FAQ

Frequently asked questions

The straight answers, before you start.

How accurate is the AI's assessment?

Every AI-generated rating, narrative and gap finding is a starting point, not a final answer: it's always editable by you before it counts as final. That's a deliberate, non-negotiable design principle behind Varða, not a footnote. Assessments are judged against the real evidence you attach per control (documents, stakeholders, context), not a policy document read cold, and the AI is instructed throughout to weigh substance over exact wording. You always have the final say.

Where is my data processed, and does it leave my organisation?

Uploaded documents and the evidence you record are sent to Anthropic's Claude API to generate your assessment, and the application itself is hosted on Microsoft Azure in Australia (Australia East region). Varða doesn't use accounts, cookies, or analytics, and it doesn't sell or share your data with advertisers, or use it to train any AI model. See our Privacy Policy for the full detail on exactly who processes what.

Does this replace my external auditor?

No. Varða is an audit-readiness and preparation tool, not the audit itself: it's built to help you find and close gaps before an auditor does, not to replace independent professional audit, legal or regulatory sign-off. Every AI-generated output should be reviewed by a suitably qualified person before you rely on it, so you walk into your next audit prepared, not blindsided.

What frameworks are supported?

ISO 27001, APRA's CPS 234 (Information Security) and CPS 230 (Operational Risk Management), the NIST Cybersecurity Framework, the ACSC's Essential 8, SMB1001 (DSI's tiered cybersecurity standard for Australian small and medium businesses), SOC 2 (the Trust Services Criteria for Security), and ISO 22301 (Business Continuity). You can assess the whole framework or pick specific controls to focus on, and more frameworks are added over time.

Is there a faster, lighter option than the full assessment?

Yes: Quick Policy Test is a fast, disposable check for when you just want a sanity read on a single document. Upload one policy and get an instant scan against a framework's controls, or a general best-practice read on its policy area if you don't have a specific framework in mind. It's not a substitute for a full, evidence-backed assessment, but it's a good first step before committing to one.

What does Varða cost?

Varða is early, so pricing is scoped around your actual frameworks, control count, and whether you need a one-off or ongoing assessment, rather than a flat per-seat number that doesn't fit most compliance teams. See our Pricing page for what's included in every engagement, or get in touch and we'll talk it through.

Still have a question?

Tell us which framework you're working against and we'll talk it through.

Get in Touch → Back to Home