Upload evidence once. Graphletter maps it to every framework below through the Secure Controls Framework, so a SOC 2 policy also counts toward ISO 27001, NIST, and more.