Step 1 · Discover
Guided discovery interview
Seven plain-language sections — company, service, customer journey, systems, team, vendors, buyer requirement — autosaved as you talk.
One afternoon
Assurance readiness · small B2B software teams
Describe how your business works. rheAI maps your services, processes, systems and risks, then generates the control package your auditor can review.
Map the work. Build the controls.
Pilot teams · anonymised at their request
Inside the platform
Each step feeds the next, so the package you export is traceable back to the interview where you described how the work happens.
Step 1 · Discover
Seven plain-language sections — company, service, customer journey, systems, team, vendors, buyer requirement — autosaved as you talk.
One afternoon
Steps 2–3 · Scope & processes
Services, processes, steps, systems, data and vendors laid out as a map, with a source badge on every AI-drafted item.
Signup
AI draft
Onboarding
human
Scheduling
AI draft
Payroll feed
human
Support
AI draft
Offboarding
human
1 real process, end to end
Steps 4–6 · Risks, controls, matrix
Risks need an objective and a named owner. Controls need the five W's plus expected evidence before they can claim to be in place.
Unauthorised access to payroll data
Quarterly access reviewIn place
Schedule pushed without approval
Two-person release checkIn progress
Vendor outage unnoticed
Monthly vendor reviewGap
Accept · edit · reject
Step 7 · Evidence
Requests per control, templates where nothing exists, SHA-256 on upload and an AI review that flags what an auditor would question.
Private bucket · never a public URL
44 items · 40 accepted
Step 8 · Test plan
Design tests written against your own controls, with the population, sample and expected artefact spelled out for the auditor.
Design-effectiveness ready
Step 9 · Report & share
Immutable report versions, a bundled export, and a revocable read-only link so your auditor can look inside while every view is logged.
Type I readiness package · v3
Report shell · RCM · processes · evidence list
Auditor link active
7 views logged · revoke anytime
Export · read-only link
Nine steps with progress, tooltips and a strong nudge to the right next move.
A tooltip-launched assistant that answers process questions in the step you're standing in.
Every suggestion labelled with source, timestamp and the person who accepted it.
Owner, contributor, viewer and auditor roles, with MFA required before upload or export.
The rheAI agent
Most readiness tools give you a checklist. rheAI gives you a working partner that proposes the next risk, rewords a control, explains what the auditor is looking for, and warns you before a gap becomes a blocker.
rheAI agent
Step-aware guidance
Step 3 · Risks
You mentioned payroll access. Teams like yours usually map 'unauthorised payroll changes' and 'access not revoked after offboarding'.
Step 5 · Controls
This control needs a named owner before it can be marked as in place. Suggest assigning the Head of Operations.
Step 7 · Evidence
Add a quarterly access review screenshot here. The auditor will look for reviewer name, date and scope.
Human-validated before anything enters the package
Interactive demo
Click through the readiness path. The agent changes its guidance at every stage — from interview questions to control wording, evidence requests and the final package.
Step 1 · Discover
rheAI agent guidance
Workspace preview
Start with the enterprise request and how your business actually works, not with a framework.
The problem
Enterprise buyers increasingly ask for assurance. Small software teams lose the deal because their processes, controls and evidence are not ready for an auditor to do anything useful with.
Normal readiness implementation
~€25k
Consultant-led project, before independent audit fees.
rheAI founding pilot
€499
For the practical package. The shortest route to materials the auditor can review.
rheAI does not give an assurance opinion and does not replace your auditor. It prepares the organisation for independent assurance.
Framework, not checkbox theatre
Off-the-shelf control libraries force you to adopt language that does not match how you operate. rheAI starts from your services, customer journey, systems and vendors, then builds a control framework that is actually owned by your business.
The controls reflect how you make money, who your customers are, and what they rely on — not a generic SaaS template.
We scope the boundary around what matters to your buyer and your growth plan, so effort goes where the audit risk is.
Every process, risk and control is written in terms your team recognises, with named owners your auditor can interview.
rheAI helps you set up exactly that: a framework shaped around your business, not a compliance layer bolted on top of it.
Inside the workspace
The same views your team works in: the nine-step path, control coverage per process, residual risk position and the evidence a person actually accepted.
Readiness gauge
Every step unlocks the next, so the links between service, risk, control and evidence stay honest instead of assembled at the end.
The readiness path
Risk and control matrix
Evidence vault
Illustrative figures from a pilot-sized workspace.
Pilot stories
“We went from the buyer's security questionnaire to a draft control package in three weeks. It would have taken us three months to produce the same thing internally.”
CTO
HR SaaS, 18 people
“For the first time I could point at a risk matrix and say 'here is exactly how we cover it'. The process descriptions actually made sense to our auditor.”
Head of Operations
Vertical SaaS, 12 people
“We had a €25k consultant quote on the table. rheAI gave us an auditor-ready package for a fraction of that, and we owned every word in it.”
CTO
B2B SaaS, 9 people
“The evidence vault alone saved us two weeks of chasing screenshots and policies. Everything is hashed, named and linked back to a control.”
Security Lead
Logistics SaaS, 22 people
Impact
0+
Pilot teams supported
0+
Weeks saved per team
€0k
Average cost avoided vs consultant-led readiness
0
Days to first reviewable package
Narrow use case
A 14-person restaurant HR SaaS handles onboarding, scheduling and payroll support. A listed customer asks for a SOC/ISAE report before signing.
rheAI interviews the team, maps the service flow, identifies risks and controls, and exports a Type I readiness package — process descriptions, RCM, evidence list and report shell.
Business-first control design
The control boundary emerges from your customer journey, systems, vendors and owners — not from a generic checklist.
Deliverables
Services, processes, systems, data flows, vendors and owners — mapped from your real customer journey.
Narratives an auditor can actually read, written from one end-to-end interview per in-scope process.
Risks per process with control name, owner, frequency, control type and status.
Expected document per control, templates where nothing exists, and an implementation tracker.
Report shell, RCM, process descriptions and evidence list, bundled as an auditor handover pack.
Every AI proposal carries source, timestamp, status and the person who accepted it.
Six weeks to proof
What we need from you
Usually a founder, CTO or ops lead. They answer the discovery interview — no compliance background needed.
The questionnaire, contract clause or email asking for a report. It sets the scope of the package.
Cloud, code, identity, ticketing, payroll, support. Names are enough; we map the rest with you.
Controls need someone accountable. Two or three names is normal for a small team.
Whatever already exists — policies, screenshots, exports. We tell you what is missing rather than assuming.
That is the interview. Everything after that is review and evidence upload in short sessions.
Control & transparency
A buyer isn't looking for a claim that you are safe. They want to see who owns what, how it works, and the proof behind it. rheAI is built so every answer you give can be traced back to something real.
Every control names the person accountable, so nothing sits in a grey zone during review.
Service, process, risk, control and evidence stay linked end to end — a buyer can follow any claim to its source.
Each control points at the artefact that proves it, instead of a paragraph saying it happens.
Every line is labelled as drafted from your documents, suggested by rheAI or written by your team.
Read-only package links are scoped to a version, expire, log every view and can be revoked.
When the buyer asks how you know, you have the boundary, the matrix and the evidence in one place.
And because you describe confidential systems, customer flows and evidence in here, the platform itself is held to the same standard:
EU-hosted infrastructure with encryption in transit (TLS 1.2+) and at rest. No customer evidence leaves the region for processing.
Role-based membership (owner, admin, contributor, reviewer) enforced by row-level security in the database, plus mandatory MFA before upload or export.
Every file is SHA-256 hashed and versioned on upload, so you can prove to an auditor that the artefact reviewed is the artefact collected.
Model calls run server-side only, with unnecessary personal data stripped first. Your content is not used to train models, and every draft is labelled AI-suggested until a person accepts it.
Read-only links are scoped to a package version, expire, log every view, and can be revoked instantly.
Append-only audit log of who changed, accepted or exported what, and hard deletion of your workspace on request.
Need our control summary or a DPA for your own vendor review? Email help@rheai.app and we send it the same day.
Pricing
Free
Understand what your buyer is really asking for.
No card needed.
Start free€499
Pay when you are ready to build the auditor package.
One-off per readiness project. Your independent auditor's fee is separate and never paid to rheAI.
Request pilot accessQuestions
No. rheAI prepares management-owned readiness material — your control boundary, process descriptions, risks, controls, evidence and a draft Type I package. An independent auditor decides the procedures they run and any opinion. rheAI never certifies anything.
Most teams get through discovery in an afternoon and reach a reviewable package in two to four weeks, depending on how quickly evidence can be gathered from the systems you already use.
No. The workspace is built for founders, engineers and operators. Every step asks plain questions about how the work actually happens, and the guide inside the portal explains what an auditor is looking for.
It drafts. It proposes processes, risks and control wording from your interview answers, and every draft is labelled as AI-suggested until a person in your team accepts it. Nothing enters your package without a human decision.
In private storage that is only reachable from your workspace. Files are hashed on upload so you can show an auditor that what they review is what you collected.
Yes. You create a read-only link scoped to the package, every view is logged, and you can revoke it whenever you like.
Each control names the exact document or screenshot an auditor expects, who owns it, and the period it must cover. You upload it once into the evidence vault; rheAI hashes it, versions it, checks it against the control's attributes and flags anything missing or contradictory before your auditor sees it.
Discovery takes an afternoon. Scope, processes, risks and controls usually land inside week two. Most pilots reach a reviewable Type I package in two to four weeks; the pace depends on how fast control owners return evidence, not on us.
It makes you Type I readiness ready: a defined control boundary, process descriptions, a risk and control matrix, evidence per control and a design-effectiveness test plan, packaged for handover. The opinion itself is issued by a licensed audit firm — rheAI prepares everything they ask for and shortens their fieldwork.
No, and we would not want to. Independence matters. We prepare the readiness package and the evidence trail so your audit firm can start on the assessment instead of chasing basics.
You export your package and we hard-delete the workspace on request, including evidence files and AI proposal history.
Contact
Send the security questionnaire, the buyer's email, or the request you are stuck on. We answer within two working days and tell you honestly whether rheAI helps.
Get in touch
help@rheai.appSupport, security questions and pilot enquiries all reach the same small team.
Request pilot accessStart your readiness workspace in minutes. Tell us what your buyer asked for and we'll reply with a clear path to your auditor-ready package — usually within two working days.
Already have a workspace? Sign in