/

Product

/

Policy management software for Microsoft 365

Stop managing compliance. Start proving it.

Policy management software built natively for Microsoft 365

Xoralia automates the complete policy lifecycle inside your Microsoft 365 tenant. Automated reviews, employee attestation, and audit-ready evidence — without adding new infrastructure or changing how your team works.

Avg. attestation rate
0 %
Active users
0
Days
Time to deploy
New infrastructure needed
£ 0
Where your time goes now
Where your focus should be with Xoralia
Chasing policy review deadlines by email
Reducing your organisation's risk exposure
Tracking attestations manually in spreadsheets
Advising leadership with real-time compliance data
Managing version confusion
Building a sustainable compliance culture
Scrambling to build evidence packs before audits
Staying ahead of regulatory change proactively
Answering "where's that policy?" for the 100th time
Enabling — not blocking — the business
Waiting weeks for approvals that stall in inboxes
Proving governance, continuously and automatically
Avg. attestation rate
0 %
Active users
0
Days
Time to deploy
New infrastructure needed
£ 0
How it works

The complete policy lifecycle, automated.

Every step, from the first draft to audit evidence, runs automatically in Microsoft 365. Accessible from within the tools your team already uses every day — Teams, SharePoint, and Outlook.

01 Draft

Author & version control

In Word, PowerPoint or any Office app. Templates can be enforced automatically.

02 Approve

Automated approval workflow

Named reviewers notified with automated reminders. No chasing.

03 Publish

Target by role, team & location

Right policy to right people. Targeted using your existing M365 (Entra ID) groups — no manual distribution lists to maintain.

04 Attest

Acknowledge in Teams or SharePoint

Employees confirm they’ve read the policy, then complete a quick knowledge check.

05 Monitor

Real-time dashboards

Who read what, when, which version? One-click audit export.

06 Renew

Automated review cycles

Owners are notified automatically before expiry so reviews can be reset on time.

Watch the full lifecycle in action

See exactly how Xoralia works and how it can be configured to meet your organisation’s requirements in a personalised demo.

Features in depth

Everything your compliance team needs.

Policy library

One source of truth. Version confusion eliminated.

Employees always see the current, approved version. No outdated documents in circulation. Every policy tagged by owner, review date, and audience — searchable from Teams or SharePoint.

  • Structured categories with metadata, ownership, and review dates
  • Version history maintained automatically — full audit trail
  • Employees can only view the current approved version
  • Search across all policies without leaving Teams or SharePoint
  • Optional public-facing policy pages for external audiences
Document workflows

You will never chase a policy review again.

Automated workflows assign owners, set deadlines, and send automated reminders — running 24/7 without manual intervention. Configure once, and it runs itself.

  • No-code workflow builder — visible and auditable by your team
  • Multi-stage approval with parallel and sequential routing
  • Review cycles restart on schedule — nothing ever lapses
  • All approval steps are timestamped and logged for audit

How much time is manual policy admin costing you?

Estimate your hours saved, FTE reclaimed, and risk reduction with Xoralia. Takes 60 seconds.

Policy attestation

Up to 99% attestation. Without chasing anyone.

Employees acknowledge policies directly inside Xoralia, Microsoft Teams or SharePoint. Automated reminders run without HR lifting a finger.

  • Acknowledge in Xoralia, Teams or SharePoint — using your existing Microsoft credentials
  • AI quiz builder (Azure OpenAI) confirms genuine understanding
  • Completion certificates are auto-generated per employee with timestamps
  • Manager dashboards show real-time team completion
  • Gap reports: instantly see who hasn’t acknowledged
Reporting & audit trail

Your audit evidence is already built.

Every acknowledgement, review, and approval is timestamped and logged automatically. Move from “we believe our policies are current” to “here is the evidence — by employee, by policy, by date.”

  • One-click audit export with timestamps, version history, and signatures
  • Pre-built frameworks: ISO 27001, FCA, NHS, GDPR, SOC 2
  • Live compliance dashboards — completion by policy, team, and individual
  • Evidence available 365 days a year — not just at audit season
AI intelligence

AI built in — not bolted on.

Powered by Azure OpenAI. All data stays inside your Microsoft 365 tenant. No third-party AI training on your content.

  • AI search — employees ask plain-English questions and get instant, accurate answers from your policies
  • Zero content sent to third-party AI models
  • No AI training on your organisation’s data
Built for your team

One platform. Four different conversations.

Audit file builds itself
Every review cycle, approval, and acknowledgement logged with timestamps — ready for any regulator, any time, without manual effort.
No policy ever lapses
Automated review cycles trigger before expiry. Owners get automated reminders. Nothing falls through on your watch, ever.
Real-time compliance visibility
Live dashboards show completion rates by policy, team, and individual. Move from hope to evidence — instantly.
Pre-built regulatory frameworks
ISO 27001, FCA, NHS, GDPR, SOC 2 reporting formats — structured from day one. Audit-ready without configuration.
Right policy, right person, automatically
Policies are targeted by role, team, and location using your existing M365 (Entra ID) groups — assigned by document owners, surfaced automatically to employees.
New starter onboarding on day one
Joining employees automatically receive all relevant policies the moment they're added to M365. Zero HR effort.
Acknowledge in Teams — where employees live
Completion rates soar because employees acknowledge inside Microsoft Teams or SharePoint, using the tools they already use every day.
Manager dashboards — no chasing
Line managers see exactly who in their team hasn't completed. Automated reminders mean HR never sends a single chase email.
Your tenant, your data — always
All data stays inside your Microsoft 365 tenant. No external transfers, no third-party hosting.
Deploy in weeks, not months
SharePoint app install, configure, and go. No infrastructure project. No complex integrations. No professional services marathon.
SSO and RBAC out of the box
Entra ID authentication. Role-based permissions through existing M365 admin tools. No new credentials for anyone.
Azure OpenAI — in-tenant
AI features powered by Azure OpenAI. No content sent to third-party models. Zero AI training on your organisation's data.
FTE hours reclaimed from admin
Review chasing, distribution, attestation tracking — fully automated. Compliance staff redirected to strategic work from week one.
Days to demonstrate ROI
Attestation rates visible from week one. Audit trails building from day one. Measurable outcomes before end of month one.
Compliance failures cost far more
A single compliance failure — fines, legal exposure, reputational damage — far exceeds the total cost of Xoralia for three years.
Predictable SaaS cost — no surprises
Clear pricing, no hidden professional services. Runs on your existing M365 investment. £0 new infrastructure budget.

“We went from dreading audits to passing with confidence. Xoralia builds our evidence automatically — we just download it on the day.”

Ready to see Xoralia for your specific role?

Book a 45-minute demo tailored to your priorities — compliance, HR, IT, or finance.

Case study
Lifearc

ISO 27001 certification achieved in 3 days.

LifeArc, a healthcare and life sciences charity, needed ISO 27001 fast. With Xoralia deployed across 500 employees, they had compliant policies distributed, acknowledged, and evidenced within days — not months.

“Xoralia provided effortless access to up-to-date policies, enabling our ISO 27001 certification in just 3 days. Implementation was seamless from start to finish.”

Days to go live
0
Employee covered
0
ISO
27001 achieved
Attestation rate
0 %
Customer reviews

Don't take our word for it.

Rated by compliance, HR, IT, and operations teams across regulated industries.

G2 review

Does exactly what it says on the tin

Xoralia has removed a huge amount of pain and manual process from my organisation, reducing our overheads (by reducing hidden costs) while also improving our quality and compliance with legal and contractual requirements.

G2 review

Improved efficiency and complicance with Xoralia

Xoralia has improved the way we handle, distribute, and track policies and procedures within our organisation. Not only does it allow us to save a lot of time, but it has helped us also to maintain and track compliance. Currently, we have a 99% attestation rate.

Ideal partner for our regulated environment

LifeArc operates in a strictly regulated sector where compliance and information security are critical. It is essential that LifeArc’s workforce have easy and effortless access to the latest up-to-date policies and procedures, which is the structure Xoralia gave us.

Free assessment

Is your organisation at compliance risk?

Answer 8 questions about your current policy management process and get a personalised compliance risk audit report — with a score, gap analysis, and specific recommendations for your sector.

Industries

Built for regulated sectors.

200+ organisations across 8 regulated industries trust Xoralia to automate their policy lifecycle.

Financial services & Banking

Suntera Global · Vina Capital

FCA · GDPR · SOC 2

Healthcare

LifeArc · Curexa

ISO 27001 · CQC · NHS frameworks

Education

Oxford University

Safeguarding · governance · audit trails

Charity & Non-profit

ClientEarth · Children International

Charity Commission · GDPR · governance

Public sector

UK Anti-Doping · Langley House

ISO 9001 · public accountability

Energy & Utilities

Key Energy Services

OFGEM · HSE · ISO 55001

Manufacturing & Retail

Nature's Sunshine · Golding

GxP · SOPs · regulated manufacturing

Construction

Haskoning

CDM · ISO 45001 · HSE compliance

Why Xoralia

Microsoft-native. Not Microsoft-adjacent.

Many compliance platforms require separate infrastructure, new logins, and complex integrations. Xoralia runs inside what your organisation already owns and trusts.

Compatibility
Xoralia
NAVEX / ConvergePoint
Manual (SharePoint folders)
Runs natively inside Microsoft 365
Native
Integration required
Partially
Data stays in your tenant
Always
Third-party hosting
Employee attestation in Microsoft Teams
Native Teams app
Email-based
Automated review & approval workflows
Full automation
Manual only
AI search
Azure OpenAI
Not Microsoft-native
Deployment time
Days to weeks
Months
Ongoing effort
One-click audit-ready evidence export
Build manually
New infrastructure required
None
External SaaS
None

Switching from NAVEX, ConvergePoint, or a manual process?

Our team will build a tailored migration plan. Most customers live within 2–4 weeks of signing.

Get started

Start your free trial — no credit card needed

Full access to Xoralia. Cancel any time.

Stop managing compliance. Start proving it.

Ready to see Xoralia running inside your Microsoft 365 environment? We can configure a free trial in your own SharePoint tenant.

Start your FREE Xoralia trial!