Openlane
Background
Scope & Ownership

Registry

Map your platforms
Turn a list of systems into the scope you can hand an auditor. Capture each platform's purpose, boundaries, and data flows in one record, and give every one a named owner accountable for it.
  • Visualize connected assets and services in an interactive graph
  • Tag systems as in-scope, production, or containing PII
The platform boundary: four environments in scope with their asset and vendor counts, and three environments recorded out of scope below it. IN SCOPEProductionCustomer-facing systems and the data they hold12 ASSETS4 VENDORSPipelineHow code is built, tested, and released5 ASSETS2 VENDORSDevelopmentStaging and test systems, no customer data4 ASSETS1 VENDOROperationsInternal tooling that supports the controls6 ASSETS5 VENDORSOUT OF SCOPESandbox4 ASSETS · 2 VENDORSLegacy apps3 ASSETS · 1 VENDORPublic2 ASSETS
Track assets and vendors
Know who you depend on and whether they meet your standards — before a customer or auditor asks. Keep a live record of every asset your platforms rely on, with vendor approval status, SOC 2 attestations, and contacts in one place.
  • Filter assets by type, owner, and scope status
  • Approval and SOC 2 status visible per vendor, not buried in a folder
ResendResendTRANSACTIONAL EMAILFOR USE · OFFFOR USE · ON
DraftJUL 02ReviewJUL 18ApprovedAUG 06OffboardSEP 30TerminatedOCT 14
Record retained after terminationHistory stays available to auditors
Know your people
See who has access to what — and prove it — without chasing spreadsheets across teams. Keep one record per person with their role, employment details, and every account they hold, with MFA status and directory coverage synced from the tools your team already uses.
  • One view of every account a person holds across your tools
  • MFA status per account, ready as access-control evidence
Google WorkspaceGoogle WorkspaceSOURCE OF TRUTHSYNCING
DIRECTORYSTATUSMFAGoogle WorkspaceGoogle WorkspaceACTIVEENFORCEDGitHubGitHubACTIVEENFORCEDSlackSlackACTIVEDISABLED

Ever needed to know who owns a system — and found no good answer?

When a system, vendor, or person carries a named owner on its record, the answer is a lookup instead of a hallway poll — and the controls and evidence tied to that record inherit the same accountability.

SOC 2 System Description

Registry is your Section 3

Infrastructure & software

Keep the infrastructure and software behind your system description current — services, data flows, and diagrams, each with an assigned owner — so it's ready when your auditor asks.

People & access

Maintain a live record of who has access to what — each person's role and every account they hold, with MFA status current as access-control evidence.

Vendors & third parties

Track every vendor your platforms depend on — approval status, SOC 2 attestations, and contacts — so your subservice organization list is current before an auditor asks.

Native Integrations

Sync people and assets from
your directories and cloud accounts

Amazon Web Services

Collect Security Hub findings, AWS Config rules, and cloud account users and groups.

FindingsUsers and GroupsAssetsCloud Checks

Authentik

Sync users and groups for directory-based access and compliance visibility.

Users and Groups

Cloudflare

Validate account access and collect security-relevant account and zone context.

Users and GroupsAssetsFindings

GitHub

Collect repository metadata and security alerts to support vulnerability and asset tracking.

VulnerabilitiesAssetsUsers and Groups

Google Cloud Security Command Center

Collect Security Command Center findings for security posture reporting.

VulnerabilitiesAssetsFindingsCloud Checks

Google Workspace

Sync Workspace users, groups, and account state for access reviews and personnel records.

Users and Groups

Microsoft Defender for Cloud

Collect Microsoft Defender for Cloud findings for security posture and vulnerability tracking.

VulnerabilitiesAssets

Microsoft Entra ID

Collect directory and identity metadata to support account hygiene and user access reviews.

Users and Groups

Okta

Sync Okta users and groups so access reviews start from your current directory.

Users and Groups

Slack

Verify workspace posture and send operational or compliance notifications.

NotificationsUsers and Groups

Tailscale

Sync devices, users, and groups for asset inventory, access management, and compliance reporting.

Users and GroupsAssets

Trusted By

Jiro HealthBuddyBeamRentBambooNextGen ComplianceAd AstraEcoPulseCentra DigitalDatavineCybermotivBuyerExperienceFlowMatchDocflow LabsJiro HealthBuddyBeamRentBambooNextGen ComplianceAd AstraEcoPulseCentra DigitalDatavineCybermotivBuyerExperienceFlowMatchDocflow Labs
Part of Registry

Get your registry in order

No credit card. 30-day free trial.