An ISMS you can
actually keep current
Track every Annex A control, run your risk register, build your Statement of Applicability, and generate the reports leadership and auditors ask for — without the spreadsheet sprawl.
All 93 controls, one register
The 2022 revision of ISO/IEC 27001, tracked control by control. Set applicability, record implementation status, attach evidence, and assign owners — the Statement of Applicability writes itself as you go.
- Implementation status per control
- Evidence attached where auditors expect it
- Owners and review dates
- Statement of Applicability, always up to date
A risk register that drives action
Log risks, score them on a 5×5 heatmap, choose a treatment — treat, tolerate, transfer or terminate — and track inherent score down to residual. Risks connect to the controls that mitigate them and the findings that prove they're real.
- Likelihood × impact scoring, inherent and residual
- Treatment plans with owners and dates
- Linked to controls and test findings both ways
- Board-ready risk posture at a glance
Seeded, not blank
A new workspace isn't an empty page. Your policies, assets and suppliers arrive scaffolded from the standard, so day one is editing rather than staring.
Policy library
Ten policies drafted against Annex A — information security, acceptable use, access control, classification, cryptography, supplier security, incident management, continuity, POPIA and secure development — each with an owner, a version, an approval status and a review date.
A.5.1Asset register
Your inventory of information and associated assets, classified public through restricted, rated for criticality, with an owner and custodian and a link to the controls that protect each one.
A.5.9Supplier register
Third parties tracked by the data they touch, their risk rating, whether a DPA is in place and when the next review falls due — the questions an auditor asks about outsourcing.
A.5.19–A.5.23Awareness training
Induction, phishing, POPIA, acceptable use and incident reporting — who has completed what, when, and when it renews.
A.6.3Compliance calendar
Everything with a date on it in one place: control reviews, policy reviews, supplier reviews, training renewals, internal audits and management reviews.
cadenceFindings & corrective actions
Nonconformities and improvement opportunities with severity, owner, root cause, corrective action and closure — the clause 10 machinery, tracked.
clause 10Audits & management reviews
The internal audit programme and the management review record, kept where the evidence already lives.
clause 9.2 / 9.3Getting started checklist
A guided path from empty workspace to audit-ready that ticks itself off as you go, so you always know the next useful thing to do.
onboardingAudit trail
An immutable log of who changed what and when, across every register — including everything the AI operator did during a test.
A.8.15Reports and trust, on demand
Written for the room they're read in
The same data, told six ways — board, IT, engineering, implementer, auditor and investigator.
- Board report — posture, risk and progress, no jargon
- IT & software reports — controls, gaps and owners, split by who fixes them
- Implementer queue — what to do next, in priority order
- Auditor pack & forensics — evidence with integrity hashes, assembled
Show customers you're serious
A shareable, read-only view of your security posture — so answering a customer's security questionnaire stops being a fire drill.
- Public Trust Center page, white-labelled on Scale
- Security questionnaires auto-answered from your ISMS
- POPIA alignment tracked alongside ISO 27001
- Framework crosswalk to SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR
Verified beats self-attested
Connect Microsoft 365, Google Workspace or Entra ID and evidence arrives from the system that enforces the control, marked verified and carrying a 90-day expiry so it can't quietly rot. Everything uploaded is SHA-256 hashed on capture.
- Verified and self-attested evidence never blur together
- Integrity hash on every artefact, visible in the auditor view
- Expiring evidence surfaces as a gap, not a silent pass
- Findings from your pen tests land as evidence automatically