Press kit
Policyseed in 60 seconds
Policyseed is a free, open-source SOC 2 policy generator: 23 questions, 22 governance policies, rendered in your browser.
Everything on this page is copy-ready and checked. The numbers were measured on 2 September 2026. If something here is out of date, open an issue on GitHub and it gets corrected at the source.
Copy and paste
Descriptions, three lengths
Use whichever fits. Nothing in them is a claim we cannot stand behind.
What it does
Three things, in order
Renders a full policy set from 23 answers
Company, product, headcount, cloud, source control, identity provider, MFA, MDM, data types, vendors, owners, scope and review cadence go in; 22 policies come out as Markdown, each with the same nine sections and a named owner role. The templates carry conditional blocks, so the text changes with the answers.
Runs in the browser, with nothing uploaded
The free generator never sends the answers anywhere: they stay in local storage and the ZIP is built on the machine. The same templates render offline through the open-source CLI, which also fails a CI build when a policy's review date has passed.
Sells one optional upgrade, the Audit Kit
Claude rewrites two sections of every policy so they name the tools the buyer actually uses, and the browser assembles Word documents, a Trust Services Criteria crosswalk workbook, an evidence checklist, acknowledgment forms, a review calendar and an auditor Q&A into one ZIP.
Free versus paid
What costs money, exactly
The whole policy set is free. One optional purchase exists, in two sizes, sold once rather than by subscription.
| Item | Price | What it includes |
|---|---|---|
| Generator, 22 templates, CLI | $0 | All 22 policies from the 23-question intake, downloaded as a Markdown ZIP. Templates and CLI are Apache-2.0 on GitHub; forking needs no attribution. |
| Audit Kit | $39 one-time | One company. AI tailoring of every policy, 22 Word documents, crosswalk.xlsx (three sheets), the evidence checklist, acknowledgment form and roster, review-calendar.ics and the auditor Q&A README. 4 generation passes (88 policy runs) on the license key. 14-day refund on request. |
| Audit Kit Agency | $149 one-time | Five company packs on one license key (20 passes, 440 policy runs), for consultants, fractional CISOs and MSPs. Same files per company. 14-day refund on request. |
Polar is the merchant of record, so it handles payment, VAT and receipts. Prices are in US dollars, and the store accepts real card payments today.
How the tailoring works
Two sentences
Claude rewrites sections 4 (Policy Statements) and 5 (Procedures) of each of the 22 policies from the buyer’s 23 intake answers, so the text names the identity provider, cloud, source control, MDM and vendors that company actually uses, while the other seven sections stay as the template wrote them. Nothing is stored server-side, because there is no database and no account: the Polar license key is the only state, and it holds nothing but how many generation passes are left.
For completeness: the tailoring request is stateless and the ZIP is assembled in the buyer’s browser, so the finished documents never exist on a server we control, and every tailored policy is marked as tailored in its document control table so a reviewer knows which sections to read most closely.
Verified facts
Numbers you can print
Each one is measured rather than estimated, and each says how.
| Fact | Number | How it is measured |
|---|---|---|
| Policies in the set | 22 | One template per policy, each with Purpose, Scope, Roles, Policy Statements, Procedures, Exceptions, Enforcement, Review Cadence and Revision History. |
| Template word count | ~39,000 | Across the 22 Markdown templates, before any intake answers are applied. |
| Trust Services Criteria mapped | 38 | The 33 common criteria (CC1 to CC9), plus Availability (A1) and Confidentiality (C1) when the buyer puts them in scope. |
| Files in a delivered Audit Kit | 48 | Measured on a real end-to-end order: 22 of 22 policies tailored with no fallbacks, producing a 523 KB ZIP whose Word files name the buyer's actual tools. |
| Indexable pages on the site | 90 | Listed in the sitemap and returning 200; 97 pages build in total, plus 76 social-card image routes. Google Search Console is verified and the sitemap submitted. |
| Template licence | Apache-2.0 | Templates, renderer and CLI are published at github.com/odedmoshe/policyseed. |
| Automated tests | 118 | All passing. CI runs the test suite and a TypeScript typecheck on every push. |
Audience
Who it is for, and who it is not for
For
- Founders and engineers at small companies who have just been asked for a SOC 2 report and need a complete, readable policy set today.
- Teams that would rather keep their policies as files in a repository, with diffs and authors, than inside a vendor's interface.
- Consultants, fractional CISOs and MSPs preparing several companies at once, which is what the Agency license is for.
- Anyone who wants to read a policy set before paying for anything, or to fork the templates and never come back.
Not for
- It is not a compliance platform. There is no dashboard, no integration with your cloud accounts and no continuous monitoring.
- It does not collect evidence. No screenshots, no ticket exports, no access reviews performed for you; the evidence checklist says what to gather, and you gather it.
- It does not replace the CPA firm. The firm you engage performs the SOC 2 examination and forms its own opinion; Policyseed prepares the policy portion of what that firm asks for.
- It is not legal advice, and not a substitute for counsel when a regulated context calls for bespoke drafting.
Limitations
The honest paragraph
Policies are one part of a SOC 2 examination, not the whole of it, and a generated policy is worth something only once a person reads it and makes it match what the company actually does. The AI tailoring rewrites two sections of each policy from a 23-answer intake, so it can be wrong about an environment it was told little about; that is why every tailored policy is flagged as tailored, and why the wording asks to be checked against the tools in front of you. Storing nothing is a privacy property and also a constraint: lose the ZIP and you rebuild it from your intake with the runs left on your license key. Policyseed does not make a company SOC 2 compliant, certified or audit-proof, it is not legal advice, and nothing here predicts the outcome of any examination.
What to call it
Policyseed — one word, capital P, lowercase s. Not PolicySeed, not Policy Seed, and not policyseed at the start of a sentence. The paid product is the Audit Kit (capital A, capital K); the larger license is the Audit Kit Agency license.
Links
Everything worth linking to
- Free generatorhttps://policyseed.vercel.app/generateThe 23 questions and the 22 policies, no account.
- Source and templateshttps://github.com/odedmoshe/policyseedApache-2.0 templates, renderer and CLI.
- Sample kithttps://policyseed.vercel.app/sampleWhat a finished Audit Kit looks like, before buying.
- Pricinghttps://policyseed.vercel.app/pricingFree, $39 and $149 side by side.
- Audit Kit detailhttps://policyseed.vercel.app/audit-kitEvery file in the ZIP and why it is there.
- Abouthttps://policyseed.vercel.app/aboutWho builds it, and the absence of auditor affiliations.
There is no press office and no mailing list. Questions and corrections go to the GitHub issue tracker; buyers reach support through the address on their Polar receipt.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.