Introduction
What CISO360AI is, how the platform is organised, and where to go next.
CISO360AI is a multi-tenant, AI-native governance, risk and compliance platform — with a built-in AI vCISO. It brings compliance automation, risk management and continuous threat exposure management (CTEM) together in one place, and ships a native Model Context Protocol (MCP) server so you can bring your own AI agent directly to your tenant.
Preview
The platform is currently offered in preview. It is provided as-is, with no warranty and no liability for preview and free-tier use. See the Terms of Service for the full posture.
What the platform does
- AI Sidekick — your AI vCISO. Expert personas that guide, draft and derive risk from compliance gaps, with a human always in the loop.
- Bring your own agent. A native MCP server with scope-gated writes; higher-risk actions need human approval. Available on every plan, including Free.
- Compliance and standards. Get audit-ready across the supported standards catalogue, mapped to a common NIST CSF 2.0 spine with bidirectional control ↔ requirement mapping and cross-framework derivation.
- Assessments and evidence. A setup wizard, coverage / maturity / gap analytics, and an evidence library with expiry reminders.
- Risk and remediation. An AI-derived risk register with inherent and residual scoring, plus a remediation inbox that turns gaps and failed checks into tracked work.
- Cloud and SaaS posture. Connect a tenant and validate configuration posture against the same NIST CSF spine — passing checks become evidence, failing ones become tracked actions.
- Continuous threat exposure management. Passive, active and deep attack-surface discovery with exposure scoring and prioritisation.
- Identity-exposure monitoring. Dark-web and leaked-credential findings for your verified domains.
How the platform is organised
Three concepts carry everything else.
| Concept | What it is |
|---|---|
| Organisation | Your tenant. Data is isolated per organisation, and every credential is bound to one. |
| Project | A scope within an organisation — its assets, assessments, risks and evidence. Every organisation has a main project, which carries the organisation's main domain. |
| Module | A capability you switch on per organisation: governance and compliance, attack-surface scanning, identity-exposure scanning, and the policy starter set. |
Consultancies, MSSPs and vCISOs run several projects — and share projects with third parties — with clean isolation between them.
Where things live
| Surface | Address |
|---|---|
| Product app | app.ciso360.ai |
| Product site, pricing and standards | ciso360.ai |
| These docs | docs.ciso360.ai |
| REST API and MCP server | api.ciso360.ai |