproof stores them and links them to the relevant controls, but AI-generated policies are generally better structured for audit purposes.Who needs to acknowledge policies?
Policy acknowledgement requirements depend on the policy type:- Security policies (acceptable use, clean desk) — all employees
- Role-specific policies — the relevant role holders
- Management policies — policy owner and senior management