Track policyacknowledgements.At any scale, instantly.

Distribute policies to ten or a thousand recipients, collect verifiable acknowledgements, and keep records ready for audits and reviews.

Get started
Try with up to 10 recipientsNo credit card
Get started in secondsMagic link access
Choose between EU or US hosting
See how it works
Policy Confirm dashboard showing compliance cycles with status, policies, and progress tracking
Principles

From policy distribution to confirmation

A structured approach to policy awareness, ownership, and evidence.

Controlled distribution

Replace scattered files, email threads, and shared drives with a single place for policies and versions. Every distribution is tied to a specific document version, a defined set of recipients, and a point in time. There is no ambiguity about what was sent, to whom, or when.

Explicit confirmation

Recipients confirm through a verified, individual action. Each confirmation is tied to a specific person, a specific policy version, and a specific point in time. Group-based targeting ensures the right people are included automatically, without manual follow-up.

Verifiable evidence

Every confirmation is timestamped and tied to a specific policy version. This creates retrievable documentation that stands on its own during audits, reviews, and compliance assessments, without requiring manual reconstruction.

How it works

From upload to verified in three steps

01

Upload & target

Upload your policy document as a PDF and define the recipient list. Group recipients by department, location, or role to ensure the correct version reaches the right individuals. Each upload creates a version-linked record that ties all subsequent confirmations to that specific document.

Policy Confirm policy detail view showing file versions, upload timestamps, and version history
02

Distribute

Each recipient receives a secure, single-use link via email. They access the assigned policy directly, read the document, and submit their confirmation. No accounts, no passwords, and no software installation required, ensuring high completion rates across technical and non-technical recipients.

Policy Confirm recipient confirmation page with single-click acknowledgement
03

Track & prove

Monitor confirmation progress in real time with a clear overview of completed, pending, and outstanding acknowledgements. When evidence is needed, generate a formal PDF certificate or export granular CSV logs containing exact timestamps, version identifiers, and individual recipient actions.

Policy Confirm dashboard showing annual policy acknowledgement cycle with recipient status and confirmation overview
Features

Built for control at
scale

Turn passive distribution into verified acknowledgement. Advanced control for administrators, seamless access for employees and receivers.

Coverage on autopilot

Acknowledgement coverage stays complete without anyone chasing it. New recipients are picked up automatically, and policies return for confirmation on the schedule you set, so nothing lapses quietly between audits.

Bulk import & group targeting

Import recipients in bulk via CSV, Excel, or Microsoft Entra ID integration. Assign them to groups for role, department, or location-based policy targeting. When new employees join a group, they inherit all active policies automatically — no manual admin work.

Version control

Every policy is versioned explicitly. When a document changes, you decide whether to start a new confirmation round or update the file for recordkeeping only. Each version is locked at dispatch and fully traceable.

Confirmation cycles

Group policies into a single, controlled confirmation cycle across teams and departments. Confirmations stay synchronized, deadlines aligned, and proofs unified at any scale.

Flexible cycle management

Handle exceptions without stalling progress. Decide whether to extend deadlines or finalize cycles as-is, while keeping confirmations consistent and cycles under control.

Magic link access

Recipients confirm policies via a secure, personal link. No accounts or passwords are required, while every confirmation remains uniquely identified and timestamped.

Your branding

Add your own logo, message, and color to everything recipients see, from the first request to the moment they confirm.

Microsoft single sign-on

Sign in using an existing Microsoft work account. No separate credentials required for administrators or recipients.

Delegated follow-up

Assign supervisors to recipient groups and let them follow up with their own teams. Outstanding confirmations are handled close to the people who owe them, not by one central admin.

Quiz questions

Add questions to any policy and every recipient must answer them all before they can confirm they have read and acknowledged it. Configure once, enforced for everyone.

eSign signatures

If preferred, require recipients to draw their signature before confirming policies. An optional add-on for use cases where a more formal acknowledgement is needed.

Verifiable documentation

Generate audit-ready proofs instantly. Get formal PDF certificates and detailed CSV logs with timestamped records for every single recipient.

PDFCSV

Full audit log

All events, including uploads, version changes, dispatches, confirmations, and closures, are logged. Nothing is implicit. Nothing is lost.

Data retention

Set how long confirmation records are kept for inactive recipients. Records are automatically deleted when the retention period expires, supporting GDPR and industry compliance requirements.

Smooth experience

No login needed for recipients

Recipients receive a secure, single-use email link with direct access to their assigned policies. The process requires no account creation, no password management, and no software installation. This accessibility-first approach ensures high completion rates across all recipients, including non-technical staff and external contractors.

  • No account
  • No password
  • No install
Illustration of the recipient experience: email with link to confirmation page
Proofs

Audit-ready documentation

Audit-ready documentation must be retrievable, version-linked, and independently verifiable. Policy Confirm provides two complementary formats: formal certificates for rapid proof of compliance, and granular data logs for detailed inspection during audits or internal reviews. Both are generated instantly and require no manual assembly.

Click to switch format

PDF confirmation certificate example with version, timestamps, and recipients
Organization certificate of compliance showing acknowledgements across all policies
CSV confirmation records example with timestamps and recipient details

Plans & Pricing

From evaluation to organization-wide rollout.

Designed for organizations operating under formal compliance requirements.

Free

No time limit
No credit card

Test and evaluate the system

Up to 10 recipients
$0 / month
  • Includes all standard features
Get started

Standard

Everything you need to run policy confirmations at scale

Up to 75 recipients
$49 / month
Up to 250 recipients
$79 / month
Up to 1000 recipients
$139 / month
  • Unlimited policies & confirmation cycles
  • Version control
  • Smart targeting
  • Microsoft Entra ID sync
  • Unlimited administrators
  • Magic link access
  • Microsoft single sign-on
  • Electronic signature (eSign)
  • Quiz questions
  • Automated reminders
  • Delegated follow-up
  • Verifiable documentation (PDF & CSV)
  • Full audit log
Get started

Enterprise

For organizations that require delegated governance, multiple entities, or tailored compliance workflows.

Frequently asked questions

Clear answers about acknowledgements, confirmations, and audit-ready documentation.

Usage & scope

Yes. It can be used for any document where you need verifiable proof that recipients have read and acknowledged the content. This includes internal guidelines, HR notices, security procedures, onboarding materials, updated terms, and mandatory internal communications.

Email and shared folders only show that a document was sent or made available. They do not provide proof that a specific person acknowledged a specific version. This platform creates explicit, traceable confirmations tied to individuals, documents, and versions.

No. Recipients confirm documents through a secure personal link. No accounts or passwords are required.

Confirmations & enforcement

Yes. All confirmation cycles are started explicitly by an administrator. Nothing is sent automatically without intent.

No. Each confirmation cycle results in one clear request. Automated reminders are only sent if the recipient has not confirmed.

The confirmation remains pending and reminders continue according to the configured schedule. If a recipient never confirms or leaves the organization, an administrator can finalize the cycle with a documented exception.

Audit, proof & compliance

Yes. Every acknowledgement is locked to a specific document version. Updates never overwrite historical confirmations.

Yes. All confirmations are logged with timestamps and version references. Audit-ready documentation can be exported as PDF certificates and detailed CSV logs.

Defensible evidence typically includes version-specific confirmations tied to identifiable individuals, timestamps, visibility into outstanding acknowledgements, and a retrievable log that can be exported without manual reconciliation. The goal is not just to show that a policy was sent, but to demonstrate traceable acknowledgement of the exact version in force.

ISO 27001 does not mandate specific software or acknowledgement mechanisms. However, it requires organizations to demonstrate awareness and control of documented information. In practice, structured acknowledgement is often the most defensible way to evidence awareness because it links individuals to a defined policy version and produces retrievable documentation during audit review.

SOC 2 does not prescribe a specific tool. Auditors testing the control environment normally ask for evidence that personnel were made aware of, and agreed to, the policies in force during the audit period. Version-specific acknowledgements with timestamps and an exportable log are one way to satisfy that request during SOC 2 evidence collection.

Email confirmation can be acceptable in small, tightly controlled environments. The risk is reconstruction: email threads rarely provide consistent version linkage, reminder history, and exportable evidence. If an auditor asks who acknowledged a specific policy version on a specific date, manual processes can become fragile and time-consuming to validate.

SharePoint can distribute policies, but version-specific acknowledgement tracking and structured export often require additional configuration.

No. This is designed for policy acknowledgements, not contract signing. For most internal compliance requirements, explicit acknowledgement with a full audit trail is sufficient.

Organizations that need reliable proof of internal communication, typically in HR, IT, compliance, security, or legal functions. It is commonly used by companies preparing for audits or strengthening internal governance.

Latest from Policy Confirm

Guides, templates, and best practices for policy management and compliance.

Start collecting verified policy acknowledgements

For a demo or specific questions about your compliance requirements, get in touch at:

Get started
Try with up to 10 recipientsNo credit card
Get started in secondsMagic link access
Choose between EU or US hosting