Catalog

One agent, every framework.

Two ways to start an engagement — and both end the same way: a testable program of controls and tests the agent runs against your evidence.

Shipped catalogs

ITGC

IT General Controls · SOX
Live

The IT general controls that underpin a SOX audit: access management, change management, IT operations & resilience, incident & security monitoring, data protection, and third-party management.

6
domains
81
controls
258
tests
View the catalog →

Cloud Security

AWS · Azure · OCI
Live

IAM, logging, networking, data protection, and key management across AWS, Azure, and OCI — each control paired with a read-only command you can run yourself.

4
domains
145
controls
145
tests
View the catalog →

SOC 2

AICPA Trust Services Criteria
Live

The Common Criteria that appear in every SOC 2, plus Availability, Confidentiality, Processing Integrity and Privacy where you commit to them. Tests are split into suitability of design and operating effectiveness for Type II.

9
domains
61
controls
116
tests
View the catalog →

ISO 27001

ISO/IEC 27001:2022 · ISMS
Live

Management clauses 4–10 plus the four Annex A themes — organizational, people, physical, and technological controls — assessed against the evidence you upload.

5
domains
123
controls
269
tests
View the catalog →

ISO 42001

ISO/IEC 42001:2023 · AI management
Live

The AI management system standard: clauses 4–10 plus all 38 Annex A controls, from AI policy and impact assessment through the system life cycle, data provenance, and third-party responsibility.

9
domains
64
controls
143
tests
View the catalog →

MAS TRM

Monetary Authority of Singapore
Live

Technology Risk Management review for MAS-regulated institutions — governance, access, change, resilience, and the Cyber Hygiene measures.

9
domains
71
controls
71
tests
View the catalog →

DPT Platform

MAS PSA · Digital Payment Token
Live

Platform audit for MAS-regulated Digital Payment Token service providers — custody, deposit and withdrawal, and the PSA compliance obligations.

10
domains
26
controls
26
tests
View the catalog →

Roadmap

Coming next

Soon

PCI DSS — Cardholder data

The payment-card security requirements for handling cardholder data.

Join the waitlist →
Soon

NIST CSF — Govern · Identify · Protect

The cybersecurity framework core functions.

Join the waitlist →