Your documents passed the last audit. Then eighteen months happened. Luescor reads every SOP and policy you have, maps each one to the controls you are assessed against, and shows you where the evidence stopped holding up, while there is still time to fix it. Your documents never leave your cloud.
30 minutes. Send one policy beforehand and watch it get assessed.
A process changes. Someone leaves. A tool is replaced. Each one is small, none of them triggers a document review, and the procedure on file goes on describing a company that has quietly stopped existing. Nobody finds out until an assessor reads it back to you in a room.
The way something is done changes on a Tuesday. The document describing it changes when somebody remembers, which is usually never. Nothing in between flags that the two no longer agree.
Which document satisfies which control usually lives in a spreadsheet built once, by someone who has since moved on, and never verified against the documents again.
A finding against a document you believed was fine means a corrective action, a response deadline, and a re-assessment. On CMMC it can mean contract eligibility you cannot afford to pause.
Compliance automation platforms connect to your stack and check configuration continuously. They do that well. They were never built to read the procedures on your file server and tell you whether they still describe what you do.
Continuous and automated. Everything here is a machine state that can be queried, so it can be re-checked every few minutes forever.
No integration can answer this. It takes reading the document against the requirement, and noticing when the two stopped agreeing.
Connecting takes minutes and the first results land the same day. The third step is the one every other tool hands back to you.
Point Luescor at SharePoint, an S3 bucket, or an Azure container. Documents are read where they already sit. Nothing is copied onto our infrastructure, and access is scoped to the one location you nominate.
Each document is read requirement by requirement. You get the passage that satisfies a control, a plain description of what is still missing, and a count of the requirements nothing in your library answers.
Versions, review dates, and sign-off on every document. When something falls out of date you hear it from us with months to spare, instead of from an assessor with days.
If most of your evidence comes from cloud integrations, a compliance automation platform will serve you better. Luescor is for the other case.
Contractors and subcontractors where a written procedure is the artifact an assessor examines, and much of the environment is on-prem or air-gapped.
Bodies whose entire management system is documentation, assessed against a standard with over a hundred clauses and no integration that can prove any of it.
Organizations running significant on-premise, custom, or legacy systems. Once automated evidence collection has taken what it can, most of what is left to prove is documentation.
Not "you should have an access control policy." The specific requirement, the sentence in your document that answers it, and a straight answer where nothing does. CMMC Level 2 is 110 practices. ISO 17011 is 155 clauses. Each one gets its own verdict.
Every output is an artifact an assessor will accept, not a dashboard screenshot you have to talk them through.
Coverage per control with the evidence cited, ready for an assessor or for your board.
Where nothing covers a control, a draft written from your own context and marked clearly for review. Never invented as fact.
Version, author, approver, date. Written as it happened rather than reconstructed under deadline.
Every unmet requirement, what is missing in plain language, and who owns closing it.
Most compliance tools are built for the six weeks before an assessment. Those six weeks are expensive precisely because of everything that went unrecorded before them. This is the part that stops the next six weeks from happening.
What changed, who approved it, when. The history an assessor asks for already exists by the time they ask.
Every document carries an interval. Overdue ones appear on your screen before they appear in someone else's finding.
Who approved which version, and when, recorded at the time. Not reconstructed from memory and an email thread on the week of the assessment.
This is the first question every security team asks, so here is the direct answer.
Then you should not buy this, and we will say so. The first assessment is what we lead with because it is the fastest way for both of us to find out whether there is a problem here worth paying to solve. If your mapping is current and your documents genuinely say what you do, you do not need us. Establishing that in week one costs you half an hour. Establishing it in month six costs considerably more.
Underneath it, on the part it does not reach. Those platforms query system state, and system state is queryable, so they do it continuously and well. A procedure is not a system state. Whether it still describes how your team works is a reading problem, not an integration problem, and it is the part those platforms hand back to you as a policy template to fill in. If your evidence is mostly cloud configuration, start with one of them. If most of what an assessor will read is documents, that is the gap we sit in.
Tell us which one. Frameworks are loaded as control text rather than built into the product, so the list reflects what has been loaded so far rather than what is possible. Internal standards and customer-specific requirement sets have the same shape as a published framework and are handled the same way. It is worth a conversation rather than an automatic no.
No, and the distinction matters more here than almost anywhere else. Where a control has nothing behind it, Luescor produces a draft from your own organizational context and marks it as a draft. It will not describe a process you do not have, it will not claim a control is met because a draft exists, and it does not approve anything. A named person still reviews and signs every document, and the record shows that they did. An assessor is entitled to ask who approved a procedure, and "the software" is not an answer that survives the question.
Both are supported. SharePoint connections resolve the tenant's cloud automatically and work against commercial, GCC High, and DoD. On-premise is less of an edge case than it sounds: because Luescor assesses documents rather than querying systems, an air-gapped environment produces exactly the same result as a cloud-native one. It is usually the environments with the least automation coverage that have the most documentation to prove.
Documents and results sit in storage you own and control, which is covered in full above. The question that section does not answer is the AI one: model calls are made to Anthropic and OpenAI, and by default they run under our accounts. You can supply your own API keys for either provider, in which case that processing runs under your agreements and your terms with them rather than ours. Luescor is hosted on commercial cloud infrastructure and is not FedRAMP authorized, which is worth knowing early if you are scoping a CUI boundary.
Nothing moves. Your documents, coverage history, notes, and generated procedures are already in your own bucket in open formats, because that is the only place they have ever been. There is no export process, no data request, and no window to act inside. Losing access to Luescor means losing the tool that reads them, not the work it produced.
The first assessment runs once storage is connected, and the number that matters arrives with it: how many requirements currently have nothing behind them. That number usually lands higher than the team expected. Getting it early is uncomfortable, and it is the entire reason to run it now rather than on the eve of an assessment, when the same number stops being a work item and becomes a schedule problem.
A working session, not a slide deck. Send a single document ahead of the call and we will map it to your framework on screen, clause by clause, while you watch. If it comes back clean, we will tell you that too.
Book a demo30 minutes · One document · No preparation needed