What you get
A released assessment as a PDF and a workbook, rendered from the record exactly as it was signed.
Risk register
Every risk with its asset, threat, the safeguards it relies on, the evidence for each, likelihood, impact and a confidence rating. A safeguard you state without evidence is rated claimed, never verified.
Treatment plans
Risks grouped into plans by what fixes them, with a target level for each. A target the safeguards cannot reach is marked rather than hidden.
Known exploited vulnerabilities
Named products and versions are checked against CISA's Known Exploited Vulnerabilities catalogue, and a match is raised in the register.
Challenge and sign-off
An independent challenge stage questions the result. Every flag it raises is resolved on the record, and release needs a business owner and a security reviewer who are two different people.
The example is a fictional credit union's member lending portal: 49 risks across three assets and one connection, marked SPECIMEN on every page. All examples.
What is checked, and what is not
Checked automatically
- Release is refused while a challenge flag is open, a plan is out of date with the register, or a sign-off is missing.
- The two sign-offs must come from two different signed-in people, and the security reviewer cannot be the person who wrote the intake.
- Analysis does not start while a statement is vague, contradicted by your evidence or unsupported. What you cannot answer is listed in the report as a stated unknown.
Not checked: your responsibility
- Whether your safeguards work as described. The assessment reads your statements and evidence; it does not test your systems.
- Systems outside the scope you describe. Flows to other systems are noted and referred to their own assessment.
- Whether the remaining risk is acceptable to your organisation. That is the sign-off's decision.
Who it is for
Teams that need a threat and risk assessment for a system before it goes live, for a customer, or for an audit, without a consultancy engagement.
$699 one-time, per assessment
- Includes up to 20 assets, 3 third parties, 10 evidence documents, 20 connections and 20 assurance inputs. Larger systems cost extra credits, shown before you start.
- Above 60 assets, Professional Review applies.
Prices in US dollars, exclusive of tax. Full detail on pricing.