The compliance studio: regime reporting from the Open Audit Record
Our compliance studio builds regime reports from the Open Audit Record, the tamper-evident log of every action across the whole operating system.

The compliance studio builds regime reports from the Open Audit Record, the tamper-evident log of every action taken across the operating system. You do not gather evidence by hand after the fact. The record is written as work happens, across every studio, and the studio turns it into structured reporting mapped to your record-keeping duties. It is verifiable offline, and it claims no certification we do not hold.
That is the whole idea. Most compliance work is the archaeology of reconstructing what happened from logs that were never designed to be read together. We invert it. The evidence is a by-product of running the business on one operating system, and the compliance studio reads it.
What the compliance studio does
The studio does three things. It reads the Open Audit Record. It maps entries to the reporting a regime asks for. It produces a report you can hand to an auditor, a regulator or your own board.
Because every studio on the platform writes to the same record, the studio is not stitching together exports from a mail system, a chat tool, a CRM and a finance package that never agreed on a format. It reads one record that already spans all of them. An approval in the finance studio, a message in the collaboration platform, a change to a customer file in the CRM: each is an action, and each is in the record.
The report is not a screenshot of a dashboard. It is a structured document tied back to the underlying events, so any line can be traced to the action that produced it. When someone asks "show me the evidence for this," the answer is one step away, not a week of email.
The Open Audit Record
The Open Audit Record is a tamper-evident record of every action across the whole operating system. Two words carry the weight.
Every action. Not just the ones a given app decided to log. The record is produced by the operating system the studios run on, so it captures what happened regardless of which studio the work happened in. That is the difference between a platform and a pile of applications: the audit trail is a property of the whole, not a feature bolted onto each part.
Tamper-evident. Entries are written so that alteration is detectable. An auditor does not have to trust that the record is intact; they can verify it. And they can do so offline. There is no live call to a vendor, no dependency on us being reachable, no assumption that the party holding the data is also the party you are checking. The record stands on its own.
That offline property matters for regulated firms. If your ability to prove what happened depends on a vendor's service being up and honest, you have not removed the risk, you have renamed it. A record you can verify yourself, on hardware you own, is a record you actually control.
Mapping to record-keeping duties
Most regimes that bind a regulated small or mid-sized firm come down to a few plain obligations. Keep records of decisions and the reasons for them. Retain communications for a defined period. Be able to reconstruct who did what, and when, on demand. Produce it to a regulator within a set window.
The compliance studio maps the Open Audit Record onto those obligations. Decisions and approvals are actions, so they are in the record with their timestamp and their actor. Communications handled inside the collaboration and email studios are actions, so retention is a property of the record rather than a mailbox someone might have emptied. Reconstruction is a query, not an excavation.
We are careful about what this is and is not. The studio helps you meet your duties. It does not certify that you have met them, and it does not confer any status. You remain the accountable party. What we give you is the evidence, assembled and verifiable, so that meeting the duty is a matter of running a report rather than mounting an investigation.
What we do not claim
We hold no certifications. Not SOC 2, not ISO 27001, not Cyber Essentials, held or in progress. If a vendor tells you their certification satisfies your obligation, read the scope: a certification of their service is not a discharge of your duty. The compliance studio is honest about this. It gives you the record and the reporting. The obligation, and the certification you may choose to pursue, remain yours.
We think that honesty is worth more than a badge. A regulated firm is not helped by a supplier who blurs the line between the supplier's assurances and the firm's own responsibilities. The Open Audit Record is useful precisely because it is your evidence, on your hardware, that you can produce whether or not any third party vouches for anything.
Why it takes an operating system, not an app
A standalone compliance tool can only report on what it can see. Bolt one onto a stack of rented services and it sees whatever those services choose to export, in whatever shape, with whatever gaps. The report is only as complete as the least cooperative log.
The compliance studio is different because it is not a bolt-on. It is one of 87 studios on a single sovereign operating system, sharing one assistant and your own data. The audit record is produced by that operating system, so the studio sees everything the business does on the platform. Clients onboard onto a focused initial set of studios and grow from there, and every studio they add writes to the same record from day one.
This is the baseline we start beyond. A private deployment where the vendor cannot see your data is table stakes. Our value is what sits on top: action-level audit through the Open Audit Record, air-gapped by default, the whole software stack you run rather than a model you have to wire into someone else's cloud, and a focus on the regulated smaller firm that the heavyweight vendors tend to leave underserved.
The assistant across the record
One assistant runs across all the studios, and it reads the Open Audit Record too. So the compliance work that used to be specialist and slow becomes conversational. Ask it to pull every approval over a threshold in the last quarter, or to assemble the communications retained for a named client, or to draft the report a specific regime expects. It works from the record, not from a summary of the record, so what it produces traces back to the underlying actions.
That does not replace the compliance officer. It removes the drudgery that stops them doing the judgement work only they can do. The evidence gathering is automatic. The interpretation stays human.
The point
Compliance is expensive because evidence is scattered and trust is outsourced. We fix both. The evidence is gathered as a by-product of running the business on one operating system, and the trust sits with a tamper-evident record you can verify offline, on hardware you own. The compliance studio turns that record into the reports your regime asks for.
You still own the obligation. We just make the evidence easy to produce, hard to alter, and yours.
Frequently asked questions
What does the compliance studio actually produce?
It assembles regime reports and record-keeping evidence from the Open Audit Record, the tamper-evident log of every action taken across the operating system. You get a structured report tied back to the underlying events, exportable and verifiable offline.
Does MICKAI hold any certification?
No. We hold no SOC 2, ISO or Cyber Essentials certification. The studio helps you meet your own record-keeping duties. It does not confer any certification, and we do not claim one.
What is the Open Audit Record?
It is a tamper-evident record of every action across the whole operating system, written as actions happen. Because the studios share one platform, the record is complete rather than stitched together from separate apps, and it can be verified offline.
Can auditors check the record without trusting us?
Yes. The record is tamper-evident and verifiable offline, so an auditor can confirm that entries have not been altered without needing a live connection to any vendor or to us.
How is this different from a private cloud deployment?
A private deployment where the vendor cannot see your data is our starting point, not our finish. The compliance studio adds action-level audit through the Open Audit Record, runs air-gapped by default, and is the software stack you run rather than a service you rent.
Is the compliance studio a separate product?
No. It is one of 87 studios on a single sovereign operating system, sharing one assistant and your own data. Clients onboard onto a focused initial set of studios and add more over time.