Service Catalog
One control library, one evidence system, one risk register, one AI CISO. Each service below is a different way in for a different problem, buyer and moment: a privacy question, a security questionnaire, an insurance renewal, a product launch in the EU. The platform does not change; the door does.
7 services
Cyber Insurance Readiness
Renewal arrives with a longer application, higher premium, a lower limit and exclusions nobody read. The controls underwriters ask about are specific and evidence-based: MFA…
Free Free check
Fraud, Identity & Account Takeover Readiness
Account takeover, payment fraud and synthetic identity are security problems that show up as customer-support tickets, chargebacks and churn long before anyone calls them an…
Free Fraud & Account Takeover Readiness Check
Fractional CISO
The company needs executive security leadership and cannot justify or find a full-time CISO.
Free Free check
Interim CISO
A CISO departure, crisis or transition has left security leadership vacant.
Free Free check
Cyber Risk Advisory
Risk is discussed in adjectives; the board wants a prioritised, quantified picture.
Free Free check
Supply Chain & Third-Party Risk Management
Vendors hold your data and your uptime; tiering, assessment and findings are ad hoc.
Free Free check
Ransomware Readiness Assessment
Readiness to prevent, detect, respond to and recover from ransomware.
Free Free check
2 services
EU Cybersecurity & NIS2 Readiness
NIS2 widened EU cybersecurity law to eighteen sectors and made management personally accountable, but whether it reaches a specific company depends on entity type, sector, size,…
Compliance & Program Leadership
SOC 2, ISO 27001, HIPAA or PCI is required and nobody owns getting there.
Free Free check
4 services
EU AI Act Readiness
The EU AI Act applies in phases: prohibited practices and AI literacy from 2 February 2025, general-purpose AI obligations from 2 August 2025, most high-risk system obligations…
Free Free check
AI Security Readiness
AI systems introduce trust boundaries the security programme never modelled: user to application, application to model, model to retrieval store, model to tools, and tools to…
Free AI Security Quick Check
AI Agent Security Readiness
Agents act. They hold credentials, call tools, read untrusted content and take actions that used to need a person. Identity, least-privilege tool authorisation, injection…
Free AI Agent Security Quick Check
AI Governance
AI is in use across the company with no inventory, policy or oversight.
Free Free check
4 services
Crypto & Digital Asset Regulatory Readiness
Which U.S. and EU digital-asset regimes MAY apply, what applies today versus what is coming, and the open legal questions. A readiness indicator, never a legal determination.
Free Free check
DORA Readiness (Digital Operational Resilience)
DORA has applied to EU financial entities since 17 January 2025, and it reaches the ICT providers that serve them through contract. Supervisors expect an ICT risk framework,…
Financial Institution Cybersecurity Readiness Review
NCUA and FFIEC examination readiness for banks and credit unions.
Free Free check
GLBA Safeguards Compliance
FTC Safeguards Rule, 16 CFR Part 314.
Free Free check
3 services
Secure SDLC & Product Security Readiness
Enterprise customers, federal buyers and now EU product regulation expect proof that the software you ship was built securely: threat models, code review, dependency control,…
Free Secure SDLC Quick Check
Software Supply Chain Security & SBOM Readiness
A customer asks for an SBOM, a regulator asks how you would know if a component you ship carried a known exploited vulnerability, and the honest answer is a package manifest and…
Free Free check
EU Cyber Resilience Act Readiness
The Cyber Resilience Act puts cybersecurity obligations on products with digital elements sold in the EU: secure-by-design requirements, vulnerability handling, an SBOM, and…
Free Cyber Resilience Act Quick Check
2 services
Operational Resilience Program
Business continuity, disaster recovery, third-party dependency, cyber incident response and crisis management are usually five plans owned by four teams. Operational resilience…
Free Operational Resilience Quick Check
Business Resilience (BCP / DR)
Business continuity and disaster recovery, assessed separately and never merged.
Free Free check
3 services
Enterprise Security Readiness & Questionnaire Response
Enterprise deals stall in security review. The questionnaire arrives with 300 questions, three people answer it from memory over two weeks, the answers contradict last quarter's,…
Free Enterprise Security Readiness Check
Trust Center Readiness
A trust page that lists an expired certificate, a claim nobody can evidence or a policy that legal never approved is worse than no trust page. Buyers check. The discipline is…
Free Trust Center Readiness Check
Executive & Board Advisory
The board needs reporting it can act on and oversight it can evidence.
Free Free check
What every service runs on
These are not sold separately. They are the reasons a finding in one service counts everywhere else.
Control Crosswalk Engine
One control satisfies requirements in many frameworks; evidence attaches to the control, not the framework. The engine keeps that true across everything in the library.
Regulatory Applicability Engine
Which regulations MAY apply, why, with what confidence, and what would change the answer. Deterministic rules over the client profile; every determination carries its evidence and its conditions.
Automated Regulatory Change Management
Regulations change. The engine detects a change, identifies affected requirements, controls and clients, recalculates applicability and readiness, alerts the owners, and publishes a new framework version while…
Bundles by buyer and moment
Startup Security Foundation
Customers are starting to ask, and there is no programme to point to.
Companies building their first security programme · Foundation
Fractional CISO · Cyber risk · Enterprise readiness · Cyber insurance · Secure SDLC · Ransomware
SaaS Enterprise Readiness
Enterprise procurement is slowing every deal.
B2B SaaS moving upmarket · Enterprise Growth
Enterprise readiness · Compliance leadership · Trust Center · Secure SDLC · Supply chain & SBOM · Privacy readiness · Third-party risk
Healthcare Security
HIPAA, ransomware and business continuity are one exposure.
Providers, payers and health-tech · Regulated Industry
Compliance leadership · Ransomware · BCP / DR · Privacy readiness · Cyber insurance · Operational resilience
Fintech Security
Bank partners, regulators and fraud all arrive at once.
Payments, lending, banking-as-a-service and their partners · Regulated Industry
FI readiness · GLBA Safeguards · Fraud & ATO · DORA · Privacy readiness · Cyber insurance · Third-party risk · BCP / DR · Operational resilience
Crypto / Digital Asset
Several regulators, two continents, and the rules are still moving.
Exchanges, custodians, issuers, wallet providers · Regulated Industry
AI Company
Governance, security, the EU AI Act and agent risk have no owner.
Companies building or deploying AI products · AI Governance
AI governance · AI security · EU AI Act · AI agent security · Secure SDLC · Supply chain & SBOM
EU Expansion
GDPR, NIS2, DORA, the AI Act and the CRA reach different parts of the business on different dates.
Companies entering or growing in the EU · Compliance
Privacy readiness · NIS2 · DORA · EU AI Act · Cyber Resilience Act · Supply chain & SBOM
Enterprise Sales Accelerator
Security review is the longest step in the sales cycle.
Sales-led companies losing time in security review · Enterprise Growth
This assessment provides a readiness indicator based on the information provided. It is not an audit, a certification, or a guarantee of security outcomes.
Not sure which door?
Thirty minutes. We ask about the problem, not the framework, and recommend one primary service with the reasoning written down.