This is the actual product navigation — every module group and every page inside it. Risks link to controls, controls carry evidence, incidents raise non-conformances. Change one thing and it updates everywhere it matters.
Six more sidebar pages sit outside the modules — Dashboard, Calendar, Tasks, Document Library, Help Center and Chatbot — for 73 pages in total. See every one in the full capability list.
Nine groups, each with its own pages. Everything below is in the standard price except the two marked as premium.
9 pages · the deepest section of the product
12 sortable columns, 9 filter dimensions, a 5×5 heat map you can click to filter, and an 11-tab detail view per risk.
178 shared templates across 16 categories, with a guided wizard and AI-assisted risk extraction.
Four treatment types with progress and budget tracking, so a mitigation nobody funded is visible as such.
Dynamic ranking with key-risk flagging and historical trend tracking.
Board-level register with oversight tracking — the backbone of a Provision 29 declaration.
Threat library linked to risks, vulnerabilities and the controls that mitigate them.
Technical vulnerability register tied back to critical assets and risk exposure.
Executive, operational and financial views with interactive heat maps.
Six AI-generated report types, from landscape analysis to control-gap review.
5 pages · 1,109 mapped controls
Grouped by framework pack into collapsible tables, with five evidence types per control and a one-click affirm action.
Compliance objectives tracked against owners, target dates and measurable outcomes.
Eight audit types with guided wizards, plus AI-drafted findings for the auditor to review.
Tracked to the ISO clause, with corrective actions, owners, due dates and escalation on slip.
Six root-cause analysis methods, so the analysis fits the incident rather than defaulting to five whys.
13 pages · continuous, evidence-based due diligence
Portfolio-wide risk, confidence and coverage across every monitored third party.
The vendor pool, with org-defined tags and named relationship owners.
Anyone proposes, admins approve — approval registers the vendor and queues its first scan.
Continuous monitoring with 16 assurance feeds refreshing behind each dossier.
Triage findings that need a human decision, with the evidence attached.
Route registry corrections for admin review so records get fixed at source.
Fifteen passive probes per domain — DNS, TLS, headers, email posture, subdomains and more.
Scan health and freshness, so you know what has actually been checked and when.
Concentration and blast radius across your third parties, with shared ownership visible.
Vendors you track by hand, alongside the monitored pool.
Merge manually-tracked vendors into monitored records without losing history.
Native questionnaires launched straight from a monitored vendor.
Financial and credit signals, with insolvency treated as a hard stop.
7 pages · ISO 42001 and the EU AI Act
Every AI initiative in one view, with a Fund / Fix / Freeze triage matrix and model-risk distribution.
Inventory with four risk tiers, status workflow and impact assessments.
Registry with training-data lineage, bias monitoring and deployment status.
Readiness across eight domains, in full, quick or domain-specific modes.
AI-specific assessments with automated risk extraction and control mapping.
Guided classification establishing your role and risk tier, then the obligations that actually apply.
Fundamental-rights impact assessments for the systems that require them.
9 pages · seven disclosure frameworks
E, S and G pillar scores with trend lines, emissions totals and an incident feed.
Scope 1, 2 and 3 with an emission-factor library, auto-calculation and data-quality tagging.
40+ metrics mapped to GRI, SASB, TCFD, CSRD, CDP and SDG targets.
CSRD-aligned double materiality on a four-quadrant matrix with configurable thresholds.
Seven framework programmes enabled per company, each with templates and completion tracking.
Net-zero and diversity goals with trajectory modelling and SBTi linking.
Vendor ESG scoring with risk-tier classification, linked to vendor management.
Framework-specific AI reports for CDP, CSRD, GRI, ISSB, SASB, TCFD and the SDGs.
Step-by-step guidance through each disclosure regime.
2 pages · ISO 22301 aligned
Business impact analysis with RTO, RPO and MTPD, 13 threat scenarios, recovery strategies, crisis teams, communication plans, exercises and live activations — rolled into a BC readiness score.
The asset register that recovery objectives and dependency mapping are built on.
14 surfaces · a per-company security intelligence service
A tenant-fenced conversational analyst that answers on your estate, vendors, exposure and forecasts — and only yours.
Declare your technology estate once; it is matched to the live CVE/KEV corpus per system, with KEV and critical alerting.
Live CVE, KEV and campaign intelligence with a ‘hits your estate’ lens, plus estate-specific forward attack chains shipping detection signals for your SOC.
A per-company daily brief synthesised through your estate and vendor watchlist, with 583 adversary profiles linked from your threats.
207 countries scored on the STEMPLES-Plus model, plus regulatory deadlines and horizon-scanning for your declared jurisdictions.
Strategic risk matrix and trajectory, with estate CVEs, deadlines and intelligence signals as one prioritised action list.
5 pages · governed change with approvals
Volume, risk and approval status across the change pipeline.
Every proposed change with its risk assessment and affected assets.
Your queue — what is waiting on you, with the context to decide.
Scheduled changes in one view, so collisions are visible before they happen.
Approval routing and thresholds configured to your governance model.
3 pages · 29 courses, 337 modules, 723 templates
723 templates generated with live streaming from your own platform data, with branded DOCX export and version history.
29 interactive courses across 337 modules, with quizzes, certificates and auditor-checkable verification codes.
Step-by-step completion guides from first assessment through to certification.
The day-to-day layer, and the controls underneath it
Where the work actually lands each morning, across every module.
Version-controlled storage that control evidence links directly to.
An always-on compliance assistant answering clause-level questions across all 29 standards.
Cloud posture visibility for risk and compliance users, not just admins.
Connect the systems your evidence already lives in.
Field-level change history across the platform — actor, timestamp, before and after.
Role-based access control, SAML 2.0 SSO against any conforming identity provider, and TOTP two-factor.
Hand ownership over cleanly when people move on, so a departure never orphans a risk.
Escalation levels and sign-off authority configured to your governance model.
We will walk it line by line against the actual product.