Test like an attacker.
Report like an auditor.
Xee Security runs AI-guided offensive tests against your systems, then turns every finding into evidence your ISO/IEC 27001 auditor will accept. Two disciplines that usually live in separate tools — in one place.
Security is only real
when you can prove it.
A clean scan report and a folder of policies aren't proof. Xee Security connects the test that finds a weakness to the control that should have stopped it — so what you claim and what's true are the same thing.
One platform, two jobs it does properly
Most teams buy a scanner from one vendor and a compliance spreadsheet from another, then spend weeks stitching them together by hand. Xee Security does both, and keeps them connected.
Find what an attacker would
Scoped, authorised testing that behaves like a real adversary — accelerated by an AI operator that reasons about your surface instead of running a fixed checklist, and supervised throughout by a qualified tester.
- Reconnaissance & probing across your authorised hosts
- AI-validated findings — each one confirmed, not just flagged
- Run and monitored by our security testers, start to finish
- Approval-gated actions so nothing risky runs unattended
- Findings become evidence against the control they break, automatically
Prove it to the auditor
A working ISO/IEC 27001:2022 information security management system — not a template. Findings flow straight in as evidence against the controls they affect.
- Risk & control registers with a live Statement of Applicability
- Policies, assets, suppliers and training seeded from the standard
- Six report lenses — board, IT, developer, implementer, auditor, forensics
- Trust Center to share your posture with customers
Rather more than a control checklist
The registers are the start. What makes an ISMS survive contact with a real year is everything that keeps it current — and everything that turns it back into revenue.
Risk register
A 5×5 heatmap, treatment decisions, inherent → residual scoring, and every risk tied to the controls that treat it.
the spinePolicy library
Ten policies scaffolded from the standard, with owners, versions, approval status and review dates.
A.5.1Asset register
Information and assets classified, rated, owned — and linked to the controls protecting them.
A.5.9Supplier register
Third parties tracked by data touched, risk rating, DPA status and review cadence.
A.5.19–23Awareness training
Who has done which module, when, and when it's next due. Overdue records land on the calendar.
A.6.3Compliance calendar
Every dated obligation in one view — control, policy and supplier reviews, training, audits.
cadenceFindings & audits
Nonconformities with root cause and corrective action, the internal audit programme, management reviews.
clause 9–10Verified evidence
Connect M365, Google Workspace or Entra ID and evidence moves from self-attested to verified — with a 90-day expiry.
integrationsForensics & chain of custody
SHA-256 on every artefact, a searchable timeline, and the incident controls behind it.
worst dayEveryone gets the version
they can act on
Board report
Readiness, trend, top business risks and assurance status — in plain language, printed into the pack.
IT report
The A.8 technical surface by domain: identity, logging, backup, vulnerability, malware, network.
Software report
Only the secure-SDLC controls development owns, plus the findings that belong to them.
Work queue
What to do next, ordered by what moves readiness furthest this week.
Auditor pack
Scope, evidence sample with hashes, audit programme, nonconformities, management reviews.
Forensics
Activity timeline and chain-of-custody register, built before the incident rather than during it.
The part that pays for itself
Security review is where deals stall. A public Trust Center and questionnaires auto-answered from live control state turn your ISMS from a cost centre into the thing that unblocks the contract.
- Public Trust Center — no login, always current, your own subdomain on Scale
- Vendor questionnaires answered from the control register, with citations
- One control set mapped to POPIA, SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR
- Score history, so "we're improving" is a line on a chart
Bring clients, earn every month
Refer or resell Xee and earn 20–30% recurring commission for as long as your customer stays — free to join, no targets.
- Recurring, not once-off
- Volume tiers that lift your whole book
- A referral link and code of your own
- Paid out monthly
Verified beats self-attested
Connect Microsoft 365, Google Workspace or Entra ID and evidence arrives from the system that enforces the control — hashed on capture, and expiring after 90 days so it can't quietly rot.
- SHA-256 integrity hash on every artefact
- Verified and self-attested never blur together
- Expiring evidence surfaces as a gap
- Your pen-test findings land here too
Built for the work, not the demo
Penetration testing
Authorised, AI-guided and expert-supervised, with a full report, remediation guidance and a re-scan.
ISO 27001 workspace
All 93 Annex A controls, a live Statement of Applicability, and evidence in one place.
Framework crosswalk
Comply once, satisfy many — POPIA, SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR from one control set.
Reporting
Board, IT, developer, implementer, auditor and forensics views from the same source of truth.
Verified evidence
Evidence pulled from the systems that enforce your controls, hashed on capture and never left to go stale.
Trust Center
A shareable posture page and questionnaire answers, so security reviews stop being a scramble.