Supplier register
Legal entity, hosting, classification and representatives with every linked artefact in one file.
Supplier assurance and agreements, ISMS projects and change control, incidents, identity governance, backup and disaster recovery, XDR log intelligence and threat hunting, registers and board reporting — every module sharing one 3×3 risk methodology and one audit trail.
Single risk methodology across suppliers, projects and exceptions
Controls mapped to policies, evidence and supplier answers
Cross-domain telemetry, detections, hunting and attack-graph investigations
Onboarding → assessment → agreements → audit
Legal entity, hosting, classification and representatives with every linked artefact in one file.
Suppliers answer the ISO 27001:2022 questionnaire without an account; evidence lands on the record.
Inherent and residual ratings on a strict likelihood × impact matrix, banded Low / Medium / High.
Template-versioned agreements, dual e-signature and a full envelope event trail.
Annual supplier audits with evidence capture, R&CC review and a PDF sign-off pack.
Provider T&Cs, DPAs, sub-processor lists and enforced data-portability exit plans.
Initiation → design → build → test → closure
Initiation → Design → Build → Testing → Deployment → Closure, gated by R&CC approvals.
AI-drafted scope of work mapped to Annex A controls, versioned and approved before build.
Extract risks from the specification, treat them, then formally accept residual risk on the matrix.
Project and BAU change requests, external token approvers and append-only implementation logs.
AI-assisted planning linked to risks and changes, with DPIA and BIA generators.
CAPAs from findings and incidents with owners, due dates, evidence and lock-on-completion.
Backups, DR, configuration, incidents & secrets
Veeam job ingestion, plan-vs-actual coverage and missing-backup alerting per server.
Runbooks, tested status and replication tracking across the Hyper-V estate.
Approved baselines, CI references, immutable revision history and MS-Info viewer.
Lifecycle, evidence, RCA, SLA clocks, regulatory notification advice and PIR generation.
Live host inventory with BitLocker posture, groups and access permissions.
AES-256-GCM secrets with per-record permissions, reveal logs and step-up MFA.
Entra ID, multi-domain AD, GPO and bulk change
User lookup, licence review, sign-in log analysis and account state management.
Mirrored users, groups, computers and OUs across multiple domains, with revisions and one-click reversion.
365 account creation, licence pools, group management and clean-down without deletion.
Live directory graph with drag-and-drop OU moves, search-to-expand and in-place user creation.
Filtered targeting, impact preview, ADSI write-back and full rollback of any bulk change.
Describe intent in plain English to draft Group Policy, or harvest and edit existing GPOs via the agent.
24 prebuilt reports including lockout analysis, licence usage and sign-in risk.
Telemetry → detection → hunting → response → investigation
Windows event telemetry from HMAC-signed agents, agent health and host risk scoring across the estate.
Normalised events with fast filtering over millions of rows, backed by daily rollups for instant dashboards.
MITRE-mapped detections with underlying command evidence, one-click bulk remediation and suppression.
Entra sign-ins and directory audits, Cato network telemetry and endpoint feeds ingested every five minutes.
Automated containment with a blast-radius guard that blocks privileged accounts, Tier 0 OUs and servers.
Indicator management with scheduled sweeps and tracked hunt outcomes.
Per-entity baselines with z-score anomaly scoring, nightly rebuilds and first-seen flags.
Interactive cross-domain graph, attack timeline, AI assessment and STIX 2.1 export.
Auto-seeded live cases, continuous re-correlation, SLA/MTTR metrics and a MITRE heatmap.
Threat feeds, network, service desk and assets
Approved external feeds, acknowledgement tracking and recommended policy wording changes.
Clustered, source-credibility-weighted stories feeding straight into BIA reporting.
Live GraphQL metrics for sites, throughput and security events with automated report generation.
InvGate service-desk ingestion with volume, category and resolution trend analysis.
Asset lookup with automated end-of-life tracking against suppliers and projects.
Device approval portal with compliance audits, plus enterprise app credential lifecycle and alerting.
Policies, legal, permits, competency, reporting
Versioned library with acknowledgement tracking and Annex A control satisfaction references.
Obligation tracking with refresh hooks and evidence linked per requirement.
Sequential refs, project linkage and approver sign-off.
Skills matrix with current vs target levels, evidence and immutable history.
Annex A 8.24 certificate and key inventory with 90/60/30-day expiry alerting and exceptions.
Unified registers, PDF/DOCX board pack and a downloadable platform manual.
Access control, workflow, search and agents
SAML SSO, group RBAC, attribute rules, segregation-of-duties matrix and step-up MFA.
Low-code multi-stage approvals with reminders, escalations, SLAs and conditional routing.
One ⌘K bar with natural-language querying across risks, controls, assets, suppliers, audits, policies, incidents and actions.
Pin any module as an interactive live widget for one-click access.
Guided delivery workflow where each topic is closed out by explicit acceptance.
MCP server, interactive Teams approvals, on-prem AD/GPO/XDR agents and scheduled sync jobs.
Every risk — supplier, project, exception or incident — is scored on the same 3×3 likelihood × impact matrix and banded Low / Medium / High. No "Critical" tier, no 5-point scales, no reconciliation between registers at audit time.
R&CC approval gates on ISMS stages, DPIAs and change requests. Append-only implementation evidence, immutable audit events, template-version locking on issued agreements, and a board pack export covering KPIs, open risks and exceptions.
Sign in to the platform