SOC 2 Type II · HIPAA Security Rule · NIST CSF 2.0 · CCPA/CPRA · NIST AI RMF 1.0
All-in-one Notion workspace for US compliance and governance programmes.
Manage SOC 2, NIST CSF, HIPAA and AI governance activities through a structured operational workspace covering risks, controls, incidents, audits, vendors and executive reporting.
Designed as a practical alternative to spreadsheets, disconnected documents and expensive GRC software.
Organisation
$590 + VAT
one-time · single organisation · internal use
Consultant
$1,790 + VAT
one-time · single consultant · multi-client
Consultant Pro
$3,490 + VAT
one-time · consulting firm · team use
New to this? Try the free US Starter — 3 core databases, realistic seed data, no credit card.
Try the free Starter →Every database is linked bidirectionally. SOC 2 evidence links to controls. Controls link to risks, findings and audit items. Incidents link to breach notification requirements and safeguards.
Also included: Executive dashboard · 6 report templates (SOC 2 Readiness, HIPAA Security Summary, Risk Register Summary, Vendor Risk Summary, AI Governance Report, Board GRC Report) · Documentation & User Guide · Seed data — MedFlow Technologies scenario
US Compliance Workspace — Organisation
$590 + VAT · one-time · single organisation · internal use
Includes
Licence terms
SaaS companies, healthcare organisations, technology firms and internal compliance teams.
US Compliance Workspace — Consultant
$1,790 + VAT · one-time · single consultant · multi-client
Includes
Licence terms
Independent consultants, security advisors, compliance specialists and virtual CISO providers.
US Compliance Workspace — Consultant Pro
$3,490 + VAT · one-time · consulting firm · team use
Includes
Licence terms
Consulting firms, managed compliance providers and professional advisory teams.
All v1.x updates included. Major version upgrades (v2.0+) offered at discounted pricing for existing licence holders. Full licence terms →
Does this make my organisation SOC 2 compliant?
No. SOC 2 Type II certification requires an independent audit by a licensed CPA firm. This workspace organises your controls, collects your evidence and tracks your readiness — so that when the auditor arrives, you are prepared. It accelerates readiness; it does not replace the audit.
Does this make my organisation HIPAA compliant?
No. HIPAA compliance is an ongoing operational requirement, not a certification. This workspace structures your PHI inventory, tracks your safeguards and documents your risk analysis. It does not replace legal review or constitute a HIPAA compliance certification.
What is the difference between Consultant and Consultant Pro?
The Consultant licence is for a single consultant working across multiple client engagements independently. Consultant Pro adds multiple user seats so an entire consulting team can collaborate internally and share the framework across the firm.
Is this suitable for a pre-SOC 2 startup?
Yes. Many organisations purchase this workspace to structure their security programme before beginning the formal SOC 2 audit process. The seed data shows you what a mature SOC 2 programme looks like inside the workspace.
Where is my compliance data stored?
In your own Notion workspace. AltShift has no access to your data.
Is this legal or regulatory advice?
No. This is a structured operational workspace. It does not constitute legal, regulatory or compliance advice and does not guarantee certification, audit success or regulatory compliance.
Delivered as a Notion workspace — requires an active Notion account. Notion is a trademark of Notion Labs, Inc. AltShift is not affiliated with or endorsed by Notion Labs, Inc. SOC 2 is a service mark of the American Institute of Certified Public Accountants.