Skip to content
CyberArmorApplication security engineering
São Paulo, Brasil · Governance, risk and compliance

We turn the compliance spreadsheet into evidence that carries a date.

Your client answers to a regulator, and the answer has to be in a document someone signs. 93 ISO/IEC 27001:2022 controls, 47 SOC 2 criteria and 90 OWASP SAMM v2 activities come loaded in the product. Those are catalogues, not certifications — we hold neither ISO 27001 nor SOC 2, and there is no certification process open.

SARIFCYCLONEDXNESSUS XMLCSV

Three behaviours that change the number your client reads

0,75the confidence recorded when a finding is linked to a controlThe match is by keyword, so it suggests and you confirm or reject.
2separate figures on screen: what is compliant, and what was assessedMerging them is how a coverage number lies.
Validityevidence carries a date, and expired evidence stops supporting the controlContinuous evidence collection.

None of the three is a feature name. Each is a behaviour that moves a figure someone will be audited on.

In your day

The part of compliance that lives in a spreadsheet today

  • I need the framework already loaded

    ISO/IEC 27001:2022 with 93 controls, SOC 2 with 47 criteria and OWASP SAMM v2 with 90 activities come in the product. These are catalogues to work against, not certifications we hold.

  • I need each client separate, with their own history

    One record per client company, each with its own assessment history, score and reports. The questionnaire changes with the client profile, and the score is computed in code.

  • I need the report without writing it from scratch

    The executive report comes out drafted, in six fixed sections: summary, risks by impact, what is in good shape, and a 90-day plan, as a PDF. You review, correct and sign — you do not write it from zero.

Before and after

Measured against your process today, not against a competitor

Preparing evidence for an audit: from the spreadsheet to the signed report.
StepYour process todayWith the platform
Collecting evidenceBy hand, file by file, before every auditCollected from the scan and the hardening, with an expiry date
Linking a technical finding to a controlSomeone decides from memory, and the decision is not written downSuggested by keyword with the confidence recorded; you confirm or reject
Evidence past its validityStays in the spreadsheet as if it still countedStops supporting the control
Saying how compliant the client isOne percentage, mixing assessed with compliantTwo separate numbers on the screen
The final reportWritten from scratch, every timeAlready drafted; you review and sign
Limits

What we do not do

Every limit below was read in the code before it was written here, and it is in writing before the proposal, not after it.

  • Three catalogues were checked. Three others were not.

    ISO/IEC 27001:2022, SOC 2 and OWASP SAMM v2 were counted item by item. CIS, CSA and NIST CSF exist in the code with fewer items than their own documentation promises, so they are not on this page. A control map for a local data-protection law or a banking regulation has not been checked in the source — when it has, it will appear here with the number.

  • We organise and evidence. We do not certify.

    The platform does not guarantee compliance and does not "meet a requirement". The match between finding and control is by keyword, with the confidence recorded: it suggests, it does not classify. The opinion is signed by you.

  • White label does not exist

    The report carries our brand in the header and footer of every page. Changing it takes a code change and a rebuild.

  • PDF only, and no portal for your client

    No Word, no Excel. And there is no portal where the company you assess logs in to see its own risk: what it gets is the document you send.

  • The platform is not live yet

    Infrastructure is being rebuilt. There is no signup, no trial and no billing.

Next step

Tell us which framework your client is audited against and we will tell you what is loaded.

If the answer is a catalogue that has not been counted yet, we will say so in the conversation.

Talk to the engineer