Spire connects to your infrastructure (AWS, GitHub, GCP, Vercel, Cloudflare, Clerk, Supabase, Stripe, Resend) and continuously collects compliance evidence — CloudTrail logs, IAM policies, branch protection, secret scanning, MFA enforcement, and more.
An AI agent evaluates evidence against 66 controls across SOC 2 Type II and the EU AI Act, producing pass/fail/warning verdicts with evidence citations and remediation guidance.
The questionnaire module accepts vendor security assessments in any format (PDF, DOCX, CSV, markdown). AI maps each question to your evidence library, generates responses with confidence scores, attaches supporting evidence, and flags uncertain answers for review. A 200-question questionnaire drops from 40 hours to under 4.
The dashboard shows real-time control status, AI compliance summary with gap analysis, controls grid with progress bars, and structured evidence export for auditors.