← All kits
For teams standing up governance for SOC 2, ISO or a raise · Internal policies

The policy backbone your company runs on.

An auditor or investor asks for your policy set — and you’ve got a folder of half-finished Google Docs.

Thirteen board-ready policies — governance, security, data protection, AI use, IP, confidentiality and trade compliance — the canonical rulebook your AI Act, GDPR, IP and contract toolkits all plug into, with a register to prove rollout.

NEW · JULY 2026Thirteen policies plus the Adoption Console — ownership, sign-off and acknowledgement tracking in one live register.

✓ 14-day money-back guarantee. one-off €690 · ordered by email, invoiced same day · ZIP in your inbox on payment · fully editable · single-business licence

Policies Register and Adoption Console from the pack — ownership, sign-off and acknowledgement tracking
Actual screen · Adoption Console · v1.0, June 2026 build
What’s inside

Everything you deploy, in one download.

Editable Word masters with styled PDF previews — plus self-contained HTML consoles that run in your browser, offline. Built to a single standard and cross-referenced where it counts.

13 board-ready policies5 interactive toolsWord + PDF preview eachoffline HTML · dated print records

The thirteen policies — brand, adopt, attest

  • Core governance: Code of Conduct & Ethics · Anti-Bribery & Corruption · Whistleblowing · Conflict of Interest
  • IT & AI security: Information Security · Acceptable Use · BYOD & Remote Work · AI Use
  • Commercial & regulatory: Data Protection & Privacy · Contracts · IP & Trademarks · Confidentiality · Trade Compliance

Interactive tools (5) — policies made live

  • Policies Register & Adoption Console — ownership, sign-off and acknowledgement tracking
  • Audit Evidence Mapper — map each policy to the evidence an auditor asks for (SOC 2 / ISO 27001)
  • Whistleblowing Case Console — intake and case log, EU Whistleblowing Directive-aware
  • Conflicts & Gifts Register — declarations, kept current
  • AI Use Gate — screen a planned AI use against your policy and get an escalation verdict, logged

How the tools work

  • A single HTML file each — double-click, it opens in your browser
  • Runs in your browser: nothing is uploaded — what you type never leaves your machine
  • Save a session and pick it up later; keep dated records
  • Print a dated PDF readout for your audit file

What you download

  • One ZIP, delivered to your inbox on payment — usually within the hour
  • Documents as editable Word masters plus a styled PDF preview of each
  • Tools as self-contained HTML files — no install, no account
  • Version-dated · single-business licence (no resale or redistribution)
Proof, not promises

Judge the work before you pay.

An actual document page from the shipped kit is below — and the free tool runs on the same expert layer, so the sharpest preview is to run it.

First page of the Information Security Policy styled preview from the pack
Actual page · Information Security Policy preview (Word master included)
free · no sign-up

Don’t take our word for it — try the thinking.

The free Internal Policies Gap-Check runs on the same senior expertise that built this kit — a live read of your own position, not a teaser. The free check is the kit’s thinking, without the kit’s documents. If the diagnosis is this specific, that’s what the treatment is like.

Run the free Internal Policies Gap-Check →

On this page: an actual console screen (top) and an actual document page from this kit. More samples on request.

Thirteen board-ready policies for less than an afternoon of consulting.

Governance, security, data protection, AI use, IP, confidentiality — the canonical set, citation-backed, consistent across all thirteen, and mapped to ISO 27001 and SOC 2. €690.

Why you can rely on it
EXPERT
BUILT

Fifteen years, 10,000+ contracts and corporate documents, and both sides of M&A went into this kit — including a recent USD 40M+ software exit. It was built from casework, and it's maintained like casework: cited, dated, updated when the law moves.

Cited to source · version-dated · current as of July 2026

Want the set installed and rolled out for you? See the Internal Policies Review.

See the assessment

Kit fee credited in full against the Internal Policies Review · not sure which fits? Book a free intro call ›

The policy menu

Wherever you are with your policies, here’s what fits.

Pick the one that matches where you are — each stands alone, buy in any order or on its own. Your team does the work with our templates; that’s why this costs a fraction of a consultancy.

Check yourself — free
Internal Policies Gap-CheckScores your policy pack and points to the fix, free.Open ›
Get assessed
Internal Policies Review · €3,200Up to 15 policies reviewed, 5 marked up, ISO/SOC 2 mapped.Open ›
Get the documentsyou’re here
Internal Policies Pack · €690Thirteen board-ready policies with a live adoption and evidence console.On this page
Get it done, keep it current
Fractional · a free intro callOngoing upkeep, or a policy-set briefing call.Open ›
Questions

Before you buy.

Can’t I generate these myself?

You can generate something. Whether it’s coherent, citation-backed, consistent across thirteen documents and defensible to an auditor is another matter. The pack is the canonical set, mapped to ISO 27001 and SOC 2, with a register to prove rollout.

Will this satisfy a SOC 2 or ISO auditor?

The set is mapped to ISO 27001 and SOC 2, and the adoption tracker is built to evidence that each policy was approved and rolled out — which is what auditors actually test.

Can I edit everything?

Yes — the policies are working Word files: drop in your company name and approvers and they’re board-ready. The registers and consoles are live browser tools — save a session, export print a dated record.

Isn’t this just legal advice in a box?

No — it’s a set of expert-built template documents and guidance you deploy yourself, not legal advice and not a review of your business. The documents are drafted to market-standard positions for a typical software and technology company and are yours to adapt. Buying them creates no lawyer–client relationship or privilege, and Xprofesso LLC is not a law firm.

What you’re buying: deployable, editable source documents — the governance, security and governance, security and commercial policy set procurement asks for — plus guidance to implement them, built by a senior practitioner.

What it isn’t: a check of your specific setup, confirmation the documents are sufficient for your facts or jurisdiction, or an opinion on enforceability. Want your actual policy stack checked? That’s the Policies Assessment. Need a formal opinion or a filing? That’s a licensed lawyer.

Direct line · reply within one business day

A question before you buy?

One message — no account, no call required. It lands in our Proton inbox.

Proton (Switzerland) · no ad-tech · purged after 12 months

Prefer to talk it through? Book a free 20-minute intro call ›

Turn the folder of drafts into a real rulebook.

€690, one-off. In your inbox within the hour of payment, fully editable, backed by a 14-day money-back guarantee.