The GRC audit workspace where your evidence never leaves your Drive.
ISO 27001 · SOC 2 · GDPR · Israeli Privacy Law — run real compliance engagements while every file stays in the customer's own Google Drive.
Vanta, Drata & co. ingest your policies, access lists and audit trail into their multi-tenant database.
Regulated clients won't upload sensitive evidence into a consultant's third-party SaaS. Deals stall.
Switch vendors or consultants and you re-import everything. The audit trail isn't really yours.
Joujik Mutualwork gives consultants and their clients one structured place to run a compliance engagement end-to-end. The twist: the evidence stays in the customer's own Google Drive.
Files land in your Drive, in a clean ISO/Annex-A folder tree. We store only pointers + keys.
Consultant ↔ client, with role-aware access and an immutable, shared audit log.
ISO 27001, SOC 2, GDPR & Israeli Privacy Law ship as static, expert-built templates — no LLM guesswork.
drive.file scope onlyWe can touch only the files our app creates in your Drive — never the rest. The smallest useful scope, no Google CASA audit baggage.
Row-level security on every table, plus per-engagement membership checks — a consultant on one engagement can't see another's data.
OAuth refresh tokens are AES-256-GCM encrypted, key-separated, never logged, never sent to the browser.
An append-only NDJSON of every action is retained in your .joujik/ folder — exportable and auditor-friendly.
| Joujik Mutualwork | Vanta · Drata | Monday · Notion | |
|---|---|---|---|
| Where evidence files live | Your Google Drive | Their servers | Their servers |
| Where the audit log lives | Your Drive (.joujik/) | Their database | No audit surface |
| If the vendor goes away | You keep everything | Export & hope | Export & hope |
| Switch vendor mid-engagement | Hand over a Drive link | Re-import all | Re-import all |
| GDPR access / export / delete | Native in your Drive | Via the vendor | Via the vendor |
A real engagement, walked through next — ISO/IEC 27001:2022.
Two clear portals — consultant and client. Access is by approval (private beta), and either side can own the Drive folder — the owner keeps the evidence, even if the other party changes.


Choose ISO 27001:2022 and the engagement spins up a Drive folder and materialises the 93 Annex A controls + clauses 4–10 as 126 audit tasks — ready for evidence.
The engagement owner invites the counterpart by email with a role. Client side and consultancy side are tracked separately — with a live, shared member list.


Mark each of the 93 Annex A controls applicable or excluded — with a justification (per clause 6.1.3). Submit, and the applicable controls become live tasks.
The client uploads evidence (straight to Drive); the consultant runs an internal-audit review of each control — comply, OFI or non-conformity — with a quality tag and a comment to the client.


93 Annex A controls + clauses 4–10 · 94 comply · 21 OFI · 11 non-conformity — every verdict logged.


The app provisions a clean ISMS/ + Annex A/ tree with a folder per control —
created via Google's drive.file scope. Your evidence, your ownership, your portability.
Export a polished, branded PDF: cover page, the complete Statement of Applicability, and per-control evidence, verdicts & review history. Markdown & JSON exports too.
Generated from the live engagement — the 126-control ISO 27001 example shown here.


Each ships with an expert-built, framework-specific setup wizard — not a generic checklist.
93 controls + clauses 4–10
184 TSC items
39 mapped obligations
81 obligations
A guided wizard walks Security, Availability, Confidentiality, Processing Integrity & Privacy — Type I vs II, carve-out vs inclusive — each decision cites the AICPA TSP and is logged.


A 12-step classification — role, territorial scope, DPO trigger, transfers, special categories — with the exact legal basis (Art. 3(2), Art. 27…) cited at every turn.
A 7-step Hebrew/English wizard classifies the entity & database, then auto-derives the security level (תקנה 21) and generates exactly the tasks that apply.


Whether you're a partner, an investor, a potential customer, or the idea just resonates at this level — I'd love to hear from you.
Joujik Mutualwork · beta · mutualwork.joujik.com