For consultants, MSPs and vCISOs
Every client's ISO documentation, from one account
Open every client from one portfolio. Each has its own profile, scope, documents and branding, while generation draws from one shared credit pool, so you spend the engagement on judgment, not rewriting.
The problem
You rebuild the same set for every client
Every engagement starts the same way: copy the last client's folder, find-and-replace the company name, and hope nothing of the old client survives. Then weeks of adapting policies to a business they were never written for, reconciling documents that have drifted apart across engagements, and reformatting everything into the new client's template.
The writing is the least valuable part of your engagement, and it is the part that eats the margin. It is also where the risk lives: one stale reference to the wrong company in a delivered document is a bad email to receive.
The workflow
From new client to delivered set
-
1
Add a client
Each client is its own workspace with its own company profile, scope and brand. Give it their name, website, logo and colors in one sitting.
-
2
Generate their set
PolicyMint selects the documents that client actually needs, drafts each one from their profile, checks every section with three independent verifiers, and flags anything only the client can answer.
-
3
Deliver in their branding
Word, PDF and spreadsheet exports carry the client's logo and colors, with clause mappings and their Statement of Applicability assembled. Switch to the next client in a click.
The catalog
What you can deliver
ISO 27001
The full document set: the core plus the topic policies that fit each client's scope.
General cyber
Everyday security policies for clients who want the documents without pursuing certification.
Every document cites the clauses it satisfies, and each client's Statement of Applicability is assembled from what their documents actually cover.
- ISO 27001 documents
-
36
ISO 27001 documents
tiered by what each client actually needs
- ISO 42001 documents
-
21
ISO 42001 documents
for AI management systems
- Clauses and controls mapped
-
182
Clauses and controls mapped
every document cites the ones it satisfies
- Verifiers per section
-
3
Verifiers per section
on a different model to the writer
The economics
One pool, no per-client seats
A$1,360US$889£689€819
inc GST · 4,000 credits · one shared pool
One pool funds every client workspace you manage: each set written, triple-verified and delivered in that client's branding. No per-client license, no per-client platform seat, no procurement conversation per engagement.
Compare that with a GRC platform seat per client, publicly reported at about A$14,000+ (US$10,000+)US$10,000+about £7,400+ (US$10,000+)about €8,700+ (US$10,000+) a year per company, where the documents are a side feature. If a client needs continuous monitoring, use a platform for that; PolicyMint is the documentation layer, and the two work together.
- Complete client sets per pack
-
~4
complete client sets, with credits left over
- Credits per full set
-
~900
credits per full client set
- Per-client seats
-
A$0US$0£0€0
per-client seats or licenses
Who runs it
Three ways the same workspace earns
The independent consultant
You sell judgment, not typing. Generate the client's baseline set in an afternoon, then spend the engagement on scoping, risk and audit readiness, where your rate is actually earned.
The MSP
Security documentation becomes a productized service. Onboard a client, stand up their set the same day, and keep every client's documents separate, current and in their own brand.
The vCISO
Run several ISMSs without several tools. The switcher keeps each client's scope, profile and documents cleanly apart, and the pool means no per-client procurement conversation.
Be clear
The documentation, not the certificate
Your clients are certified by an accredited certification body, and your judgment is what gets them through it. If your practice also needs the training or exam pathway, the Mindset Cyber family runs PECB-accredited ISO courses, and MindsetPrep covers exam preparation. For tracking each client's control implementation, our sister tool ControlStack maps the same controls in an interactive tracker.
PolicyMint produces the documentation your clients are audited against, not the certificate itself.
Consultant FAQ
Running client documentation, answered
The questions consultants ask before they put a client on it.
Is the output white-label?
Every document carries the client's logo, colours and name, not ours and not yours. It reads as that client's documentation because it is: drafted from their profile, mapped to the clauses that apply to them, and exported in their branding.
How is client data kept separate?
Each client is its own workspace with its own profile, documents and branding. Nothing carries across automatically: what you learn about one client stays theirs. Within a client's workspace, the answers you give are remembered, so later documents for that client never ask the same question twice.
How does the credit pool work across clients?
One prepaid Consultant pool funds every client workspace you manage. Generating for any client draws from the same pool, so there is no per-client license, seat or minimum. You buy capacity once and point it wherever the work is.
How is this different from a GRC platform seat per client?
A platform charges an annual, per-company subscription and does continuous monitoring; documents are a side feature. PolicyMint is the documentation layer: it writes, checks and brands each client's set, priced per document rather than per client per year. Many consultants use both, with PolicyMint producing the documents the platform then tracks.
Which standards can I deliver with it?
ISO/IEC 27001:2022 and ISO/IEC 42001:2023 document sets, including the Statement of Applicability, plus a set of general cyber security policies for clients who want the documents without pursuing certification.
Does this replace my role in the engagement?
No. It replaces the typing. Scoping, risk judgment, implementation guidance and audit preparation remain yours; PolicyMint gets a complete, consistent, verified document set onto the table on day one instead of week six.
Stop rebuilding the same document set
Add a client once. Get their full set, written for their business, in their branding, checked before you hand it over.
Your first document is on us. We ask for a card to begin and you are not charged for it, and there is no sales call. See pricing