Everything in
the platform
Most of what we've built never makes it onto a feature list. This is the whole thing — the registers you run day to day, the reports that come out of them, and the testing and trust signals that turn all of it into something a customer will accept.
The management system
ismsGetting started
A guided checklist that walks a new tenant from empty workspace to audit-ready, ticking itself off as you complete each step.
onboardingRisk register
The spine. A 5×5 inherent-risk heatmap, treat / tolerate / transfer / terminate decisions, inherent → residual scoring, and every risk mapped to the controls that treat it.
clause 6.1Control register
All 93 Annex A controls, filterable, each with review cadence, the risks it treats and its crosswalk to other frameworks.
annex aStatement of Applicability
The certification artefact, generated live from control state. Print to PDF or export CSV — never rewritten by hand.
clause 6.1.3Policy library
Ten policies scaffolded from the standard — acceptable use, access control, classification, cryptography, supplier security, incident management, continuity, POPIA, secure development — with owners, versions, approval status and review dates.
A.5.1Asset register
The inventory of information and associated assets, classified public → restricted, rated for criticality, with an owner and a custodian, each linked to the controls that protect it.
A.5.9Supplier register
Third parties tracked by the data they touch, their risk rating, whether a DPA is in place, and when their review falls due.
A.5.19–A.5.23Awareness training
Who has completed which module, when, and when it's next due — induction, phishing, POPIA, acceptable use, incident reporting. Overdue records surface on the calendar.
A.6.3Operating it
day to dayCompliance calendar
Every obligation with a date on it in one view — control reviews, policy reviews, supplier reviews, training renewals, audits and management reviews.
cadenceFindings & corrective actions
Nonconformities and opportunities for improvement with severity, owner, root cause, corrective action and closure tracking.
clause 10Audits & management reviews
The internal audit programme and the management review record — the clause 9 machinery auditors check first.
clause 9.2 / 9.3Evidence with integrity hashes
Every uploaded file is SHA-256 hashed on capture, so the auditor and forensics views carry a verifiable integrity record rather than a folder of screenshots.
chain of custodyIntegrations
Connect Microsoft 365, Google Workspace or Entra ID and evidence moves from self-attested to independently verified — with a 90-day expiry so it can't go quietly stale.
verified evidenceAudit trail
An immutable log of who changed what and when, across every register — including everything the AI operator did during a test.
A.8.15Reports & views
six lensesBoard report
A plain-language executive one-pager: readiness, trend, top business risks, framework coverage, assurance status. Prints straight into the board pack.
execIT report
The A.8 technical surface by domain — identity, logging, backup, vulnerability, malware, network — with verified evidence and open technical actions.
opsSoftware report
The secure-SDLC controls engineering actually owns, dev-facing questionnaire answers, and engineering findings.
engineeringImplementer queue
A prioritised work list: not-started controls, reviews falling due, open findings by date, risks still needing treatment.
do this nextAuditor pack
An assessor's read-only view — scope, readiness, an evidence sample with hashes, the audit programme, nonconformities and management reviews. Prints as a pack.
assuranceForensics
An investigator's view: searchable activity timeline, evidence chain-of-custody register with SHA-256 hashes, and the incident-response and logging controls behind it.
incidentOffensive testing, connected
penetration testingAI-guided testing
Bounded, skill-driven testing against a scope you sign, with a full transcript of every action taken — including the ones the scope guard blocked.
validatedExpert-run, not unattended
The automation covers ground; a qualified security tester scopes the work, monitors the run as it happens, triages what comes back and signs the report.
supervisedApproval-gated actions
Nothing intrusive runs until a person approves it, and deny-by-default is the shipped behaviour rather than a setting you have to find.
human in the loopFindings become evidence
Every validated issue lands against the Annex A control it breaks, with proof attached — and a clean pass is recorded as evidence toward that control.
closed loopSigned reporting
Reports are reviewed and signed by a person before they reach you, with severity, proof and remediation per finding.
human sign-offTurning compliance into sales
signalTrust Center
A public, login-free posture page you can send to a prospect mid-deal — on your own subdomain on Scale.
publicQuestionnaire auto-answer
Vendor security questionnaires answered from live control state instead of a spreadsheet someone filled in last year.
sales unblockFramework crosswalk
One control set mapped onto POPIA, SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR. Comply once, satisfy many.
5 frameworksScore history
A monthly readiness time series, so "we're improving" is a line on a chart rather than a claim.
trendYour account
adminTeam & roles
Role-based access with email invites — owner, member, and a read-only external auditor role that sees the pack and nothing else.
rbacPlans & billing
Rand plans billed monthly, with self-serve upgrade, downgrade, cancel and resume. VAT receipts emailed automatically.
self-serveWeekly compliance digest
An email summarising what's due, what slipped and what changed — so the ISMS nudges you instead of waiting to be opened.
stay currentSupport & status
In-app support requests that reach our team and acknowledge you straight away, plus a public status page.
A.5.24Refer & earn
Refer another company and credit is applied to your next charge the moment they upgrade, with a record showing exactly why your bill went down.
creditYour data, yours
Export the Statement of Applicability, the auditor pack and your registers whenever you want. Nothing is held hostage by a subscription.
exportOne deliberate exception. The compliance platform is fully self-serve — sign up, verify, and you land in a seeded ISMS without talking to anyone. Penetration testing deliberately isn't: every test is scoped, monitored and signed off by one of our security testers, with an approval gate on anything active. A report reaching you unreviewed is a liability, so that split is on purpose.