> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Started with Compliance

> Get started with Iru Compliance: frameworks, controls, actions, evidence, sources, and Trust Center. Follow the recommended setup order and core concepts.

Iru Compliance helps you run frameworks such as **SOC 2** or **ISO 27001**, collect evidence against controls, and publish a **Trust Center** for customers and auditors when your subscription includes it. Follow **Recommended setup** below: complete **Organization profile**, add frameworks, connect **Sources**, and work **Actions**. For who can add frameworks, connect integrations, edit Trust Center, and other tasks, see [Compliance Permissions](/en/compliance/compliance-permissions).

<Info>
  Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support).
</Info>

## About Iru Compliance

You can add standards such as **SOC 2**, **ISO 27001**, **ISO 42001**, and **HIPAA** in your tenant. Other catalogs (for example **GDPR**, **NIST CSF**) appear when your tenant makes them available. Open **Frameworks** to see what you can add.

Iru uses your **organization profile** (industry, company size, tech stack, and security tooling) so generated **controls** match how you work. After setup, when connected **Sources** or policy **artifacts** change, [Adaptive Compliance](/en/compliance/adaptive-compliance) can propose updates to control and action text so your frameworks stay aligned with how you operate. **Trust Center** is optional: it publishes approved certifications and documents externally. See [Trust Center Management](/en/compliance/trust-center/trust-center-management).

## Recommended Setup

<Steps>
  <Step title="Navigate to the Account Menu Button">
    In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu).
  </Step>

  <Step title="Open Organization profile">
    Select **Organization** to open **Organization profile**. Iru may prompt you while you add a framework.

    <Frame>
      <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-org.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=f8a368153bc4b87d3a4aa49961d54a20" alt="Account menu with Organization option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-org.png" />
    </Frame>
  </Step>

  <Step title="Enter edit mode">
    On **Organization profile**, click **Edit** at the top right.
  </Step>

  <Step title="Complete your company details">
    Fill in the fields that apply. For example: **company logo**, **company name**, **business description**, **industry**, **business type**, **company size**, **company language**, whether you have an **IT department**, and **security team size**. Keep this information current as your environment changes.
  </Step>

  <Step title="Save your changes">
    Click **Save changes**.
  </Step>

  <Step title="Add a framework">
    On the left navigation bar, expand **Compliance** and select **Frameworks**. Use AI-assisted setup, CSV import, migration from a supported product, or a custom framework. See [Frameworks Management](/en/compliance/frameworks-management).
  </Step>

  <Step title="Connect sources">
    Expand **Compliance** and select **Sources**. Turn on the **toggle** for each integration that should supply evidence (identity, HR, cloud, code hosts, and others). See [Sources Management](/en/compliance/sources-management).
  </Step>

  <Step title="Assign actions">
    Expand **Compliance** and select **Actions**. Review **actions**, assign owners, set due dates, and attach or confirm evidence. See [Actions Management](/en/compliance/actions-management).
  </Step>
</Steps>

## Core Concepts

**Frameworks**\
Standards your organization tracks. You can run several at once; one piece of evidence can cover more than one obligation when requirements overlap.

**Controls**\
Requirements mapped to the framework. They may come from AI generation, import, or manual entry.

**Actions**\
Tasks linked to controls. Descriptions tell the product and connected **Sources** what evidence to collect.

**Artifacts**\
Files and records (policies, exports, screenshots, logs, reports) tied to actions and controls. See [Artifacts Management](/en/compliance/artifacts-management).

**Sources**\
Integrations that pull or attach evidence for the actions they support. See [Sources Management](/en/compliance/sources-management).

## What You Can Do Next

* Turn framework language into controls and actions with owners and due dates.
* Gather evidence manually or through **Sources**; validate artifacts where the product supports it.
* Track readiness from framework and action views.
* Review Iru AI control update recommendations when integrations or policies change. See [Adaptive Compliance](/en/compliance/adaptive-compliance).
* Publish selected content through **Trust Center** when your plan includes it.

## Related Articles

* [Frameworks Management](/en/compliance/frameworks-management): add frameworks, imports, and migrations.
* [Adaptive Compliance](/en/compliance/adaptive-compliance): review and approve Iru AI recommendations when controls should reflect new integrations or policies.
* [Platform Workflows](/en/compliance/platform-workflows): how profile, frameworks, sources, actions, and evidence connect.
* [Sources Management](/en/compliance/sources-management): connector guides by category (use search and **Category** on **Sources**).

## Related Product Documentation

* [Iru Overview](/en/iru/platform-overview/iru-overview): how Endpoint, Identity, Compliance, Trust Center, and Iru AI fit together.
* [Getting Started](/en/endpoint/getting-started/getting-started): Endpoint setup from foundation through platform setup, Blueprints and Library, and enrollment; pair with the [Iru Endpoint Compliance source](/en/compliance/sources/iru-endpoint-source) when controls need device evidence.
* [Team Member Role Permissions](/en/iru/access/team-member-role-permissions): organization roles (alongside [Compliance Permissions](/en/compliance/compliance-permissions)).
