Scrut.io: Compliance Automation That Keeps You Audit-Ready, Without the Spreadsheets
For growing UK businesses, security certifications like ISO 27001 and Cyber Essentials are increasingly non-negotiable – clients expect them, procurement teams ask for them, and insurers are starting to require them. The challenge is getting there and staying there without it becoming a part-time job for someone in your team. Scrut.io is a compliance automation platform that centralises the whole process: frameworks, evidence collection, risk management, and audit readiness, all in one place. Dr Logic works with clients to set it up, connect it to the tools already in your stack, and keep it running as part of ongoing managed IT support.
The traditional route to ISO 27001 or SOC 2 certification involves spreadsheets, folders of screenshots, a consultant who disappears after delivery, and a frantic scramble every time an audit comes around. Scrut replaces that with continuous, automated monitoring — pulling evidence directly from the tools your business already uses, mapping it to the relevant controls, and flagging gaps before they become problems. For businesses managing sensitive client data or operating in regulated sectors, that shift from periodic compliance to always-on readiness makes a meaningful difference.
Dr Logic recommends Scrut.io to clients who are ready to move beyond ad hoc security documentation and build a programme that holds up over time. Whether you’re pursuing your first certification or maintaining existing accreditations, we can bring it under the same IT Success® Plans umbrella as the rest of your managed IT – so there’s one team, one relationship, and one view of your security posture.
What Dr Logic Delivers with Scrut.io
- Platform setup and framework configuration. We connect Scrut to your existing tools, including JumpCloud, Microsoft 365, and Google Workspace, and configure the relevant compliance frameworks from the outset. Whether you’re targeting ISO 27001, Cyber Essentials, GDPR, or a combination, we structure the platform to reflect your actual environment rather than a generic template.
- Ongoing compliance monitoring and gap management. Once live, Scrut runs automated tests against your controls continuously. Dr Logic reviews flagged gaps as part of your managed service, prioritises remediation, and ensures that control failures don’t quietly pile up between review cycles.
- Evidence collection from your existing stack. Scrut pulls compliance evidence automatically from JumpCloud identity data, Microsoft 365 configurations, Google Workspace access logs, and other connected tools. Dr Logic handles the integration and validates that evidence is mapping correctly to the right controls, removing the manual effort of chasing documentation before an audit.
- Risk register and vendor risk management. We help you build and maintain a live risk register inside Scrut, aligned to your chosen frameworks. Where your business relies on third-party vendors handling sensitive data, we can use Scrut’s vendor risk tools to track and document their security posture, increasingly expected under ISO 27001 and GDPR.
- Audit preparation and auditor access. When certification time approaches, Dr Logic works alongside you to close any remaining gaps and prepare the evidence package. Scrut allows auditors to work directly inside the platform, which cuts the back-and-forth of traditional audit processes considerably.
- Policy documentation and version control. Scrut includes a library of auditor-approved policy templates that Dr Logic customises to reflect how your business actually operates. Policies are stored, versioned, and kept current inside the platform, so you’re never hunting for a document that was last updated three years ago.
- Integration with the wider Dr Logic security stack. Scrut sits alongside the cyber security work we do with clients, including Cyber Essentials certification support, giving a consolidated view of your security posture rather than treating compliance as a standalone exercise.
Certifications and Credentials
Dr Logic’s relationship with Scrut.io is as a referral partner, we recommend and actively work with the platform across our client base, but do not resell licences directly. Scrut.io pricing is agreed directly between your business and Scrut.
Our team holds relevant experience in compliance frameworks including ISO 27001 and Cyber Essentials, and as an Apple Premium Technical Partner we bring that same standard of vendor knowledge to the tools we deploy on clients’ behalf. Where Scrut’s implementation requires deeper InfoSec consultancy, we work alongside qualified partners to ensure nothing is left to guesswork.
Is Scrut the Right Fit, or Should You Take a Different Approach?
The honest answer is: it depends on where you are in your compliance journey and how much ongoing work you want to carry yourself.
If you’re starting from scratch with ISO 27001 or SOC 2 and you want a structured, technology-led programme that keeps you audit-ready year-round rather than scrambling every 12 months, Scrut is a strong fit. It’s particularly well-suited to businesses with an existing SaaS stack, the integrations with JumpCloud, Microsoft 365, and Google Workspace mean a lot of the evidence collection happens automatically rather than manually.
If you only need Cyber Essentials and don’t anticipate pursuing ISO 27001 or other frameworks, the platform may be more than you need. In that case, we’d typically handle Cyber Essentials directly through Dr Logic’s Cyber Essentials service without a dedicated compliance platform sitting underneath it.
And if you’re weighing Scrut against hiring a consultant or doing it manually with spreadsheets, that approach can work for a first certification, but it tends to fall apart at renewal time. The evidence gathering starts again from scratch, the documentation has drifted, and the consultant is no longer around. A platform like Scrut is a better long-term investment once you’ve decided compliance is an ongoing commitment rather than a one-off project.
If you’re not sure which route makes sense for your business, get in touch and we’ll give you a straight answer.
FAQs
What is Scrut.io and what is it used for?
Scrut.io is a compliance automation platform that helps businesses achieve and maintain security certifications such as ISO 27001, SOC 2, GDPR, and Cyber Essentials. It automates the collection of compliance evidence from your existing tools, monitors your security controls continuously, and manages the documentation and risk registers required for audit. The goal is to make compliance something that runs in the background rather than a periodic crisis.
Does Dr Logic manage Scrut.io for clients?
Yes. Dr Logic works with clients to set up and configure Scrut, connect it to the tools in your stack, and manage ongoing compliance monitoring as part of your IT service. We review flagged gaps, support audit preparation, and keep your compliance programme aligned with your chosen frameworks, rather than leaving you to run the platform yourself after an initial setup.
How does Scrut integrate with JumpCloud, Microsoft 365, and Google Workspace?
Scrut has native integrations with all three. It pulls identity and device data from JumpCloud, including MFA enforcement and user access records, and syncs user and configuration data from Microsoft 365 and Google Workspace to automate evidence collection for access controls and administrative oversight. Dr Logic handles the integration setup and validates that data is mapping correctly to your compliance controls.
Does it matter which compliance framework I'm pursuing – will Scrut work for Cyber Essentials as well as ISO 27001?
Scrut supports over 60 frameworks out of the box, including ISO 27001, SOC 2, GDPR, HIPAA, and PCI DSS. Cyber Essentials is a simpler certification and can typically be handled without a dedicated compliance platform – Dr Logic tends to manage that directly through its Cyber Essentials service. For ISO 27001 or multi-framework programmes, Scrut adds real value by keeping controls and evidence in one place and reducing duplicated effort across standards.
Is Scrut relevant for Cyber Essentials compliance?
Scrut can support the security controls required for Cyber Essentials, particularly around access management, patch management, and device configuration. That said, for businesses pursuing Cyber Essentials as a standalone certification, it’s worth discussing whether the full platform is the right investment at that stage. For businesses that are also pursuing ISO 27001 or operating in regulated sectors, bringing Cyber Essentials under Scrut gives you a single source of truth across all your compliance activity.
We already have an IT support contract – do we need a separate compliance tool?
Not necessarily, it depends on what certifications you need and how seriously you’re treating ongoing compliance. Many businesses manage with a combination of IT support and ad hoc documentation for their first Cyber Essentials, and that’s fine. Where Scrut earns its place is when you’re pursuing ISO 27001 or SOC 2, managing sensitive client data, or reaching the point where your compliance programme needs to be continuous rather than periodic. At that stage, a dedicated platform pays for itself quickly in time saved and audit stress avoided.
Scrut isn't cheap – is there a more cost-effective route?
Scrut’s pricing is bespoke and agreed directly with their team, so costs vary based on your organisation’s size and the frameworks you’re managing. For some businesses, particularly those at early stages of their compliance journey, a consultant-led approach to ISO 27001 may have a lower upfront cost. The trade-off is that it typically produces a point-in-time snapshot rather than an ongoing programme, and the cost of re-running that process at renewal, or responding to a client security questionnaire mid-year, can quickly exceed what a platform costs annually. It’s worth doing the maths on the full picture rather than comparing platform fees against a first-year consultant quote.
Ready to Build A Compliance Programme That Holds Up Between Audits, Not Just During Them?
Let’s talk about how Scrut.io, can reduce the complexity of audits, improve visibility, and support your security roadmap.

























