Independence & ethics
The compliance industry has a trust problem. Viglyn is built to fix it.
Compliance treated as a product to be sold, not a standard to be earned
Much of the compliance industry is structured to make hollow reports easy: template policies copied across hundreds of clients, evidence nobody can verify after the fact, and platforms that sit so close to the auditor that the conclusions are shaped before the examination begins. When the company preparing your compliance program also steers your auditor's opinion, independence doesn't exist, and your report isn't worth the PDF it's printed on.
That's not a paperwork problem. Reports built that way collapse under due diligence, and the companies holding them carry the damage.
The cost of a hollow report
Your enterprise deals depend on it
If your SOC 2 was built on evidence nobody can verify, a single due-diligence call can unravel your biggest contract.
Liability flows downstream
When a vendor's hollow compliance leads to a breach, regulators don't ask who generated the report. They ask who signed off on it.
Re-audits are expensive
Companies caught with certifications that don't hold up face re-audits, lost customers, and reputational damage that takes years to recover from.
Trust is non-renewable
Your customers trust your security posture because of your report. A report that can't survive scrutiny doesn't just risk compliance. It risks that trust.
Independence is the whole point
AICPA professional standards require auditors to be independent of the entities they examine, and ISO certification bodies operate under the same principle through accreditation. That independence is the structural foundation that gives a report its meaning.
- The examination belongs to the independent auditor or certification body, never to us
- Viglyn hosts the workflow: evidence requests, scoped access, comments, workpapers
- You control how deep the auditor's access goes; we control none of their conclusions
Architecture, not assurances
Independence and honesty aren't policies we wrote down. They're decisions built into how the platform works.
True auditor independence
Auditors work in Viglyn through their own scoped access path, with structured evidence requests and audit-scoped comments under clear visibility rules. We never draft conclusions, suggest findings, or influence the examination. The opinion is the auditor's alone.
Evidence that proves itself
Automated evidence is the actual response from your systems, hashed for integrity at capture. Manual uploads carry a full audit trail. Workpapers export with their integrity hashes, so what leaves Viglyn stays verifiable outside it.
Gaps shown as gaps
If a control lacks evidence, it shows as a gap, not a fiction. Failing checks appear in your score with a severity breakdown, and the trend is visible to you before it's visible to anyone else.
Nothing hidden from auditors
Scope control cuts both ways: only in-scope items count toward your score, but out-of-scope items stay visible to auditors, and a reason is recorded for every scope decision. Nothing quietly disappears.
Your data stays yours
Database-level tenant isolation between customers, object-level permissions, and separate scoped access paths for auditors and vendors. Your audit data is never passed around in shared spreadsheets or unsecured links.
A transparent process
Every check result, every scope decision, every risk treatment, and every remediation step is recorded with its reasons. No black boxes, and no mystery reports appearing overnight. If something isn't ready, we tell you.
Five things we will never do differently
- 01
We will never fabricate evidence, test results, or audit documentation.
- 02
We will never pre-write or influence an auditor's conclusions.
- 03
We will never hide a gap. Out-of-scope items stay visible to auditors, and every scope decision records a reason.
- 04
We will never share your confidential audit data outside the audit process.
- 05
We will always tell you the truth about your compliance posture, even when it means more work.
Hold us to it
Book a demo and ask the hard questions. We'd rather earn the trust than assume it.