← All help articles
Security policy generator
Draft audit-ready security policies from your live posture, with unconfirmed controls flagged as actions rather than claimed as done.
Auditors, insurers, and enterprise buyers all ask for written security policies. Rather than starting from a blank template you can't honestly stand behind, the policy generator drafts each policy from what we can actually see in your account — and is upfront about what it can't confirm.
What it does
- Offers a catalog of common security policies (access control, data handling, incident response, and more).
- Generates a ready-to-adopt draft for the policy you pick, populated from your live posture.
- Is honest by construction: a control we can confirm from your account is written up as in place, while anything we can't confirm is flagged "Action required" — never dressed up as done. What you send to an auditor matches reality.
- Reflects the compliance frameworks you're already tracking, so the language lines up with the standards you're being measured against.
How to set it up
- Open Security Policies.
- Pick a policy from the catalog.
- Generate the draft and review the preview.
- Adopt or export the document, then complete any "Action required" items and regenerate to fold them in.
The more of your posture we can see — domains added, integrations connected, findings resolved — the more of each policy fills in automatically instead of landing in the action list.
How to read your results
- Each generated policy is split into sections. Sections backed by a confirmed control read as done; sections we can't verify are clearly marked "Action required."
- Treat the action items as a short to-do list: finish them (for example, publish a privacy notice or turn on a missing control), then regenerate so the policy reflects the improvement.
- Because the draft is grounded in real signals, you can hand it to an auditor or a prospect knowing it won't over-claim on your behalf.
Related: Compliance & SOC 2 readiness explains the framework posture these policies draw on.