See Every Obligation.
Miss Nothing.

Iris scans your defense contracts for compliance clauses, tells you exactly what you need to do, and maps obligations to CMMC, NIST 800-171, and 330+ frameworks — automatically.

Download for Windows See How It Works
12
Clause categories detected
337
Compliance frameworks mapped
297
CMMC assessment objectives
110
NIST 800-171 controls
Built for: DFARS 252.204-7012 CMMC Level 2 NIST 800-171 ITAR / EAR FAR 52.204-21 Desktop App

Stop Reading Contracts Manually

Iris does in minutes what takes compliance teams weeks — and catches what they miss.

Contract Clause Scanner

Drop in PDFs and Word docs. Iris finds every DFARS, FAR, ITAR, and EAR clause — across your entire contract portfolio. No clause missed, regardless of how it's worded.

AI Deep Scan

AI reads each clause and tells you exactly what to do — not "comply with ITAR" but "register with DDTC, designate an Empowered Official, screen all personnel for U.S. person status."

Compliance Action Plan

Synthesizes all obligations across all contracts into a single, prioritized action plan. Grouped by domain, assigned by role, ranked by urgency. Hand it to your team.

Framework Gap Analysis

Maps contract clauses to CMMC, NIST 800-171, ISO 27001, and 330+ other frameworks. Shows exactly which controls you need and which you already cover.

Assessment Objective Mapping

Goes deeper than control-level mapping. Evaluates each of the 297 CMMC assessment objectives individually — the level of detail a C3PAO assessor expects.

Documents Never Leave

Iris is a desktop app. Your contract documents stay on your machine. Only extracted clause text is sent for AI analysis — never the original document. Ever.

Everything You Need

From contract scanning to framework compliance — one tool.

PDF & Word Parsing

PDF.js and mammoth.js extract text locally. No cloud processing.

Regex Clause Detection

Built-in library catches DFARS, FAR, ITAR, EAR, CUI, and flow-down language.

Multi-Provider AI

Built-in AI included. Or bring your own: Anthropic, OpenAI, Azure, Gemini, Ollama.

Cross-Contract Matrix

See which clauses appear in which contracts. One view across your entire portfolio.

Severity Ratings

Critical, high, medium, low — based on regulatory impact and penalty risk.

Actionable Obligations

Specific tasks a compliance officer can assign. Not restatements of regulations.

337 Framework Mappings

SCF-powered cross-reference: CMMC, NIST, ISO, SOC 2, FedRAMP, HIPAA, and more.

CMMC AO-Level Gaps

All 297 assessment objectives evaluated individually. Novel depth nobody else offers.

PDF & CSV Export

Professional reports with severity badges, obligation checklists, and action plans.

SharePoint & OneDrive

Microsoft 365 SSO. Scan documents from SharePoint Online and OneDrive for Business.

Scheduled Auto-Rescan

Monitors document sources. Notifies you when new contracts appear or change.

Custom Clause Library

Enterprise customers add their own clause patterns. Import/export between instances.

GRC Integration

Push findings to ControlPoint GRC. Updates CUI scoping, SSP, and POA&M automatically.

Annual Review Alerts

Flags contracts approaching their anniversary. Never miss a compliance review cycle.

Microsoft SSO

One sign-in handles licensing, SharePoint, and OneDrive. No separate credentials.

Enterprise API

REST API for programmatic scanning. Integrate Iris into your CI/CD or GRC pipeline.

How It Works

From contract documents to compliance action plan in four steps.

1

Load Contracts

Drop in PDFs or Word docs from your desktop, network share, SharePoint, or OneDrive. Iris recursively scans all subfolders.

2

Scan for Clauses

Regex detection catches every DFARS, FAR, ITAR, EAR, CUI, and flow-down reference. Builds a cross-contract compliance matrix.

3

AI Deep Scan

AI analyzes each clause and tells you exactly what your company needs to do — specific, actionable, assignable tasks.

4

Map to Frameworks

Auto-maps obligations to CMMC, NIST 800-171, and 330+ frameworks. Shows gaps down to individual assessment objectives.

Simple, Transparent Pricing

AI analysis included in every paid tier. No per-scan charges.

Starter

$199/mo
For small contractors getting started with compliance
  • Up to 15 contracts
  • 1 user
  • Local file scanning
  • Basic clause library
  • PDF & CSV export
  • SharePoint / OneDrive
  • AI Deep Scan
  • Framework Analyzer
  • Auto-rescan
Get Started

Enterprise

$899/mo
For large organizations with complex contract portfolios
  • Unlimited contracts
  • Unlimited users
  • Everything in Professional
  • Multiple SharePoint sites
  • Custom clause patterns
  • Import/export clause libraries
  • REST API access
  • Priority support
  • Custom onboarding
Contact Sales

Why Iris?

Compare Iris to how you're doing it today.

CapabilityManual / SpreadsheetsLegal ReviewControlPoint Iris
Scan 75 contractsWeeksWeeks + $$$Minutes
Catch every clauseHuman errorDepends on attorneyExhaustive regex + AI
Actionable obligationsManual interpretationYes, expensiveAI-generated checklists
Cross-contract matrixManual spreadsheetNot their jobAutomatic
Framework mappingSeparate projectNot their scope337 frameworks, instant
CMMC AO-level gapsDoesn't existDoesn't exist297 objectives evaluated
Documents stay localYesShared with firmDesktop app
Ongoing monitoringManualPer-engagementAuto-rescan + alerts

Frequently Asked Questions

Do my contract documents leave my computer?
No. Iris is a desktop application. Your documents are parsed locally using PDF.js and mammoth.js. Only extracted clause text is sent for AI analysis — never the original document. If you use Ollama (local AI), nothing leaves your machine at all.
What AI providers are supported?
AI analysis is included with Professional and Enterprise tiers via ControlPoint's built-in provider. You can also bring your own: Anthropic (Claude), OpenAI (ChatGPT), Azure OpenAI (FedRAMP compatible), Google Gemini, or Ollama for fully air-gapped local AI.
How does the framework mapping work?
Iris uses the Secure Controls Framework (SCF) — a metaframework with 1,234 controls mapped across 337 compliance frameworks and 175,000+ cross-references. When a contract clause triggers a framework requirement, Iris maps it through the SCF to show exactly which controls apply in every related framework.
What makes the CMMC assessment objective mapping special?
Most tools map at the control level: "ISO 27001 A.8.32 covers CMMC CM.L2-3.4.1." But CMMC assessors evaluate at the assessment objective level — there are 297 individual objectives across the 110 controls. Iris evaluates each one individually to show if your existing certifications actually satisfy what a C3PAO will check.
Can I use Iris without the AI features?
Yes. The regex-based clause scanner, cross-contract matrix, and framework mapping all work without AI. The Starter tier includes scanning and export without AI Deep Scan.
Does Iris integrate with ControlPoint GRC?
Yes. "Send to GRC" pushes findings into ControlPoint GRC to update your CUI scoping, flag NIST 800-171 control families as in-scope, pre-populate SSP system descriptions, and create POA&M items for identified gaps.
Is this legal advice?
No. ControlPoint Iris is a compliance analysis tool, not a law firm. Always consult qualified legal counsel for compliance determinations. Iris helps your compliance team work faster and more thoroughly, but it does not replace legal advice.

Ready to See Every Obligation?

Download ControlPoint Iris and scan your first contract in minutes.

Download for Windows Contact Sales