You did the work.Now prove it.
Governance software for small and mid-sized businesses that have real obligations and no compliance team. ProofWorks turns the work you already do — policies, approvals, risk decisions — into proof. leaps and bounds does the same for what your automations and AI agents do without you. Every action leaves a receipt an auditor can check.
Not a compliance team.
A small team wears every hat, and that works for a long time. The limit, when it arrives, isn't workload. Approving your own work and attesting to your own work are the two jobs that stop being credible the moment the person doing the work holds them as well. Fine at five people. Untenable at fifty. Nothing went wrong in between — the company simply crossed the line where the roles have to separate.
They came with the contracts you signed, the regulations you fall under, and the cover you renew each year. They belong to the business because the business agreed to them — they can't be handed down to whoever happens to run the servers, and they don't lapse because nobody wrote them out. Most organisations have never named theirs. Everything after this depends on that list existing.
This part isn't ours. Building it, running it and keeping it up is your IT provider's work, and they should keep it — howldr sells no managed services, no monitoring, and no hardware. We work alongside delivery rather than in place of it, and we're glad to hand over the documentation to work from. What matters here is only that execution leaves a record behind it — including the automated kind, running at 3am, that nobody is watching.
The pack is everyone the record touches: the owner carrying the obligation, the manager who approves it, the person who does the work, and whoever comes asking two years from now. Proof belongs to all of them at once, and that shared claim is what gives it weight. howldr issues every receipt from the system itself and attributes it by authentication, so each one carries who acted, when, and against which version. The record stands on its own — and it keeps standing after the people move on.
Systems that produce and keep the proof as you work — not after the fact.
howldr ProofWorks Open SourcePolicies, evidence, risk, access reviews, vendors and obligations — every action a receipt. → leaps and bounds Open-Source GateDeterministic control for automations and AI agents. Move by leaps, stay in bounds. →Fixed-scope engagements with a written deliverable. We advise and document; your IT partner handles delivery and day-to-day support.
Obligations readiness reviewWhat you're on the hook for, what you can prove, and where the gaps are. → Technology StrategyIndependent assessment and second opinions — decisions documented so they hold up later. →A plain-English picture of what your organisation is actually on the hook for — the obligations that apply, what you can currently evidence, and where the gaps are. Written findings, a prioritised action list, and a walkthrough call. Scoped and quoted to your situation, because a ten-person firm with one contract and a fifty-person firm under three frameworks are not the same job. Tell us what you're dealing with and we'll tell you what it takes.
howldr is led by Pat Burgess — a CISSP with roughly three decades in IT and security. He has served as a Senior Director of IT and led infrastructure and messaging engineering across healthcare, financial, and education environments. His experience spans HIPAA, FERPA, PCI, GDPR, and NIST 800-53 and CSF compliance; Microsoft 365, Exchange, and Active Directory; VMware, Hyper-V, and SAN storage; data-center design, disaster recovery, and business continuity; enterprise DNS, DHCP, and identity; and hands-on security operations. A U.S. Navy veteran. That background is why howldr's software is built the way it is: the people who had to produce the evidence are the ones who designed the system that keeps it. Not because it was too much work — because proving it was never the same job as doing it.