Seven connected stages — Scope, Govern, Assess, Evidence, Audit, Remediate, Report — everything linked, nothing re-keyed.
Bring your frameworks into scope, assess every control, attest with four-eyes sign-off, and prepare for audit — the Archer-style spine.
Author professional, branded policies for any clause from a best-practice sample + wizard — versioned, with your organisation's logo on the cover.
5×5 register with residual scoring, risk appetite, FAIR-style loss modelling and Key Risk Indicators — migrate from a spreadsheet and export to Excel.
An incident & loss-event register linked to the risks it touches, plus an alerts & escalation engine — overdue findings, breached KRIs and critical risks.
A versioned library of every applicable regulation — ISO, PCI, SOC 2, the full NCA set, the SAMA suite, PDPL and the Australian regime — with change tracking.
Connect Microsoft 365 / Google and auto-verify controls, attach evidence, raise findings and update your scores — without manual entry.
Plan audits over a scoped framework, test controls independently, raise findings and issue an opinion with certification readiness.
Findings with SLAs, exceptions & waivers with expiry, maker-checker approvals, and a tamper-evident audit trail across everything.
Assess and monitor suppliers, tier them by criticality, track their controls and reviews, and fold vendor risk back into your overall posture.
A live inventory of the systems, data, applications and services in scope — linked to the controls, risks and evidence that apply to each.
Run security-awareness training and simulated-phishing campaigns, then evidence completion and click-rates straight against your controls.
Every policy versioned in a central register, published to your people, with per-employee acknowledgement tracking — proof your policies are read, not just written.
Board-ready views of compliance status, risk posture and audit readiness — with a live Statement of Applicability and a Trust centre.
Generate the controlled ISMS Scope document a certification body actually opens — and give Clause 6.2 objectives, Clause 9.1 monitoring measures and the Clause 7.2 competence register somewhere to live.
A Clause 9.3.2 review pack assembled from your own scope, risks, audits and Statement of Applicability — one meeting discharging the requirement for every management system you hold.
Import a Qualys, Tenable or Defender export — deduplicated by CVE and asset, reopening what came back, with the SLA clock running from first seen — then promote anything material into a governance finding or risk.
Invite your audit firm to one engagement by link — no account needed. Evidence requests with sample selection and due dates, answered in place, accepted or returned with a reason.