Assessments with the evidence attached.
Gap analyses, DPIAs and FRIAs, conformity and authorisation. Your own agent runs them end to end, interviewing you where the method needs it. Every finding links to the provision it rests on, and the report carries a receipt a reviewer can verify.
The free run is a gap analysis or a DPIA on a system you describe, watermarked. Your own policies and evidence come with Team.
The information-security policy names supplier risk but sets no requirements for contracts, monitoring or offboarding. Article 21(2)(d) expects the measures to cover supply-chain security.
Illustrative example; the NIS2 citation is a served row
One method per question, with variants per regime.
Each family is a fixed method your agent walks through with you. Variants carry the regime-specific requirements, so a DORA gap analysis and a NIS2 gap analysis ask different questions and cite different articles.
| Family | Variants | Input | From |
|---|---|---|---|
| Gap analysis | NIS2 (EU, NL, PL), DORA and its ICT-contract and register variants, CRA, EU AI Act, MDR, IVDR, MDCG cyber, HIPAA, NIST CSF, R155, MiCA CASP, AMLR, US | A described system; your policies and evidence on Team | Free teaser · Premium · Team |
| DPIA and FRIA | GDPR DPIA with DE and SE variants, AI Act FRIA with SE variant, drone DPIA | A described processing; your documents on Team | Free teaser · Premium · Team |
| Risk and incident notification | Risk assessment, incident notification | A described system | Premium |
| Conformity and authorisation | Machinery gap, drone operator compliance, drone product conformity, SORA operational authorisation, C-UAS | A described product or operation | Premium |
The served catalogue is what your agent lists when it calls the gateway; this table follows it. Workflow directory · Threat models and TARAs moved to security risk
Interview, fetch, decide, deliver.
Scope
Your agent asks what the method needs: the system, the processing, the framework, the documents on Team.
Fetch
Every requirement is looked up in the served corpora. Nothing is asserted from memory; a missing source is marked unresolved.
Decide
Findings are stated against the provision and the evidence. On Team, a reviewer records a decision on each.
Deliver
A rendered report plus a receipt that names what it rests on. Verify it later, without asking us.
{
"receipt_id": "0000-19ac-7e21",
"workflow": "gap_analysis_nis2",
"findings": 31,
"cited_rows": 94,
"unresolved": 2,
"reviewer": "decision pending",
"artifacts": ["report.pdf", "report.json"],
"integrity": "sha256:6f0c…a19d"
}Illustrative receipt
Controls, risk and the ledger.
One spine, mapped
NIST 800-53 under CSF 2.0 with reviewed mappings to ISO 27001, C5, NIS2, DORA and CRA. Findings land on controls you already run.
Its own product now
Threat models, TARAs and CVE findings scored against the system you described. Security risk and threat intelligence
A person signs the receipt
Our team reviews a run or runs it for you, scope agreed before work starts. Expert delivery
Signed, per tenant
On Company, every run and decision is recorded in a signed ledger you can export as an audit package.
Run one assessment free.
A gap analysis or a DPIA on a system you describe. Watermarked, cited, yours.