Live IT & MSPCompliance & GRC Operational · v0.1.0

ControlLedger

Run the controls. Keep the proof. Schedule the recurring controls you run for each client, attest them with evidence, and hand insurers and auditors a dated Evidence Pack in one click.

The problem, in your words

Insurers and auditors ask MSPs for proof of tested backups, access reviews and MFA, and the evidence lives in spreadsheets, ticket notes and Slack. GRC platforms map frameworks at a per-client price but do not run the recurring work.

“A typical one means chasing evidence from four or five places… we were the ones digging through two platforms at 9pm to piece it together. Controls were all there, we just could not surface them cleanly under pressure.”

“I work at an MSP and do 90% of the audits. Some (40%) of companies are asking for proof of tested backups. Proof of when we last did user/security audits. Proof of MFA.”

“The thing neither tool handles especially well: running the actual recurring compliance work. Who does the quarterly access review… At MSP scale across multiple clients, this tends to live in spreadsheets and Slack until you outgrow it.”

How it works

  1. Add a client, apply a control set: pick "MSP default 8", "HIPAA lite" or "Cyber-insurance renewal basics", assign a technician; ControlLedger computes every next-due date.

  2. Log each result with evidence: the assignee records pass, fail, exception or not applicable, attaches the screenshot or export, and can request a client co-sign by magic link.

  3. Generate the Evidence Pack: choose a client and date range; the PDF carries the control matrix, attestation log, file hashes, exceptions, co-signatures and an insurer summary page.

What you get

Screenshots

ControlLedger: landing
ControlLedger: landing
ControlLedger: dashboard sample
ControlLedger: dashboard sample
ControlLedger: apply controls
ControlLedger: apply controls
ControlLedger: dashboard applied
ControlLedger: dashboard applied
ControlLedger: evidence pack page
ControlLedger: evidence pack page
ControlLedger: pack generated
ControlLedger: pack generated
ControlLedger: verify
ControlLedger: verify

Pricing

Flat monthly prices. Limits are enforced with upgrade prompts, never by losing data. Cancel any time from the app's billing page. Refund policy.

Free

$0

  • 1 client
  • 1 user
  • Full control library
  • Evidence Pack PDF
Start free

Solo

$29 per month

  • 5 clients
  • 3 users
  • Reminders and digests
  • Client co-sign
  • Zip export
Start on Solo

MSP

$79 per month

  • Unlimited clients
  • 10 users
  • Client share links
  • Your logo on packs
  • Priority support
Start on MSP

Questions

Where is my evidence stored and who can see it?
On our servers, hashed on upload, served only to signed-in users of your account or through expiring links. You set a retention period; an archived client's files are hard-deleted after 30 days.
What happens when I cancel?
Billing stops at the end of the period and the account returns to Free limits; records stay readable. Generate a final Evidence Pack and zip per client first. Email [email protected] to have the account and its files deleted.
Does it replace our GRC platform or PSA checklists?
No. GRC platforms map frameworks and policies; PSAs run tickets. ControlLedger runs the recurring controls and keeps the proof: schedule, attestation with evidence, and the pack you hand to a carrier or auditor.
Do clients, insurers or auditors need an account?
No. A client contact co-signs through a magic link that covers one attestation and expires in 14 days. Insurers and auditors receive the PDF, the zip or an expiring read-only share link. Only your technicians log in.
Is this legal, insurance or audit advice?
No. Every pack states that it records attestations made by your account. ControlLedger does not judge whether a control is adequate or make anyone compliant. Your client signs their own carrier forms; the pack is the evidence behind the signature.
How do I get my data out?
Generate an Evidence Pack for any client and date range: a PDF on every plan, plus a zip of every evidence file on Solo and MSP. Each file's SHA-256 is printed in the pack; /verify confirms a pack hash while the account exists.

What it is not

Guides