Send policies. Collect acknowledgements. Have the proof.

Policyflow distributes policies to your employees, records who has confirmed which version, and exports the evidence auditors ask for. Built for ISO 27001, SOC 2, NIS2 and GDPR programmes.

  • Free for teams up to 15 employees — no card on signup
  • Recipients confirm through a personal link, no accounts needed
  • Questions? hello@applikeable.com
Policyflow campaigns dashboard

EU data residency

Hosted in Frankfurt. Backups never leave the EU.

Framework coverage

ISO 27001, SOC 2, NIS2, GDPR and DORA acknowledgement evidence.

Free up to 15 employees

Full product on every plan. Pricing changes with headcount only.

Paddle as Merchant of Record

Billing, VAT and invoicing handled by Paddle.

What Policyflow is

The layer between your policies and the people they apply to.

Write or upload, route for approval, distribute by campaign — every step recorded against a named person and a document version.

WriteApproveDistributeConfirm

What an acknowledgement is

A named person confirming they read and understood a specific policy version.

Name, version and timestamp — the evidence auditors match against the document in force at the time.

A. Müller · SalesRemote Work Policy · v2.1Confirmed 14 Mar 09:41

The policy builder

A policy starts as the clauses it has to answer, not an empty page. Choose the policy type and the standard behind it — Policyflow lays out the clauses that belong in it and keeps count of the ones the document still leaves open.

The Policyflow policy builder: an ISO 27001 clause library on the left, the Information Security Policy draft in the middle with clause A.5 Access Control being dropped into the Scope section, and a coverage panel on the right showing 3 of 15 clauses in place.
An Information Security Policy drafted against ISO 27001 — clause A.5 Access Control dropped into Scope, 3 of 15 clauses in place.

The clause library sits beside the document

Every clause in the standard is listed next to the draft. Drag one in, or click to insert it where the cursor is.

Coverage is counted while you write

A running count of clauses in place against clauses in scope, and one action that inserts whatever is still outstanding.

Approved wording comes back

Wording you have settled on is saved as approved content and offered first the next time the same clause comes up.

The policies you already have

Most policies are already written, and rewriting them to adopt a tool is a poor trade. Upload the PDF instead: Policyflow reads the document, wraps each passage that carries a requirement as an editable brick, and leaves the rest of the page as it was written.

Reading your document Finding the text, headings and tables in your PDF.

Your wording is never rewritten

The model chooses passages by position and cannot supply replacement text. Every sentence in the draft is a sentence from your document.

The original stays with it

The uploaded PDF is kept and stays downloadable. Before the draft is saved, the import is checked to reproduce the document exactly.

Requirements become bricks

Obligations, responsibilities and procedures arrive as editable bricks. Headings, definitions and signatures arrive as ordinary text.

The workflow, end to end

Three steps between a blank page and a signed-off, exportable record.

01

Draft and approve

Write in the editor or upload a PDF. Route through reviewers — every sign-off pins to the version it approved.

Information Security Policy

v3.2
  • ComplianceApproved
  • LegalApproved
  • CISOAwaiting review

02

Distribute to the right people

Launch a campaign to the groups that need it. Each person gets a personal link by email — no account required.

Q1 policy rollout

142 recipients
  • Acceptable Use PolicySent
  • Remote Work PolicySent
  • Data Protection NoticeSent

03

Track progress and export evidence

Follow completion in real time, remind anyone outstanding, and export a certificate or row-level log when you're done.

138 of 142 confirmed97%
PDF certificateCSV log

4 reminders queued · closes 28 Mar

The compliance year

ISO 27001 asks for policies reviewed “at planned intervals”. That is a year-shaped question, and a list of due dates answers it badly. Policyflow draws the whole year as one face — what is scheduled, what is running, and what already happened — so the gaps are visible before an auditor finds them.

2026

January 2026JanFebruary 2026FebMarch 2026MarApril 2026AprMay 2026MayJune 2026JunJuly 2026JulAugust 2026AugSeptember 2026SepOctober 2026OctNovember 2026NovDecember 2026Dec

36

activities

3 overdue

  • Bureau Nordic (surveillance)Auditor access, 1 Jan - 14 Feb 2026, logged
  • Security awareness 2026Attestation campaign, 8 Jan - 27 Feb 2026, completed
  • ISO 27001 mappings reviewedFramework sign-off, 22 Jan 2026, logged
  • 4 policy versions publishedPolicy published, 15 Feb 2026, logged
  • 6 joiners enrolledOnboarding wave, 15 Feb 2026, logged
  • Information Security Policy reviewPolicy review, 16 Feb 2026, completed
  • Annual risk assessmentRisk assessment, 2 Mar 2026, completed
  • Privileged access reviewAccess review, 31 Mar 2026, completed
  • Acceptable Use refreshAttestation campaign, 6 Apr - 8 May 2026, completed
  • 11 joiners enrolledOnboarding wave, 15 Apr 2026, logged
  • Internal ISMS auditInternal audit, 20 Apr 2026, completed
  • Management review meetingManagement review, 12 May 2026, completed
  • Incident Response Plan v7Policy published, 15 May 2026, logged
  • 4 joiners enrolledOnboarding wave, 15 May 2026, logged
  • ISO 27001 packageEvidence package, 28 May 2026, logged
  • Certus Assurance (stage 2)Auditor access, 1 Jun - 15 Jul 2026, logged
  • Data retention clauseContent review, 30 Jun 2026, overdue (needs attention)
  • Privileged access reviewAccess review, 30 Jun 2026, completed
  • Critical supplier assessmentSupplier review, 14 Jul 2026, overdue (needs attention)
  • 18 joiners enrolledOnboarding wave, 15 Jul 2026, logged
  • Acceptable Use Policy reviewPolicy review, 10 Aug 2026, overdue (needs attention)
  • 9 policy versions publishedPolicy published, 15 Aug 2026, logged
  • 9 joiners enrolledOnboarding wave, 15 Aug 2026, logged
  • Incident Response Plan v7Attestation campaign, 17 Aug - 3 Sep 2026, open
  • ISO 27001 packageEvidence package, 20 Aug 2026, logged
  • Certus Assurance (interim)Auditor access, 24 Aug - 24 Oct 2026, open
  • Disaster recovery testContinuity test, 15 Sep 2026, due soon (needs attention)
  • Supplier Security Policy reviewPolicy review, 21 Sep 2026, due soon (needs attention)
  • Privileged access reviewAccess review, 30 Sep 2026, due soon (needs attention)
  • Privacy refresher (scheduled)Attestation campaign, 5 Oct - 6 Nov 2026, upcoming
  • Sub-processor disclosureContent review, 12 Oct 2026, upcoming
  • Internal ISMS auditInternal audit, 20 Oct 2026, upcoming
  • Remote Working PolicyPolicy review, 4 Nov 2026, upcoming
  • Management review meetingManagement review, 12 Nov 2026, upcoming
  • ISO 27001 mapping sign-offFramework sign-off, 22 Dec 2026, upcoming
  • Privileged access reviewAccess review, 31 Dec 2026, upcoming

Nine feeds, not a to-do list

Policy reviews, publications, wording up for re-approval, the recurring plan, framework sign-off, campaigns, joiner intakes, auditor access and evidence packages — all on one face.

Things that take time are drawn as time

A campaign is not a date, it is the six weeks it stayed open. Auditor access is the window somebody could see your evidence room. Both are arcs, at their real width.

The year you can prove, not just plan

Half of it is already behind you. What was signed off, when, by whom, and against which clause stays on the wheel — so the record and the plan are the same picture.

One product, priced by headcount

Every tier is the same Policyflow — same features, same exports, same support. The only variable is how many people you cover. Start on the free plan and move up when you outgrow it.

How many employees need to sign off?

Up to 250 employees

502505001,0002,5002,500+

Core

Run policy sign-off across your whole organisation.

€155/ mo

billed annually

Save €408 a year

10 admin seats included

Everything in Free, plus

  • Approval workflows
  • Group-based targeting
  • Automated reminders
  • Policy template library
  • Role-based access (Admin / Editor / Approver / Viewer)
  • Azure AD & Google Workspace sync
  • SSO via Microsoft & Google
  • Email support

Compliance

Coming soon

Framework mapping, auditor access, and scheduled reporting.

Pricing to follow

Included with Core during preview. Separate pricing when it ships.

Everything in Core, plus

  • ISO 27001:2022 framework mapping
  • Compliance calendar & review cadence
  • Scheduled report builder
  • Manager follow-up escalation
  • External auditor portal
  • Public trust center
  • Joiner lifecycle automation
  • AI policy assistant

Custom

Above 2,500 employees, or non-standard requirements.

Let's talk

Non-standard security, billing, or contract requirements.

Everything in Compliance, plus

  • SAML & SCIM provisioning
  • Multi-entity sub-organisations
  • Uptime SLA & security review
  • DPA and data residency options
  • Invoice & purchase-order billing
  • Named point of contact
Contact us

Free — up to 15 employees

Evaluate Policyflow with a small group. No time limit, no card required.

Start free

All plans include unlimited policies, full version history and audit-ready exports. Need something different? Contact us.

Subscriptions are sold through Paddle as Merchant of Record. Review our Terms of Service, Privacy Policy, and Refund Policy. Questions before purchase? Email hello@applikeable.com.

What's in the product

Enough depth for the people who own compliance, simple enough for everyone who just needs to read and confirm.

Authoring

Draft, review, and keep every version accountable.

  • Version control

    Every edit snapshots the previous version. Confirmations stay pinned to what people actually read.

  • Approval workflows

    Route drafts through reviewers in sequence. Each sign-off records against the document version.

  • Review dates

    Set a review date at publication. Policyflow flags policies before they go stale.

Rollout

Reach the right people without accounts or installs.

  • Directory sync

    Groups sync from Azure AD or Google Workspace. Joiners inherit policies on day one.

  • Campaigns

    Bundle related policies into one rollout with a shared deadline and progress view.

  • Link-based access

    Recipients confirm through a personal, single-use link — nothing to install.

Evidence

Track completion and produce what auditors ask for.

  • Automated reminders

    Remind anyone outstanding on your schedule. Confirmed recipients are left alone.

  • Exports

    PDF certificate for the summary, CSV log for row-level detail — version and timestamp on every line.

  • Audit log

    Uploads, edits, approvals, sends, and confirmations all land in the activity log.

What recipients see

One email, one link, one confirmation — the three things below are the whole experience. It works the same on a phone as on a laptop, so office staff, field teams and external contractors all complete it the same way.

01

A link in their inbox

One email naming the policy, with one button. Nothing to open, nothing to install, no password to remember.

Northwind Group

09:02

To anna.muller@northwind.example

Information Security Policy needs your sign-off

Hi Anna — have a read and confirm you're happy with it. Takes about three minutes.

Read and sign

No attachment to open. No password to set.

02

The version they were sent

The link opens the exact version that was in force when it went out — not whatever the latest edit happens to be.

Requested by Northwind Group

Information Security Policy

Versionv3.2
  • 3.1 Access follows least privilege.
  • 3.2 Credentials are never shared.
  • 3.3 Devices lock after five idle minutes.

A later edit becomes v3.3. This link stays on v3.2.

03

Confirm, and it's on the record

They slide to confirm. Their name, the version and the exact time are written to the record as they do it.

By signing, you confirm you have read and understood this policy and agree to comply with its terms.

Signed
SignerAnna Müller
Versionv3.2
Confirmed14 Mar 09:41

Certificate available to download on the spot.

Evidence in two formats

Good evidence is tied to a version, linked to a named person, and available months later. Policyflow keeps both formats ready: a summary certificate for the one-pager, and a row-level log for anyone who wants to go through the detail.

The one-page summary

A PDF that wraps up a finished campaign: which policy, which version, who was in scope, how many confirmed and when. Ready for a regulator or a vendor questionnaire without reformatting.

Certificate

Information Security Policy v3.2

Exported
In scope142
Confirmed138
Completion97.2%

The full log

One row per action: person, policy version, status change and timestamp, down to the individual click. Opens directly in Excel or your GRC tool.

RecipientVersionConfirmed
Sarah Chenv3.210:42
Marcus Johnsonv3.211:08
Elena Kowalskiv3.213:21
Daniel Parkv3.216:55

Common questions

Where does ISO 27001 stand on policy acknowledgements?
The standard doesn't name a tool or method. It asks for evidence that people know the rules they work under, and that documented information is actively managed. In practice an auditor looks for a clear trail linking each person to the version of the policy that applied to them — which is the record Policyflow keeps.
What does a defensible acknowledgement record look like?
Four things: a named person, a precise timestamp, a specific version of the document, and a way to retrieve it all without reconstructing the story. Policyflow stores every confirmation with all four, so producing evidence is an export, not a project.
Can we track this in Outlook or SharePoint instead?
For ten people in one room, probably. With staff turnover, multiple revisions and reminders to chase, mailbox- and file-share-based tracking breaks down: you end up scrolling threads to work out which version someone confirmed, or bolting workflows and spreadsheets onto SharePoint until you've rebuilt a policy tool by hand.
Does this only work for formal policies?
No. Any document that needs a named sign-off against a specific version fits: codes of conduct, data processing notices, contractor agreements, internal SOPs, onboarding packs.
Will employees need to log in somewhere?
No. Every recipient gets a personal link by email. They open it, read the policy and confirm — nothing to install, nothing to remember, and every action is still tied to the individual who performed it.
Won't people get spammed with reminders?
No. Reminders only go to people who haven't confirmed, on the schedule you set. Anyone who has confirmed is left alone.
Which version of a policy does a confirmation point to?
The version that was live when the campaign went out. Updating the policy later creates a new version; historical confirmations stay pinned to the one people actually read.
How quickly can we get up and running?
Most teams send their first campaign within an hour of signing up: create the workspace, add a policy, optionally sync your directory, pick an audience and send.
Which compliance frameworks does it support?
Any framework that requires managed policies and proof of acknowledgement — ISO 27001, SOC 2, GDPR, NIS2, DORA and HIPAA among others. The mechanics are the same across all of them.

Start with your first policy

Create a workspace, add a policy and send your first campaign today. Free for teams up to 15 employees, no card required.