For Financial Services & Legal Firms

Real-Time Compliance Enforcement for Regulated Industries

The only operations playbook that doesn't just document rules — it enforces them.

Compliance Dashboard — Q2 2026 Live Enforcement ✓
87%Overall
22
Compliant
4
In Review
2
Violations
Client Funds Segregation Compliant
Annual Client Communication Review Due in 3 days
AML Transaction Monitoring Alert sent

Not just documentation. Enforcement.

Most compliance tools document your rules. FirstParty enforces them — with real-time status tracking, automated alerts, and an audit trail built for regulators.

Real-Time Rule Enforcement

28 pre-built compliance rules with live status tracking. Know your compliance score at any moment — not just at audit time. Statuses update in real time as your team works.

🔔

Automated Alerts & One-Click Acknowledgment

Violations trigger immediate alerts. Team members acknowledge with one click — creating a dated, auditable record of every compliance action taken.

📋

Audit Trail & Exportable Reports

Every status change, acknowledgment, and review is logged automatically. Generate shareable compliance reports for auditors and regulators in seconds — no login required on their end.

👥

Role-Based Team Management

Admin, Compliance Officer, and Viewer roles out of the box. Control exactly who can update rules, acknowledge alerts, or view sensitive compliance data.

From setup to audit-ready in minutes

1

Set Your Rules

Start with 28 pre-built rules for regulated industries. Mark N/A, set priorities, add custom rules for your firm.

2

Rules Are Enforced

Every rule is tracked in real time. Your live compliance score updates as your team works through the playbook.

3

Violations → Alerts

When a rule falls out of compliance, alerts fire immediately. One-click acknowledgment creates a timestamped record.

4

Share With Auditors

Generate read-only compliance reports with a single link. Auditors and regulators need no login to view them.

Simple pricing for growing firms

Start free. No credit card required. Upgrade when you need more seats or custom rules.

Enterprise
Contact
Sales
Custom rules, unlimited team members, and dedicated support for larger firms.
  • Everything in Starter
  • Custom compliance rules
  • Unlimited team members
  • Full audit history
  • Priority support & onboarding
Contact Sales
Loading rules...

Welcome back

Log in to track compliance across your 28 rules.

New here? Create an account

Get started

Create your account and start tracking compliance today.

Already have an account? Log in

Compliance Dashboard

Track your compliance across all 28 rules.

Applicable Rules
28
Compliant
0
Overdue
0
N/A Rules
0
Compliance Score
0%
0
Compliant
0
In Progress
0
Needs Review
0
Not Started

Rule Compliance Tracker

Loading rules...

Audit Log

Complete record of all compliance actions taken by your team. Required for regulatory compliance.

to
Timestamp User Action Rule / Entity Details
Loading...

Company Settings

Personalize your compliance playbook to fit your business.

Company Profile

About Rule Overrides

Every rule in the 28-rule playbook applies by default. If a rule doesn't apply to your business — for example, a law firm doesn't need the same rules as a SaaS startup — you can mark it as Not Applicable from the Dashboard.

N/A rules are excluded from your compliance score and hidden from the active tracker. You can set a custom priority (Low / Medium / High / Critical) for any rule that needs special attention.

Notifications

Get notified about compliance events even when you're not logged in.

Loading preferences…

Webhooks

Push compliance events to Slack, Teams, or any HTTP endpoint in real-time.

Event types: compliance.status_changed compliance.alert_created compliance.scan_completed compliance.escalation compliance.score_changed compliance.remediation_created compliance.remediation_resolved
Loading…

API Keys

Programmatic access for CI/CD pipelines, SIEM integrations, and automated reporting.

Endpoints: GET /api/v1/score GET /api/v1/compliance GET /api/v1/rules GET /api/v1/audit
Authenticate with Authorization: Bearer fp_...
Loading…

Team

Manage team members and their access levels.

Members

Loading…
Loading invite details…

Plan & Billing

Manage your subscription. Upgrade to unlock exports, team management, and public compliance reports.

Current Plan
Free Active
No payment required
Available Plans
Free
$0/mo
Get started with compliance tracking for small teams.
  • 28 pre-built compliance rules
  • Up to 3 team members
  • Real-time alerts & audit trail
  • 90-day audit history
  • Basic compliance dashboard
Professional
$149/mo
For established firms that need public reports and unlimited access.
  • Everything in Starter
  • Unlimited team members
  • Public compliance reports
  • Custom rule prioritization
  • Priority support

Admin Analytics

Product usage and engagement metrics.

Enter Admin Secret

Stored in sessionStorage only. Set ADMIN_SECRET env var on the server.

Custom Rules

Define compliance rules specific to your business. Custom rules participate in scoring, alerts, and scans alongside the 28 pre-built rules.

Loading…

Add Custom Rule

Scheduled Reports

Automatically email compliance reports to stakeholders on a weekly or monthly basis. Requires Professional plan.

New Scheduled Report

One email address per line

Compliance Frameworks

Activate SOC 2, HIPAA, or GDPR rule packs. Each framework adds industry-standard controls to your compliance checklist.

Professional Plan
Loading frameworks…

Compliance Analytics

Score trends, category breakdown, and activity timeline.

Compliance Score Over Time

Past 30 days
Loading chart…

Category Breakdown

Loading…

Activity Timeline

Loading…

Remediation

Assign fix tasks to your team for every non-compliant rule. Track from open to verified.

Open
In Progress
Overdue
Due Soon
Verified
Avg Fix Time
Loading…

New Remediation Task

Task Detail

Loading…

Mark Resolved

Compliance Calendar

Regulatory deadlines, certification renewals, and recurring obligations

Overdue
Due This Week
Due This Month
Completion Rate

SunMonTueWedThuFriSat

New Deadline

Skip Deadline

Risk Matrix

Likelihood × impact scoring for each compliance rule. Identify your highest-exposure risks and track mitigation progress.

Total Assessed
Avg Risk Score
Critical (20–25)
High (13–19)
Unmitigated
5×5 Risk Heat Map Click a cell to filter the list below
x
Low (1–5)
Medium (6–12)
High (13–19)
Critical (20–25)

Top 5 Highest-Risk Rules

Loading...
All Assessments
Rule Category Likelihood Impact Score Mitigation Assessed By
Loading...

Assess Rule Risk

Score: —

Policies

Attach formal written policies to compliance rules. Auditors ask for this first.

Professional Plan

Training

Track certifications, completions, and regulatory training requirements per team member.

Professional Plan

New Policy

Audit Packages

Export complete compliance bundles for auditor delivery — frameworks, evidence, remediation history, and score trends in one structured export.

Professional Plan
Summary
Category Breakdown 0
Controls 0
Evidence Artifacts 0
Remediation Tasks 0
Score History 0
Risk Assessments 0
Audit Trail 0

Generate Audit Package

Bundle compliance data, evidence, and remediation history into a structured export for your auditor.

Loading frameworks…

Regulatory Changes

Track regulatory updates, assess impact on your controls, and manage remediation workflows.

Professional Plan

Compliance Incidents

Document security events, track response timelines, manage regulatory notifications.

Professional Plan

Vendor Risk

Assess, score, and monitor third-party compliance exposure. Required by SOC 2 CC9.2 and FINRA supervisory obligations.

Professional Plan

Documents

Centralized document repository with retention schedules for FINRA Rule 17a-4, SEC Rule 17a-4, and SOC 2 CC7.2 compliance.

Professional Plan

Notifications

Your activity feed across all GRC modules

Total
Unread
Today
Active Modules

Notification Preferences

Control which events create in-app notifications. Changes take effect immediately.

Module / EventIn-AppEmailDigest
Loading preferences…

Preferences are per-user. Team members can configure their own notification settings independently.

404

Page not found

That page doesn't exist. It may have moved or never existed in the first place.

Something went wrong

An unexpected error occurred. Please refresh the page to continue.

Upgrade Required

This feature requires a paid plan. Upgrade to unlock CSV exports, team management, and public compliance reports.

Add Proof Artifact

Executive Dashboard

Board-ready GRC scorecard across all compliance dimensions.

Professional Plan

Report Templates

Pre-built SOC 2, HIPAA, FINRA, and GDPR templates. One click to generate a regulator-ready report from live platform data.

Loading templates…

Automation Workflows

Trigger-action rules that auto-escalate, notify, and update across all GRC modules. The active enforcement layer that keeps your compliance posture current.

Total Rules
Active
Total Triggers
Built-in Templates
Rules
Execution History
Loading rules…

Audit Trail

Tamper-evident activity log across all GRC modules. Required by SOC 2 CC7.2, HIPAA §164.312(b), and FINRA 3110(b)(4).

Events (30d)
Today
Unique Actors
Deletes
Exports
When Actor Module Action Entity IP
Loading…

Single Sign-On

Configure SAML/OIDC identity providers · Enforce SSO for your organization · Audit login sessions

SSO Configurations

Connect your identity provider. Enforce SSO to require all users to authenticate via IDP.

Loading…

Auditor Portal

Invite external auditors, regulators, and assessors with scoped, time-limited access to your compliance data.

Total Invitations
Active
Pending
Total Accesses
Loading…

Access Control

Define roles, set granular module permissions, and assign team members to control who can read, write, and manage each GRC area.

Loading…

GRC Scorecard

Live compliance posture across all modules — decision-ready for the board.

Professional Plan

API Keys

Authenticate with X-API-Key: fp_... or Authorization: Bearer fp_...

Loading…

Identity Provider Configurations

Each config represents one IdP trust relationship (Okta, Azure AD, etc.)

Loading…