Docs

Introduction

What CISO360AI is, how the platform is organised, and where to go next.

CISO360AI is a multi-tenant, AI-native governance, risk and compliance platform — with a built-in AI vCISO. It brings compliance automation, risk management and continuous threat exposure management (CTEM) together in one place, and ships a native Model Context Protocol (MCP) server so you can bring your own AI agent directly to your tenant.

Preview

The platform is currently offered in preview. It is provided as-is, with no warranty and no liability for preview and free-tier use. See the Terms of Service for the full posture.

What the platform does

  • AI Sidekick — your AI vCISO. Expert personas that guide, draft and derive risk from compliance gaps, with a human always in the loop.
  • Bring your own agent. A native MCP server with scope-gated writes; higher-risk actions need human approval. Available on every plan, including Free.
  • Compliance and standards. Get audit-ready across the supported standards catalogue, mapped to a common NIST CSF 2.0 spine with bidirectional control ↔ requirement mapping and cross-framework derivation.
  • Assessments and evidence. A setup wizard, coverage / maturity / gap analytics, and an evidence library with expiry reminders.
  • Risk and remediation. An AI-derived risk register with inherent and residual scoring, plus a remediation inbox that turns gaps and failed checks into tracked work.
  • Cloud and SaaS posture. Connect a tenant and validate configuration posture against the same NIST CSF spine — passing checks become evidence, failing ones become tracked actions.
  • Continuous threat exposure management. Passive, active and deep attack-surface discovery with exposure scoring and prioritisation.
  • Identity-exposure monitoring. Dark-web and leaked-credential findings for your verified domains.

How the platform is organised

Three concepts carry everything else.

ConceptWhat it is
OrganisationYour tenant. Data is isolated per organisation, and every credential is bound to one.
ProjectA scope within an organisation — its assets, assessments, risks and evidence. Every organisation has a main project, which carries the organisation's main domain.
ModuleA capability you switch on per organisation: governance and compliance, attack-surface scanning, identity-exposure scanning, and the policy starter set.

Consultancies, MSSPs and vCISOs run several projects — and share projects with third parties — with clean isolation between them.

Where things live

SurfaceAddress
Product appapp.ciso360.ai
Product site, pricing and standardsciso360.ai
These docsdocs.ciso360.ai
REST API and MCP serverapi.ciso360.ai

Next steps

On this page