Press kit

Policyseed in 60 seconds

Policyseed is a free, open-source SOC 2 policy generator: 23 questions, 22 governance policies, rendered in your browser.

Everything on this page is copy-ready and checked. The numbers were measured on 2 September 2026. If something here is out of date, open an issue on GitHub and it gets corrected at the source.

Copy and paste

Descriptions, three lengths

Use whichever fits. Nothing in them is a claim we cannot stand behind.

One line18 words
Policyseed is a free, open-source SOC 2 policy generator: 23 questions, 22 governance policies, rendered in your browser.

Short description40 words
Policyseed is a free, open-source SOC 2 policy generator. Twenty-three questions render twenty-two governance policies in your browser: no signup, nothing uploaded. A $39 Audit Kit adds AI tailoring to your tools, Word documents, a criteria crosswalk and acknowledgment forms.

Long description120 words
Policyseed is a free, open-source generator for the 22 governance policies a company needs for a SOC 2 program. You answer 23 questions about your company, stack and data; the policies render in your browser from Apache-2.0 templates. There is no signup, no upload and no database: the free set downloads as Markdown. The optional Audit Kit, $39 once, uses Claude to rewrite each policy's Policy Statements and Procedures so they name your tools, then builds a ZIP in your browser containing 22 Word documents, a Trust Services Criteria crosswalk workbook, an evidence checklist, acknowledgment forms, a review calendar and an auditor Q&A. Policyseed produces governance policy templates. It is not legal advice, and the CPA firm performs the examination.

What it does

Three things, in order

  • Renders a full policy set from 23 answers

    Company, product, headcount, cloud, source control, identity provider, MFA, MDM, data types, vendors, owners, scope and review cadence go in; 22 policies come out as Markdown, each with the same nine sections and a named owner role. The templates carry conditional blocks, so the text changes with the answers.

  • Runs in the browser, with nothing uploaded

    The free generator never sends the answers anywhere: they stay in local storage and the ZIP is built on the machine. The same templates render offline through the open-source CLI, which also fails a CI build when a policy's review date has passed.

  • Sells one optional upgrade, the Audit Kit

    Claude rewrites two sections of every policy so they name the tools the buyer actually uses, and the browser assembles Word documents, a Trust Services Criteria crosswalk workbook, an evidence checklist, acknowledgment forms, a review calendar and an auditor Q&A into one ZIP.

Free versus paid

What costs money, exactly

The whole policy set is free. One optional purchase exists, in two sizes, sold once rather than by subscription.

ItemPriceWhat it includes
Generator, 22 templates, CLI$0All 22 policies from the 23-question intake, downloaded as a Markdown ZIP. Templates and CLI are Apache-2.0 on GitHub; forking needs no attribution.
Audit Kit$39 one-timeOne company. AI tailoring of every policy, 22 Word documents, crosswalk.xlsx (three sheets), the evidence checklist, acknowledgment form and roster, review-calendar.ics and the auditor Q&A README. 4 generation passes (88 policy runs) on the license key. 14-day refund on request.
Audit Kit Agency$149 one-timeFive company packs on one license key (20 passes, 440 policy runs), for consultants, fractional CISOs and MSPs. Same files per company. 14-day refund on request.

Polar is the merchant of record, so it handles payment, VAT and receipts. Prices are in US dollars, and the store accepts real card payments today.

How the tailoring works

Two sentences

Claude rewrites sections 4 (Policy Statements) and 5 (Procedures) of each of the 22 policies from the buyer’s 23 intake answers, so the text names the identity provider, cloud, source control, MDM and vendors that company actually uses, while the other seven sections stay as the template wrote them. Nothing is stored server-side, because there is no database and no account: the Polar license key is the only state, and it holds nothing but how many generation passes are left.

For completeness: the tailoring request is stateless and the ZIP is assembled in the buyer’s browser, so the finished documents never exist on a server we control, and every tailored policy is marked as tailored in its document control table so a reviewer knows which sections to read most closely.

Verified facts

Numbers you can print

Each one is measured rather than estimated, and each says how.

Measured on 2 September 2026.
FactNumberHow it is measured
Policies in the set22One template per policy, each with Purpose, Scope, Roles, Policy Statements, Procedures, Exceptions, Enforcement, Review Cadence and Revision History.
Template word count~39,000Across the 22 Markdown templates, before any intake answers are applied.
Trust Services Criteria mapped38The 33 common criteria (CC1 to CC9), plus Availability (A1) and Confidentiality (C1) when the buyer puts them in scope.
Files in a delivered Audit Kit48Measured on a real end-to-end order: 22 of 22 policies tailored with no fallbacks, producing a 523 KB ZIP whose Word files name the buyer's actual tools.
Indexable pages on the site90Listed in the sitemap and returning 200; 97 pages build in total, plus 76 social-card image routes. Google Search Console is verified and the sitemap submitted.
Template licenceApache-2.0Templates, renderer and CLI are published at github.com/odedmoshe/policyseed.
Automated tests118All passing. CI runs the test suite and a TypeScript typecheck on every push.

Audience

Who it is for, and who it is not for

For

  • Founders and engineers at small companies who have just been asked for a SOC 2 report and need a complete, readable policy set today.
  • Teams that would rather keep their policies as files in a repository, with diffs and authors, than inside a vendor's interface.
  • Consultants, fractional CISOs and MSPs preparing several companies at once, which is what the Agency license is for.
  • Anyone who wants to read a policy set before paying for anything, or to fork the templates and never come back.

Not for

  • It is not a compliance platform. There is no dashboard, no integration with your cloud accounts and no continuous monitoring.
  • It does not collect evidence. No screenshots, no ticket exports, no access reviews performed for you; the evidence checklist says what to gather, and you gather it.
  • It does not replace the CPA firm. The firm you engage performs the SOC 2 examination and forms its own opinion; Policyseed prepares the policy portion of what that firm asks for.
  • It is not legal advice, and not a substitute for counsel when a regulated context calls for bespoke drafting.

Limitations

The honest paragraph

Policies are one part of a SOC 2 examination, not the whole of it, and a generated policy is worth something only once a person reads it and makes it match what the company actually does. The AI tailoring rewrites two sections of each policy from a 23-answer intake, so it can be wrong about an environment it was told little about; that is why every tailored policy is flagged as tailored, and why the wording asks to be checked against the tools in front of you. Storing nothing is a privacy property and also a constraint: lose the ZIP and you rebuild it from your intake with the runs left on your license key. Policyseed does not make a company SOC 2 compliant, certified or audit-proof, it is not legal advice, and nothing here predicts the outcome of any examination.

What to call it

Policyseed — one word, capital P, lowercase s. Not PolicySeed, not Policy Seed, and not policyseed at the start of a sentence. The paid product is the Audit Kit (capital A, capital K); the larger license is the Audit Kit Agency license.

Links

There is no press office and no mailing list. Questions and corrections go to the GitHub issue tracker; buyers reach support through the address on their Polar receipt.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.