Asset inventory
One catalogue of everything that needs protecting, with the business context that decides what matters.
- Hardware, cloud services, databases, applications, data stores, and suppliers
- Criticality, data classification, and regulated scope per asset
- Owner and business unit, so tasks route to somebody accountable
- Repeat scans update records rather than duplicating them
Discovery and import
Bring in results from the scanner you already run, or find what is listening yourself.
- Nessus, Tenable.sc, and Tenable.io exports
- CSV and TSV, with column names matched against aliases rather than fixed
- Built-in TCP discovery for instances inside your own network
- One ingest pipeline, so every source is deduplicated and scored identically
Attack surface mapping
The routes an attacker could take from an exposed asset to something that matters.
- Relationships between assets form a traversable graph
- Paths scored by hop probability multiplied by target value
- Blast radius per asset, which is the argument for segmentation
- Assets with no route from the perimeter shown separately, because working segmentation deserves credit
Exploit-aware prioritisation
A queue ordered by what is genuinely dangerous, not by CVSS alone.
- CISA KEV listing and ransomware association
- EPSS exploit probability and exploit code maturity
- Asset criticality, environment, and network exposure
- The reasoning shown beside every score, so an analyst can disagree with it
Risk register
Inherent, residual, and target positions with an owner and a treatment decision.
- 5x5 matrix with thresholds you configure
- Residual calculated from the controls actually in place
- Appetite and tolerance, so out-of-appetite risks surface on their own
- Assessment history, so you can show a risk improving
Quantified financial risk
Exposure in money, with the distribution rather than a single misleading average.
- Loss event frequency multiplied by a three-point magnitude estimate
- Ten thousand simulated years, reported as mean, median, and 95th percentile
- Itemised components: downtime, breach response, fines, legal, and churn
- Return on investment for a proposed control
Control library
What you have implemented, how well it works, and what it costs to run.
- Implementation status separate from measured effectiveness
- Control testing with results and scheduled retests
- A control that failed its last test earns no credit against risk
- Implementation and annual operating cost, for budget conversations
Remediation workflow
Named owners, deadlines from your own policy, and reporting on whether they are met.
- Tasks raised automatically from critical findings and treatment plans
- SLA deadlines derived from severity and shortened for exposed assets
- Blocked work visible rather than silently stalled
- SLA adherence measured over a trailing ninety days
Compliance reporting
Assessed positions against the frameworks your customers and regulators ask about.
- NIST CSF 2.0 with implementation tiers, all 106 subcategories
- ISO/IEC 27001:2022 Annex A, all 93 controls
- CIS Critical Security Controls v8.1
- Map a control once and satisfy every framework it touches
Evidence library
Artefacts attached where an assessor will look for them.
- SHA-256 content hash, so you can prove nothing was altered
- Explicit validity windows, because old evidence proves nothing about today
- Reusable across requirements and frameworks
- Restricted items hidden from users who should not see them
Executive reporting
One posture score, the trend behind it, and the exposure in money.
- Posture score that accounts for open exploitable exposure, not just the register
- Daily snapshots, so history stays stable when records are later edited
- Risks outside the appetite the board itself signed off
- White-labelled board reports on Enterprise
Platform
The parts that make it usable by a real organisation.
- Multi-tenant, with users able to belong to several organisations
- Eight ordered roles, with time-boxed access for external auditors
- Append-only audit trail with secret redaction
- REST API and single sign-on on higher tiers