one platform · thirty-plus modules

Everything in
the platform

Most of what we've built never makes it onto a feature list. This is the whole thing — the registers you run day to day, the reports that come out of them, and the testing and trust signals that turn all of it into something a customer will accept.

93
Annex A controls, seeded on day one
10
policies drafted from the standard's scaffold
6
report lenses over the same data
5
frameworks crosswalked from one control set

The management system

isms

Getting started

A guided checklist that walks a new tenant from empty workspace to audit-ready, ticking itself off as you complete each step.

onboarding

Risk register

The spine. A 5×5 inherent-risk heatmap, treat / tolerate / transfer / terminate decisions, inherent → residual scoring, and every risk mapped to the controls that treat it.

clause 6.1

Control register

All 93 Annex A controls, filterable, each with review cadence, the risks it treats and its crosswalk to other frameworks.

annex a

Statement of Applicability

The certification artefact, generated live from control state. Print to PDF or export CSV — never rewritten by hand.

clause 6.1.3

Policy library

Ten policies scaffolded from the standard — acceptable use, access control, classification, cryptography, supplier security, incident management, continuity, POPIA, secure development — with owners, versions, approval status and review dates.

A.5.1

Asset register

The inventory of information and associated assets, classified public → restricted, rated for criticality, with an owner and a custodian, each linked to the controls that protect it.

A.5.9

Supplier register

Third parties tracked by the data they touch, their risk rating, whether a DPA is in place, and when their review falls due.

A.5.19–A.5.23

Awareness training

Who has completed which module, when, and when it's next due — induction, phishing, POPIA, acceptable use, incident reporting. Overdue records surface on the calendar.

A.6.3

Operating it

day to day

Compliance calendar

Every obligation with a date on it in one view — control reviews, policy reviews, supplier reviews, training renewals, audits and management reviews.

cadence

Findings & corrective actions

Nonconformities and opportunities for improvement with severity, owner, root cause, corrective action and closure tracking.

clause 10

Audits & management reviews

The internal audit programme and the management review record — the clause 9 machinery auditors check first.

clause 9.2 / 9.3

Evidence with integrity hashes

Every uploaded file is SHA-256 hashed on capture, so the auditor and forensics views carry a verifiable integrity record rather than a folder of screenshots.

chain of custody

Integrations

Connect Microsoft 365, Google Workspace or Entra ID and evidence moves from self-attested to independently verified — with a 90-day expiry so it can't go quietly stale.

verified evidence

Audit trail

An immutable log of who changed what and when, across every register — including everything the AI operator did during a test.

A.8.15

Reports & views

six lenses

Board report

A plain-language executive one-pager: readiness, trend, top business risks, framework coverage, assurance status. Prints straight into the board pack.

exec

IT report

The A.8 technical surface by domain — identity, logging, backup, vulnerability, malware, network — with verified evidence and open technical actions.

ops

Software report

The secure-SDLC controls engineering actually owns, dev-facing questionnaire answers, and engineering findings.

engineering

Implementer queue

A prioritised work list: not-started controls, reviews falling due, open findings by date, risks still needing treatment.

do this next

Auditor pack

An assessor's read-only view — scope, readiness, an evidence sample with hashes, the audit programme, nonconformities and management reviews. Prints as a pack.

assurance

Forensics

An investigator's view: searchable activity timeline, evidence chain-of-custody register with SHA-256 hashes, and the incident-response and logging controls behind it.

incident

See how the six lenses differ →

Offensive testing, connected

penetration testing

AI-guided testing

Bounded, skill-driven testing against a scope you sign, with a full transcript of every action taken — including the ones the scope guard blocked.

validated

Expert-run, not unattended

The automation covers ground; a qualified security tester scopes the work, monitors the run as it happens, triages what comes back and signs the report.

supervised

Approval-gated actions

Nothing intrusive runs until a person approves it, and deny-by-default is the shipped behaviour rather than a setting you have to find.

human in the loop

Findings become evidence

Every validated issue lands against the Annex A control it breaks, with proof attached — and a clean pass is recorded as evidence toward that control.

closed loop

Signed reporting

Reports are reviewed and signed by a person before they reach you, with severity, proof and remediation per finding.

human sign-off

How a penetration test runs →

Turning compliance into sales

signal

Trust Center

A public, login-free posture page you can send to a prospect mid-deal — on your own subdomain on Scale.

public

Questionnaire auto-answer

Vendor security questionnaires answered from live control state instead of a spreadsheet someone filled in last year.

sales unblock

Framework crosswalk

One control set mapped onto POPIA, SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR. Comply once, satisfy many.

5 frameworks

Score history

A monthly readiness time series, so "we're improving" is a line on a chart rather than a claim.

trend

Your account

admin

Team & roles

Role-based access with email invites — owner, member, and a read-only external auditor role that sees the pack and nothing else.

rbac

Plans & billing

Rand plans billed monthly, with self-serve upgrade, downgrade, cancel and resume. VAT receipts emailed automatically.

self-serve

Weekly compliance digest

An email summarising what's due, what slipped and what changed — so the ISMS nudges you instead of waiting to be opened.

stay current

Support & status

In-app support requests that reach our team and acknowledge you straight away, plus a public status page.

A.5.24

Refer & earn

Refer another company and credit is applied to your next charge the moment they upgrade, with a record showing exactly why your bill went down.

credit

Your data, yours

Export the Statement of Applicability, the auditor pack and your registers whenever you want. Nothing is held hostage by a subscription.

export

One deliberate exception. The compliance platform is fully self-serve — sign up, verify, and you land in a seeded ISMS without talking to anyone. Penetration testing deliberately isn't: every test is scoped, monitored and signed off by one of our security testers, with an approval gate on anything active. A report reaching you unreviewed is a liability, so that split is on purpose.

Start with the free plan.
The 93 controls are already there.