Platform

Everything between the first scan and the audit.

34 pages and 333 API endpoints behind one read-only role. Grouped here by the question you are actually trying to answer, not by the order of the nav.

Measured from source · September 2026

01 · Reachability

What do I have, and who can reach it?

The graph every other module hangs on. Scan-based: each scan replaces the previous graph.

Infrastructure graph

22 AWS resource types and 12 relationship types. policy_grants (which IAM roles reach an S3 bucket or DynamoDB table, parsed from identity policies) and allows_traffic_to (security group to security group, with protocol and port) are first-class edges, so "who can reach this bucket" is one hop with the path attached.
s3://ci-artifacts → 30 roles · via policy_grants

Discovery Intelligence

A written narrative over the graph: what the account is, how it clusters into workloads, who appears to own what, where the orphans and hot spots are. Grounded in the scan, not generated from nothing.

Topology view

Layout: hierarchy, organic, tree, circle. Scope: all, ISO, prod, exposed, findings. Overlay: architecture, compliance, risk, evidence. The graph and the control set on the same canvas.
LAYOUT hierarchy · SCOPE exposed · OVERLAY compliance

Scans & schedules

Run on demand or on a schedule. 12 scanner modules, AWS only. Findings carry severity, resource, region and the controls they bear on.

Findings

Severity-ranked, filterable, mapped to ISO 27001 and SOC 2 controls from the finding itself.

Monitoring

Between scans a CloudTrail poller records change and drift events into an event feed. Resolve one at a time or in bulk.

Remediation

The copilot drafts the fix: reasoning, AWS CLI, Terraform where it applies. An admin confirms each action; every execution is written to the audit log with who authorised it. Nothing runs on its own.

Assets

IT asset inventory, with AWS resources imported from the scan.

apigateway:rest_api · apigatewayv2:api · cloudfront:distribution · dynamodb:table · ec2:igw · ec2:instance · ec2:nat_gateway · ec2:route_table · ec2:security_group · ec2:subnet · ec2:vpc · ecs:cluster · ecs:service · eks:cluster · elasticache:cluster · elbv2:load_balancer · elbv2:target_group · iam:role · lambda:function · rds:instance · route53:zone · s3:bucket

02 · The standard

What does the standard require of me?

Three frameworks first-class. Every control is Verified, Failing or Not assessed — the denominator never shrinks.

Compliance

ISO 27001:2022 (93 Annex A controls, 21 scanner-checked), ISO 42001:2023 (38 controls across A.2–A.10, 3 partly evidenceable by scanning), SOC 2 (28 TSC controls). NIS2 and DORA as requirement crosswalks. GDPR, HIPAA, PCI DSS, NIST 800-53 and CIS Controls as mapping references.

Control mapping

Which findings and which evidence satisfy which control, per framework. Editable and versioned.

Readiness

Per-framework checklists of what an audit will need and you do not yet have. The copilot suggests next actions.

ISO Journey

Certification sequenced into steps, not a wall of controls. See the full journey below →

On ISO 42001. It is a management-system standard. 3 of its 38 controls can be partly evidenced by scanning; the other 35 are answered by an assessment and a named owner. isops gives you the structure, the evidence trail and the audit-readiness around those decisions — it does not automate them.
03 · The ISMS

What will the auditor ask to see?

The artefacts. Each one is a real module with its own records, owners and history — not a checkbox.

Policies

31 built-in templates, version history, review cycles and approval. Optionally backed by a git repository, so the policy set is reviewed like source.

Statement of Applicability

All 93 Annex A controls, included or excluded, each with a justification. The copilot drafts justifications for the control owner to edit and approve; it is instructed never to assert a control is implemented unless your context says so.

Risk register

5×5 likelihood/impact matrix, heatmap, treatment plans and owners.

Evidence

Timestamped, control-linked records. Scan results attach themselves; everything else is attached by hand.

Incidents

Records, timelines, outcomes. The copilot proposes a classification.

CAPA

Corrective and preventive actions, tracked to closure.

Audit programme

Internal audits with findings and follow-up. The copilot drafts findings from the evidence.

Management review

The Clause 9.3 leadership review, as a record.

Access reviews

Periodic entitlement review campaigns.

Penetration tests

Engagement records and remediation tracking.

Training

Security-awareness assignment and completion, including bulk assign.

People

The employee register A.6 depends on.

Vendors

Third-party risk: questionnaires, scoring, tiering, review dates. The copilot drafts the assessment.

04 · Outside the building

How do I show it to people outside?

Auditors, prospects and their security questionnaires — each gets a scoped view, never the keys.

Reports (PDF)

Compliance report, risk assessment, executive summary, evidence package. Figures are recomputed at generation time from the same scoring source as the dashboard, so a report cannot disagree with the UI. Every report states that it reflects automated control posture and is not a certification.
compliance · risk-assessment · executive-summary · evidence-package

Auditor portal

Scoped token login with its own entry point. The auditor sees a summary, per-framework controls and evidence, policies, an incident summary and audit reports. Read-only. No seat, no screenshots by email.

Trust centre

A public page presenting your automated control posture to prospects — labelled as posture. It will not say "certified".

Security questionnaires

Paste a questionnaire; it is split into questions and each is answered from your own evidence and policies, for you to review before it leaves.

05 · Fit and trust

How does it fit my stack, and can I trust it?

It reads your cloud and stores your evidence, so its own security is part of the product.

Integrations

GitHub, GitLab, Jira, Okta, Slack, Google Workspace, AWS.

Notifications & webhooks

In-app notifications, Slack, and outbound webhooks for anything else.

Developers

The platform's REST API with scoped API keys. 333 endpoints across 44 modules.

Audit log

Every platform action, including who authorised each remediation.

Admin, settings, SSO

Roles: admin, viewer (default), auditor. SAML/OIDC single sign-on. Per-organisation tenancy scoping enforced centrally at the data-access layer.

Architecture

Self-hosted Docker in your own AWS account. Read-only IAM role. Fail-closed authentication on every API route. Secrets encrypted at rest and never returned by the API.

ISO 27001:2022

Seventeen steps, in order, with the artefacts attached to the step that needs them.

Certification is a sequence, not a wall of 93 controls. The ISO Journey lays out 17 steps from scoping to the certification audit and tracks each as not started, in progress or done. The Risk Register, Statement of Applicability, Documents, Audits and Training live as tabs inside the journey, so the risk register is built at the step that asks for a risk register.

08 · Complete Statement of Applicability — review all 93 Annex A controls and
justify inclusion or exclusion.

Tabs: Checklist · Risk Register · Statement of Applicability · Documents · Audits · Training

AI copilot

Twelve things it drafts. Nothing it decides.

Optional, provider-agnostic, and every output is a draft a named human edits and approves.

CapabilityLives inWhat it drafts
generate-policyPoliciesA policy from a template and your organisation's context.
soa-justificationISO Journey › SoAA 2–3 sentence inclusion or exclusion justification for a control, with marked placeholders wherever your context does not support a claim.
risk-treatmentRisk registerA treatment plan for a risk.
risk-assessmentRisk registerAn assessment of a risk.
gap-analysisComplianceWhere you fall short of a framework.
evidence-gap-analysisEvidenceWhich controls lack evidence.
readiness-suggestionsReadinessNext actions for audit preparation.
vendor-assessmentVendorsA third-party risk assessment.
classify-incidentIncidentsA severity and category for an incident.
generate-audit-findingsAudit programmeInternal-audit findings from the evidence.
compliance-queryAnywhereAn answer to a natural-language compliance question, from platform context.
executive-briefReportsA posture summary written for the board.

Also drafted

  • Security questionnairesparse splits a pasted questionnaire into questions; answer drafts each answer from your evidence.
  • Remediation — drafts the reasoning, the AWS CLI steps and Terraform where it applies.
  • Discovery Intelligence — the narrative over the graph (see Reachability).
Optional. The platform runs without an AI provider. You lose the drafting layer, not the scanning, mapping, evidence or the ISMS.
Provider-agnostic. Anthropic, OpenAI or AWS Bedrock. Keys are encrypted at rest and never returned by the API. Turn it off and no customer data leaves your deployment.
Human-reviewed, by construction. Drafts are labelled as drafts. The SoA prompt is instructed never to assert a control is implemented, tested or effective unless your context says so. Remediation commands are parsed into an argument vector and never passed through a shell; only aws invocations are permitted; execution needs an admin role and an explicit per-action confirmation, and is audit-logged with the actor.

See it against your own AWS account.

30-minute demo. Real account. First audit pack exported before we're done.