Features

Everything needed to run a risk programme, and nothing that gets in the way

Asset inventory

One catalogue of everything that needs protecting, with the business context that decides what matters.

  • Hardware, cloud services, databases, applications, data stores, and suppliers
  • Criticality, data classification, and regulated scope per asset
  • Owner and business unit, so tasks route to somebody accountable
  • Repeat scans update records rather than duplicating them

Discovery and import

Bring in results from the scanner you already run, or find what is listening yourself.

  • Nessus, Tenable.sc, and Tenable.io exports
  • CSV and TSV, with column names matched against aliases rather than fixed
  • Built-in TCP discovery for instances inside your own network
  • One ingest pipeline, so every source is deduplicated and scored identically

Attack surface mapping

The routes an attacker could take from an exposed asset to something that matters.

  • Relationships between assets form a traversable graph
  • Paths scored by hop probability multiplied by target value
  • Blast radius per asset, which is the argument for segmentation
  • Assets with no route from the perimeter shown separately, because working segmentation deserves credit

Exploit-aware prioritisation

A queue ordered by what is genuinely dangerous, not by CVSS alone.

  • CISA KEV listing and ransomware association
  • EPSS exploit probability and exploit code maturity
  • Asset criticality, environment, and network exposure
  • The reasoning shown beside every score, so an analyst can disagree with it

Risk register

Inherent, residual, and target positions with an owner and a treatment decision.

  • 5x5 matrix with thresholds you configure
  • Residual calculated from the controls actually in place
  • Appetite and tolerance, so out-of-appetite risks surface on their own
  • Assessment history, so you can show a risk improving

Quantified financial risk

Exposure in money, with the distribution rather than a single misleading average.

  • Loss event frequency multiplied by a three-point magnitude estimate
  • Ten thousand simulated years, reported as mean, median, and 95th percentile
  • Itemised components: downtime, breach response, fines, legal, and churn
  • Return on investment for a proposed control

Control library

What you have implemented, how well it works, and what it costs to run.

  • Implementation status separate from measured effectiveness
  • Control testing with results and scheduled retests
  • A control that failed its last test earns no credit against risk
  • Implementation and annual operating cost, for budget conversations

Remediation workflow

Named owners, deadlines from your own policy, and reporting on whether they are met.

  • Tasks raised automatically from critical findings and treatment plans
  • SLA deadlines derived from severity and shortened for exposed assets
  • Blocked work visible rather than silently stalled
  • SLA adherence measured over a trailing ninety days

Compliance reporting

Assessed positions against the frameworks your customers and regulators ask about.

  • NIST CSF 2.0 with implementation tiers, all 106 subcategories
  • ISO/IEC 27001:2022 Annex A, all 93 controls
  • CIS Critical Security Controls v8.1
  • Map a control once and satisfy every framework it touches

Evidence library

Artefacts attached where an assessor will look for them.

  • SHA-256 content hash, so you can prove nothing was altered
  • Explicit validity windows, because old evidence proves nothing about today
  • Reusable across requirements and frameworks
  • Restricted items hidden from users who should not see them

Executive reporting

One posture score, the trend behind it, and the exposure in money.

  • Posture score that accounts for open exploitable exposure, not just the register
  • Daily snapshots, so history stays stable when records are later edited
  • Risks outside the appetite the board itself signed off
  • White-labelled board reports on Enterprise

Platform

The parts that make it usable by a real organisation.

  • Multi-tenant, with users able to belong to several organisations
  • Eight ordered roles, with time-boxed access for external auditors
  • Append-only audit trail with secret redaction
  • REST API and single sign-on on higher tiers

The fastest way to judge this is to look at it

A trial starts with a worked example organisation, so nothing is an empty screen.

× Something went wrong. Reload the page to continue.