Everything between the first scan and the audit.
34 pages and 333 API endpoints behind one read-only role. Grouped here by the question you are actually trying to answer, not by the order of the nav.
What do I have, and who can reach it?
The graph every other module hangs on. Scan-based: each scan replaces the previous graph.
Infrastructure graph
22 AWS resource types and 12 relationship types. policy_grants (which IAM roles reach an S3 bucket or DynamoDB table, parsed from identity policies) and allows_traffic_to (security group to security group, with protocol and port) are first-class edges, so "who can reach this bucket" is one hop with the path attached.
s3://ci-artifacts → 30 roles · via policy_grants
Discovery Intelligence
A written narrative over the graph: what the account is, how it clusters into workloads, who appears to own what, where the orphans and hot spots are. Grounded in the scan, not generated from nothing.
Topology view
Layout: hierarchy, organic, tree, circle. Scope: all, ISO, prod, exposed, findings. Overlay: architecture, compliance, risk, evidence. The graph and the control set on the same canvas.
LAYOUT hierarchy · SCOPE exposed · OVERLAY compliance
Scans & schedules
Run on demand or on a schedule. 12 scanner modules, AWS only. Findings carry severity, resource, region and the controls they bear on.
Findings
Severity-ranked, filterable, mapped to ISO 27001 and SOC 2 controls from the finding itself.
Monitoring
Between scans a CloudTrail poller records change and drift events into an event feed. Resolve one at a time or in bulk.
Remediation
The copilot drafts the fix: reasoning, AWS CLI, Terraform where it applies. An admin confirms each action; every execution is written to the audit log with who authorised it. Nothing runs on its own.
Assets
IT asset inventory, with AWS resources imported from the scan.
apigateway:rest_api · apigatewayv2:api · cloudfront:distribution · dynamodb:table · ec2:igw · ec2:instance · ec2:nat_gateway · ec2:route_table · ec2:security_group · ec2:subnet · ec2:vpc · ecs:cluster · ecs:service · eks:cluster · elasticache:cluster · elbv2:load_balancer · elbv2:target_group · iam:role · lambda:function · rds:instance · route53:zone · s3:bucket
What does the standard require of me?
Three frameworks first-class. Every control is Verified, Failing or Not assessed — the denominator never shrinks.
Compliance
ISO 27001:2022 (93 Annex A controls, 21 scanner-checked), ISO 42001:2023 (38 controls across A.2–A.10, 3 partly evidenceable by scanning), SOC 2 (28 TSC controls). NIS2 and DORA as requirement crosswalks. GDPR, HIPAA, PCI DSS, NIST 800-53 and CIS Controls as mapping references.
Control mapping
Which findings and which evidence satisfy which control, per framework. Editable and versioned.
Readiness
Per-framework checklists of what an audit will need and you do not yet have. The copilot suggests next actions.
ISO Journey
Certification sequenced into steps, not a wall of controls. See the full journey below →
What will the auditor ask to see?
The artefacts. Each one is a real module with its own records, owners and history — not a checkbox.
Policies
31 built-in templates, version history, review cycles and approval. Optionally backed by a git repository, so the policy set is reviewed like source.
Statement of Applicability
All 93 Annex A controls, included or excluded, each with a justification. The copilot drafts justifications for the control owner to edit and approve; it is instructed never to assert a control is implemented unless your context says so.
Risk register
5×5 likelihood/impact matrix, heatmap, treatment plans and owners.
Evidence
Timestamped, control-linked records. Scan results attach themselves; everything else is attached by hand.
Incidents
Records, timelines, outcomes. The copilot proposes a classification.
CAPA
Corrective and preventive actions, tracked to closure.
Audit programme
Internal audits with findings and follow-up. The copilot drafts findings from the evidence.
Management review
The Clause 9.3 leadership review, as a record.
Access reviews
Periodic entitlement review campaigns.
Penetration tests
Engagement records and remediation tracking.
Training
Security-awareness assignment and completion, including bulk assign.
People
The employee register A.6 depends on.
Vendors
Third-party risk: questionnaires, scoring, tiering, review dates. The copilot drafts the assessment.
How do I show it to people outside?
Auditors, prospects and their security questionnaires — each gets a scoped view, never the keys.
Reports (PDF)
Compliance report, risk assessment, executive summary, evidence package. Figures are recomputed at generation time from the same scoring source as the dashboard, so a report cannot disagree with the UI. Every report states that it reflects automated control posture and is not a certification.
compliance · risk-assessment · executive-summary · evidence-package
Auditor portal
Scoped token login with its own entry point. The auditor sees a summary, per-framework controls and evidence, policies, an incident summary and audit reports. Read-only. No seat, no screenshots by email.
Trust centre
A public page presenting your automated control posture to prospects — labelled as posture. It will not say "certified".
Security questionnaires
Paste a questionnaire; it is split into questions and each is answered from your own evidence and policies, for you to review before it leaves.
How does it fit my stack, and can I trust it?
It reads your cloud and stores your evidence, so its own security is part of the product.
Integrations
GitHub, GitLab, Jira, Okta, Slack, Google Workspace, AWS.
Notifications & webhooks
In-app notifications, Slack, and outbound webhooks for anything else.
Developers
The platform's REST API with scoped API keys. 333 endpoints across 44 modules.
Audit log
Every platform action, including who authorised each remediation.
Admin, settings, SSO
Roles: admin, viewer (default), auditor. SAML/OIDC single sign-on. Per-organisation tenancy scoping enforced centrally at the data-access layer.
Architecture
Self-hosted Docker in your own AWS account. Read-only IAM role. Fail-closed authentication on every API route. Secrets encrypted at rest and never returned by the API.
Seventeen steps, in order, with the artefacts attached to the step that needs them.
Certification is a sequence, not a wall of 93 controls. The ISO Journey lays out 17 steps from scoping to the certification audit and tracks each as not started, in progress or done. The Risk Register, Statement of Applicability, Documents, Audits and Training live as tabs inside the journey, so the risk register is built at the step that asks for a risk register.
08 · Complete Statement of Applicability — review all 93 Annex A controls and justify inclusion or exclusion.
Tabs: Checklist · Risk Register · Statement of Applicability · Documents · Audits · Training
Twelve things it drafts. Nothing it decides.
Optional, provider-agnostic, and every output is a draft a named human edits and approves.
| Capability | Lives in | What it drafts |
|---|---|---|
| generate-policy | Policies | A policy from a template and your organisation's context. |
| soa-justification | ISO Journey › SoA | A 2–3 sentence inclusion or exclusion justification for a control, with marked placeholders wherever your context does not support a claim. |
| risk-treatment | Risk register | A treatment plan for a risk. |
| risk-assessment | Risk register | An assessment of a risk. |
| gap-analysis | Compliance | Where you fall short of a framework. |
| evidence-gap-analysis | Evidence | Which controls lack evidence. |
| readiness-suggestions | Readiness | Next actions for audit preparation. |
| vendor-assessment | Vendors | A third-party risk assessment. |
| classify-incident | Incidents | A severity and category for an incident. |
| generate-audit-findings | Audit programme | Internal-audit findings from the evidence. |
| compliance-query | Anywhere | An answer to a natural-language compliance question, from platform context. |
| executive-brief | Reports | A posture summary written for the board. |
Also drafted
- Security questionnaires — parse splits a pasted questionnaire into questions; answer drafts each answer from your evidence.
- Remediation — drafts the reasoning, the AWS CLI steps and Terraform where it applies.
- Discovery Intelligence — the narrative over the graph (see Reachability).
See it against your own AWS account.
30-minute demo. Real account. First audit pack exported before we're done.