SortOps
The backup has not been restored. It has been backed up
Thirteen tools for the person who is the entire IT and compliance function. Each one produces a specific artifact you can hand to an auditor or a client, and pricing runs from $39 a month to a $249 one-time license.
The list of things you hope are fine
You inherited this. Nobody wrote any of it down, and now you’re the one who has to answer for it.
The backup job reports success every night. It has never been restored, so what it actually reports is that the job ran. Somebody left in March and there are four systems where nobody checked whether their account was removed. There’s a spreadsheet of SaaS subscriptions that was accurate in January. A certificate expires in eleven days and the only thing that knows that is the certificate. When the client’s security questionnaire arrives, you’ll answer it from memory and hope the memory is right.
None of this is negligence. It’s what happens when the whole function is one person who also fixes the printer. The problem is that “I think it’s fine” and “here is the evidence it’s fine, dated last Tuesday” are the same amount of true and a very different amount of useful.
Each tool produces one artifact
The pitch you usually get is a platform: an agent on every endpoint, a dashboard, an annual contract, and a promise that it will make you compliant. It won’t. Compliance is a set of things that happened, with records that they happened, and no dashboard does that on your behalf.
So each of these does one job and emits one output. The access recertification packager produces a signed, dated review with the reviewer’s name on it. The restore monitor produces the result of an actual restore, not a job status. The seat reconciler produces a list of what you pay for against what’s in use. That’s the unit of work, and it’s why the tools are priced separately and can be bought one at a time.
They run locally. No agent fleet, no credentials in a vendor cloud, no new attack surface added by the tool that was supposed to reduce it.
Start here
Three of these cover the failures that actually end careers. Pick by which one you’d least like to be asked about.
Backup Restore Test Monitor
Backup Restore Test Monitor, $39 a month. Buy this one first. A backup that has never been restored is not a backup, it’s a hypothesis, and the day you find out is always the worst possible day. This runs a real restore on a schedule and tells you the minute one fails. It’s the highest ratio of consequence to cost on the page.
User Access Recertification Packager
User Access Recertification Packager, $79 a month. Buy this if you have an audit or a client security review on the calendar. Access review is the control most often claimed and least often evidenced, because doing it by hand across six systems takes a day and produces a spreadsheet nobody signed. This produces the package, with names and dates on it.
SaaS Seat & License Reconciler
SaaS Seat & License Reconciler, $49 a month. Buy this if the honest answer to “how many seats are we paying for” is a shrug. It usually pays for itself on the first pass, because leavers stay licensed for months and nobody is looking.
The 13 tools, grouped by what they produce
Evidence an auditor or a client will ask for
| Tool | The artifact it produces | Price |
|---|---|---|
| User Access Recertification Packager | A completed access review: who has what, who signed off, on what date | $79 per company / month |
| Policy & Control Gap Checker | The list of controls you claim and the ones you can’t currently evidence | $49 per company / month |
| Vendor Risk & DPA Tracker | A vendor register with the DPA status and the data each one touches | $49/mo |
| License / Cert / Permit Expiry Radar | Every expiry date in the org, with warning before it lapses rather than after | $75 one-time (bundle) |
| SLA & Uptime Report Generator | The uptime report your client’s contract says you owe them monthly | $39/mo |
The things nobody has actually verified
| Tool | The artifact it produces | Price |
|---|---|---|
| Backup Restore Test Monitor | Proof that a restore ran and what came back, weekly, not a green job status | $39/mo |
| SMB IT Off-Ramp / Documentation Scanner | The documentation for the environment you inherited and nobody wrote down | $65/mo (or $250 audit) |
What you own and what you’re paying for
| Tool | The artifact it produces | Price |
|---|---|---|
| SaaS Seat & License Reconciler | Seats billed against seats used, per app, with the leavers still in there flagged | $49 per company / month (flat, up to about 50 seats) |
| IT Asset Lifecycle Tracker | An asset register that survives a laptop refresh and an offboarding | $39/mo |
| Cloud Cost / API Usage Advisor for Indie Devs | Where the bill is actually coming from, before the next one arrives | $65 one-time |
Data that does not agree with itself
| Tool | The artifact it produces | Price |
|---|---|---|
| Entity Resolver / Master Data Map | One customer record where you currently have four spellings of it | $75/mo (bundled engine) |
| Legacy Access/Excel Migration Analyzer | A map of what’s inside the Access database before you try to move it | $249 one-time + migration service |
| AI QA / Citation Layer for AI outputs | A citation and a check on anything a model produced before it goes to a client | $39/mo per seat + usage |
Why local-first is a control, not a marketing line
You’re the one who has to prove things happened. That’s the job. Which means the evidence has to be under your control, not retrievable by asking a vendor nicely.
Local-first here means the tool reads your systems from a machine you own, writes its output to your disk, and keeps a tamper-evident log you can export in full. When an auditor asks for the access review from Q1, you produce it. You do not open a support ticket with a software company, wait, and then explain to the auditor why the evidence for your control lives inside another company’s retention policy. Retention is a decision you get to make, and you cannot make it if the record isn’t yours.
There’s a second-order point that this audience will already have spotted. Every SaaS tool you add is a row you have to add to your own vendor register, a DPA to chase, and a sub-processor list to review. A compliance tool that increases your vendor risk surface in order to measure your vendor risk surface is a poor trade. These do not hold credentials in a cloud, do not deploy an agent fleet, and do not require you to grant a third party standing access to the systems you’re accountable for.
Honest limits, stated plainly
These tools do not certify you. If you’re pursuing SOC 2 Type II or ISO 27001, you’ll need an auditor and, realistically, an evidence platform like Vanta or Drata that maps controls to a framework and talks to your auditor. What’s here does the underlying work and produces the artifacts. It does not produce a report with an auditor’s opinion on it, and nothing that costs $49 a month ever will.
We do not currently hold a SOC 2 report ourselves. The mitigating fact is structural rather than rhetorical: the tools run on your hardware and do not transmit your data to us, so a vendor audit of us has a much smaller scope than it would for a cloud product.
No agents, so no remote remediation. These read and report. They do not push a config, disable an account, or fix the finding for you. That’s deliberate, and if you want a tool with write access to your production estate, buy an RMM instead.
Not for an org with a security team. If there’s a CISO, a GRC lead and a ticketing workflow, you have process these tools assume you don’t have. This is built for the person who is all three of those roles and also owns the printer.
Start with one job
Pick the tool for the job costing you the most time. Every tool has a free trial and needs no card.
Frequently asked questions about SortOps
What is IT operations & compliance software, and what does SortOps do for an owner-as-IT?
IT operations & compliance software is the set of tools that keeps a small organization’s systems documented, its backups honest, and its risks visible, without a dedicated IT team behind it. SortOps is how SortSuite groups those tools for the person who became the IT department by accident, the owner, the ops lead, or the compliance manager who now owns the servers, the accounts, and the audit questions. IT operations & compliance software should assume that person has other jobs too, which is why these tools run locally and produce plain answers rather than dashboards that need a specialist to read.
The work here is the part of a business nobody sees until it breaks. Systems and accounts drift out of documentation. Backups run for months without anyone confirming they can actually restore. The same client or vendor exists three times across three tools. AI-drafted reports go out with claims nobody checked. SortOps takes each of those quiet risks and gives it a tool. You can see the full set on the IT operations and compliance page.
Take documentation. The SMB IT Off-Ramp and Documentation Scanner scans your systems and files to build a self-serve inventory, flags backup, security, and documentation gaps before they become emergencies, and produces a handoff runbook so an outside provider can onboard fast. That is work small firms usually pay an MSP to do. IT operations & compliance software of this kind lets the accidental admin see what they actually have.
Most owners in this seat want a map of the risk rather than a certification project. The NIST Cybersecurity Framework gives one, organizing the whole problem into govern, identify, protect, detect, respond, and recover. You do not have to adopt it formally to borrow its logic, and the SortOps tools line up naturally with its stages, from taking inventory to testing that you can recover.
What ties SortOps together is a bias toward proof over assumption. The Backup Restore Test Monitor does not trust that a backup ran. It runs a test restore and builds an evidence pack showing the restore worked, which is what an auditor or an insurer actually asks for. Each tool is sized for an owner-operator who needs a defensible answer, not an enterprise console. IT operations & compliance software works best when it turns a nervous guess into something you can show. You add the piece that closes your scariest gap first and bring in the next one only when the risk moves, which keeps both the cost and the learning where a one-person IT function can carry it. The person in this seat rarely wanted the job and almost never has time to run a full IT program, so the tools are built to give a defensible answer in an afternoon rather than a project plan that assumes a team. That framing runs through every SortOps piece, and it is the main reason IT operations & compliance software of this kind looks different from the MSP consoles it sits against. The goal is always a plain answer the owner can act on and show, not a console that needs a specialist to interpret.
How does IT operations & compliance software help me meet frameworks like NIST and the FTC Safeguards Rule?
Small organizations increasingly get asked to show real security controls, by insurers, by larger customers, or by a regulator. IT operations & compliance software helps by producing the evidence those frameworks expect as a byproduct of normal operating, rather than as a scramble the week before an assessment. The point is to make the control real and the proof findable.
Start with the map. The NIST Cybersecurity Framework organizes security into govern, identify, protect, detect, respond, and recover, which is a sensible skeleton even for a five-person shop. Identify is where documentation lives, and a self-serve inventory of your systems and accounts is the first thing most small firms cannot produce. IT operations & compliance software that builds that inventory is doing the identify work for you.
Access control is where many small teams fall short. The NIST SP 800-171 security requirements sets out access-control expectations for protecting sensitive information in nonfederal systems, and the core idea is that only the right people reach the right data. Tools that surface stale accounts, forgotten API keys, and quiet permission drift make that principle checkable rather than aspirational. IT operations & compliance software should show you who and what can reach your systems.
Some small firms also fall directly under the FTC Safeguards Rule, which requires certain businesses that handle customer financial information to keep a written security program with administrative, technical, and physical safeguards. The FTC describes who is covered and what the program includes in its overview of the Safeguards Rule for business. Even where the rule does not strictly bind you, its structure is a fair model, and evidence that your controls run is exactly what it expects.
The Backup Restore Test Monitor is a good example of framework logic made concrete. Recover, in NIST terms, means little if your backups have never been tested. The tool runs a real restore and packages the result as evidence, which is the difference between claiming you have backups and proving they work. Insurers now ask that question directly on cyber applications, and larger customers ask it in vendor reviews, so a ready evidence pack answers a question you will increasingly be asked whether or not a formal framework applies to you.
The written program requirement is worth taking seriously even at small scale. A short document that names who owns security, what you protect, and how you respond turns scattered habits into something you can hand an auditor. IT operations & compliance software supplies the raw material for that document, the inventory, the access picture, and the restore evidence, so writing it is a matter of assembling facts you already have rather than inventing them under pressure.
None of this makes the software your auditor or your compliance officer. It does not grant you a certification or interpret a control on your behalf. What it does is make the underlying control operate and leave a record, which is the part small teams most often miss. Decide which framework stage is weakest for you, usually documentation or recovery, and start there. You can compare the tools that map to each stage on the IT operations and compliance overview.
Where does my data live with these tools, and what happens if there is a breach or a dead drive?
The SortOps tools are local-first, so your inventory, your backup evidence, your account maps, and your source documents stay on the machine where you run them rather than on a copy in a vendor’s cloud. For a small organization that is its own IT department, that keeps the sensitive picture of your systems out of yet another third-party service. IT operations & compliance software that runs locally gives you fewer places to defend.
The hard question is not only where data sits day to day, but what happens when something goes wrong. The FTC has a plain guide for that. Its data breach response guide for business tells you to move quickly to secure operations, fix the vulnerability that let it happen, and notify the right parties. A local inventory of what you run and who can reach it is exactly what makes that response fast, because you cannot contain what you cannot see. IT operations & compliance software that keeps your systems documented shortens the worst day. The same guide is clear that notification obligations depend on knowing whose data was involved, which is another reason a current inventory of what you hold and where it sits is not paperwork but the backbone of any real response.
Backups are the other half. Most disaster-recovery setups assume a restore will work and never test it. The Backup Restore Test Monitor actually runs a test restore and records the result, so a dead drive is a recovery you have rehearsed rather than a gamble. That evidence pack is also what an insurer or auditor wants after an incident, when assumption is not good enough.
Disposal is the quiet risk nobody plans for. When you retire a laptop, a drive, or a phone, the data on it has to be rendered unrecoverable, and the NIST SP 800-88 guidelines for media sanitization explain how to do that properly rather than just dragging files to the trash. The documentation scanner helps you know which devices held sensitive data in the first place, so sanitization is deliberate instead of hopeful. A laptop sold or handed down with a client database still readable on it is a breach waiting to be discovered, and it is the kind of exposure that never shows up in day-to-day operations until someone recovers the drive. Knowing which machines to wipe, and wiping them the way the guidelines describe, closes that gap before it opens. IT operations & compliance software that ties disposal back to your inventory turns a hopeful delete into a deliberate control.
Local-first carries one honest trade. Backup and safe disposal are on you. If the machine dies and you kept no copy, the data is gone, and no cloud is quietly holding a spare. That is why the restore monitor exists, and why an external backup on a schedule you control belongs in the plan. IT operations & compliance software gives you the private-by-default position, and tested backups plus proper media sanitization are what make it safe. You can see how each SortOps tool handles data on the IT operations and compliance page before you commit to one.
How is SortOps different from IT Glue, Hudu, Veeam, or NinjaOne?
The tools SortOps sits against are built for managed service providers and enterprise IT, and they leave a clear gap for the owner who is their own IT department. IT Glue and Hudu document systems, but for MSPs managing many clients. Veeam and NinjaOne handle backup and monitoring at a scale and price aimed above a small shop. IT operations & compliance software from SortOps is shaped for the single accidental admin instead, which changes both what it does and what it costs.
Take documentation. IT Glue and Hudu assume an MSP is the user, entering and maintaining records across a book of clients. The SMB IT Off-Ramp and Documentation Scanner assumes the opposite, that the owner needs a self-serve inventory of their own systems without hiring anyone, and it even produces the handoff runbook for when they do bring in outside help. That is a tool built for the person MSP software is usually sold around. The runbook matters more than it sounds, because the moment you hire an MSP or a new hire inherits your systems, the first thing they need is an accurate picture of what exists, and most small firms cannot produce one. IT operations & compliance software that generates that picture on its own turns a painful handoff into a quick one.
Take backup. The enterprise suites are strong, but they are priced and staffed for a dedicated IT function, and even they often skip the restore test. The Backup Restore Test Monitor does one thing the big tools assume you handle elsewhere. It proves the restore works and packages the evidence. That proof matters against the recover stage of the NIST Cybersecurity Framework, where an untested backup counts for very little.
Ownership is the other divide. The MSP and enterprise platforms hold your data on their infrastructure and price per endpoint or per technician. SortOps tools are local-first, keep your files on your own machine, and several are sold as a one-time desktop purchase. For an ops lead cleaning up duplicate records across tools, the Entity Resolver and Master Data Map brings entity resolution down to small-business pricing, where DataLadder or Senzing simply are not built for that budget.
The blunt version. If you are an MSP or you run a real IT team, the incumbent platforms are made for you. If you are the owner who inherited IT and you want to keep your own files, pay a price sized to a small business, and close the two or three risks that actually threaten you, that is what SortOps is for. IT operations & compliance software does not have to be built for someone else’s business model. Compare the pieces on the IT operations and compliance overview and start with your biggest exposure. There is no per-endpoint contract, no minimum seat count, and no assumption that you manage other people’s networks for a living. You are buying a tool to answer a question about your own systems, which is a different purchase than the platforms were designed to sell.
Can these tools check my AI-generated reports and clean up duplicate records across systems?
Yes, and both are fast-growing reasons an ops or compliance lead reaches for IT operations & compliance software. Teams now draft reports with AI and juggle the same entities across disconnected tools, and both create risk that is easy to miss until it reaches a client or an auditor. SortOps has a tool aimed at each.
On AI output, the AI QA and Citation Layer checks AI-written summaries and reports against your original source documents and flags claims and figures that the source does not back. That adds a governance step before AI content goes out the door. For a compliance lead, an unsupported number in a report that reaches an auditor is a real problem, and IT operations & compliance software that catches it first is doing quiet risk control. AI is fast and confident and occasionally wrong in ways that read perfectly, which is exactly the failure mode a citation check is built to catch. Running that check before content leaves the building is far cheaper than retracting a claim after a client or a regulator has already read it.
On duplicate records, the Entity Resolver and Master Data Map matches the same client, vendor, or property across your different tools and resolves them into one master list. Duplicate and inconsistent records are not just messy. They undermine every report and reconciliation built on top of them, and they make it impossible to say cleanly what you actually hold. One vendor recorded three ways can hide double payments, split spend, and a compliance obligation you did not know you had. Resolving them into one entity is the difference between a report you can act on and a pile of records you have to reconcile by hand every time a question comes up.
That connects to a control frameworks care about. Knowing exactly what data and which entities you hold is the identify function of the NIST Cybersecurity Framework, and you cannot protect or account for records you have not resolved. A clean master list is quietly a security artifact, not just a tidiness win. IT operations & compliance software that resolves your entities makes the rest of your controls honest.
What none of these tools do is make the judgment for you. The AI QA layer flags unsupported claims but does not decide what is true, and the resolver proposes matches but leaves the merge to you. Both keep a record of what they did, which is the point for anyone who may have to explain a decision later. IT operations & compliance software speeds up review and cleanup. It does not replace the person accountable for the result. The accountability stays with you, and the tedious first pass, reading every claim against a source or comparing every record against every other, moves to software that does not get tired or skip a row. That is the part a human does badly at volume and a tool does well.
If unchecked AI output or scattered duplicate records are your two biggest exposures, those are the tools to try first. See how they fit with the rest of SortOps on the IT operations and compliance page and start with the one that removes the most risk.
Close
Each tool produces one artifact with a date on it, on hardware you control, and exports without asking us. Start with the restore test, because that’s the one that will hurt.
Start free trial No card. From $39 a month.