Disclaimer: Independent educational project. Not affiliated with GoRico. Built by Kaushal Khodifad. Data from public sources; figures are estimates.return to portfolio
Disclaimer: Independent educational project. Not affiliated with GoRico.
TechCorp Solutions
3 Active Programs
TC

Policies

Policy register with live control mappings and AI-drafting provenance.

Draft New Policy
5

Total Policies

4

Published

1

In Draft / Review

2

AI-drafted (model recorded)

1 policy has no control mappings: Acceptable Use Policy. A policy that maps to no control is shelf-ware an auditor will flag - link it to the requirements it satisfies. (Computed live from policy_control_links, not asserted.)
PolicyFrameworksMapped ControlsStatusVersionNext ReviewOwner
Information Security Policy

Top-level information security policy establishing the organization's commitment to protecting information assets.

SOC 2 / ISO 27001
CC1.1A.5.1
Publishedv2.12027-01-15CISO
Access Control Policy

Policy governing logical and physical access controls to TechCorp systems, applications, and data.

SOC 2 / ISO 27001 / HIPAA
CC6.1CC6.2CC6.3A.5.15164.312(a)(1)
Publishedv1.32027-02-01IT Manager
Incident Response PolicyAI-drafted

Policy and procedures for detecting, responding to, and recovering from information security incidents.

SOC 2 / ISO 27001 / HIPAA
CC7.3CC7.4A.5.24164.308(a)(6)
Publishedv1.02027-03-10Security Operations Lead
Data Classification and Handling PolicyAI-drafted

Policy defining data classification levels and corresponding handling, storage, and transmission requirements.

SOC 2 / ISO 27001
CC6.7A.5.12
In Reviewv1.0-CISO
Acceptable Use Policy

Policy governing acceptable use of TechCorp information systems, devices, and network resources by employees and contractors.

unmapped
none linked
Publishedv1.22026-11-20IT Manager

Synthetic demo register. Framework tags and control citations are joined live from policy_control_links → controls → frameworks - nothing typed in. Per the committed schema (db/schema.sql), a policy flagged AI-drafted must permanently record the model used; drafts from the Policy Generator are scaffolding for the named owner, never auto-approved.

↑ Independent educational project by Kaushal Khodifad. GoRico is a real company in the GRC & compliance automation space; this design and the underlying prototype were built by Kaushal as a portfolio study. Not affiliated with, endorsed by, or representative of GoRico's actual product. Data is from public sources. Figures are estimates.

Return to portfolioOpen the live demo