Documentation Index
Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
Use this file to discover all available pages before exploring further.
What is a control?
A control is a specific security or operational requirement that a compliance framework mandates. Every framework is made up of controls — DORA has around 70, ISO 27001 has 93, and SOC 2 has roughly 60 criteria. Examples of controls:- “Implement multi-factor authentication for all privileged accounts”
- “Conduct annual penetration testing of critical systems”
- “Maintain a documented incident response plan”
Controls are only visible when Advanced Mode is enabled for your organization. Go to Settings → Organization to enable it.
Control structure
Each control contains:| Field | Description |
|---|---|
| Status | Not started / In progress / Implemented / Not applicable |
| Owner | The team member responsible for this control |
| Evidence | Evidence tasks linked to this control |
| Policies | Internal policies that satisfy this control |
| Risks | Risks that this control mitigates |
| Framework mapping | Which frameworks reference this control |
How controls map to frameworks
Controls are the shared layer beneath multiple frameworks. A single control — like “Encrypt data at rest” — can satisfy requirements across DORA, ISO 27001, and SOC 2 simultaneously. When you collect evidence for a control, all frameworks that reference it are updated automatically.Updating control status
- Go to Controls and open a control
- Click Status and select the current state
- Add a note if needed (useful for partial implementations)
Not started
Control has not been addressed yet.
In progress
Implementation is underway but not complete.
Implemented
Control is fully implemented and evidenced.
Not applicable
Control does not apply to your organization’s scope.
Linking evidence
Evidence tasks are the primary way controls move to Implemented status. To link evidence to a control:- Open the control
- Click Add evidence
- Select an existing evidence task or create a new one
- Once the evidence task is marked complete, the control status updates automatically
Assigning owners
Every control should have an owner — the person accountable for implementation and ongoing compliance.- Open a control
- Click Owner → search for a team member
- The owner receives notifications when evidence expires or the control status changes
Owners do not need to collect evidence themselves. They are accountable for ensuring it gets done.
Filtering and searching
Use filters to focus on what matters:| Filter | Use case |
|---|---|
| Framework | View controls for a specific framework (e.g., DORA only) |
| Status | Find all controls that are not started or in progress |
| Owner | See what a specific person is responsible for |
| Evidence expiry | Surface controls with expiring evidence |
Exporting for audits
Before an audit, export your controls for review:- Go to Controls
- Apply any filters (e.g., by framework)
- Click Export
- Choose CSV or the full evidence package (ZIP)