Full capability list

Everything in the platform,
page by page.

73 pages, grouped exactly as the product groups them — this page mirrors the sidebar you will see after signing in. 67 sit inside the module groups; the other 6 are Dashboard, Calendar, Tasks, Document Library, Help Center and Chatbot. Nothing here is on a roadmap.

9
Modules
31
Capabilities
73
Pages in total
1,109
Mapped controls

Every section is open. Collapse the ones you do not need.

Main 4 pages
PageWhat it does
Dashboard "Mission Control" — a company-scoped landing page where a user reads current risk posture (AI briefing, heat map, overdue items) and drills into whatever needs attention.
Calendar One GRC calendar overlaying auto-generated due dates from every module (audits, findings, BCP exercises, corrective actions, vendor/risk/control reviews, EU AI Act, change windows) with manual events.
Tasks Read-only unified worklist aggregating every due-dated remediation item across six modules, overdue-first.
Document Library Company/org-scoped repository with folder tree, versioned uploads, in-page preview, admin recycle bin.
Risk Management 2 capabilities9 pages
CapabilitiesEnterprise risk register and heatmapsUK Provision 29 principal-risk reporting
PageWhat it does
Risk Register The enterprise risk register — create, score, treat, link and sign off individual risks, with a 5×5 heat map and per-risk deep-dive.
Risk Assessments Run structured, company-scoped questionnaire assessments from a shared template catalog, then generate AI reports and extract risks from them.
Risk Treatments Manage mitigation actions against risks — ownership, schedule, budget, progress. 3 tabs (All / My Treatments / Overdue); 13 columns, all sortable. 6 filters + header scope.
Top 10 Risks Present the ten highest-scoring risks with a weighted multi-criteria evaluation view. 2 view modes (table / cards). 6 filters + clear-all; client pagination; sortable columns.
Principal Risks The board-level principal-risk register (UK Corporate Governance Code Provision 28/29) with annual-report disclosure drafting and multi-signatory sign-off.
Threats A threat catalogue (actors, techniques, sources) linkable to risks. 10 sortable columns. 5 filters; stat cards by status and trend; create/view/edit/delete with 17 fields including threat_actor, threat_type, source, last_observed, and mitre_tactic +…
Vulnerabilities Vulnerability register with CVE/CVSS enrichment and remediation tracking, linkable to both risks and threats.
Risk Dashboards Three role-oriented analytics views (executive / operational / financial). 3 switchable dashboards; company + department + ERM-category filters; date range; settings modal with configurable auto-refresh.
Risk Reports Generate AI-written GRC reports from templates, stream them live, archive them, and control who can see each one.
Compliance 5 capabilities5 pages
CapabilitiesISO 27001 pre-mappedComposite 0-100% assurance scoreInternal audit executionIncident RCA and anonymous reporting29 standards pre-mapped with completion guides
PageWhat it does
Controls Register of implemented controls, grouped by the ISO/framework pack each came from, with an evidence/assurance case per control.
Objectives Register of organisational objectives with progress %, KPI target/current, budget, multi-owner.
Audits Full audit lifecycle — programme-driven planning, a guided question-by-question fieldwork wizard, findings management, and AI-generated reports.
Non-Conformances Read-only NCR log listing non-conformances raised from incidents, with ISO clause reference.
Incidents Incident register with full response lifecycle, RCA, CAPA, and bridges out to Non-Conformance, Change Management and Business Continuity.
TPRM 11 capabilities13 pages
CapabilitiesNative third-party risk intelligenceNATO Admiralty evidence gradingContinuous outside-in attack-surface monitoringSecurity questionnaires and vendor response portalAnswers AI-verified against independent evidenceAI verdicts on every uploaded evidence documentCombined rating with a published formulaSanctions, PEP and debarment screeningFinancial due diligenceRegistry identity and beneficial-ownership graphModern-slavery registry screening
PageWhat it does
Dashboard Third-party risk posture for one company — rating distribution, risk×criticality heatmap, programme progress, alert trend and four work queues.
Third Parties Browse the shared the shared intelligence layer intelligence pool and add entries to this company's monitored list.
Third-Party Requests Staff-submitted onboarding request, reviewed by an org admin; approval writes the vendor into the shared pool.
Monitored Third Parties The company's curated monitored list with two-tier sign-off, ownership, tagging, scan-depth control and assessment launch.
Review Queue Open continuous-monitoring alerts for the company's monitored third parties. One sortable alert table (5 columns, severity sorted as a rank not a string), aria-sort on every header, vendor-name prefix stripped from the title, row → dossier.
Fix Queue Human adjudication of the low-confidence tail of the the shared intelligence layer Resolver Agent's identity corrections and the nightly duplicate-merge sweep.
Attack Surface Pool-wide list of completed external-exposure scans, one row per domain. Client search over domain/entity, 6 sortable columns, dedup per domain keeping the highest-scoring completed scan, row → dossier. Grades A–E with contrast-corrected text colours.
Monitoring The detailed continuous-monitoring feed — change alerts and posture swings with per-finding drill-down.
Supply Chain Map Blast-radius and concentration risk across the intelligence graph, plus geographic concentration.
Manual Third Parties Flat, org-wide registry of hand-entered third parties. Nothing from the shared intelligence pool.
Reconcile Manual Identify hand-entered vendors that already exist in the shared intelligence pool and replace them with automated monitoring.
Third Party Assessments Questionnaire engine — instantiate a template against a vendor, answer weighted questions, score it, run the internal + external (vendor portal) review workflow.
Credit Checks Opt monitored third parties into paid Creditsafe checks on a chosen cadence, project annual spend live, review history and failure alerts. credit-settings (not in the sidebar) manages the per-company BYOK key and cost model.
vCISO 4 capabilities14 pages
CapabilitiesOwn-estate CVE/KEV matchingEstate-specific threat forecastsConversational security analystGeopolitical country risk scoring
PageWhat it does
Dashboard Board-level exposure across your own infrastructure, software and SaaS estate, with the advisories that drive it.
Copilot A tenant-fenced conversational analyst that answers on your estate, vendors, exposure and forecasts — and only yours.
Estate Register Declare your technology estate — systems and software components — from a curated catalog, per company.
Estate Security Your declared estate matched to the live CVE/KEV corpus, per system, with KEV and critical alerting.
Threat Radar Active adversary campaigns matched to your monitored vendors and to your own company, each scored on severity and likelihood and expandable to the companies it affects, alongside forward-looking predictive forecasts.
Action Queue Estate CVEs, regulatory deadlines and intelligence signals as one prioritised action list.
Briefings A per-company daily intelligence brief, synthesised through your estate and vendor watchlist.
News The live news corpus rendered per company — relevance-tagged security news with estate and vendor context.
Threats Live threat intelligence with mitigations, relevance-tagged per company and linked to adversary profiles.
Forecasts Estate-specific forward attack chains with detection signals ready for your SOC — refreshed weekly, on demand, and the moment a new estate is synced.
Adversaries 583 adversary profiles with full detail, linked from your threats and forecasts.
Regulatory Regulatory deadlines and horizon-scanning, defaulting to your declared jurisdictions, with per-company tracking.
Geo Risk 207 countries scored on the STEMPLES-Plus model — sortable table, heatmap, and rich country profiles with radar diagrams and sourced indicators.
Horizon Briefs Strategic view — STEMPLES risk matrix, likelihood-by-impact grid, defender-vs-adversary trajectory and a full risk register.
Business Continuity 2 capabilities2 pages
CapabilitiesISO 22301 business continuityBCP live activation with actual-vs-planned RTO
PageWhat it does
BCP Management 6 stat cards, 9 module cards with live counts, BC Readiness gauge, top-5 Critical Functions, top-5 Upcoming Exercises, recent activity, quick actions.
Critical Assets The asset register behind risk and continuity work — five category views, a 22-field record covering classification, ownership, location, value and recovery objectives, and straight-line depreciation on capital items.
Change Management 1 capability5 pages
CapabilitiesGRC-native change management
PageWhat it does
Dashboard 9 click-through KPI tiles — open changes, drafts awaiting submission, pending my approval, scheduled next 7d, success rate 90d, emergency rate 90d, failed/rolled-back 90d, changes causing incidents 90d, overdue PIRs — the last four going alert-red when non-zero.
Change Register 7 filters incl. source manual vs CI/CD, all applied client-side over the fetched list — all real. + New Change modal min(1100px,94vw) with Details + 4 full-size plan tabs, each showing a filled dot when written and a red * when a rollback…
My Approvals Cards from /changes/approvals/pending. Per card: ref, title, type chip, risk chip, category, submitted time, proposed window, the user's own eligible tier(s), and a ✓/✗ readiness strip across implementation/test/rollback/comms + "rollback tested" so a decision can…
Change Calendar Two views — Monday-first 42-cell grid and a list. Shared filters plus a 7-mode window range (Upcoming / Next 30 / Next 90 / Selected month / Past / Unscheduled / All) and a sortable date column. Freeze overlay on both views;
Settings Per-user account settings. Profile update. Password change, with enforced complexity (minimum 8 characters; must contain uppercase, lowercase and numbers) and confirmation matching.
AI Governance 2 capabilities7 pages
CapabilitiesISO 42001 AI management systemEU AI Act module
PageWhat it does
AI Portfolio 4 stat cards; Fund/Fix/Freeze three-column matrix with top-5 use cases and scores; proportional model-risk bar with legend; maturity gauge with a "Not Assessed → Start Assessment" fallback. 3 quick actions.
AI Use Cases 6 stat cards. 9-column table; 4-tab modal (Basic Info, Classification, AI Models, Risk Score — the last two deliberately disabled on create with "Save first to link models").
AI Models 6 stat cards; 10-column sortable table. Unlike Use Cases this page fetches once and filters/sorts client-side, with an honest Showing {n} of {m} models — its search, filters and sort are real.
AI Maturity 8-column sortable list with aria-sort; create modal with full or domain-specific type and a checkbox-card picker over the 8 domains; view modal with overall score, level, per-domain breakdown and priority improvements.
AI Risk Toolkit A structured assessment across 32 risk items spanning the AI lifecycle, filterable by lifecycle stage, linkable to a use case or model, and worked through with named assessor, reviewer and DPO roles against published ICO practical-steps guidance.
EU AI Act Classification Wizard: 6 steps — Introduction → Article 5 Prohibited Practices → GPAI check → High-Risk / Annex III → Value-chain role → Result, each with contextual help, auto-saved wizard…
FRIA (Article 27) The fundamental rights impact assessment required by Article 27 of the EU AI Act, run as a guided workflow against a registered AI system and filed alongside its classification and model record.
ESG & Sustainability 1 capability9 pages
CapabilitiesESG and CSRD/ESRS reporting
PageWhat it does
ESG Dashboard Org-wide rollup of emissions by scope, pillar scores, framework document progress, goals, ESG incidents, alert bar.
Carbon Accounting GHG-Protocol emissions register — log activity data, pick a factor, auto-calculate tCO2e, run a verification workflow.
ESG Metrics Record period values against a catalogue of standard E/S/G metric definitions, with baseline/target/change tracking.
Materiality Create a CSRD-style double-materiality assessment and score standard ESG topics on impact vs financial axes.
ESG Frameworks Per-company, per-framework workspace showing framework documents to complete and metric coverage.
Goals & Targets CRUD over ESG goals with baseline→current→target progress, derived status, SBTi/intensity metadata, computed milestone timeline.
Supply Chain ESG Flat table of supplier ESG assessments with a create-only modal and a deep link into the TPRM vendor dossier.
ESG Reports Generate AI-written ESG framework "master documents" per company via a streaming Claude call, then archive, view, download as DOCX, or delete.
ESG Guides Static launcher of 7 cards opening pre-built framework how-to HTML guides in a new tab.
ISO & Training 2 capabilities3 pages
CapabilitiesAI document generationInteractive training with auto-certificates
PageWhat it does
AI ISO Documents AI-generated compliance document production against a chosen framework, driven by interview questions and document templates.
ISO Training Self-contained LMS shipping standard-specific courses as TypeScript data, with lesson player, module quizzes, progress tracking and PDF certificates.
ISO & Security Guides Index of the HTML completion guides, categorised (Regulatory / Cybersecurity / ISO / platform).
Help & Support 2 pages
PageWhat it does
Help Center Standalone documentation site serving all 58 guides with sidebar nav, TOC and a client-side router.
Chatbot Persistent multi-conversation AI compliance assistant, optionally scoped to one standard, streaming Claude's reply token-by-token.
Across the platformHash-chained, append-only forensic audit trail

That is the whole product.
One price covers it.

No module is held back, and nothing on this page is an add-on except TPRM & vCISO.