ISMS Copilot Docs

Why connect a specialist

When a skill file is enough, what a maintained framework registry adds, and what the published benchmark actually shows.

Coding agents can carry framework knowledge in a skill file or project instructions. Sometimes that is enough. This page states plainly what connecting ISMS Copilot adds, what it does not, and what the published evidence shows, including the losses.

What a skill file does well

A skill file is a prompt plus reference notes you maintain yourself. It rides in your harness, costs nothing beyond your model subscription, and works with no vendor connection. For the most established frameworks, it is hard to beat: in our published same-model benchmark, on ISO 27001, GDPR and SOC 2, the best hand-written consultant prompt was statistically at parity with the full product (88.0% vs 88.9%). If your work stays there and your file is current, a skill file may be all you need.

What a maintained registry does differently

The curated framework modules ISMS Copilot injects are a registry, not a prompt you own:

  • Currency is our job, not yours. Modules carry edition stamps and last-verified dates, and the registry is corrected when standards are revised or renumbered. A skill file goes stale when a framework moves, whether or not you notice.
  • Disclosure is built into the API plane. Model API completions name the modules they used (through the x-isms-frameworks header and the ismscopilot response object), so you can check what grounded the answer instead of trusting the prompt that claims to.
  • The citation record is checkable. In the same benchmark, outside the trap battery, the naked model fabricated 8 control or article identifiers; the full product fabricated zero.

The second pass

One agent doing everything has no second reader. Connected over MCP, ISMS Copilot can hold real conversations as the specialist, with your workspaces, memories, and company context, and the same work can get a second pass against curated framework references. That is a mechanism, not a proven advantage: the benchmark did not evaluate second-agent review, and we make no claim that it was tested.

What the evidence shows, and what it does not

The scaffold benchmark (2026-09-02) compared arms on the identical base model. The only variable is what surrounds the request:

ArmOverall
Naked model68.0%
Best hand-written prompt76.0%
Hand-written prompt + knowledge module96.9%
Full ISMS Copilot92.1%
  • On frameworks that are young or regional (ISO 42001, Australia's ISM, DORA, NIS 2, TISAX, Singapore's MTCS), the product scored 94.7% against 66.3% for the best hand-written prompt. This is where the registry earns its keep.
  • The pre-registered primary verdict was a TIE (92.1% vs 76.0%, inside the frozen judge-variance band), and we report it as a tie.
  • The losses are published: a hand-written prompt supplied with the same knowledge module, date, and documents outscored the product (98.7% vs 92.1%), and the product failed one of four trap questions while the knowledge-armed DIY arms refused it.

This is not a comparison against Claude or any frontier model, and it supports no claim that hallucinations are eliminated. Read the method and caveats on the benchmark page.

What it costs

  • Account MCP (pat-isms-…): covered by your existing chat subscription and its 4-hour session window. No credits, no separate billing.
  • Model API (sk-isms-…): prepaid credits for a bounded sub-agent completion. Live rates live in the console, which is the source of truth.

When to connect

If your work stays on the big three frameworks and you maintain your file, start with the file. Reconsider when the frameworks you answer against age out of reliable model knowledge, when you need answers that cite what they used, or when the compliance step should stop spending your model subscription's context and credits. To connect, see Connect Claude Code, Connect Cursor and Codex, or Connect any MCP client.

On this page