Skip to main content
ISO 27001 · NIS2 · CIS · NIST CSF · SOC 2

Cybersecurity & IT Security Management

Manage security controls across 11 frameworks, quantify and treat risks, and monitor your entire threat surface — from the free MVSP baseline to full enterprise certification.

Active cybersecurity compliance modules — ready to use today.

Cybersecurity Controls
Community

Cybersecurity Controls (CSC)

Available

Track and manage cybersecurity controls across 11 frameworks with automated GAP analysis. ISO/IEC 21827:2008 maturity levels, visual dashboards, and task-linked evidence management — from the free MVSP baseline to full enterprise coverage.

  • MVSP, GDPR, ISO 27001, NIS2, CIS, C5, SOC 2, NIST CSF, OWASP ASVS, PCI DSS & ISO 42001
  • Automated GAP analysis per framework
  • ISO/IEC 21827:2008 maturity scoring
  • Task-linked evidence collection
Risk Management
Premium

Risk Management (Risk)

Available

Identify, assess, treat, and monitor cybersecurity risks with a structured quantitative methodology. ISO 27001 and ISO 27005 aligned — with visual risk heatmaps, a comprehensive risk register, and full audit trails.

  • Quantitative risk likelihood × impact scoring
  • Risk register with treatment tracking
  • Visual risk heatmap dashboard
  • ISO 27001 & ISO 27005 methodology
Asset Inventory
Ultimate

Asset Inventory (Assets)

Available

Discover, enroll, and continuously monitor every laptop, server, VPS, and cloud instance you run. The inventory is collected from the machines themselves with osquery — so it is accurate on the day of the audit.

  • osquery agents for Windows, macOS, and Linux
  • Owner & classification assignments
  • Risk linkage per asset
  • Integration with CSC controls

Modules in development — sign up to get notified when they launch.

Coming Soon
Incident Management

Incident Management (Incidents)

Premium

Track, manage, and respond to security incidents with structured workflows, automated notifications, and comprehensive audit trails. Streamline incident response and demonstrate your incident handling capabilities to auditors.

  • Incident reporting & tracking
  • Automated workflow & notifications
  • Response templates & playbooks
  • Audit trail & evidence collection
See what's planned
Coming Soon
Vendor Assessment

Vendor Assessment (Vendors)

Ultimate

Evaluate third-party vendors with structured security and compliance questionnaires. Reduce supply chain risk with a repeatable, evidence-based vendor assessment process integrated into your compliance program.

  • Structured vendor security questionnaires
  • Risk scoring per supplier
  • Evidence storage & follow-up tracking
  • Linked to controls & risk register
See what's planned

Start building your security compliance program

The Community plan is free forever. MVSP and GDPR controls are available immediately — no credit card required.