Contact

Contact Nank.ai

Tell us which framework you need, when you need it, and what your buyer is asking for. A compliance manager reads every message and replies within one business day.

How to reach us

Any of these reaches the same team. Use whichever suits you.

+1 (647) 296-3299

Monday to Friday, 9am to 6pm Eastern.

[email protected]

Scoping questions, RFPs and security questionnaires.

Nank.ai on LinkedIn

Follow for guidance from our compliance library.

Already have an RFP or a questionnaire?

Send it with your message. We will tell you what it will take to answer every line, and which answers you do not have yet.

Send us a message

The more you say about your timeline and your buyer’s requirement, the more useful our first reply will be.

Name
Tell us your compliance needs and timeline.
After you submit

What happens next

No drip sequence, no discovery form to fill in before anyone talks to you.

STEP 01

A person reads it

Your message goes to a compliance manager, not a shared marketing inbox.

STEP 02

We reply in one business day

A direct answer, and one or two questions if the scope is not yet clear.

STEP 03

A 30-minute call

Your framework, your timeline, what you already run, and what your buyer is asking for.

STEP 04

A written scope and price

What we would do, in what order, and what it costs. No obligation to proceed.

What we do

Three ways we work with you

Most clients start with the first and add the others as the programme grows.

Compliance as a Service

A dedicated compliance manager owns the result and leads the work, rather than handing you advice and a checklist. SOC 2, ISO 27001, ISO 42001 and HIPAA.

AI-powered compliance platform

One place for controls, evidence and continuous monitoring across every framework you carry, so a control you implement once counts everywhere it maps.

Privacy and security professional services

Risk assessments, policy, penetration test coordination and privacy work, for teams who need a specific piece rather than a full programme.

Frequently asked questions

No, and no one can do both. A SOC 2 report comes from a licensed CPA firm and an ISO 27001 certificate comes from an accredited certification body. Both have to be independent of the work they assess. We build and run the programme, prepare the evidence, and manage the auditor relationship. The opinion stays with them. But we have partnered with an audit firm to help our clients secure more competitive audit pricing.

SOC 2, ISO 27001, ISO27701, ISO 42001, HIPAA, GDPR and CSA CMM. We can easily add any new framework or your customer framework to our platform.

If you carry more than one, the control work is shared across them rather than repeated. Tell us the full set in your message.

Scoping takes one call and a written proposal. Once you sign, the readiness work starts that week. What decides your finish date is the observation window, not the paperwork, so the earlier conversation is worth having before your buyer sets a deadline for you.

Yes. We run from Toronto and work with clients across Canada and the United States. We kept your data in your where a buyer or a regulator requires it.

Prefer to read first?

The compliance library covers SOC 2, ISO 27001 and ISO 42001 in the same detail we would give you on a call.

Scroll to Top