Pentest Today.
policy generator

Every policy an enterprise security review asks for

Generate tailored security policies, plans, and diagrams from a short intake — written for your stack and ready to attach to a partner's security questionnaire.

Security policies

17
access-control.mdSOC 2 · CC6.1

Access Control Policy

Defines how identities are provisioned, authenticated, authorized, and deprovisioned across your systems.

cryptography.mdSOC 2 · CC6.7

Cryptography Policy

Sets standards for encryption in transit and at rest, key management, and approved algorithms.

data-handling.mdSOC 2 · CC6.5

Data Handling & Classification Policy

Classifies data by sensitivity and defines handling, storage, and disposal rules for each tier.

vendor-risk.mdSOC 2 · CC9.2

Vendor Risk Management Policy

Governs how third parties are assessed, onboarded, and monitored for security risk.

change-management.mdSOC 2 · CC8.1

Change Management Policy

Ensures changes to systems are reviewed, tested, approved, and tracked.

risk-assessment.mdSOC 2 · CC3.2

Risk Assessment Policy

Defines how risks are identified, scored, treated, and reviewed.

acceptable-use.mdSOC 2 · CC1.1

Acceptable Use Policy

Defines acceptable use of company systems, devices, and data by employees.

password.mdSOC 2 · CC6.1

Password & Authentication Policy

Sets password strength, MFA, and credential management requirements.

data-retention.mdGDPR · Art. 5

Data Retention & Deletion Policy

Defines how long data is kept and how it's securely deleted.

backup.mdISO · A.8.13

Backup & Recovery Policy

Ensures critical data is backed up, encrypted, and restorable.

vuln-management.mdSOC 2 · CC7.1

Vulnerability Management Policy

Defines how vulnerabilities are scanned, triaged, and remediated within SLAs.

security-training.mdSOC 2 · CC1.4

Security Awareness Training Policy

Requires regular security training for staff and tracks completion.

information-security.mdSOC 2 · CC1.1

Information Security Policy

The umbrella policy that states your security objectives, scope, and who is accountable for them.

secure-sdlc.mdSOC 2 · CC8.1

Secure SDLC Policy

Defines how security is built into design, code review, testing, and release rather than bolted on afterwards.

ai-governance.mdISO 42001 · Clause 5

AI Governance Policy

Establishes who owns AI risk, how new AI use cases get reviewed, and what is recorded about them.

ai-acceptable-use.mdISO 42001 · Annex A

AI Acceptable Use Policy

Sets the rules for staff using AI tools: what may be pasted into them, what must never be, and who approves new tools.

ai-vendor-review.mdSOC 2 · CC9.2

AI Vendor Review Policy

Defines how AI vendors and subprocessors are assessed before they touch your data, and re-assessed after.

Security plans

2

Audit deliverables

1