Frequently asked questions
- Is the generator really free?
- Yes. The 22 templates, the renderer and the CLI are published under Apache-2.0 on GitHub, and the web generator runs entirely in your browser without an account. The Audit Kit ($39 one-time) is optional and adds AI tailoring plus the Word, spreadsheet and calendar files.
- Do you store my answers or my policies?
- No. The free generator never sends your answers to a server; they are kept in your browser's local storage so you can come back to them. If you buy the Audit Kit, the answers travel as metadata on the Polar checkout and are sent to the tailoring API for the duration of each request. Policyseed has no database and stores nothing.
- Are these policies enough to pass a SOC 2 audit?
- Policies are one part of a SOC 2 examination, not the whole of it. The CPA firm you engage examines your controls and forms its own opinion; the policies must describe what you actually do, and you need evidence that the procedures run. Policyseed produces governance policy templates and, in the Audit Kit, AI tailoring and audit-prep documents. It is not legal advice and it does not guarantee any examination outcome.
- How is this different from the free templates on GitHub?
- StrongDM Comply and JupiterOne security-policy-templates are good open-source policy sets, and vendor template packs exist as well. Policyseed adds instant customization in the browser (conditional content by identity provider, MDM, data types, scope and work model), a CLI check that fails CI when a review is overdue, and the optional Audit Kit with Word documents, a criteria crosswalk, an acknowledgment form and a review calendar.
- What exactly does the Audit Kit add?
- Claude rewrites sections 4 (Policy Statements) and 5 (Procedures) of each policy using your intake, so the text names your identity provider, cloud, source control and vendors. You get 22 DOCX files, crosswalk.xlsx with an evidence checklist, policy-acknowledgment.docx, review-calendar.ics and a README with 25 auditor questions, all assembled as a ZIP in your browser. Four generation passes per license key; refund within 14 days on request.
- Can I run it in CI instead of the browser?
- Yes. The CLI (npx policyseed init, build, check) renders the same 22 policies from an intake.yaml file with no network calls, and check exits 1 when any policy's last revision date is older than its review cadence. The docs include a GitHub Action that runs it weekly.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.