Governance, risk & compliance
Map a control once.
Satisfy every framework.
One control library behind risk, compliance, policy, assets, third parties, and audit. Assess it once and report against every standard that references it.
Runs on your own infrastructure or hosted. Isolation is row-level either way.
Mapped out of the box · extensible to any authority
Control library
Frameworks are views, not silos
One control carries a graded mapping to every standard that references it, with one standard marked primary and your own internal standard sitting alongside the published ones.
Frameworks and controlsControl
Privileged access is reviewed each quarter by the system owner
PPTDF applicability
One owner · one procedure · one evidence trail
Architecture
Three decisions that shape everything else
Jurisdictions and authorities are data
Model the regulator that supervises you, then map controls to it. Nothing about the engine is hard-coded to one rulebook.
Framework coverageRuns on-premise or as SaaS
Single-tenant on your own infrastructure, or multi-tenant hosted. Isolation is row-level by company either way.
Platform architectureImmutable audit log
Every change is recorded in an append-only log, alongside per-module evidence review and approval trails.
Security and trustAssess
Scored against written descriptors, not opinion
Every question in the library defines what each maturity level actually means, so two assessors reach the same number.
Level 3: Well Defined
A standard process is defined and followed across the organisation.
Every question in the control library carries its own written descriptor at each level.
Govern
Ten asset states, each separately permissioned
A coordinator moves an asset to review. Only an approver can approve it. The split is enforced by the permission model, not by convention.
Draft·asset-coordinator creates
Monitor
Indicators that know what they are attached to
Thresholds resolve to within, warning, or critical, and each indicator links to the controls and findings it bears on.
Privileged accounts without review
KRI · monthly · owner: Security Operations
Control
Segregation of duties you can actually evidence
Permission bundles operate at the level of individual lifecycle transitions, with declared conflict rules and logged exceptions.
| Action | asset-viewer | asset-coordinator | asset-approver | asset-admin |
|---|---|---|---|---|
| View | Allowed | Allowed | Allowed | Allowed |
| Create and edit | Not allowed | Allowed | Not allowed | Allowed |
| Submit for intake | Not allowed | Allowed | Not allowed | Allowed |
| Send to review | Not allowed | Allowed | Not allowed | Allowed |
| Send back | Not allowed | Allowed | Allowed | Allowed |
| Approve | Not allowed | Not allowed | Allowed | Allowed |
| Activate | Not allowed | Not allowed | Allowed | Allowed |
| Module settings | Not allowed | Not allowed | Not allowed | Allowed |
Every module ships bundles at this granularity. Segregation-of-duties conflicts are declared as rules, with logged exceptions.
In the platform
What each module actually does
Frameworks & Controls
One library, every framework as a view
A control carries graded mappings to each standard that references it, with one marked primary.
Explore the moduleControl
Privileged access is reviewed each quarter by the system owner
PPTDF applicability
One owner · one procedure · one evidence trail

Reporting
The pack the board reads comes from the same record
Reporting draws directly from the register, so the number in the board pack and the number in the platform cannot drift apart between quarters.
- Board rollup snapshots generated from the live register, not re-keyed
- Hierarchy aggregates so a group view and an entity view agree
- Report jobs, schedules, and saved presets for recurring packs
- Share links, webhooks, and BI export where the pack has to leave the platform
Products
Twelve modules on one data model
Every module reads and writes the same underlying record, so a vendor engagement, a policy exception, and an audit finding all point at the same control.
Risk
Compliance & Governance
Compliance Management
Assessments, evidence, maturity scoring, delegation
Frameworks & Controls
Jurisdictions, authorities, domains, controls, standards mapping
Policy Management
Lifecycle, versioning, approvals, and control mapping
Findings & Remediation
Findings, severity, assignees, remediation, audit trails
Operations
Who it is for
Organisations that get inspected
Supervised sectors where a control failure is a reportable event, and where the same programme has to satisfy several authorities at once.
- Banking & FinanceVendor tiering, contract obligations, and group-wide assurance under continuous supervision.
- GovernmentNational digital programmes, asset governance, and permissioned approval chains.
- Energy & UtilitiesOT and IT risk on one register, with deep supply chains and critical asset inventories.
- TelecomInfrastructure-scale third-party risk and converged operational and cyber exposure.

Frameworks
Every standard in one model
International baselines, national regulations, and your own internal standards live in the same control model, mapped to each other rather than maintained in parallel.
- Control library imported and mapped
- Assessment templates and questionnaires
- Maturity scoring per framework
- Evidence reuse across mapped controls
| Framework | Scope | Type |
|---|---|---|
| NCA ECC | Essential cybersecurity controls, configurable to your jurisdiction | National |
| SAMA CSF | Financial-sector cyber framework for regulated institutions | Financial |
| PDPL | Personal data protection, mappable to any privacy regime | Privacy |
| ISO/IEC 27001 | International ISMS standard with Annex A controls | Global |
| NIST CSF | Identify → Protect → Detect → Respond → Recover | Global |
| Your regulator | Define the authority, its domains, and its controls, then assess against it | Configurable |
Writing
Notes from the compliance trenches
Practitioner notes on the problems that recur across programmes, written for people who already run one.

Practitioner Guide
Everybody Is at Level 3
Run a maturity self-assessment across a large organisation and the results cluster in the middle with suspicious consistency. It is not that everyone is genuinely at the same level. It is that the middle is the safest place to stand. Here is what the levels are supposed to mean and why the jump to level 4 is the one that actually costs something.
8 min read

Practitioner Guide
Red, Amber, Green Is Not a Number
Someone on the board asks what the exposure is worth, and the heat map cannot answer. It was never built to. Here is what goes wrong when ordinal scales get treated as arithmetic, what quantifying a risk actually involves, and which risks are not worth quantifying at all.
9 min read

Practitioner Guide
The Supplier You Never Signed a Contract With
Three of your critical vendors go down on the same morning. None of them are competitors, none share an owner, and nothing in your register connects them. They were all running on the same platform underneath. Here is why fourth-party concentration is invisible to most vendor programmes, and what it takes to see it.
9 min read
See it running against your frameworks
Bring the standards you are held to and the way your entities are structured. We will walk the risk, compliance, and audit workflows end to end against them.
