Four stages. You only have to be present for two of them.
ConformOps sits above the tools you already run. It collects evidence, maps it to cited rules, holds decisions open until a human makes them, and then keeps operating the file as the product moves.
Time from signup to first result- 0–4 minProduct facts
- 4–6 minSource connected, secrets redacted
- 6–12 minAssessment run, register populated
- thenYour gap queue, in priority order
Write down what you actually ship
Intended purpose, market role, distribution, proposed category, support period, and the Article 32 facts. Six fields and three checkboxes. They stay editable - and every later conclusion points back to them.
- Market role
Manufacturer - Distribution
Commercial product - Proposed category
Default product - Support period
60 months - Article 32 route facts☐ Harmonised standards applied in full☐ Common specification applied☐ European cybersecurity certificate held
Evidence gets collected, redacted and pinned
Repository, ZIP, or just the files that matter. Secrets are redacted before storage, indexing or AI. What remains is a sanitized snapshot bound to a commit, with hashes - so the same run can be reproduced and reviewed.
packages.lock.json218 components resolved.github/workflows/release.ymlSBOM job foundSECURITY.mdintake and disclosure foundappsettings.json L12api credential → [REDACTED]docs/ops.md L44DefaultAdminPassword kept readablebin/, obj/, vendor/excluded
Nothing becomes a conclusion until you say so
Rules are versioned and cited - the Regulation is marked binding, guidance is marked non-binding. Proposals sit as proposals. Approvals are appended, never overwritten, and bound to the exact assessment they were made against.
Optional AI can propose an evidence mapping. It cannot mark a requirement met, approve a risk, pick a route, or sign anything.
- Scope confirmationProduct facts recorded 14 Aug · awaiting accountable confirmationpending
- Classification approvalProposed: default product · no Annex III core functionality identifiedpending
- Risk assessment sign-offTwo product-security risks are still UNASSESSED - no invented likelihoodblocked
- Declaration gateCannot close while a scope, classification, risk or documentation gate is openblocked
Then it operates: releases, clocks, reviewers
Every new release makes a new snapshot and a delta. Reporting cases run the 24h / 72h / final clocks. External assessment work and certificates have a register. Reviewers get a workbook instead of raw JSON.
- Evidence coverage
64% → 71% - New components
+6 - Conclusions invalidated
3 - New OSV matches
1
- Early warning · 24h
filed 03:12 - Notification · 72h
due in 41h - Final report
not yet due