Audiso
AI & network security Β· completed Β· Auditor, ai & web devoloper, web & network security Β· Jun 2026
Audiso is an intelligent AI-powered platform designed to simplify and automate ISO/IEC 27001 security audits in healthcare environments. It enables auditors to assess compliance, analyze evidence, identify security gaps, generate professional audit reports, and calculate compliance scores through AI-assisted tools.

- React
- TypeScript
- PostgreSQL
- Vite
- Tailwind CSS
- Flask
Overview
π Audiso β Intelligent ISO/IEC 27001 Audit Platform
Audiso is an intelligent AI-powered platform designed to support and automate ISO/IEC 27001:2022 security audits, with a particular focus on healthcare and hospital environments.
The platform combines cybersecurity, network auditing, artificial intelligence, computer vision, document analysis, and automated reporting to help auditors collect evidence, evaluate security controls, identify vulnerabilities and non-conformities, and generate professional audit reports.
π― Project Vision
Audiso aims to transform traditional security auditing from a mainly manual and time-consuming process into a structured, intelligent, and AI-assisted workflow.
The platform helps auditors move from:
Audit β Evidence Collection β Analysis β Risk Identification β Compliance Evaluation β Report Generation
while maintaining the auditor's role in the final decision-making process.
π Main Features
π₯ Hospital & Audit Management
- Create and manage healthcare organizations and audit missions.
- Select and manage the audited hospital/site.
- Organize audits by zones, rooms, infrastructure, and security domains.
- Track audit progress and collected evidence.
- Centralize audit information in a single platform.
π ISO/IEC 27001 Compliance Assessment
Audiso provides structured checklists and assessments covering areas such as:
- Network architecture
- Physical security
- Server rooms and racks
- Cabling infrastructure
- Electrical infrastructure
- Access control
- Asset management
- Documentation
- Network security
- Security practices
- Identification of non-conformities
The platform can calculate a compliance score and provide a structured overview of the organization's security posture.
π€ AI-Powered Audit Modules
Audiso integrates several specialized AI components designed to assist auditors throughout the audit lifecycle.
β StarISO β AI Audit Report Assistant
StarISO allows auditors to answer a structured set of audit questions through a form, then uses AI to analyze the responses and generate audit findings, recommendations, and a professional report.
It can:
- Analyze auditor responses.
- Interpret audit findings.
- Identify potential non-conformities.
- Generate descriptive observations.
- Propose recommendations.
- Structure audit conclusions.
- Assist in producing professional ISO-oriented reports.
ποΈ Viso β AI Computer Vision Auditor
Viso is an AI-powered visual analysis module designed to analyze photographs captured during physical and infrastructure audits. (multi-agent system)
It can assist with identifying visible security and infrastructure issues such as:
- Cable disorder
- Rack organization problems
- Missing or inadequate equipment
- Physical security weaknesses
- Unlocked cabinets
- Infrastructure anomalies
- Environmental issues
- Other visible audit evidence
The visual analysis can then be transformed into structured audit observations and recommendations.
π RatiSO β Intelligent Compliance Analysis
RatiSO focuses on analyzing audit documentation and evaluating compliance. (The output is a score out of 10) It can assist with:
- Extracting relevant information from audit documents.
- Analyzing audit evidence.
- Evaluating compliance indicators.
- Calculating compliance scores.
- Identifying security gaps.
- Supporting the generation of audit summaries.
The objective is to provide auditors with a clearer view of the organization's overall security and compliance posture.
π¬ Audiso Assistant
Audiso Assistant is a multimodal multi-agent system that integrates RAG, a live speech agent, a text-based agent, Speech-to-Text (STT), and shared memory to enable contextual and collaborative interactions between agents.
It can assist auditors with:
- ISO/IEC 27001 questions.
- Cybersecurity concepts.
- Audit-related explanations.
- Document analysis.
- Evidence interpretation.
- Context-aware assistance.
The assistant is designed to work with the platform's audit context to provide more relevant responses.
π‘οΈ Cybersecurity Focus
Audiso was designed with cybersecurity and information security principles at its core.
The platform can help auditors identify weaknesses related to:
- Network security
- Physical security
- Access control
- Asset management
- Infrastructure security
- Security documentation
- Vulnerability management
- Risk management
- Security monitoring
- Environmental protection
- Business continuity considerations
It is particularly useful for audits involving network infrastructure, server rooms, IT equipment, and healthcare information systems.
π Network & Infrastructure Auditing
A major component of Audiso focuses on the assessment of IT infrastructure.
Auditors can document and evaluate:
- Network architecture
- Routers and switches
- Server infrastructure
- Network racks
- Structured cabling
- Patch panels
- Network equipment organization
- Physical access to infrastructure
- Electrical protection
- UPS availability
- Cooling and environmental conditions
- Network security weaknesses
This allows technical infrastructure observations to be integrated into the broader ISO/IEC 27001 audit process.
πΈ Evidence & Photo Management
Audiso allows auditors to associate evidence with audit observations.
Evidence may include:
- Photographs
- Audit responses
- Documents
- Infrastructure information
- Technical observations
- Supporting files
This creates a structured relationship between:
Control β Evidence β Finding β Risk β Recommendation
π Automated Report Generation
One of Audiso's main objectives is to reduce the time required to produce professional audit documentation.
The platform can generate structured reports containing:
- Audit information
- Scope
- Methodology
- Audit findings
- Evidence
- Non-conformities
- Recommendations
- Compliance scores
- Domain-level assessments
- Overall conclusions
Reports can be exported into professional document formats such as PDF and Word.
π Authentication & Access Control
Audiso includes security mechanisms designed to protect audit information.
The platform supports:
- User authentication
- Role-based access
- Administrator management
- Secure sessions/tokens
- OTP-based authentication
- Google/Firebase authentication
- Activity tracking
- Administrative controls
π€ Main Roles
Auditor
Can:
- Conduct audits
- Collect evidence
- Complete checklists
- Analyze findings
- Generate reports
- Use AI audit assistants
Administrator
Can additionally:
- Manage users
- Manage audit configurations
- Manage AI prompts
- Monitor activity
- Manage platform settings
πΊοΈ Audit Site Management
Audiso can integrate geographical information to help auditors manage audit locations.
The platform can provide:
- Hospital/site information
- Location visualization
- Site identification
- Audit location context
ποΈ Technical Architecture
Audiso was developed using a modern web architecture combining frontend, backend, database, authentication, AI services, and security mechanisms.
Frontend
- React
- TypeScript
- Vite
- Tailwind CSS
- Modern responsive UI
- Lucide icons
Backend
- Flask
- REST API architecture
- Authentication services
- Audit management services
- AI integration
- Report generation
- File management
Database
- PostgreSQL
- Structured relational data model
- Audit data management
- User and role management
- Activity logging
AI & Intelligent Services
- Large Language Models (LLMs)
- Retrieval-Augmented Generation (RAG)
- Computer Vision
- AI-assisted report generation
- Document analysis
- Speech-to-Text
- Context-aware AI assistance
Security
- JWT authentication
- OTP authentication
- Role-Based Access Control (RBAC)
- Secure API communication
- Activity logging
- Input validation
- Security testing
- Vulnerability assessment
π Audit Workflow
βββββββββββββββββββββββ
β Create Audit β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β Select Hospital/Siteβ
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β Collect Evidence β
β Photos / Documents β
ββββββββββββ¬βββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββ
β AI-Assisted Analysis β
β β
β StarISO β Viso β RatiSO β AI β
ββββββββββββββββββ¬ββββββββββββββββ
β
βΌ
βββββββββββββββββββββββ
β Identify Findings β
β & Non-Conformities β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β Compliance Scoring β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β Recommendations β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β Generate Report β
β PDF / Word β
βββββββββββββββββββββββ
π₯ Real-World Audit Application
Audiso was developed
Challenges
Traditional ISO/IEC 27001 audits are often manual, time-consuming, and difficult to centralize. Auditors need to collect evidence, analyze photos and documents, answer numerous compliance questions, identify security gaps, calculate scores, and prepare detailed reports. This process can lead to fragmented information, repetitive work, and inconsistent analysis.
Solutions
Audiso provides an AI-powered intelligent auditing platform that centralizes the entire audit workflow. It combines ISO/IEC 27001 compliance assessment, AI agents, RAG, computer vision, multimodal analysis, shared memory, and automated report generation to assist auditors in analyzing evidence, identifying potential non-conformities, generating recommendations, and producing a compliance score out of 10.
Results
Audiso transforms the traditional audit process into a faster, smarter, and more structured workflow. It enables auditors to centralize evidence, leverage AI for analysis, identify security gaps, and generate professional audit reports with measurable compliance results. Key Results:
- β‘ Reduced manual audit workload
- π€ AI-assisted analysis and recommendations
- πΈ Automated analysis of visual audit evidence
- π RAG-based access to relevant security knowledge
- π§ Shared context between AI agents
- π Automated professional audit reports
- π Compliance score out of 10
- π Better visibility into cybersecurity and ISO/IEC 27001 compliance gaps