Scope
What are we actually assessing?
The legacy Free Snapshot route is retained for indexed-link continuity, but the service is now focused on security readiness rather than general workflow automation.
The purpose is triage, not a certification claim.
What are we actually assessing?
Which gaps deserve priority?
What can be proved today?
Gap assessment, readiness, technical remediation or managed GRC?