offensive security & compliance, one platform

Test like an attacker.
Report like an auditor.

Xee Security runs AI-guided offensive tests against your systems, then turns every finding into evidence your ISO/IEC 27001 auditor will accept. Two disciplines that usually live in separate tools — in one place.

ISO/IEC 27001:2022 POPIA-aligned Rand pricing · PayFast

Security is only real
when you can prove it.

A clean scan report and a folder of policies aren't proof. Xee Security connects the test that finds a weakness to the control that should have stopped it — so what you claim and what's true are the same thing.

93
Annex A controls tracked end to end
6
report lenses over one dataset
5
frameworks from a single control set
R0
start free, upgrade when you're ready
two disciplines, one platform

One platform, two jobs it does properly

Most teams buy a scanner from one vendor and a compliance spreadsheet from another, then spend weeks stitching them together by hand. Xee Security does both, and keeps them connected.

offense

Find what an attacker would

Scoped, authorised testing that behaves like a real adversary — accelerated by an AI operator that reasons about your surface instead of running a fixed checklist, and supervised throughout by a qualified tester.

  • Reconnaissance & probing across your authorised hosts
  • AI-validated findings — each one confirmed, not just flagged
  • Run and monitored by our security testers, start to finish
  • Approval-gated actions so nothing risky runs unattended
  • Findings become evidence against the control they break, automatically

How the engine is bounded →

compliance

Prove it to the auditor

A working ISO/IEC 27001:2022 information security management system — not a template. Findings flow straight in as evidence against the controls they affect.

  • Risk & control registers with a live Statement of Applicability
  • Policies, assets, suppliers and training seeded from the standard
  • Six report lenses — board, IT, developer, implementer, auditor, forensics
  • Trust Center to share your posture with customers

Inside the ISMS →

the whole thing

Rather more than a control checklist

The registers are the start. What makes an ISMS survive contact with a real year is everything that keeps it current — and everything that turns it back into revenue.

Risk register

A 5×5 heatmap, treatment decisions, inherent → residual scoring, and every risk tied to the controls that treat it.

the spine

Policy library

Ten policies scaffolded from the standard, with owners, versions, approval status and review dates.

A.5.1

Asset register

Information and assets classified, rated, owned — and linked to the controls protecting them.

A.5.9

Supplier register

Third parties tracked by data touched, risk rating, DPA status and review cadence.

A.5.19–23

Awareness training

Who has done which module, when, and when it's next due. Overdue records land on the calendar.

A.6.3

Compliance calendar

Every dated obligation in one view — control, policy and supplier reviews, training, audits.

cadence

Findings & audits

Nonconformities with root cause and corrective action, the internal audit programme, management reviews.

clause 9–10

Verified evidence

Connect M365, Google Workspace or Entra ID and evidence moves from self-attested to verified — with a 90-day expiry.

integrations

Forensics & chain of custody

SHA-256 on every artefact, a searchable timeline, and the incident controls behind it.

worst day

See all 30+ modules

one dataset, six readers

Everyone gets the version
they can act on

board

Board report

Readiness, trend, top business risks and assurance status — in plain language, printed into the pack.

it

IT report

The A.8 technical surface by domain: identity, logging, backup, vulnerability, malware, network.

engineering

Software report

Only the secure-SDLC controls development owns, plus the findings that belong to them.

implementer

Work queue

What to do next, ordered by what moves readiness furthest this week.

auditor

Auditor pack

Scope, evidence sample with hashes, audit programme, nonconformities, management reviews.

investigator

Forensics

Activity timeline and chain-of-custody register, built before the incident rather than during it.

Compare the six lenses

compliance as revenue

The part that pays for itself

Security review is where deals stall. A public Trust Center and questionnaires auto-answered from live control state turn your ISMS from a cost centre into the thing that unblocks the contract.

  • Public Trust Center — no login, always current, your own subdomain on Scale
  • Vendor questionnaires answered from the control register, with citations
  • One control set mapped to POPIA, SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR
  • Score history, so "we're improving" is a line on a chart

See the Trust Center

trust.yourcompany.co.zapublic
ISO/IEC 27001:2022 readiness87%
POPIA alignmenttracked
Last penetration testJul 2026
Open major nonconformities0
Questionnaire turnaroundsame day
for consultants & MSPs

Bring clients, earn every month

Refer or resell Xee and earn 20–30% recurring commission for as long as your customer stays — free to join, no targets.

  • Recurring, not once-off
  • Volume tiers that lift your whole book
  • A referral link and code of your own
  • Paid out monthly

Partner programme →

evidence

Verified beats self-attested

Connect Microsoft 365, Google Workspace or Entra ID and evidence arrives from the system that enforces the control — hashed on capture, and expiring after 90 days so it can't quietly rot.

  • SHA-256 integrity hash on every artefact
  • Verified and self-attested never blur together
  • Expiring evidence surfaces as a gap
  • Your pen-test findings land here too

How evidence gets in →

what you get

Built for the work, not the demo

01

Penetration testing

Authorised, AI-guided and expert-supervised, with a full report, remediation guidance and a re-scan.

02

ISO 27001 workspace

All 93 Annex A controls, a live Statement of Applicability, and evidence in one place.

03

Framework crosswalk

Comply once, satisfy many — POPIA, SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR from one control set.

04

Reporting

Board, IT, developer, implementer, auditor and forensics views from the same source of truth.

05

Verified evidence

Evidence pulled from the systems that enforce your controls, hashed on capture and never left to go stale.

06

Trust Center

A shareable posture page and questionnaire answers, so security reviews stop being a scramble.

See your systems the way an attacker does.
Then prove they're locked down.