Platform Pillars Governance & Compliance
Pillar 05 · Governance & Compliance

Audit prep stops
being a project.

Policy and control mapping, evidence collection, posture dashboards. PCI, ISO 27001, NIST and ASD Essential 8 — out of the box.

Log Detection Intel Vuln Gov
One data
model
What it is

Controls are evidenced continuously.

Not once a year. Audit prep becomes a report you generate — not a project you run.

What it does

Four layers, working together.

01

Pre-built framework templates

PCI DSS, ISO 27001:2022, NIST CSF, ASD Essential 8 — controls mapped, evidence requirements defined, ready to apply.

  • PCI DSS
  • ISO 27001:2022
  • NIST CSF
  • ASD Essential 8
02

Continuous evidence collection

Evidence streams from the same data the SOC uses. Logs, configurations, alerts — automatically attached to control IDs.

  • Auto-attached to controls
  • Streaming, not snapshotted
  • Evidence pack export
03

Posture dashboards

See coverage, gaps and drift per framework. One page, board-ready. One pivot to the underlying evidence.

  • Per-framework dashboards
  • Coverage + gap + drift
  • Board-ready exports
04

Multi-framework mapping

One control evidences against multiple frameworks. Don't evidence the same thing four times.

  • Many-to-many mapping
  • Avoid duplicate evidence work
  • Custom frameworks supported
How it works

The pipeline, end to end.

1

Map

Frameworks -> controls -> evidence requirements

2

Collect

Evidence streams from existing telemetry

3

Attest

Drift flagged, gaps tracked, owners notified

4

Report

Board pack, auditor pack, regulator response

Cross-cutting · AI Governance

Govern your AI use — ISO 42001, EU AI Act, NIST AI RMF.

AI governance is a first-class framework. Model inventory, AI-specific evidence collection, board-ready AI risk reporting.

See AI Security & Governance →
Who it's for

Made for the team you actually have.

GRC teams

Stop evidencing the same control four times. Map once, attest continuously, export to whichever framework the auditor wants.

Internal audit

Get evidence that's tied to the source — not a screenshot in a spreadsheet. Drift is visible the day it happens, not the quarter it gets reviewed.

CISOs & boards

Show posture as a number, mapped to the framework the regulator cares about. Sourced from analyst data.

One platform

How it works with the other pillars.

Governance isn't a separate tool. It works on the same data as everything else.

Be audit-ready, not audit-prepped.

Pilot includes one governance framework loaded — see what evidence appears automatically.

Run a pilot Talk to a GRC lead