Platform / Policy Studio

The documents, without the blank page.

Policy Studio drafts the six documents every security programme needs - shaped to your organisation from a few plain-English answers, written in UK English. Refine them in place, review, export board-ready - then put them to work.

A short call about your organisation, then a full demo if it fits - no obligation.

The documents

Six documents every programme needs.

Each one drafted around your answers - your systems, your team, your ways of working - not a template with your name pasted in.

Incident Response Plan

Who does what when something goes wrong - roles, escalation, communications and recovery, written to be followed at 2am.

Information Security Policy

The parent document that frames your whole programme - scope, responsibilities and the standards everything else hangs from.

Acceptable Use Policy

What staff can and cannot do with your systems and data - clear enough that people actually read and follow it.

Access Control Policy

How access is granted, reviewed and revoked - least privilege, admin separation, joiners, movers and leavers.

Business Continuity & DR Plan

How the organisation keeps operating through disruption - priorities, recovery objectives and who leads the return.

Data Protection Policy

How personal data is handled, protected and retained - aligned with UK GDPR and written for the people who process it.

How it runs

From a few answers to a rolled-out policy.

01

Answer a few questions

Plain-English prompts about your organisation - how you work, what you run, who's responsible - shape every section of the draft.

02

Assura drafts

A complete, structured document in UK English - and Policy Studio only recommends documents you're actually missing, never busywork.

03

Refine and review

Ask for changes in plain English - "tighten the remote-access section" - and review the result in place until it reads like yours.

04

Export and roll out

Export a board-ready PDF, then put it to work: staff acknowledge it through a tracked link, and it stands as evidence in your assessments.

Drafting

Drafted around your answers.

A downloaded template is someone else's policy with your logo. Policy Studio asks about your organisation first - your systems, your structure, your appetite - and drafts each section around what you said, in UK English that won't need translating for a UK auditor.

  • Your answers shape the content, not just the letterhead
  • UK English, UK regulatory framing
  • Recommends only the documents you're missing
"We're a 40-person SaaS team" Sized accordingly
"Everyone works remotely" Remote-first controls
Refining

Refine without the copy-paste.

The first draft is never the last. Tell Policy Studio what to change in plain English and it redrafts just that - tighter, stricter, simpler - while everything you'd already approved stays put. When it reads like yours, export it.

  • Plain-English refinement, section by section
  • Review in place - no exporting to Word and back
  • Board-ready PDF export when you're done
Make the password section stricter and add a rule for contractors.
Done - password minimums raised, and a new contractor-access clause added under section 4.
Rollout

Policies that go to work.

A policy in a drawer protects nobody. Everything Policy Studio produces plugs into the rest of the platform: staff acknowledge it through a tracked attestation link, it stands as evidence where your assessments call for documentation, and your dashboard knows it exists.

  • Staff attestation through the People module, tracked per person
  • Counts as evidence in the controls it documents
  • Your policy coverage shows up on the dashboard, not in a folder
Policy exported 14 of 16 staff attested
Attached as evidence ISO 27001 · A.5.1
Questions

Asked and answered.

Are these just templates with our name on?

No. Policy Studio asks about your organisation first and drafts each section around your answers - your size, your systems, your ways of working. Two organisations get two genuinely different documents.

Can our solicitor or consultant review them?

Please do - that's what the export is for. Refine the draft until it reads right, export the PDF, and route it through whoever signs your documents off. They're your documents; Assura just does the drafting.

How do staff acknowledge a policy?

Through the People module: each person gets a tracked attestation link, and you can see exactly who has read and acknowledged which policy - evidence auditors like.

Do the policies count toward certification?

They stand as evidence wherever a framework asks for documented policy - which most do, repeatedly. Assura attaches them to the controls they document, so the assessment sees them automatically.

Get started

Start with the policy you keep putting off.

Book a demo and we'll draft one with you, live - your organisation, your answers, your document.

Prefer to pick a time? Book a 15-minute intro · or leave your email and we'll come to you.