Fifteen modules. One spine. One truth.
Not a suite of bolt-ons. One register, one permission model, one audit trail.
Why shared data matters
The asset record you create in Assets is the same record Privacy points at from a RoPA entry, that Third-Party Risk links to a vendor, and that a business impact analysis derives an RTO from. When that system is decommissioned, all four move together.
That is the practical difference between one platform and a set of separate tools. No exports, no reconciliation, and no asking which copy is the current one.
Reporting, AI and approvals
Core risk and compliance work
Operational modules
SHARED DATA REGISTER
Organization structure
GovernanceSupporting modules
- Library and Marketplace
- Administration and audit log
Module directory
Twelve modules have their own pages here. The other three, Library, Marketplace and Administration, support all of them.
- 01
Governance
The organizational structure every other module is scoped to.
- Org tree and folders
- Perimeters
- Policies
- 02
Risk Management
A live register wired to controls, treatment and the board.
- Risk assessments
- Configurable risk matrices
- Three-layer scoring
- 03
Compliance
Run every framework from one place.
- Assessments
- Applied controls
- Evidence
- 04
Continuous Control Monitoring
Evidence that refreshes itself.
- Connections
- Collection runs
- Rules
- 05
Audits
Internal, external and technical audit in one place.
- Internal audit
- External audit
- Technical audit and VAPT
- 06
Assets
The inventory the rest of the platform depends on.
- Asset inventory
- Processes as first-class objects
- Data classification
- 07
Incidents
Incident lifecycle with the regulatory clock running.
- Incident register
- Intake
- Routing rules
- 08
Business Continuity and DR
Plans that reference the same inventory everything else does.
- Business Impact Analysis
- Continuity plans
- Tabletop exercises
- 09
Privacy
Oman PDPL and GDPR operations, not a policy document.
- RoPA
- DPIA
- DSAR
- 10
Third-Party Risk
Manage the extended enterprise, without the questionnaire dying in an inbox.
- Vendor inventory
- Tiering
- Questionnaire templates
- 11
Reports
Written for the person reading them, not for the person exporting them.
- Audience templates
- Custom report builder
- Exports
- 12
AI Copilot
AI configured for each tenant, on the provider you choose. Suggestions stay subject to review.
- Ask the assistant
- Drafting
- Suggestions
Supporting modules
- 13LibraryFrameworks, reference controls, risk matrices and mapping sets that every module draws on.
- 14MarketplaceSigned, versioned content and connector packs, synced daily or installed by signed upload.
- 15AdministrationIdentity with SSO and SCIM, sixteen built-in roles, approval workflows and an immutable log of every state change.
What holds it together
Identity and access
- SAML 2.0 SSO
- OIDC
- JIT provisioning
- IdP group to role mapping
- SCIM 2.0 user and group provisioning
- MFA: authenticator app, email OTP, recovery codes
- Step-up MFA on destructive actions
- Optional IP allowlists
- Session management
- Invitations
- Sixteen built-in roles with granular folder-scoped permissions
- Segregation-of-duties rules
Automation and workflow
- Configurable approval workflow builder: Owner, Reviewers, Approvers, Attestations
- Reusable across modules
- Defaults to line-manager approval
- Unified approvals inbox with a live badge
- Tasks and issues
- Notification preferences with digests
- Per-tenant SMTP
Data and reporting
- Audience report templates
- Custom report builder
- CSV, Excel and PDF export
- OData v4 for Power BI
- REST API with tenant API tokens
- Outbound webhook subscriptions with a delivery log
- Global Cmd-K search across every module
Content and marketplace
- Preloaded library of frameworks and reference controls
- Risk matrices and mapping sets
- Policy templates and evidence templates
- Incident response playbooks
- Central Marketplace delivering Ed25519-signed, versioned content and connector packs
- Daily automatic sync on connected sites, signed manual upload for air-gapped ones
- In-app update notifications
Operations and trust
- Immutable audit log
- Tenant-scoped backups
- Tenant branding
- Guided install and onboarding wizards
- In-app software updates for on-premises
- Licence activation, online or fully offline
- Subscription and seat enforcement
The daily loop
- 01
Scope your organization
Build the org tree and define the perimeters that will be assessed.
- 02
Activate frameworks
Pick from the frameworks available in the library, and attach them to a perimeter.
- 03
Assess once
Requirement by requirement, with status, score and attached evidence.
- 04
Review mappings
Accept or reject the suggested related controls where a mapping set exists.
- 05
Treat what is above appetite
Open treatments with owners and success criteria, or formally accept.
- 06
Monitor continuously
Let connectors refresh the control evidence on a schedule.
- 07
Report to the board
The audience template is already the right shape. Nothing gets rebuilt in Excel.
See the platform on your own estate.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.