The platform

Nine modules.
Sixty-seven pages.
One system of record.

This is the actual product navigation — every module group and every page inside it. Risks link to controls, controls carry evidence, incidents raise non-conformances. Change one thing and it updates everywhere it matters.

9
Module groups
67
Pages in these nine modules
29
Standards covered
1,109
Mapped controls

Six more sidebar pages sit outside the modules — Dashboard, Calendar, Tasks, Document Library, Help Center and Chatbot — for 73 pages in total. See every one in the full capability list.

Every module

What each part of the platform does

Nine groups, each with its own pages. Everything below is in the standard price except the two marked as premium.

Risk Management

9 pages · the deepest section of the product

Learn more

Risk Register

12 sortable columns, 9 filter dimensions, a 5×5 heat map you can click to filter, and an 11-tab detail view per risk.

Risk Assessments

178 shared templates across 16 categories, with a guided wizard and AI-assisted risk extraction.

Risk Treatments

Four treatment types with progress and budget tracking, so a mitigation nobody funded is visible as such.

Top 10 Risks

Dynamic ranking with key-risk flagging and historical trend tracking.

Principal Risks

Board-level register with oversight tracking — the backbone of a Provision 29 declaration.

Threats

Threat library linked to risks, vulnerabilities and the controls that mitigate them.

Vulnerabilities

Technical vulnerability register tied back to critical assets and risk exposure.

Risk Dashboards

Executive, operational and financial views with interactive heat maps.

Risk Reports

Six AI-generated report types, from landscape analysis to control-gap review.

Compliance & Audit

5 pages · 1,109 mapped controls

Learn more

Controls

Grouped by framework pack into collapsible tables, with five evidence types per control and a one-click affirm action.

Objectives

Compliance objectives tracked against owners, target dates and measurable outcomes.

Audits

Eight audit types with guided wizards, plus AI-drafted findings for the auditor to review.

Non-Conformances

Tracked to the ISO clause, with corrective actions, owners, due dates and escalation on slip.

Incidents

Six root-cause analysis methods, so the analysis fits the incident rather than defaulting to five whys.

Third-Party Risk Management Premium

13 pages · continuous, evidence-based due diligence

Learn more

TPRM Dashboard

Portfolio-wide risk, confidence and coverage across every monitored third party.

Third Parties

The vendor pool, with org-defined tags and named relationship owners.

Third-Party Requests

Anyone proposes, admins approve — approval registers the vendor and queues its first scan.

Monitored Third Parties

Continuous monitoring with 16 assurance feeds refreshing behind each dossier.

Review Queue

Triage findings that need a human decision, with the evidence attached.

Fix Queue

Route registry corrections for admin review so records get fixed at source.

Attack Surface

Fifteen passive probes per domain — DNS, TLS, headers, email posture, subdomains and more.

Monitoring

Scan health and freshness, so you know what has actually been checked and when.

Supply Chain Map

Concentration and blast radius across your third parties, with shared ownership visible.

Manual Third Parties

Vendors you track by hand, alongside the monitored pool.

Reconcile Manual

Merge manually-tracked vendors into monitored records without losing history.

Third Party Assessments

Native questionnaires launched straight from a monitored vendor.

Credit Checks

Financial and credit signals, with insolvency treated as a hard stop.

AI Governance

7 pages · ISO 42001 and the EU AI Act

Learn more

AI Portfolio

Every AI initiative in one view, with a Fund / Fix / Freeze triage matrix and model-risk distribution.

AI Use Cases

Inventory with four risk tiers, status workflow and impact assessments.

AI Models

Registry with training-data lineage, bias monitoring and deployment status.

AI Maturity

Readiness across eight domains, in full, quick or domain-specific modes.

AI Risk Toolkit

AI-specific assessments with automated risk extraction and control mapping.

EU AI Act

Guided classification establishing your role and risk tier, then the obligations that actually apply.

FRIA (Article 27)

Fundamental-rights impact assessments for the systems that require them.

ESG & Sustainability

9 pages · seven disclosure frameworks

Learn more

ESG Dashboard

E, S and G pillar scores with trend lines, emissions totals and an incident feed.

Carbon Accounting

Scope 1, 2 and 3 with an emission-factor library, auto-calculation and data-quality tagging.

ESG Metrics

40+ metrics mapped to GRI, SASB, TCFD, CSRD, CDP and SDG targets.

Materiality

CSRD-aligned double materiality on a four-quadrant matrix with configurable thresholds.

ESG Frameworks

Seven framework programmes enabled per company, each with templates and completion tracking.

Goals & Targets

Net-zero and diversity goals with trajectory modelling and SBTi linking.

Supply Chain ESG

Vendor ESG scoring with risk-tier classification, linked to vendor management.

ESG Reports

Framework-specific AI reports for CDP, CSRD, GRI, ISSB, SASB, TCFD and the SDGs.

ESG Guides

Step-by-step guidance through each disclosure regime.

Business Continuity

2 pages · ISO 22301 aligned

Learn more

BCP Management

Business impact analysis with RTO, RPO and MTPD, 13 threat scenarios, recovery strategies, crisis teams, communication plans, exercises and live activations — rolled into a BC readiness score.

Critical Assets

The asset register that recovery objectives and dependency mapping are built on.

vCISO Premium

14 surfaces · a per-company security intelligence service

Learn more

Copilot

A tenant-fenced conversational analyst that answers on your estate, vendors, exposure and forecasts — and only yours.

Estate Register & Security

Declare your technology estate once; it is matched to the live CVE/KEV corpus per system, with KEV and critical alerting.

Threat Radar & Forecasts

Live CVE, KEV and campaign intelligence with a ‘hits your estate’ lens, plus estate-specific forward attack chains shipping detection signals for your SOC.

Briefings, News & Adversaries

A per-company daily brief synthesised through your estate and vendor watchlist, with 583 adversary profiles linked from your threats.

Geo Risk & Regulatory

207 countries scored on the STEMPLES-Plus model, plus regulatory deadlines and horizon-scanning for your declared jurisdictions.

Horizon Briefs & Action Queue

Strategic risk matrix and trajectory, with estate CVEs, deadlines and intelligence signals as one prioritised action list.

Change Management

5 pages · governed change with approvals

Learn more

Change Dashboard

Volume, risk and approval status across the change pipeline.

Change Register

Every proposed change with its risk assessment and affected assets.

My Approvals

Your queue — what is waiting on you, with the context to decide.

Change Calendar

Scheduled changes in one view, so collisions are visible before they happen.

Settings

Approval routing and thresholds configured to your governance model.

ISO & Training

3 pages · 29 courses, 337 modules, 723 templates

Learn more

AI ISO Documents

723 templates generated with live streaming from your own platform data, with branded DOCX export and version history.

ISO Training

29 interactive courses across 337 modules, with quizzes, certificates and auditor-checkable verification codes.

ISO & Security Guides

Step-by-step completion guides from first assessment through to certification.

Workspace & Administration

The day-to-day layer, and the controls underneath it

Learn more

Dashboard, Calendar & Tasks

Where the work actually lands each morning, across every module.

Document Library

Version-controlled storage that control evidence links directly to.

Help Centre & Chatbot

An always-on compliance assistant answering clause-level questions across all 29 standards.

Cloud Monitoring

Cloud posture visibility for risk and compliance users, not just admins.

Integrations

Connect the systems your evidence already lives in.

Audit Log

Field-level change history across the platform — actor, timestamp, before and after.

Admin & SAML SSO

Role-based access control, SAML 2.0 SSO against any conforming identity provider, and TOTP two-factor.

User Reassignment

Hand ownership over cleanly when people move on, so a departure never orphans a risk.

Risk Escalation

Escalation levels and sign-off authority configured to your governance model.

Bring your requirements list.

We will walk it line by line against the actual product.