Salvik
Compliance management platform native to the European and Spanish regulatory frame. Its axis is the unified control model: implement once, comply many times. Every cross-mapping carries a confidence level, a justification and a citation, so the mapping can be audited instead of believed.
- Asserted
- “We comply with four frameworks at once.”
- Leaves as
- Requirement served or not, with confidence, justification and citation
- Frameworks
- ISO/IEC 27001:2022 · ISO/IEC 42001:2023 · NIS2 · ENS
- Model
- Unified control with quantified cross-mapping
- Trace
- Confidence, justification and citation per mapping
- Stack
- Next.js · React · TypeScript · PostgreSQL/Supabase
Measured in the open demo
4frameworks Seeded in the data model
265requirements Clauses, Annex A controls, articles and measures from 4 frameworks
85% Of the 26 unified controls serve two or more frameworks
12/15 Of the 15 obligations from arts. 20, 21 and 23 of NIS2 modelled in the demonstration organisation, served by ISO 27001 + ENS
Source: Salvik's demonstration organisation. It does not come from clients.
Which frameworks each demo control serves
12 bands · 26 controls
| Control band | ISO/IEC 42001 |
NIS2 | ISO/IEC 27001 |
ENS |
|---|---|---|---|---|
| Risk management | Serves | Serves | Serves | Serves |
| AI governance | Serves | Does not serve | Serves | Serves |
| Physical security | Does not serve | Does not serve | Serves | Serves |
| Governance & policy | Does not serve | Serves | Serves | Serves |
| Access control | Does not serve | Serves | Serves | Serves |
| Security operations | Does not serve | Serves | Serves | Serves |
| Cryptography | Does not serve | Serves | Serves | Serves |
| Incident response | Does not serve | Serves | Serves | Serves |
| Continuity | Does not serve | Serves | Serves | Serves |
| People | Does not serve | Serves | Serves | Serves |
| Third parties | Does not serve | Serves | Serves | Serves |
| Development | Does not serve | Serves | Serves | Serves |
The order is not alphabetical: the three bands that break the pattern — risk, AI governance and physical security — head the table, and the 42001 column sits against the labels so its shape can be read: two served cells and a block of ten absences. The 27001 and ENS columns are at 100% in this set and therefore sit on the right: they distinguish nothing.
An absence describes this set of controls, not the scope of the standard. ISO/IEC 42001 does cover governance (clause 5.2), people (A.3), third parties (A.10) and lifecycle (A.6): what the column says is that the demonstration organisation holds only 8 AI controls, and 4 of them cross no other framework.
The grid counts bands, not controls: each band groups several of the 26 unified controls, so the 85% in the figures column is not what you read here.
Controls in this band serve this framework None of them serves it in this set
Source: Salvik's demonstration organisation — 4 frameworks, 265 requirements, 26 unified controls grouped into 12 bands. Measured in the open demo; it does not come from clients.