UK SaaS compliance preparation

Get compliance-ready, calmly.

TrueComply turns a 15-minute questionnaire into a tailored SOC 2 & UK GDPR draft pack, delivered within 48 hours — so the next time a customer or investor asks about your security posture, you have a considered answer.

Draft documents for preparation — not legal advice or certification.

Illustrative sample pages — every pack is generated from your own answers.

48hDraft pack delivery
8Tailored documents
15 minOf your time
£0Pilot cost
The situation

Compliance questions arrive before you're ready for them

A customer's procurement team, an investor's diligence list, a partner's legal counsel — someone will ask. The usual options each have a catch.

Consultants are excellent — later

Thorough and credible, but engagements start north of £10,000 and are designed for companies further along than you are today.

Templates fool no one

Generic documents don't reflect your actual stack, data flows or team — and the people reviewing them can tell within a page.

Doing it alone costs weeks

Evenings spent reading ICO guidance and SOC 2 criteria without knowing what "good" looks like, or where to begin.

What you receive

Eight documents, tailored to how your company actually works

Generated from your answers about your business, data, tools and team — then delivered as an editable, branded pack you can review, refine and share.

1
Executive summaryWhere you stand and what matters first
2
UK GDPR data handling policyCollection, processing, storage and lawful bases
3
SOC 2-style access control policyWho can access what, and how it's governed
4
Incident response policyWhat happens when something goes wrong
5
Risk registerYour key risks, scored and owned
6
Gap analysisWhat sits between today and audit-ready
7
30-day action checklistPrioritised next steps your team can actually take
8
Branded PDF exportReady to share with clients, investors and advisors
A look inside

Sample pages from a draft pack

Illustrative examples of the format and level of detail — your pack is generated from your own answers, stack and data flows.

UK GDPR Data Handling Policy
TC-POL-001 · v1.0 · Prepared for review
DRAFT
§ 1.1 — Purpose

This policy defines how [Company] collects, processes and stores personal data in accordance with the UK General Data Protection Regulation and guidance issued by the Information Commissioner's Office.

§ 1.2 — Scope

This policy applies to all employees, contractors and systems that collect, process or store customer or employee personal data, including the third-party tools listed in the sub-processor register.

§ 2.1 — Lawful bases for processing

Personal data is processed only where a lawful basis under Article 6 applies. For each processing activity, the applicable basis is recorded in the data inventory maintained by the data protection lead.

§ 2.2 — Data minimisation

Only personal data necessary for the stated purpose is collected. Fields, logs and analytics are reviewed quarterly to remove data no longer required.

ILLUSTRATIVE SAMPLE · ALIGNED: UK GDPR · ICO GUIDANCEPAGE 1 OF 9
Risk Register
TC-RSK-001 · Scored, owned, reviewed monthly
MFA not enforced on all admin toolsOwner: CTO · Likelihood: High · Impact: HighHIGH
No formal employee offboarding processOwner: Ops · Likelihood: Medium · Impact: HighMEDIUM
Sub-processor register incompleteOwner: Founder · Likelihood: High · Impact: MediumMEDIUM
Backup restoration untestedOwner: CTO · Likelihood: Low · Impact: HighMEDIUM
ILLUSTRATIVE SAMPLE
30-Day Action Checklist
TC-ACT-001 · Prioritised from your gap analysis
Week 1Enforce MFA across all admin toolsCloses your highest-severity risk first
Week 1Appoint a data protection leadA named owner for policies and requests
Week 2Publish the incident response runbookFrom draft policy to working procedure
Week 3Complete the sub-processor registerEvery tool that touches personal data, listed
ILLUSTRATIVE SAMPLE
In development — pilot members get first access

Your pack doesn't gather dust. It stays alive.

Documents drift out of date the day they're written. The TrueComply portal keeps yours honest: every policy maps to named checks, owners re-confirm them on a schedule, and your readiness score moves as your company does.

CHECKS

31 attested checks

Each policy claim becomes a check with a named owner — passing, failing, or awaiting an answer. No mystery about where you stand.

RE-ATTESTATION

Quarterly re-confirmation

Owners are asked to re-confirm on a schedule that matches how fast things change. Nothing to remember; nothing silently stale.

EVIDENCE

A timestamped trail

Every answer, change and document version is logged. When a customer asks "since when?" — you have the receipt.

How it works

Three steps. One evening of your time, at most.

STEP ONE

Answer a short questionnaire

Your business, the data you handle, your tools, team size and current security practices.

About 15 minutes
STEP TWO

We prepare your draft pack

AI drafts structured documents from your answers, aligned to UK GDPR and SOC 2 preparation, and each pack is reviewed for coherence before it's sent.

We do the work
STEP THREE

Delivered within 48 hours

A clear, editable, branded pack arrives in your inbox — ready to review with your team or share with the people asking questions.

24–48 hours
Our promise to you

We'll always be precise about what this is

What you can expect

  • A fast, structured documentation starting point
  • A clear view of your gaps and what to address first
  • Genuine preparation before engaging consultants or auditors

What we'll never claim

  • That this constitutes legal advice
  • That it's ICO certification or a formal SOC 2 audit
  • That it guarantees compliance

In plain terms: TrueComply provides AI-assisted draft documentation for preparation purposes only. Always consult a qualified legal, security, or compliance professional before relying on any documentation for formal audits or regulatory decisions. In compliance, trust is the product — overclaiming would be a strange way to earn yours.

The free pilot

We're welcoming a small cohort of UK startups

FreeNo credit card · In exchange for honest feedback · Limited places
  • 15-minute onboarding questionnaire
  • One complete 8-document draft pack
  • Branded PDF report
  • Optional feedback call
  • First access to the living portal when it launches
Pilot applications are temporarily pausedSecurity and privacy controls are being completed before collection resumes

TrueComply is not collecting pilot applications through this website until the production intake path has server-side validation, abuse protection, processor review, and final legal terms.

When applications reopen, submissions will be handled through a Cloudflare-protected endpoint rather than a direct third-party form post.

Register interest by email

Please do not send confidential customer data, credentials, special category data, or full compliance questionnaires by email.

Questions

Asked often, answered honestly

Is this legally binding advice?

No. TrueComply provides AI-assisted draft documentation. Speak with a qualified legal, security, or compliance professional before relying on documents for formal audits or legal decisions.

Is this only for UK companies?

The current pilot is focused on UK-based startups and UK GDPR preparation.

How long does it take?

About 15 minutes of your time for the questionnaire, and your draft pack is delivered within 24–48 hours.

We already have some policies — is this still useful?

Yes. Include what you have in the questionnaire, and the pack helps identify missing or weak areas rather than starting from zero.

What is the living portal?

A private page where your pack stays current: each policy maps to named checks, owners re-confirm them quarterly, and every change is logged with a timestamp. It's in development — pilot members get first access. Readiness tracking is self-attested and remains a preparation tool, not certification.

What happens to the data I share?

This website is not currently collecting application or questionnaire data. When intake reopens, TrueComply will publish the live Privacy Policy, sub-processor list, retention periods, and deletion route before accepting submissions.