Why we run the system instead of selling the software
We built a compliance platform, watched capable teams struggle to operate it, and concluded we had solved the wrong half of the problem.
CompStack started as a platform. Standards loaded as structured requirements, controls attached, evidence linked, audits generated from real scope. It works, and we still build it every week.
What we kept seeing was a pattern the software did not fix.
The pattern
An organisation carries a certificate. Compliance sits with two or three people who also have other jobs, usually the jobs they were actually hired for. The system is held together by one person's memory and a spreadsheet that lives on their machine.
They buy a platform, which is a rational response. Six months later the platform holds last year's documents, and the audit pack is still assembled by hand in the weeks before the visit.
Nothing went wrong in a way anyone could point at. The person who had no time to run the management system now had no time to run the management system and administer a tool. Buying software moved the work to a different screen. It did not remove it.
What compliance actually fails on
It is almost never knowledge. The compliance managers we work with know their standard better than we do. It is almost never willingness either.
It is timing. A document review that slips a month. Evidence gathered after the fact instead of as the work happened. A finding revisited next cycle in much the same words. Each is small, none is anyone's fault, and together they are why a system that was fine two years ago is not fine now.
Timing is not a software problem. It is a question of who owns the schedule, and in most organisations the honest answer is nobody, because the people it belongs to are busy delivering whatever the organisation exists to deliver. When a delivery deadline and a document review land in the same week, delivery wins. That is the correct call.
So we changed what we sell
We now run the management system. Document reviews, evidence collection, the internal audit programme, findings follow-up, the risk register and the preparation for every certification visit. One fixed monthly fee covers the work and the platform together.
The software did not become less important. It became the place the work lands and the reason the service can be checked. Everything we do sits in a workspace that belongs to the client, so nothing we claim requires trusting us. Log in and look, or read the monthly report and never log in at all. The work is the same either way.
What we gave up
Selling software is a better business on paper. It scales more cleanly, the margins are simpler, and you are not accountable for outcomes you do not control. Running the system means we are on the hook for whether the certificate holds, which is a harder promise and a slower company.
It is also the only version where the thing we sell and the thing the client wants are the same thing. Nobody wants a compliance platform. They want the certificate to hold and the auditor to leave without writing anything.
Where we are honest about the limits
This model does not suit everyone. Organisations with a strong compliance function and the hours to run it should buy the platform alone, and we will price that. Organisations whose deciding factor is price will find a cheaper number elsewhere, and we will say so on the first call.
And we are early. We would rather say that than build a logo wall out of pilots, which is why our proof page is a list of tests you can run on us instead of testimonials you cannot check.
